internal/notify/redact_test.go

3f4afd2210627e46fd0cea1f5831857af71638f6
gitbay/internal/notify/redact_test.go history · blame · raw

39 lines · 1428 bytes

 1package notify
 2
 3import "testing"
 4
 5// The log names the queue row, not the person. A relay's rejection quotes
 6// the address it rejected, so the error text is redacted too — otherwise
 7// dropping the recipient field would move the leak rather than close it
 8// (#173).
 9func TestRedactAddresses(t *testing.T) {
10	cases := []struct{ in, want string }{
11		{"550 5.1.1 <alice@example.test>: Recipient address rejected",
12			"550 5.1.1 <<address>>: Recipient address rejected"},
13		{"dial tcp 10.0.0.1:587: connect: connection refused",
14			"dial tcp 10.0.0.1:587: connect: connection refused"},
15		{"554 alice@a.test, bob@b.test both unknown",
16			"554 <address>, <address> both unknown"},
17		{"x509: certificate signed by unknown authority", "x509: certificate signed by unknown authority"},
18	}
19	for _, c := range cases {
20		if got := redactAddresses(c.in); got != c.want {
21			t.Errorf("redactAddresses(%q) = %q, want %q", c.in, got, c.want)
22		}
23	}
24}
25
26// Whatever the relay says, no @ survives into the log line.
27func TestRedactLeavesNoAddress(t *testing.T) {
28	for _, s := range []string{
29		"550 <a.b+tag@sub.example.co.uk> over quota",
30		`smtp: 553 "weird name"@host.test refused`,
31		"relay said: alice@example.test; bob@example.test",
32	} {
33		if got := redactAddresses(s); containsAddress(got) {
34			t.Errorf("address survived redaction: %q -> %q", s, got)
35		}
36	}
37}
38
39func containsAddress(s string) bool { return addressPat.MatchString(s) }