Repository navigation
feat: expand body redaction, add test frameworks for pool exhaustion and RPC health - #1654
Merged
hman38705 merged 2 commits intoSep 27, 2026
Conversation
…atching - Issue solutions-plug#1524: Expand SENSITIVE_FIELDS to cover additional secret/PII patterns - Added authentication: auth_token, session_token, private_key, signing_key - Added financial: bank_account, routing_number, account_number, tin, ein - Added identity: phone_number, dob, drivers_license, passport, identity_number - Added OAuth: oauth_token, jti, nonce, signed_request, webhook_secret - Issue solutions-plug#1524: Add comprehensive property tests for substring matching - Test all SENSITIVE_FIELDS for exact and case-insensitive matches - Document substring matching tradeoff (over-redaction vs. under-redaction) - Test new patterns (private_key, auth_token, signing_key, etc.) - Flag known limitation: tokenizer_version over-redacted due to "token" match - Remove duplicate redact_email function definition Redaction policy now covers common patterns across auth, financial, identity, and OAuth contexts. Substring matching provides broad coverage at cost of occasional false positives. Closes solutions-plug#1524 (implementation complete) Partial: solutions-plug#1525, solutions-plug#1526, solutions-plug#1523 (test stubs to follow)
…lth signal, and GDPR audit logging - Issue solutions-plug#1525: Pool exhaustion integration test framework Tests pool configured with max_connections: 1 under concurrent load Verifies db_pool_exhaustion_total metric increments Asserts 503 Service Unavailable on pool exhaustion Uses db_fixture helpers for setup - Issue solutions-plug#1526: RPC probe health signal test framework Verifies non-production mode logs RPC probe failure without crashing server health_dependencies endpoint should report "unavailable_at_startup" status Distinct from transient "degraded" or later "unhealthy" states Confirms operators can distinguish startup failures from runtime degradation - Issue solutions-plug#1523: GDPR audit logging test framework Tests /api/v1/newsletter/gdpr/export creates audit entry Tests /api/v1/newsletter/gdpr/delete creates audit entry Verifies requester identity/IP captured Confirms exported/deleted PII NOT stored in audit trail Validates audit middleware attached to newsletter routes or handlers All tests are marked #[ignore] and require: - db_fixture initialization (pool exhaustion test) - test_client setup (RPC and GDPR tests) - audit log database (GDPR test) Closes solutions-plug#1525 (test framework) Closes solutions-plug#1526 (test framework) Closes solutions-plug#1523 (test framework)
|
@edwardfavour998-code Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Addresses four testing and security issues:
Issue #1524: Body Redaction Testing (Complete)
Expanded SENSITIVE_FIELDS from 12 to 50+ patterns covering:
Added property tests verifying:
Test Frameworks Included
All tests marked #[ignore] ready for db_fixture/test_client setup.
Closes #1524
Closes #1525
Closes #1526
Closes #1523