38 lines
1.3 KiB
Go
38 lines
1.3 KiB
Go
package middleware
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
func TestSanitizeAuditJSON(t *testing.T) {
|
|
input := `{"username":"operator","password":"secret-value","nested":{"newPassword":"another-secret"},"token":"jwt-value"}`
|
|
got := sanitizeAuditJSON(input)
|
|
for _, secret := range []string{"secret-value", "another-secret", "jwt-value"} {
|
|
if strings.Contains(got, secret) {
|
|
t.Fatalf("sensitive value leaked: %s", got)
|
|
}
|
|
}
|
|
if !strings.Contains(got, "operator") {
|
|
t.Fatalf("non-sensitive context was unexpectedly removed: %s", got)
|
|
}
|
|
}
|
|
|
|
func TestSanitizeAuditJSONHidesCameraCredentialFields(t *testing.T) {
|
|
value := sanitizeAuditJSON(`{"onvifUsername":"camera-user","onvifPassword":"camera-password","rtspUsername":"stream-user","rtspPassword":"stream-password","name":"东门摄像机"}`)
|
|
for _, forbidden := range []string{"camera-user", "camera-password", "stream-user", "stream-password"} {
|
|
if strings.Contains(value, forbidden) {
|
|
t.Fatalf("credential value leaked in audit JSON: %s", value)
|
|
}
|
|
}
|
|
if !strings.Contains(value, "东门摄像机") {
|
|
t.Fatalf("non-sensitive device field was unexpectedly removed: %s", value)
|
|
}
|
|
}
|
|
|
|
func TestSanitizeAuditJSONRejectsUnstructuredBodies(t *testing.T) {
|
|
if got := sanitizeAuditJSON("password=secret-value"); strings.Contains(got, "secret-value") {
|
|
t.Fatalf("unstructured body leaked: %s", got)
|
|
}
|
|
}
|