Files
trufflehog/pkg/detectors/stripepaymentintent/stripepaymentintent_integration_test.go
Casey Tran 47e7b7cd74
Lint / golangci-lint (push) Waiting to run
Lint / semgrep (push) Waiting to run
Scan for secrets / test (push) Waiting to run
Test / test (push) Waiting to run
Test / test-community (push) Waiting to run
Release / mark-latest (push) Canceled after 0s
Release / Release (push) Canceled after 0s
Split out detector types into separate proto file in order to narrow CODEOWNERS scope (#4871)
We want to move the detector types out of the Scanning team purview. So I split off detector types into its own proto file (so that file detector_type.proto can be owned by the Integrations team), regenerated the pb files with "make protos", and made the detector files use the new generated detector_type.pb.go. Included the new detector_type.proto file in CODEOWNERS and made CODEOWNERS categories that contain larger teams be towards the top so that more fine grained ownership is filtered properly.
2026-04-07 16:16:31 -05:00

147 lines
4.3 KiB
Go
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
//go:build detectors
// +build detectors
package stripepaymentintent
import (
"context"
"fmt"
"testing"
"time"
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detector_typepb"
)
func TestStripepaymentintent_FromChunk(t *testing.T) {
ctx, cancel := context.WithTimeout(context.Background(), time.Second*5)
defer cancel()
testSecrets, err := common.GetSecret(ctx, "trufflehog-testing", "detectors2")
if err != nil {
t.Fatalf("could not get test secrets from GCP: %s", err)
}
secret := testSecrets.MustGetField("STRIPE_SECRET")
paymentIntent := testSecrets.MustGetField("STRIPE_PAYMENT_INTENT")
secretInactive := testSecrets.MustGetField("STRIPE_INACTIVE")
type args struct {
ctx context.Context
data []byte
verify bool
}
tests := []struct {
name string
s Scanner
args args
wantVerified bool // Instead of expecting exact results, check if any result is verified
wantResultCount int // Expected number of results
wantErr bool
wantVerificationErr bool
}{
{
name: "found, verified",
s: Scanner{},
args: args{
ctx: context.Background(),
data: []byte(fmt.Sprintf("You can find a stripepaymentintent secret %s and payment intent: %s within", secret, paymentIntent)),
verify: true,
},
wantVerified: true, // At least one result should be verified
wantResultCount: 1, // 1 client secret × 1 key = 1 result
wantErr: false,
wantVerificationErr: false,
},
{
name: "found, unverified",
s: Scanner{},
args: args{
ctx: context.Background(),
data: []byte(fmt.Sprintf("You can find a stripepaymentintent secret %s and payment intent %s within but not valid", secretInactive, paymentIntent)),
verify: true,
},
wantVerified: false, // No results should be verified
wantResultCount: 1, // 1 client secret × 1 key = 1 result
wantErr: false,
wantVerificationErr: false,
},
{
name: "not found",
s: Scanner{},
args: args{
ctx: context.Background(),
data: []byte("You cannot find the secret within"),
verify: true,
},
wantVerified: false,
wantResultCount: 0, // No results expected
wantErr: false,
wantVerificationErr: false,
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
got, err := tt.s.FromData(tt.args.ctx, tt.args.verify, tt.args.data)
if (err != nil) != tt.wantErr {
t.Errorf("Stripepaymentintent.FromData() error = %v, wantErr %v", err, tt.wantErr)
return
}
// Check result count
if len(got) != tt.wantResultCount {
t.Errorf("Stripepaymentintent.FromData() got %d results, want %d", len(got), tt.wantResultCount)
return
}
// Check each result
hasVerified := false
for i := range got {
// Check that all results have the correct detector type
if got[i].DetectorType != detector_typepb.DetectorType_StripePaymentIntent {
t.Errorf("Stripepaymentintent.FromData() result %d has wrong DetectorType", i)
}
// Check that raw secret is present
if len(got[i].Raw) == 0 {
t.Fatalf("no raw secret present in result %d: \n %+v", i, got[i])
}
// Check that RawV2 is present (should contain client secret + key)
if len(got[i].RawV2) == 0 {
t.Fatalf("no rawV2 present in result %d: \n %+v", i, got[i])
}
// Check verification error expectation
if (got[i].VerificationError() != nil) != tt.wantVerificationErr {
t.Fatalf("wantVerificationError = %v, verification error = %v", tt.wantVerificationErr, got[i].VerificationError())
}
// Track if any result is verified
if got[i].Verified {
hasVerified = true
}
}
// Check verification expectation
if hasVerified != tt.wantVerified {
t.Errorf("Stripepaymentintent.FromData() hasVerified = %v, want %v", hasVerified, tt.wantVerified)
}
})
}
}
func BenchmarkFromData(benchmark *testing.B) {
ctx := context.Background()
s := Scanner{}
for name, data := range detectors.MustGetBenchmarkData() {
benchmark.Run(name, func(b *testing.B) {
b.ResetTimer()
for n := 0; n < b.N; n++ {
_, err := s.FromData(ctx, false, data)
if err != nil {
b.Fatal(err)
}
}
})
}
}