diff --git a/.gitignore b/.gitignore index 8b0f26a..bc7a78b 100644 --- a/.gitignore +++ b/.gitignore @@ -18,4 +18,14 @@ terraform/bootstrap/.bootstrap_state.json **/.terraform/ **/.terraform.lock.hcl **/tfplan -**/*.tfstate* \ No newline at end of file +**/*.tfstate* + +# Credential patterns (v1.14, REQ-146) +*.pem +*.key +*.p12 +*.pfx +*.cer +*.crt +*.jks +*.keystore \ No newline at end of file diff --git a/tests/test_no_secrets_tracked.py b/tests/test_no_secrets_tracked.py new file mode 100644 index 0000000..56f575e --- /dev/null +++ b/tests/test_no_secrets_tracked.py @@ -0,0 +1,35 @@ +"""v1.14 (REQ-146): no credential-looking files are tracked by git.""" +import subprocess +import sys +from pathlib import Path + +import pytest + +ROOT = Path(__file__).resolve().parent.parent + +CREDENTIAL_EXTENSIONS = [".pem", ".key", ".p12", ".pfx", ".cer", ".crt", ".jks", ".keystore"] + + +def test_no_credential_files_tracked(): + """Assert no file with a credential extension is tracked by git.""" + result = subprocess.run( + ["git", "ls-files"], + cwd=str(ROOT), + capture_output=True, + text=True, + ) + if result.returncode != 0: + pytest.skip("git not available or not a repo") + tracked = result.stdout.strip().split("\n") + cred_files = [ + f for f in tracked + if any(f.endswith(ext) for ext in CREDENTIAL_EXTENSIONS) + ] + assert cred_files == [], f"credential files tracked by git: {cred_files}" + + +def test_gitignore_has_credential_patterns(): + """Assert .gitignore contains the credential-pattern catch-all.""" + gitignore = (ROOT / ".gitignore").read_text() + for ext in [".pem", ".key", ".p12", ".pfx"]: + assert f"*{ext}" in gitignore, f".gitignore missing credential pattern *{ext}" \ No newline at end of file