Unify trunk on main: initialization → main #3
@@ -1787,6 +1787,15 @@ test("the real modules resolve together, and compose a declaration a host accept
|
|||||||
`only ${containers.length} containers; mailu alone is nine`);
|
`only ${containers.length} containers; mailu alone is nine`);
|
||||||
for (const c of containers) {
|
for (const c of containers) {
|
||||||
for (const [key, value] of Object.entries(c.env ?? {})) {
|
for (const [key, value] of Object.entries(c.env ?? {})) {
|
||||||
|
// **An absolute path is a reference to a secret, not a secret**, and naming one is the
|
||||||
|
// whole design: the mesh delivers a credential as a file and a module says where.
|
||||||
|
//
|
||||||
|
// Excluded because `/` is in the base64 alphabet, so any path of 24 characters or more
|
||||||
|
// matched — `MESH_BROKER_FILE=/var/lib/mesh/builder/broker` was reported as a credential
|
||||||
|
// the broker would see. A check that fires on the right shape for the wrong reason is
|
||||||
|
// worse than none: it is the one that gets suppressed, and then it is not there when it
|
||||||
|
// is right.
|
||||||
|
if (String(value).startsWith("/")) continue;
|
||||||
assert.doesNotMatch(String(value), /^[A-Za-z0-9+/]{24,}={0,2}$/,
|
assert.doesNotMatch(String(value), /^[A-Za-z0-9+/]{24,}={0,2}$/,
|
||||||
`${c.name} carries something secret-shaped in env.${key}, which the broker would see`);
|
`${c.name} carries something secret-shaped in env.${key}, which the broker would see`);
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user