mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-10-06 20:31:57 +00:00
* fix(auth): require Google authentication in cloud mode Remove the public shared-key mechanism and fail closed on Google auth while adding submit-route throttling. * fix(auth): address review follow-ups Fail closed on whitespace-only Google configuration and centralize shared authentication behavior. * test(auth): use non-secret Google client fixture Make the public test identifier explicit so secret scanning does not misclassify it as an API key. * test(auth): avoid OAuth-shaped fixture Use a format-neutral audience value so secret scanning can distinguish the fixture from a real client identifier. * chore(security): suppress public OAuth fixture Document the scanner false positive without suppressing any runtime credential flow.
8 lines
357 B
JSON
8 lines
357 B
JSON
{
|
|
"suppressions": [
|
|
{
|
|
"id": "gitleaks-generic-api-key-45",
|
|
"justification": "False positive. tests/test_submit_order.py defines a synthetic Google OAuth audience used only for mocked token verification. OAuth client IDs are public identifiers, this fixture is not a credential, and the tests make no real Google or AWS calls."
|
|
}
|
|
]
|
|
}
|