feat(config): wrap credentials in SecretStr (audit S-4)
database_url, migration_database_url, mcp_auth_token and the mathpix app id/key are now pydantic SecretStr, so they render as '**********' in any repr/log/traceback instead of leaking the plaintext credential. Consumers (db.get_conn, cli.migrate, mcp._require_http_token, mathpix.extract_formulas) call .get_secret_value() at the point of use. Tests updated to the SecretStr type. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -8,7 +8,10 @@ from codex.config import Settings, get_settings
|
||||
def test_settings_defaults() -> None:
|
||||
"""Settings() is constructable without env vars; expected defaults are set."""
|
||||
s = Settings()
|
||||
assert s.database_url == "postgresql://researcher:change_me@localhost:5432/papers"
|
||||
assert (
|
||||
s.database_url.get_secret_value()
|
||||
== "postgresql://researcher:change_me@localhost:5432/papers"
|
||||
)
|
||||
assert s.embedding_model == "BAAI/bge-m3"
|
||||
assert s.embedding_dim == 1024
|
||||
|
||||
@@ -20,7 +23,7 @@ def test_settings_env_override(monkeypatch: object) -> None:
|
||||
mp: pytest.MonkeyPatch = monkeypatch # type: ignore[assignment]
|
||||
mp.setenv("DATABASE_URL", "postgresql://x:y@h:5432/db")
|
||||
s = Settings()
|
||||
assert s.database_url == "postgresql://x:y@h:5432/db"
|
||||
assert s.database_url.get_secret_value() == "postgresql://x:y@h:5432/db"
|
||||
|
||||
|
||||
def test_get_settings_is_singleton() -> None:
|
||||
|
||||
Reference in New Issue
Block a user