Skip to main content

Pytest plugin to hide sensitive data in test reports

Project description

pytest-mask-secrets

pytest-mask-secrets is a plugin for pytest that removes sensitive data from test reports.

Based on the configuration, it searches for specified secrets, passwords, and tokens in the records and replaces them with asterisks.

While this feature is usually provided by CI tools, it can be insufficient in many situations as it only strips secrets from the captured output. A common case of leaking secrets is through generated JUnit files that are not curated by CI tools. Therefore, it is necessary to have such functionality at the pytest level.

Installation

pip install pytest-mask-secrets

Usage

pytest-mask-secrets needs to know which values to mask. These values are read from environment variables. The list of these variables is passed in the MASK_SECRETS environment variable, which contains a comma-separated list of all environment variables containing secrets. Here is an example:

export PYPI_API_TOKEN=mytoken
export SOME_PASSWORD=mypassword
export MASK_SECRETS=PYPI_API_TOKEN,SOME_PASSWORD

pytest

With pytest-mask-secrets installed, all occurrences of "mytoken" and "mypassword" will be eliminated from the report.

Automagic Identification of Variables with Secrets

If MASK_SECRETS_AUTO is set to anything other than zero ("0"), all environment variables containing the words "TOKEN", "SECRET," "PASSWORD," or "PASSWD" in their names are considered sensitive, and their values are removed from the report.

This discovery mode should be used with caution. CI workflows, in particular, should rely on an explicit list of secret variables. Under certain circumstances, this method can lead to the leakage of other sensitive data (if, by accident, a secret from an environment variable matches text commonly present in the test report). Nevertheless, this method can still be useful for example for local execution to prevent accidental leaks through copy-and-paste.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pytest_mask_secrets-1.1.0.tar.gz (3.0 kB view details)

Uploaded Source

Built Distribution

pytest_mask_secrets-1.1.0-py3-none-any.whl (4.0 kB view details)

Uploaded Python 3

File details

Details for the file pytest_mask_secrets-1.1.0.tar.gz.

File metadata

  • Download URL: pytest_mask_secrets-1.1.0.tar.gz
  • Upload date:
  • Size: 3.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: pdm/2.17.3 CPython/3.10.12 Linux/6.5.0-1025-azure

File hashes

Hashes for pytest_mask_secrets-1.1.0.tar.gz
Algorithm Hash digest
SHA256 9cd676cf9908adc86bd3e247b7167934631e76b1630e7f395885f15632265812
MD5 b6fbfba167f52c41563d400b6f848136
BLAKE2b-256 94e72c2ca71d51391d83829379bd63c1d9ed601777f2714b7bd3db9fe1742c1b

See more details on using hashes here.

File details

Details for the file pytest_mask_secrets-1.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for pytest_mask_secrets-1.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 8dd1c514147041c696c6692e8b2cd4f65f4825f3b61dc8274a16b55c873491b2
MD5 3efdfab3f4c1252cbd972d824ca5865a
BLAKE2b-256 3e739bfe6fc2435809aa69848615d77c545bf9a7bcc9b00b43438c28069266d5

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page