[PR #22102] test: add comprehensive unit tests for encrypter module #29839

Closed
opened 2026-02-21 20:46:20 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/22102

State: closed
Merged: Yes


Description

Add comprehensive unit tests for core.helper.encrypter module.

Core Functionality Tests

  • Token obfuscation with various input scenarios
  • Encryption and decryption operations
  • Batch decryption performance optimization
  • Error handling for invalid inputs

Security-Focused Tests

  • Cross-tenant isolation: Ensures tokens encrypted for one tenant cannot be accessed by another
  • Tampered ciphertext detection: Verifies the system rejects modified encrypted data
  • Encryption randomness: Confirms same plaintext produces different ciphertext (prevents pattern analysis)
  • RSA size limits: Tests behavior with oversized inputs

Edge Cases

  • Empty tokens and special characters (null bytes, emoji, Unicode)
  • Base64 encoding/decoding edge cases
  • Database and key management error scenarios

The extensive test coverage is intentional given the critical nature of encryption functionality in the system.

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/22102 **State:** closed **Merged:** Yes --- ## Description Add comprehensive unit tests for `core.helper.encrypter` module. ### Core Functionality Tests - Token obfuscation with various input scenarios - Encryption and decryption operations - Batch decryption performance optimization - Error handling for invalid inputs ### Security-Focused Tests - **Cross-tenant isolation**: Ensures tokens encrypted for one tenant cannot be accessed by another - **Tampered ciphertext detection**: Verifies the system rejects modified encrypted data - **Encryption randomness**: Confirms same plaintext produces different ciphertext (prevents pattern analysis) - **RSA size limits**: Tests behavior with oversized inputs ### Edge Cases - Empty tokens and special characters (null bytes, emoji, Unicode) - Base64 encoding/decoding edge cases - Database and key management error scenarios ### The extensive test coverage is intentional given the critical nature of encryption functionality in the system. ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:46:20 -05:00
yindo closed this issue 2026-02-21 20:46:20 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#29839