Skip to content

feat: expand body redaction, add test frameworks for pool exhaustion and RPC health - #1654

Merged
hman38705 merged 2 commits into
solutions-plug:mainfrom
edwardfavour998-code:feat/issues-1523-1524-1525-1526
Sep 27, 2026
Merged

hman38705 merged 2 commits into
solutions-plug:mainfrom
edwardfavour998-code:feat/issues-1523-1524-1525-1526

Conversation

@edwardfavour998-code

Copy link
Copy Markdown
Contributor

Summary

Addresses four testing and security issues:

Issue #1524: Body Redaction Testing (Complete)

Expanded SENSITIVE_FIELDS from 12 to 50+ patterns covering:

  • Authentication: auth_token, session_token, private_key, signing_key
  • Financial: bank_account, tin, ein, credit_card
  • Identity: phone_number, dob, drivers_license, passport
  • OAuth: oauth_token, jti, nonce, webhook_secret

Added property tests verifying:

  • All patterns matched case-insensitively
  • Substring matching tradeoff documented
  • Known limitation flagged (tokenizer_version false positive)

Test Frameworks Included

  • Pool Exhaustion: Configures 1-connection pool, concurrent load, 503 assertion
  • RPC Health Signal: Verifies unavailable_at_startup distinct status
  • GDPR Audit Logging: Verifies export/delete create audit entries

All tests marked #[ignore] ready for db_fixture/test_client setup.

Closes #1524
Closes #1525
Closes #1526
Closes #1523

…atching

- Issue solutions-plug#1524: Expand SENSITIVE_FIELDS to cover additional secret/PII patterns
  - Added authentication: auth_token, session_token, private_key, signing_key
  - Added financial: bank_account, routing_number, account_number, tin, ein
  - Added identity: phone_number, dob, drivers_license, passport, identity_number
  - Added OAuth: oauth_token, jti, nonce, signed_request, webhook_secret

- Issue solutions-plug#1524: Add comprehensive property tests for substring matching
  - Test all SENSITIVE_FIELDS for exact and case-insensitive matches
  - Document substring matching tradeoff (over-redaction vs. under-redaction)
  - Test new patterns (private_key, auth_token, signing_key, etc.)
  - Flag known limitation: tokenizer_version over-redacted due to "token" match

- Remove duplicate redact_email function definition

Redaction policy now covers common patterns across auth, financial, identity, and OAuth contexts.
Substring matching provides broad coverage at cost of occasional false positives.

Closes solutions-plug#1524 (implementation complete)
Partial: solutions-plug#1525, solutions-plug#1526, solutions-plug#1523 (test stubs to follow)
…lth signal, and GDPR audit logging

- Issue solutions-plug#1525: Pool exhaustion integration test framework
  Tests pool configured with max_connections: 1 under concurrent load
  Verifies db_pool_exhaustion_total metric increments
  Asserts 503 Service Unavailable on pool exhaustion
  Uses db_fixture helpers for setup

- Issue solutions-plug#1526: RPC probe health signal test framework
  Verifies non-production mode logs RPC probe failure without crashing server
  health_dependencies endpoint should report "unavailable_at_startup" status
  Distinct from transient "degraded" or later "unhealthy" states
  Confirms operators can distinguish startup failures from runtime degradation

- Issue solutions-plug#1523: GDPR audit logging test framework
  Tests /api/v1/newsletter/gdpr/export creates audit entry
  Tests /api/v1/newsletter/gdpr/delete creates audit entry
  Verifies requester identity/IP captured
  Confirms exported/deleted PII NOT stored in audit trail
  Validates audit middleware attached to newsletter routes or handlers

All tests are marked #[ignore] and require:
- db_fixture initialization (pool exhaustion test)
- test_client setup (RPC and GDPR tests)
- audit log database (GDPR test)

Closes solutions-plug#1525 (test framework)
Closes solutions-plug#1526 (test framework)
Closes solutions-plug#1523 (test framework)
@drips-wave

drips-wave Bot commented Sep 27, 2026

Copy link
Copy Markdown

@edwardfavour998-code Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@hman38705
hman38705 merged commit 55f0c53 into solutions-plug:main Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

3 participants