Skip to content

Commit a7b5d28

Browse files
committed
test(secret-guard): add CL-8999 ordering keepers for glob and device-path legs
1 parent 5509622 commit a7b5d28

1 file changed

Lines changed: 29 additions & 0 deletions

File tree

‎src/plugins/secret-guard-plugin.test.ts‎

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -443,6 +443,35 @@ describe("commandReferencesSensitivePath shell-variable expansion (CL-8999)", ()
443443
}
444444
});
445445

446+
describe("secret-guard ordering keepers (CL-8999)", () => {
447+
// H1: the pure-listing leg precedes the `?`/`[` glob check — moving the
448+
// glob check earlier would prompt on a listing that never dumps contents.
449+
test("pure listing with ?/[...] globs still lists freely", () => {
450+
expect(commandReferencesSensitivePath("ls .en?")).toBeUndefined();
451+
expect(commandReferencesSensitivePath("ls .en[v]")).toBeUndefined();
452+
});
453+
454+
// H3: the cmd device-path exemption precedes the `?` check — the `?` in
455+
// `\\?\…` must not fail closed to a prompt.
456+
test("cmd device-path names keep working", () => {
457+
expect(
458+
isSensitiveShellToken(
459+
String.raw`\\?\C:\repo\notes.txt`,
460+
process.cwd(),
461+
true,
462+
() => false,
463+
"cmd",
464+
),
465+
).toBe(false);
466+
});
467+
468+
// H7: a piped ls loses the listing exemption and takes the resolve leg,
469+
// so the glob check fires and prompts.
470+
test("piped listing with a ? glob prompts", () => {
471+
expect(commandReferencesSensitivePath("ls .en? | cat")).toBeDefined();
472+
});
473+
});
474+
446475
describe("secretGuardPlugin run_shell", () => {
447476
// Shell commands that mention a secret path are no longer hard-denied here —
448477
// they require operator approval at the permission gate. The plugin only

0 commit comments

Comments
 (0)