mirror of
https://github.com/tiennm99/keepalive.git
synced 2026-10-11 03:13:31 +00:00
- Generated service names come only from a URL host, a key=value DSN's host=, or a MySQL tcp() address, so a password in a key=value DSN can no longer end up in the name printed on every log line. - connect_timeout is added only to postgres:// and postgresql:// URLs (parsed, so it never lands after a fragment) or as a key=value token, never glued onto a key=value value containing "://". - Driver parse errors that quote password fragments (mongo escape errors, lib/pq's missing "=" error) are replaced with generic hints. - MongoDB keeps its client only after a successful connect, so a failed connect is not disconnected twice. - Couchbase gets ready_timeout plus 1 minute to connect, so raising ready_timeout takes effect. - Shutdown waits at most 7 seconds, inside Docker's 10-second grace period. - Each adapter declares its config keys; unknown keys anywhere in the file, including under config, log a warning without blocking start.
24 lines
786 B
Go
24 lines
786 B
Go
package main
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
func TestHostFromEndpointNeverLeaksDSNSecrets(t *testing.T) {
|
|
for _, tc := range []struct{ in, want string }{
|
|
{"postgres://u:p@db.example.com:5432/k", "db.example.com"},
|
|
{"host=db.example.com user=u password=SeCrEt:x dbname=k", "db.example.com"},
|
|
{"host='db.example.com,db2.example.com' password=SeCrEt:x", "db.example.com"},
|
|
{"user=u password=SeCrEt:x dbname=k", ""},
|
|
{"postgres://u:SeCrEt%zz@db.example.com:5432/k", ""},
|
|
{"u:SeCrEt@tcp(db.example.com:3306)/k", "db.example.com"},
|
|
{"cache.example.com:6379", "cache.example.com"},
|
|
} {
|
|
got := hostFromEndpoint(tc.in)
|
|
if got != tc.want || strings.Contains(strings.ToLower(got), "secret") {
|
|
t.Errorf("hostFromEndpoint(%q) = %q, want %q", tc.in, got, tc.want)
|
|
}
|
|
}
|
|
}
|