Luigit
repositories / dotfiles

dotfiles

bugabingas dorkfiles

owned by admin

pi/agent/skills/google-workspace/scripts/source-safety.test.js

Raw
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const test = require('node:test');

const root = path.join(__dirname, '..');
const common = fs.readFileSync(path.join(root, 'scripts', 'common.js'), 'utf8');
const workspace = fs.readFileSync(path.join(root, 'scripts', 'workspace.js'), 'utf8');

test('oauth code uses runtime token/client variables, not embedded secret literals', () => {
  assert.match(common, /refresh_token:\s*refreshToken,/);
  assert.match(common, /google\.oauth2\(\{ version: 'v2', auth: authClient \}\)/);
  assert.match(common, /authClient\.credentials\.access_token/);
  assert.match(common, /access_token:\s*accessToken,/);
  assert.match(common, /refresh_token:\s*refreshToken \|\| null,/);
  assert.match(common, /token_type:\s*tokenType \|\| undefined,/);
  assert.match(workspace, /const auth =\s*authClient \|\|\s*\(await authorize/);
});