internal/notify/redact_test.go
39 lines · 1428 bytes
3 symbols in this file
1package notify
2
3import "testing"
4
5// The log names the queue row, not the person. A relay's rejection quotes
6// the address it rejected, so the error text is redacted too — otherwise
7// dropping the recipient field would move the leak rather than close it
8// (#173).
9func TestRedactAddresses(t *testing.T) {
10 cases := []struct{ in, want string }{
11 {"550 5.1.1 <alice@example.test>: Recipient address rejected",
12 "550 5.1.1 <<address>>: Recipient address rejected"},
13 {"dial tcp 10.0.0.1:587: connect: connection refused",
14 "dial tcp 10.0.0.1:587: connect: connection refused"},
15 {"554 alice@a.test, bob@b.test both unknown",
16 "554 <address>, <address> both unknown"},
17 {"x509: certificate signed by unknown authority", "x509: certificate signed by unknown authority"},
18 }
19 for _, c := range cases {
20 if got := redactAddresses(c.in); got != c.want {
21 t.Errorf("redactAddresses(%q) = %q, want %q", c.in, got, c.want)
22 }
23 }
24}
25
26// Whatever the relay says, no @ survives into the log line.
27func TestRedactLeavesNoAddress(t *testing.T) {
28 for _, s := range []string{
29 "550 <a.b+tag@sub.example.co.uk> over quota",
30 `smtp: 553 "weird name"@host.test refused`,
31 "relay said: alice@example.test; bob@example.test",
32 } {
33 if got := redactAddresses(s); containsAddress(got) {
34 t.Errorf("address survived redaction: %q -> %q", s, got)
35 }
36 }
37}
38
39func containsAddress(s string) bool { return addressPat.MatchString(s) }