test: second-pass coverage for the memorable bridge

Policy lookup outcomes (plain dir, repo without policy, corrupt .git/config
fails closed); repoPolicyTier timeoutMs; line/col at line starts, after blank
lines, CRLF and first char; tolerant first-JSON-object parsing; keyed rate
limit; uninstall never creates a config just to say off and flips consent in
a GSTACK_STATE_ROOT outside the removed state dir.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Garry Tan
2026-09-09 03:33:11 +00:00
co-authored by Claude Fable 5.1
parent abf5d96400
commit 3b4f955181
4 changed files with 126 additions and 8 deletions
+14
View File
@@ -589,6 +589,20 @@ describe("redactFindingSpans — machine-egress masking (#1947)", () => {
}
});
test("line/col at boundaries: line start, after blank lines, first char, last unterminated line", () => {
const token = "ghp_" + "1234567890abcdefghijklmnopqrstuvwxyz";
const at = (text: string) => {
const f = scan(text, { repoVisibility: "private" }).findings.find((x) => x.id === "github.pat");
expect(f).toBeDefined();
return [f!.line, f!.col];
};
expect(at(`a\nb\n${token} x`)).toEqual([3, 1]);
expect(at(`a\n\n\n ${token}`)).toEqual([4, 3]);
expect(at(token)).toEqual([1, 1]);
expect(at(`one\r\ntwo ${token}`)).toEqual([2, 5]);
expect(redactFindingSpans(`a\nb\n${token} x`, { repoVisibility: "private" })).toBe("a\nb\n<REDACTED-github.pat> x");
});
test("multiline input redacts a finding past the first line (locateSpan line/col path)", () => {
const token = "ghp_" + "1234567890abcdefghijklmnopqrstuvwxyz";
const out = redactFindingSpans(`line one\nline two has ${token}\nline three`, {