Skip to content

Commit f3c995a

Browse files
committed
test(mcp): use live-shaped token in structured redaction test
The criterion-4 test fed the redaction marker itself, asserting both P and not-P. Feed a constructed live-shaped token and assert the marker is present with the raw token absent in content and detail.
1 parent 24d2c57 commit f3c995a

1 file changed

Lines changed: 9 additions & 4 deletions

File tree

‎src/mcp/plugin.test.ts‎

Lines changed: 9 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -273,18 +273,23 @@ describe("mcpClientToAgentTools", () => {
273273
});
274274

275275
test("credential-shaped values inside structured content are redacted", async () => {
276-
const secret = "sk-live-abcdefghij1234567890";
276+
const rawToken = ["sk-", "live-", "k".repeat(24)].join("");
277277
const result = await runEnvelopeTool(
278278
{
279279
blocks: [],
280-
structuredContent: { token: secret },
280+
structuredContent: { token: rawToken },
281281
},
282282
"c-mcp-structured-secret",
283283
);
284284

285+
expect(result.detail).toEqual({ token: CREDENTIAL_REDACTION });
285286
expect(result.content).toContain(CREDENTIAL_REDACTION);
286-
expect(result.content).not.toContain(secret);
287-
expect(JSON.stringify(result.detail)).not.toContain(secret);
287+
expect(result.content).not.toContain(rawToken);
288+
expect(result.content).not.toContain("sk-live-");
289+
const detailJson = JSON.stringify(result.detail);
290+
expect(detailJson).toContain(CREDENTIAL_REDACTION);
291+
expect(detailJson).not.toContain(rawToken);
292+
expect(detailJson).not.toContain("sk-live-");
288293
});
289294

290295
test("thrown transport failures still surface as error results", async () => {

0 commit comments

Comments
 (0)