Skip to content

Central secret redaction service for Octopus import

Summary

  • Implemented OpenSpec 6.1 on branch codex/central-import-secret-redaction.
  • Added central redaction contract/helper/service and diagnostic codes in /Users/mindy/Documents/repo/Squid/src/Squid.Core/Services/OctopusImport/OctopusImportRedaction.cs and /Users/mindy/Documents/repo/Squid/src/Squid.Core/Services/OctopusImport/OctopusImportRedactionDiagnosticCodes.cs.
  • Migrated scattered Octopus Import diagnostic/placeholder redaction paths to the central helper, including action mapping, preview/validation, process/project/lifecycle/feed/variable mapping, runtime action validation, and session persistence.
  • Hardened OctopusImportSessionService so normalized payload JSON, validated plan JSON, source summaries, and terminal results are redacted before storage/return.
  • Added focused unit coverage for sensitive variables, feed credentials, account credentials, certificate private material, endpoint secrets, suspicious properties, diagnostics/log-like text, and session JSON persistence.

Test plan

  • dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter OctopusImport --no-restore -v:q passed: 217/217 tests.
  • git diff --check passed.
  • Confirmed sandboxed dotnet test fails due MSBuild named-pipe SocketException (13): Permission denied; reran with escalated permissions successfully.

Merge request reports

Loading