Skip to content

Hardened cleanup logging and secret-leak regression coverage

Summary

  • Hardened OctopusImportTemporaryUploadCleanupService so cleanup failures are logged and persisted with sanitized error text instead of raw exception text, removing a structured-log secret leakage path.
  • Added OctopusImportSecretLeakRegressionTests to cover final import responses, preview/validation responses, diagnostics, and resource outcome serialization with secret-like values present in source data.
  • Verified the import surface does not emit sensitive values through normal flows, validation failures, or cleanup/error paths, while keeping the change scoped to the existing redaction contract and diagnostic pipeline.

Test plan

  • dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter FullyQualifiedName~OctopusImportSecretLeakRegressionTests --no-restore -m:1 -p:UseSharedCompilation=false
  • dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter FullyQualifiedName~OctopusImport --no-restore -m:1 -p:UseSharedCompilation=false (247 tests passed)
  • Confirmed structured-log cleanup regression coverage for secret redaction and persisted cleanup errors

Merge request reports

Loading