test.govlab/quality/core/quality/eslint/no-hardcoded-secrets.eslint.rule.test.ts

test.govlab/quality/core/quality/eslint/no-hardcoded-secrets.eslint.rule.test.ts is a file in Codebase Testing. 50 lines of code and 0 definitions.

import { expect, test } from "vitest";
import { RuleTester } from "eslint";
import noHardcodedSecrets from "@govlab/quality/core/quality/eslint/no-hardcoded-secrets.eslint.rule.ts";

const CREDENTIAL = ["user", "pass"].join(":");

const authorized = function authorized(userinfo: string, host: string): string {
    return [`https://${userinfo}`, host].join("@");
};

const runCases = function runCases(
    name: string,
    ruleModule: Parameters<RuleTester["run"]>[1],
    cases: Parameters<RuleTester["run"]>[2],
): number {
    const tester = new RuleTester({ languageOptions: { ecmaVersion: 2025, sourceType: "module" } });
    tester.run(name, ruleModule, cases);
    return cases.valid.length + cases.invalid.length;
};

test("no-hardcoded-secrets bounds credential detection to the URL authority", () => {
    expect(
        runCases("no-hardcoded-secrets", noHardcodedSecrets, {
            invalid: [
                {
                    code: `const dsn = "${authorized(CREDENTIAL, "internal.example.com/db")}";`,
                    errors: [{ messageId: "secretValueDetected" }],
                },
                {
                    code: `const r = "https://gw.example.com/redirect?next=${authorized(CREDENTIAL, "evil.example.com")}";`,
                    errors: [{ messageId: "secretValueDetected" }],
                },
                {
                    code: `const u = "${authorized(CREDENTIAL, "[::1]:8080/x")}";`,
                    errors: [{ messageId: "secretValueDetected" }],
                },
                {
                    code: `const u = "${authorized(":pass", "internal.host/x")}";`,
                    errors: [{ messageId: "secretValueDetected" }],
                },
            ],
            valid: [
                {
                    code: 'const href = "https://fonts.googleapis.com/css2?family=JetBrains+Mono:wght@400;500;700&display=swap";',
                },
                { code: 'const logo = "https://govlab.ai/assets/images/raw/govlab-logo.png";' },
                { code: 'const u = "https://example.com/path?a=1&sort=name:asc&owner=team@corp";' },
                { code: 'const u = "https://[::1]:8080/status";' },
                { code: 'const u = "https://user@example.com/a:b";' },
                { code: 'const u = "https://example.com:8080/redirect?next=a:b@c";' },
            ],
        }),
    ).toBeGreaterThan(0);
});