Unify trunk on main: initialization → main #3
@@ -1787,6 +1787,15 @@ test("the real modules resolve together, and compose a declaration a host accept
|
||||
`only ${containers.length} containers; mailu alone is nine`);
|
||||
for (const c of containers) {
|
||||
for (const [key, value] of Object.entries(c.env ?? {})) {
|
||||
// **An absolute path is a reference to a secret, not a secret**, and naming one is the
|
||||
// whole design: the mesh delivers a credential as a file and a module says where.
|
||||
//
|
||||
// Excluded because `/` is in the base64 alphabet, so any path of 24 characters or more
|
||||
// matched — `MESH_BROKER_FILE=/var/lib/mesh/builder/broker` was reported as a credential
|
||||
// the broker would see. A check that fires on the right shape for the wrong reason is
|
||||
// worse than none: it is the one that gets suppressed, and then it is not there when it
|
||||
// is right.
|
||||
if (String(value).startsWith("/")) continue;
|
||||
assert.doesNotMatch(String(value), /^[A-Za-z0-9+/]{24,}={0,2}$/,
|
||||
`${c.name} carries something secret-shaped in env.${key}, which the broker would see`);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user