@@ -116,7 +116,7 @@ func TestRedact(t *testing.T) {
116116 wantReplacements : 1 ,
117117 wantByRule : map [string ]int {"aws-access-token" : 1 },
118118 mustNotContain : []string {"FAKE-AWS-KEY-NOT-A-REAL-PATTERN" },
119- mustContain : []string {"[REDACTED :aws-access-token]" , "untouched" , "run " , " now" },
119+ mustContain : []string {"[CHAINLOOP_TRACE_REDACTED :aws-access-token]" , "untouched" , "run " , " now" },
120120 },
121121 {
122122 name : "same secret across three leaves" ,
@@ -148,23 +148,23 @@ func TestRedact(t *testing.T) {
148148 findings : []Finding {{RuleID : "r1" , Secret : "nSEC" }},
149149 wantReplacements : 1 ,
150150 mustNotContain : []string {"before" , "after" },
151- mustContain : []string {"[REDACTED :r1]" },
151+ mustContain : []string {"[CHAINLOOP_TRACE_REDACTED :r1]" },
152152 },
153153 {
154154 name : "secret ending on the backslash of an escape keeps the leaf" ,
155155 doc : `{"a":"{\"url\":\"https://h/x?sig=SEC\"}"}` ,
156156 findings : []Finding {{RuleID : "r1" , Secret : `SEC\` }},
157157 wantReplacements : 1 ,
158158 wantByRule : map [string ]int {"r1" : 1 },
159- mustContain : []string {`{"a":"{\"url\":\"https://h/x?sig=[REDACTED :r1]\"}"}` },
159+ mustContain : []string {`{"a":"{\"url\":\"https://h/x?sig=[CHAINLOOP_TRACE_REDACTED :r1]\"}"}` },
160160 },
161161 {
162162 name : "secret ending on a complete escaped backslash keeps it" ,
163163 doc : `{"a":"SEC\\ after"}` ,
164164 findings : []Finding {{RuleID : "r1" , Secret : `SEC\\` }},
165165 wantReplacements : 1 ,
166166 wantByRule : map [string ]int {"r1" : 1 },
167- mustContain : []string {`{"a":"[REDACTED :r1] after"}` },
167+ mustContain : []string {`{"a":"[CHAINLOOP_TRACE_REDACTED :r1] after"}` },
168168 },
169169 {
170170 name : "protected path is left alone and recorded" ,
@@ -188,7 +188,7 @@ func TestRedact(t *testing.T) {
188188 // The copy left in the protected leaf is still found on the next
189189 // pass, where no eligible leaf holds it any more.
190190 wantUnlocated : map [string ]int {"r1" : 1 },
191- mustContain : []string {`"keepme":"SEC"` , `"other":"x [REDACTED :r1]"` },
191+ mustContain : []string {`"keepme":"SEC"` , `"other":"x [CHAINLOOP_TRACE_REDACTED :r1]"` },
192192 },
193193 {
194194 name : "finding present nowhere is classified as an artifact" ,
@@ -368,7 +368,7 @@ func TestRedactOpaqueLeaves(t *testing.T) {
368368 {
369369 name : "secret in opaque data and in text" ,
370370 doc : `{"img":{"type":"base64","data":"aaSECaa"},"t":"y SEC y"}` ,
371- want : `{"img":{"data":"aaSECaa","type":"base64"},"t":"y [REDACTED :r1] y"}` ,
371+ want : `{"img":{"data":"aaSECaa","type":"base64"},"t":"y [CHAINLOOP_TRACE_REDACTED :r1] y"}` ,
372372 },
373373 {
374374 name : "secret only in opaque data" ,
@@ -378,7 +378,7 @@ func TestRedactOpaqueLeaves(t *testing.T) {
378378 {
379379 name : "data that is not opaque is still redacted" ,
380380 doc : `{"img":{"type":"url","data":"aaSECaa"}}` ,
381- want : `{"img":{"data":"aa[REDACTED :r1]aa","type":"url"}}` ,
381+ want : `{"img":{"data":"aa[CHAINLOOP_TRACE_REDACTED :r1]aa","type":"url"}}` ,
382382 dataScanned : true ,
383383 },
384384 }
@@ -455,9 +455,9 @@ func TestRedactText(t *testing.T) {
455455 want string
456456 wantChanged bool
457457 }{
458- {name : "a secret is replaced" , text : "use " + secret + " now" , want : "use [REDACTED :test-token] now" , wantChanged : true },
458+ {name : "a secret is replaced" , text : "use " + secret + " now" , want : "use [CHAINLOOP_TRACE_REDACTED :test-token] now" , wantChanged : true },
459459 {name : "text without secrets comes back unchanged" , text : "nothing to see" , want : "nothing to see" },
460- {name : "line breaks and quotes survive" , text : "a \" quoted\" \n line " + secret , want : "a \" quoted\" \n line [REDACTED :test-token]" , wantChanged : true },
460+ {name : "line breaks and quotes survive" , text : "a \" quoted\" \n line " + secret , want : "a \" quoted\" \n line [CHAINLOOP_TRACE_REDACTED :test-token]" , wantChanged : true },
461461 }
462462
463463 for _ , tc := range testCases {
0 commit comments