[core] Skip !secret and !lambda in legacy fallback regex

Address reviewer feedback:

- legacy regex was wrapping password: !secret name and clobbering
  the dumper's user-friendly !secret round-trip; extend the negative
  lookahead to skip !secret (and !lambda) values entirely
- drop the in-replacement !lambda check now that the lookahead handles it
- reword the thread-safety claim in dump() since _SECRET_VALUES /
  _SECRET_CACHE remain module globals
- reword the SensitiveStr representer registration comment to reflect
  PyYAML's MRO-walked dispatch rather than registration order
- tighten the legacy regex comment

Adds tests for the !secret and !lambda skip paths.
This commit is contained in:
J. Nick Koston
2026-05-26 22:23:40 -05:00
parent 6d689e8297
commit bc2a811568
3 changed files with 30 additions and 32 deletions
+16 -6
View File
@@ -388,17 +388,27 @@ def test_redact_with_legacy_fallback__deduplicates_warnings(
assert len(password_warnings) == 1
def test_redact_with_legacy_fallback__suppresses_warning_for_lambda(
def test_redact_with_legacy_fallback__skips_lambda_values(
caplog: pytest.LogCaptureFixture,
) -> None:
"""Lambda values in cv.sensitive(cv.templatable(...)) fields hit the
legacy regex (Lambda isn't str so SensitiveStr tagging doesn't apply),
but the field IS tagged. The warning would mislead the author, so it's
suppressed; the first line still gets wrapped for visual parity."""
"""``!lambda`` first line is structural, body is unreachable by a
single-line regex anyway, and tagged fields shouldn't trigger a warning."""
text = ' ssid: !lambda |-\n return "x";\n'
with caplog.at_level(logging.WARNING, logger="esphome.__main__"):
out = _redact_with_legacy_fallback(text)
assert "ssid: \\033[8m!lambda |-\\033[28m" in out
assert out == text
assert not any("legacy substring" in rec.message for rec in caplog.records)
def test_redact_with_legacy_fallback__skips_secret_references(
caplog: pytest.LogCaptureFixture,
) -> None:
"""``!secret name`` is the dumper's user-friendly representation; the
name isn't the secret, so wrapping it would clobber the round-trip."""
text = " password: !secret wifi_password\n"
with caplog.at_level(logging.WARNING, logger="esphome.__main__"):
out = _redact_with_legacy_fallback(text)
assert out == text
assert not any("legacy substring" in rec.message for rec in caplog.records)