Files
wehub-resource-sync 426e9eeabd
Voice Workbench / headless workbench (mocked backends) (push) Has been cancelled
Voice Workbench / real acoustic lane (nightly, provisioned only) (push) Has been cancelled
ci / test (push) Has been cancelled
ci / lint-and-format (push) Has been cancelled
ci / build (push) Has been cancelled
ci / dev-startup (push) Has been cancelled
gitleaks / gitleaks (push) Has been cancelled
Markdown Links / Relative Markdown Links (push) Has been cancelled
Quality (Extended) / Homepage Build (PR smoke) (push) Has been cancelled
Quality (Extended) / Comment-only diff guard (push) Has been cancelled
Quality (Extended) / Format + Type Safety Ratchet (push) Has been cancelled
Quality (Extended) / Develop Gate (secret scan + UI determinism) (push) Has been cancelled
Quality (Extended) / Develop Gate (lint) (push) Has been cancelled
Chat shell gestures / Chat shell gesture + parity e2e (push) Has been cancelled
Cloud Gateway Discord / Test (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx @biomejs/biome check packages/lifeops-bench/src, benchmark-lint) (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx vitest run --config packages/lifeops-bench/vitest.config.ts --root packages/lifeops-bench --passWithNoTests, benchmark-tests) (push) Has been cancelled
Build Agent Image / build-and-push (push) Has been cancelled
Dev Smoke / bun run dev onboarding chat (push) Has been cancelled
Dev Smoke / Vite HMR dependency-level smoke (push) Has been cancelled
Electrobun Submodule Guard / electrobun gitlink is fetchable (push) Has been cancelled
Publish @elizaos/example-code / check_npm (push) Has been cancelled
Publish @elizaos/example-code / publish_npm (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / verify_version (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / publish_npm (push) Has been cancelled
Sandbox Live Smoke / Sandbox live smoke (push) Has been cancelled
Snap Build & Test / Build Snap (amd64) (push) Has been cancelled
Snap Build & Test / Build Snap (arm64) (push) Has been cancelled
Test Packaging / elizaos CLI global-install smoke (node + bun) (push) Has been cancelled
Cloud Gateway Webhook / Test (push) Has been cancelled
Cloud Tests / lint-and-types (push) Has been cancelled
Cloud Tests / unit-tests (push) Has been cancelled
Cloud Tests / integration-tests (push) Has been cancelled
Cloud Tests / e2e-tests (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Deploy Apps Worker (Product 2) / Determine environment (push) Has been cancelled
Deploy Apps Worker (Product 2) / Deploy apps worker to apps-control host (${{ needs.determine-env.outputs.environment }}) (push) Has been cancelled
Deploy Eliza Provisioning Worker / Determine environment (push) Has been cancelled
Deploy Eliza Provisioning Worker / Deploy worker to Hetzner host (${{ needs.determine-env.outputs.environment }} @ ${{ needs.determine-env.outputs.deployment_sha }}) (push) Has been cancelled
Dev Smoke / Classify changed paths (push) Has been cancelled
supply-chain / sbom (push) Has been cancelled
supply-chain / vulnerability-scan (push) Has been cancelled
Build, Push & Deploy to Phala Cloud / build-and-push (push) Has been cancelled
Test Packaging / Validate Packaging Configs (push) Has been cancelled
Test Packaging / Build & Test PyPI Package (push) Has been cancelled
Test Packaging / PyPI on Python ${{ matrix.python }} (push) Has been cancelled
Test Packaging / Pack & Test JS Tarballs (push) Has been cancelled
UI Fixture E2E / ui-fixture-e2e (push) Has been cancelled
UI Fixture E2E / fixture-e2e (push) Has been cancelled
UI Story Gate / story-gate (push) Has been cancelled
vault-ci / test (macos-latest) (push) Has been cancelled
vault-ci / test (ubuntu-latest) (push) Has been cancelled
vault-ci / test (windows-latest) (push) Has been cancelled
vault-ci / app-core wiring tests (push) Has been cancelled
verify-patches / verify patches/CHECKSUMS.sha256 (push) Has been cancelled
Voice Benchmark Smoke / voice-emotion fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voiceagentbench fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench-quality unit smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench TypeScript unit (no audio) (push) Has been cancelled
Voice Benchmark Smoke / voice bench smoke summary (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/app-core test bun run --cwd packages/elizaos test bun run --cwd packages/cloud/shared test], app-and-cli) (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/scenario-runner test bun run --cwd packages/vault test bun run --cwd packages/security test bun run --cwd plugins/plugin-coding-tools test], framework-packages) (push) Has been cancelled
Windows CI / windows ([bun run --cwd plugins/plugin-elizacloud test bun run --cwd plugins/plugin-discord test bun run --cwd plugins/plugin-anthropic test bun run --cwd plugins/plugin-openai test bun run --cwd plugins/plugin-app-control test bun run --cwd plugins/pl… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run build --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/agent --concurrency=4 node packages/scripts/run-bash-linux-only.mjs scripts/verify-riscv64-buildpaths.sh node packages/scripts/run… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run typecheck --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/cloud-shared --concurrency=4 bun run --cwd packages/core test bun run --cwd packages/shared test], core-runtime, 75) (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:43:05 +08:00

110 lines
3.7 KiB
TypeScript

// Exercises LifeOps owner workflows, connector boundaries, and scheduled-task behavior.
