Files
Christoph Schaefer 458b39efb1 fix(config): mask the Euro-Office jwt_secret as sensitive
Both sensitive-key allowlists carried an `onlyoffice` entry but nothing
for `eurooffice`, so the document server signing key was printed in
full while the ONLYOFFICE one next to it was redacted.

SystemConfig covers `occ config:list system`, which is where the key
lands when the app is configured through config.php. AppConfig covers
plain `occ config:list` and the admin support report, which is where it
lands when it is set through the app's own settings page.

Fixes: #63302

Assisted-by: ClaudeCode:claude-opus-5
Signed-off-by: Christoph Schaefer <christoph.schaefer@nextcloud.com>
2026-08-17 10:45:02 +02:00

51 lines
1.1 KiB
PHP

<?php
declare(strict_types=1);
/**
* SPDX-FileCopyrightText: 2026 Nextcloud GmbH and Nextcloud contributors
* SPDX-License-Identifier: AGPL-3.0-or-later
*/
namespace Test;
use OC\Config;
use OC\SystemConfig;
use OCP\IConfig;
use PHPUnit\Framework\MockObject\MockObject;
/**
* Class SystemConfigTest
*
* @package Test
*/
class SystemConfigTest extends TestCase {
private Config&MockObject $config;
#[\Override]
protected function setUp(): void {
parent::setUp();
$this->config = $this->createMock(Config::class);
}
public function testGetFilteredValueMasksTheEuroOfficeSecret(): void {
$this->config->method('getValue')
->willReturnMap([
['config_extra_sensitive_values', [], []],
['eurooffice', '', [
'editors_check_interval' => 0,
'jwt_secret' => 'a-document-server-signing-key',
'jwt_header' => 'AuthorizationJwt',
]],
]);
$systemConfig = new SystemConfig($this->config);
$this->assertSame([
'editors_check_interval' => 0,
'jwt_secret' => IConfig::SENSITIVE_VALUE,
'jwt_header' => 'AuthorizationJwt',
], $systemConfig->getFilteredValue('eurooffice'));
}
}