trypost/tests/Unit/Services/Social/TokenRedactorTest.php
Paulo Castellano f975171a9a test(social): close coverage gaps for TokenRedactor and 429 handling
- TokenRedactorTest (7 unit tests): all four regex patterns, multiple
  secrets in one body, null input, and the no-op pass-through case.
  Guards against silent regression of the redaction regexes (which
  previously drifted across three duplicated copies).
- ConnectionVerifierTest: HTTP 429 during refresh raises
  PlatformUnavailableException, not TokenExpiredException. Locks in
  the rate-limit-as-transient behavior added when consolidating the
  refresh logic.
2026-05-19 09:34:04 -03:00

47 lines
1.6 KiB
PHP

<?php
declare(strict_types=1);
use App\Services\Social\TokenRedactor;
test('redact strips access_token in URL form', function () {
$input = 'POST https://api.example.com?access_token=abc123xyz&page=1';
expect(TokenRedactor::redact($input))->toBe('POST https://api.example.com?access_token=[REDACTED]&page=1');
});
test('redact strips access_token in JSON form', function () {
$input = '{"data":{"access_token":"abc123xyz","expires_in":3600}}';
expect(TokenRedactor::redact($input))->toBe('{"data":{"access_token":"[REDACTED]","expires_in":3600}}');
});
test('redact strips Bearer authorization header', function () {
$input = "Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.payload.sig\n";
expect(TokenRedactor::redact($input))->toBe("Authorization: Bearer [REDACTED]\n");
});
test('redact strips "token" JSON field', function () {
$input = '{"token":"shhh-secret","other":"keep"}';
expect(TokenRedactor::redact($input))->toBe('{"token":"[REDACTED]","other":"keep"}');
});
test('redact handles multiple secrets in the same body', function () {
$input = 'access_token=one&refresh_token=two with Bearer xyz';
$output = TokenRedactor::redact($input);
expect($output)->toContain('access_token=[REDACTED]')
->toContain('Bearer [REDACTED]');
});
test('redact returns null when input is null', function () {
expect(TokenRedactor::redact(null))->toBeNull();
});
test('redact returns the input unchanged when nothing matches', function () {
$input = 'plain log line with no secrets';
expect(TokenRedactor::redact($input))->toBe($input);
});