events: an e2e test — an emitted event reaches the audit trail over the mesh's broker #2

Merged
jschoubben merged 78 commits from events/audit-e2e into initialization 2026-09-05 01:07:06 +00:00
Showing only changes of commit 5137720aa7 - Show all commits
+9
View File
@@ -1787,6 +1787,15 @@ test("the real modules resolve together, and compose a declaration a host accept
`only ${containers.length} containers; mailu alone is nine`);
for (const c of containers) {
for (const [key, value] of Object.entries(c.env ?? {})) {
// **An absolute path is a reference to a secret, not a secret**, and naming one is the
// whole design: the mesh delivers a credential as a file and a module says where.
//
// Excluded because `/` is in the base64 alphabet, so any path of 24 characters or more
// matched — `MESH_BROKER_FILE=/var/lib/mesh/builder/broker` was reported as a credential
// the broker would see. A check that fires on the right shape for the wrong reason is
// worse than none: it is the one that gets suppressed, and then it is not there when it
// is right.
if (String(value).startsWith("/")) continue;
assert.doesNotMatch(String(value), /^[A-Za-z0-9+/]{24,}={0,2}$/,
`${c.name} carries something secret-shaped in env.${key}, which the broker would see`);
}