package middleware import ( "strings" "testing" ) func TestSanitizeAuditJSON(t *testing.T) { input := `{"username":"operator","password":"secret-value","nested":{"newPassword":"another-secret"},"token":"jwt-value"}` got := sanitizeAuditJSON(input) for _, secret := range []string{"secret-value", "another-secret", "jwt-value"} { if strings.Contains(got, secret) { t.Fatalf("sensitive value leaked: %s", got) } } if !strings.Contains(got, "operator") { t.Fatalf("non-sensitive context was unexpectedly removed: %s", got) } } func TestSanitizeAuditJSONHidesCameraCredentialFields(t *testing.T) { value := sanitizeAuditJSON(`{"onvifUsername":"camera-user","onvifPassword":"camera-password","rtspUsername":"stream-user","rtspPassword":"stream-password","name":"东门摄像机"}`) for _, forbidden := range []string{"camera-user", "camera-password", "stream-user", "stream-password"} { if strings.Contains(value, forbidden) { t.Fatalf("credential value leaked in audit JSON: %s", value) } } if !strings.Contains(value, "东门摄像机") { t.Fatalf("non-sensitive device field was unexpectedly removed: %s", value) } } func TestSanitizeAuditJSONRejectsUnstructuredBodies(t *testing.T) { if got := sanitizeAuditJSON("password=secret-value"); strings.Contains(got, "secret-value") { t.Fatalf("unstructured body leaked: %s", got) } }