Files
keepalive/service_name_test.go
tiennm99 47afb85093 fix: close remaining secret leaks, timeout gaps and config blind spots
- Generated service names come only from a URL host, a key=value DSN's
  host=, or a MySQL tcp() address, so a password in a key=value DSN can no
  longer end up in the name printed on every log line.
- connect_timeout is added only to postgres:// and postgresql:// URLs
  (parsed, so it never lands after a fragment) or as a key=value token, never
  glued onto a key=value value containing "://".
- Driver parse errors that quote password fragments (mongo escape errors,
  lib/pq's missing "=" error) are replaced with generic hints.
- MongoDB keeps its client only after a successful connect, so a failed
  connect is not disconnected twice.
- Couchbase gets ready_timeout plus 1 minute to connect, so raising
  ready_timeout takes effect.
- Shutdown waits at most 7 seconds, inside Docker's 10-second grace period.
- Each adapter declares its config keys; unknown keys anywhere in the file,
  including under config, log a warning without blocking start.
2026-10-09 12:36:21 +07:00

24 lines
786 B
Go

package main
import (
"strings"
"testing"
)
func TestHostFromEndpointNeverLeaksDSNSecrets(t *testing.T) {
for _, tc := range []struct{ in, want string }{
{"postgres://u:p@db.example.com:5432/k", "db.example.com"},
{"host=db.example.com user=u password=SeCrEt:x dbname=k", "db.example.com"},
{"host='db.example.com,db2.example.com' password=SeCrEt:x", "db.example.com"},
{"user=u password=SeCrEt:x dbname=k", ""},
{"postgres://u:SeCrEt%zz@db.example.com:5432/k", ""},
{"u:SeCrEt@tcp(db.example.com:3306)/k", "db.example.com"},
{"cache.example.com:6379", "cache.example.com"},
} {
got := hostFromEndpoint(tc.in)
if got != tc.want || strings.Contains(strings.ToLower(got), "secret") {
t.Errorf("hostFromEndpoint(%q) = %q, want %q", tc.in, got, tc.want)
}
}
}