import { describe, expect, it } from "vitest";
import { redactSensitiveData } from "../src/lifeops/redact-sensitive-data.js";
/**
* `redactSensitiveData` sanitizes values before they reach audit events / logs.
* Getting it wrong leaks credentials or PII into a log line, so the key-matching
* (exact + substring), email scrubbing, truncation, recursion, and
* non-mutation all need coverage.
*/
describe("redactSensitiveData", () => {
it("fully redacts credential keys (exact + substring, case-insensitive)", () => {
expect(redactSensitiveData({ password: "hunter2" })).toEqual({
password: "[REDACTED]",
});
expect(redactSensitiveData({ token: "abc" }).token).toBe("[REDACTED]");
expect(
redactSensitiveData({ Authorization: "Bearer x" }).Authorization,
).toBe("[REDACTED]");
// substring matches
expect(redactSensitiveData({ accessToken: "x" }).accessToken).toBe(
"[REDACTED]",
);
expect(redactSensitiveData({ userPassword: "x" }).userPassword).toBe(
"[REDACTED]",
);
expect(redactSensitiveData({ clientSecret: "x" }).clientSecret).toBe(
"[REDACTED]",
);
});
it("redacts email-recipient keys entirely", () => {
const out = redactSensitiveData({
to: "a@b.com",
from: "c@d.com",
email: "e@f.com",
cc: "g@h.com",
});
expect(out).toEqual({
to: "[REDACTED]",
from: "[REDACTED]",
email: "[REDACTED]",
cc: "[REDACTED]",
});
});
it("scrubs email addresses out of otherwise-plain strings", () => {
expect(
redactSensitiveData({ note: "ping me at alice@example.com today" }).note,
).toBe("ping me at [REDACTED_EMAIL] today");
});
it("truncates subject and body after redaction", () => {
const subject = redactSensitiveData({
subject: "Re: a very very long subject line indeed",
}).subject as string;
expect(subject.endsWith("…")).toBe(true);
expect(subject.length).toBeLessThanOrEqual(21);
const body = redactSensitiveData({
body: "x".repeat(200),
}).body as string;
expect(body).toContain("[+");
expect(body).toContain("chars]");
expect(body.length).toBeLessThan(200);
});
it("honors custom subject/body preview lengths", () => {
const out = redactSensitiveData(
{ subject: "abcdefghij", body: "0123456789" },
{ subjectPreview: 3, bodyPreview: 4 },
);
expect(out.subject).toBe("abc…");
expect(out.body).toBe("0123… [+6 chars]");
});
it("recurses into nested objects and arrays", () => {
const out = redactSensitiveData({
user: { name: "Bob", email: "bob@x.com", password: "p" },
toList: ["a@b.com", "c@d.com"],
meta: { count: 3, ok: true },
});
expect(out).toEqual({
user: { name: "Bob", email: "[REDACTED]", password: "[REDACTED]" },
toList: ["[REDACTED]", "[REDACTED]"],
meta: { count: 3, ok: true },
});
});
it("guards against circular references", () => {
const obj: Record<string, unknown> = { name: "x" };
obj.self = obj;
const out = redactSensitiveData(obj) as Record<string, unknown>;
expect(out.name).toBe("x");
expect(out.self).toBe("[Circular]");
});
it("is non-mutating and passes primitives through", () => {
const input = { password: "secret", count: 1, flag: false, nil: null };
const out = redactSensitiveData(input);
expect(input.password).toBe("secret"); // original intact
expect(out.count).toBe(1);
expect(out.flag).toBe(false);
expect(out.nil).toBeNull();
expect(redactSensitiveData(42)).toBe(42);
expect(redactSensitiveData("plain text")).toBe("plain text");
});
});