From 399aef8111338cf0b03cdd79b24645ed50326191 Mon Sep 17 00:00:00 2001 From: Bryan Helmkamp Date: Sat, 19 Sep 2026 18:05:01 -0400 Subject: [PATCH] Keep the Daytona key rendering out of the test's assertion messages CodeQL read the assertion messages as a log of the credentials' Debug output. The test proves that output never holds the key, so the messages added nothing. Co-Authored-By: Claude Fable 5.1 --- lib/apps/fabro-server/src/sandbox_access.rs | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/lib/apps/fabro-server/src/sandbox_access.rs b/lib/apps/fabro-server/src/sandbox_access.rs index 657d1d043..8ab8c9dca 100644 --- a/lib/apps/fabro-server/src/sandbox_access.rs +++ b/lib/apps/fabro-server/src/sandbox_access.rs @@ -1041,9 +1041,11 @@ mod tests { let credentials = DaytonaCredentials::from_api_key("dtn_secret_key".to_string(), |name| { (name == EnvVars::DAYTONA_ORGANIZATION_ID).then(|| "org-1".to_string()) }); + // The rendering stays out of the assertion messages: a failure must + // not print the key it is checking for. let rendered = format!("{credentials:?}"); - assert!(!rendered.contains("dtn_secret_key"), "{rendered}"); - assert!(rendered.contains("org-1"), "{rendered}"); + assert!(!rendered.contains("dtn_secret_key")); + assert!(rendered.contains("org-1")); assert_eq!( credentials.config().api_key.as_deref(), Some("dtn_secret_key")