Central secret redaction service for Octopus import
Summary
- Implemented OpenSpec 6.1 on branch
codex/central-import-secret-redaction. - Added central redaction contract/helper/service and diagnostic codes in
/Users/mindy/Documents/repo/Squid/src/Squid.Core/Services/OctopusImport/OctopusImportRedaction.csand/Users/mindy/Documents/repo/Squid/src/Squid.Core/Services/OctopusImport/OctopusImportRedactionDiagnosticCodes.cs. - Migrated scattered Octopus Import diagnostic/placeholder redaction paths to the central helper, including action mapping, preview/validation, process/project/lifecycle/feed/variable mapping, runtime action validation, and session persistence.
- Hardened
OctopusImportSessionServiceso normalized payload JSON, validated plan JSON, source summaries, and terminal results are redacted before storage/return. - Added focused unit coverage for sensitive variables, feed credentials, account credentials, certificate private material, endpoint secrets, suspicious properties, diagnostics/log-like text, and session JSON persistence.
Test plan
-
dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter OctopusImport --no-restore -v:qpassed: 217/217 tests. -
git diff --checkpassed. -
Confirmed sandboxed dotnet testfails due MSBuild named-pipeSocketException (13): Permission denied; reran with escalated permissions successfully.