const assert = require('node:assert/strict'); const fs = require('node:fs'); const path = require('node:path'); const test = require('node:test'); const root = path.join(__dirname, '..'); const common = fs.readFileSync(path.join(root, 'scripts', 'common.js'), 'utf8'); const workspace = fs.readFileSync(path.join(root, 'scripts', 'workspace.js'), 'utf8'); test('oauth code uses runtime token/client variables, not embedded secret literals', () => { assert.match(common, /refresh_token:\s*refreshToken,/); assert.match(common, /google\.oauth2\(\{ version: 'v2', auth: authClient \}\)/); assert.match(common, /authClient\.credentials\.access_token/); assert.match(common, /access_token:\s*accessToken,/); assert.match(common, /refresh_token:\s*refreshToken \|\| null,/); assert.match(common, /token_type:\s*tokenType \|\| undefined,/); assert.match(workspace, /const auth =\s*authClient \|\|\s*\(await authorize/); });