Files

38 lines
1.3 KiB
Go

package middleware
import (
"strings"
"testing"
)
func TestSanitizeAuditJSON(t *testing.T) {
input := `{"username":"operator","password":"secret-value","nested":{"newPassword":"another-secret"},"token":"jwt-value"}`
got := sanitizeAuditJSON(input)
for _, secret := range []string{"secret-value", "another-secret", "jwt-value"} {
if strings.Contains(got, secret) {
t.Fatalf("sensitive value leaked: %s", got)
}
}
if !strings.Contains(got, "operator") {
t.Fatalf("non-sensitive context was unexpectedly removed: %s", got)
}
}
func TestSanitizeAuditJSONHidesCameraCredentialFields(t *testing.T) {
value := sanitizeAuditJSON(`{"onvifUsername":"camera-user","onvifPassword":"camera-password","rtspUsername":"stream-user","rtspPassword":"stream-password","name":"东门摄像机"}`)
for _, forbidden := range []string{"camera-user", "camera-password", "stream-user", "stream-password"} {
if strings.Contains(value, forbidden) {
t.Fatalf("credential value leaked in audit JSON: %s", value)
}
}
if !strings.Contains(value, "东门摄像机") {
t.Fatalf("non-sensitive device field was unexpectedly removed: %s", value)
}
}
func TestSanitizeAuditJSONRejectsUnstructuredBodies(t *testing.T) {
if got := sanitizeAuditJSON("password=secret-value"); strings.Contains(got, "secret-value") {
t.Fatalf("unstructured body leaked: %s", got)
}
}