Build latest book artifacts / build (push) Canceled after 0s
dependency resolution / resolve (3.11) (push) Canceled after 0s
dependency resolution / resolve (3.13) (push) Canceled after 0s
deploy-pages / build (push) Canceled after 0s
deploy-pages / deploy (push) Canceled after 0s
i18n consistency check / check (push) Canceled after 0s
provider adoption tests / test (chapter2/context-compression) (push) Canceled after 0s
provider adoption tests / test (chapter2/prompt-injection) (push) Canceled after 0s
provider adoption tests / test (chapter2/system-hint) (push) Canceled after 0s
provider adoption tests / test (chapter3/log-sanitization) (push) Canceled after 0s
web-search-agent tests / test (push) Canceled after 0s
web-search-agent tests / agentbook (push) Canceled after 0s
19 lines
650 B
Python
19 lines
650 B
Python
"""Regression: fine-grained github_pat_* tokens must be redacted."""
|
|
from regex_sanitizer import sanitize
|
|
|
|
|
|
def test_github_pat_fine_grained_redacted():
|
|
token = "github_pat_" + "A" * 20 + "_" + "B" * 40
|
|
text, hits = sanitize(f"Authorization: {token}")
|
|
assert token not in text
|
|
assert "[REDACTED_GITHUB_TOKEN]" in text
|
|
assert any(h["category"] == "github_token" for h in hits)
|
|
|
|
|
|
def test_classic_github_token_still_redacted():
|
|
token = "gh" + "p_" + "x" * 36
|
|
text, hits = sanitize(token)
|
|
assert token not in text
|
|
assert "[REDACTED_GITHUB_TOKEN]" in text
|
|
assert any(h["category"] == "github_token" for h in hits)
|