feat(config): wrap credentials in SecretStr (audit S-4)
database_url, migration_database_url, mcp_auth_token and the mathpix app id/key are now pydantic SecretStr, so they render as '**********' in any repr/log/traceback instead of leaking the plaintext credential. Consumers (db.get_conn, cli.migrate, mcp._require_http_token, mathpix.extract_formulas) call .get_secret_value() at the point of use. Tests updated to the SecretStr type. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -12,6 +12,7 @@ from __future__ import annotations
|
||||
from unittest.mock import MagicMock, patch
|
||||
|
||||
import pytest
|
||||
from pydantic import SecretStr
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# _require_http_token
|
||||
@@ -37,7 +38,7 @@ def test_require_http_token_returns_token_when_set() -> None:
|
||||
from codex.mcp_server import _require_http_token
|
||||
|
||||
mock_settings = MagicMock()
|
||||
mock_settings.mcp_auth_token = "super-secret-token"
|
||||
mock_settings.mcp_auth_token = SecretStr("super-secret-token")
|
||||
|
||||
with patch("codex.config.get_settings", return_value=mock_settings):
|
||||
result = _require_http_token()
|
||||
@@ -97,7 +98,7 @@ def test_main_http_with_token_calls_uvicorn() -> None:
|
||||
|
||||
mock_settings = MagicMock()
|
||||
mock_settings.mcp_transport = "http"
|
||||
mock_settings.mcp_auth_token = "test-token"
|
||||
mock_settings.mcp_auth_token = SecretStr("test-token")
|
||||
mock_settings.mcp_host = "127.0.0.1"
|
||||
mock_settings.mcp_port = 8765
|
||||
|
||||
|
||||
Reference in New Issue
Block a user