|
13 | 13 | describe '#on_complete' do
|
14 | 14 | context 'with status of 429' do
|
15 | 15 | let(:status) { 429 }
|
16 |
| - let(:response) { OpenStruct.new(headers: { 'retry-after' => 10 }) } |
| 16 | + let(:env) do |
| 17 | + env = ::Faraday::Env.from({ |
| 18 | + request_headers: { |
| 19 | + 'Authorization' => 'Bearer very-secret-token-12345' |
| 20 | + }, |
| 21 | + response_headers: { |
| 22 | + 'retry-after' => 10 |
| 23 | + }, |
| 24 | + status: status |
| 25 | + }) |
| 26 | + |
| 27 | + env[:response] = ::Faraday::Response.new(env) |
| 28 | + env |
| 29 | + end |
17 | 30 |
|
18 | 31 | it 'raises a TooManyRequestsError' do
|
19 | 32 | expect { raise_error_obj.on_complete(env) }.to(
|
20 | 33 | raise_error(Slack::Web::Api::Errors::TooManyRequestsError)
|
21 | 34 | )
|
22 | 35 | end
|
| 36 | + |
| 37 | + it 'redacts Authorization token' do |
| 38 | + error = nil |
| 39 | + begin |
| 40 | + raise_error_obj.on_complete(env) |
| 41 | + rescue Slack::Web::Api::Errors::TooManyRequestsError => e |
| 42 | + error = e |
| 43 | + end |
| 44 | + |
| 45 | + expect(error).not_to be_nil |
| 46 | + expect(error.response.env[:request_headers]['Authorization']).to eq('[REDACTED]') |
| 47 | + expect(error.inspect).not_to include('very-secret-token-12345') |
| 48 | + expect(error.inspect).to include('[REDACTED]') |
| 49 | + end |
23 | 50 | end
|
24 | 51 |
|
25 | 52 | context 'with an ok payload in the body' do
|
|
82 | 109 | )
|
83 | 110 | end
|
84 | 111 | end
|
| 112 | + |
| 113 | + context 'with SLACK_API_TOKEN in the request headers' do |
| 114 | + let(:body) do |
| 115 | + { |
| 116 | + 'ok' => false, |
| 117 | + 'error' => 'test_error' |
| 118 | + } |
| 119 | + end |
| 120 | + let(:env) do |
| 121 | + env = ::Faraday::Env.from({ |
| 122 | + response_body: body, |
| 123 | + request_headers: { |
| 124 | + 'Authorization' => 'Bearer very-secret-token-12345', |
| 125 | + 'User-Agent' => 'Test Client' |
| 126 | + }, |
| 127 | + status: status |
| 128 | + }) |
| 129 | + |
| 130 | + env[:response] = ::Faraday::Response.new(env) |
| 131 | + env |
| 132 | + end |
| 133 | + |
| 134 | + it 'redacts the Authorization header in the raised error' do |
| 135 | + error = nil |
| 136 | + begin |
| 137 | + raise_error_obj.on_complete(env) |
| 138 | + rescue Slack::Web::Api::Errors::SlackError => e |
| 139 | + error = e |
| 140 | + end |
| 141 | + |
| 142 | + expect(error).not_to be_nil |
| 143 | + expect(error.response.env[:request_headers]['Authorization']).to eq('[REDACTED]') |
| 144 | + expect(error.inspect).not_to include('very-secret-token-12345') |
| 145 | + expect(error.inspect).to include('[REDACTED]') |
| 146 | + end |
| 147 | + |
| 148 | + it 'preserves other headers' do |
| 149 | + error = nil |
| 150 | + begin |
| 151 | + raise_error_obj.on_complete(env) |
| 152 | + rescue Slack::Web::Api::Errors::SlackError => e |
| 153 | + error = e |
| 154 | + end |
| 155 | + |
| 156 | + expect(error.response.env[:request_headers]['User-Agent']).to eq('Test Client') |
| 157 | + end |
| 158 | + end |
85 | 159 | end
|
86 | 160 | end
|
0 commit comments