mirror of
https://github.com/esphome/esphome.git
synced 2026-10-05 02:21:30 +00:00
[store_yaml] Swap secrets in wrapper representers, EsphomeError on cross-anchor paths, branched warning
This commit is contained in:
@@ -615,3 +615,28 @@ def test_redacted_outside_root_secrets_gets_root_skeleton(
|
||||
assert "secrets.yaml" in files
|
||||
assert 'api_key: ""' in files["secrets.yaml"].decode()
|
||||
assert b"SUPER_SECRET" not in b"".join(files.values())
|
||||
|
||||
|
||||
def test_gather_raises_esphome_error_on_cross_anchor_path(
|
||||
project: Path, monkeypatch: pytest.MonkeyPatch
|
||||
) -> None:
|
||||
"""A file that cannot be made relative to the config root (a Windows
|
||||
cross-drive path) surfaces as EsphomeError, not a raw ValueError."""
|
||||
|
||||
def fake_relative_to(self: Path, other: Path, walk_up: bool = False) -> Path:
|
||||
raise ValueError("paths have different anchors")
|
||||
|
||||
monkeypatch.setattr(Path, "relative_to", fake_relative_to)
|
||||
discovered = _sources(project, "entry.yaml")
|
||||
with pytest.raises(EsphomeError, match="does not share a root"):
|
||||
_gather_files(discovered)
|
||||
|
||||
|
||||
def test_final_validate_unencrypted_with_secrets_names_secrets_yaml(
|
||||
caplog: pytest.LogCaptureFixture,
|
||||
) -> None:
|
||||
"""allow_unencrypted combined with include_secrets warns about the
|
||||
verbatim secrets.yaml specifically."""
|
||||
config = {CONF_ALLOW_UNENCRYPTED: True, "include_secrets": True}
|
||||
assert _run_final_validate({"api": {}}, config) is config
|
||||
assert "verbatim contents of secrets.yaml" in caplog.text
|
||||
|
||||
@@ -1557,3 +1557,21 @@ def test_merge_include_no_overlap_records_nothing(tmp_path: Path) -> None:
|
||||
assert result["api"] == {"reboot_timeout": "5min"}
|
||||
assert result["logger"] == {"level": "DEBUG"}
|
||||
assert yaml_util.take_dropped_merge_keys() == []
|
||||
|
||||
|
||||
def test_wrapper_representers_consult_is_secret() -> None:
|
||||
"""!extend / !remove payloads and scalar !include paths equal to a
|
||||
registered secret are swapped, never written in cleartext."""
|
||||
from esphome.config_helpers import Extend, Remove
|
||||
|
||||
with yaml_util.secret_values_registered({"hunter2": "the_secret"}):
|
||||
out = yaml_util.dump(
|
||||
{
|
||||
"a": Extend("hunter2"),
|
||||
"b": Remove("hunter2"),
|
||||
"c": Extend("plain_id"),
|
||||
}
|
||||
)
|
||||
assert out.count("!secret 'the_secret'") == 2
|
||||
assert "hunter2" not in out
|
||||
assert "!extend 'plain_id'" in out
|
||||
|
||||
Reference in New Issue
Block a user