[PR #24280] [Test] add unit tests for ProviderConfigEncrypter encrypt/mask/decrypt #30570

Closed
opened 2026-02-21 20:47:48 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/24280

State: closed
Merged: Yes


Fixes #24279

This PR adds a new pytest-based unit test suite for ProviderConfigEncrypter.

  • encrypt()
    • Verifies secret fields are encrypted while non-secret fields remain unchanged.
    • Ensures deep copy semantics (input dict not modified).
  • mask_tool_credentials()
    • Covers both long (>6) and short (<=6) secret values.
    • Ensures correct masking rules and immutability of input.
    • Confirms missing secret keys do not affect other fields.
  • decrypt()
    • Validates normal decryption flow.
    • Skips decryption for empty/None values.
    • Ensures exceptions are swallowed and original values are preserved.

Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes #<issue number>.

Summary

Screenshots

Before After
... ...

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/24280 **State:** closed **Merged:** Yes --- Fixes #24279 This PR adds a new pytest-based unit test suite for `ProviderConfigEncrypter`. - **encrypt()** - Verifies secret fields are encrypted while non-secret fields remain unchanged. - Ensures deep copy semantics (input dict not modified). - **mask_tool_credentials()** - Covers both long (>6) and short (<=6) secret values. - Ensures correct masking rules and immutability of input. - Confirms missing secret keys do not affect other fields. - **decrypt()** - Validates normal decryption flow. - Skips decryption for empty/None values. - Ensures exceptions are swallowed and original values are preserved. > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 1. Ensure there is an associated issue and you have been assigned to it > 1. Use the correct syntax to link this PR: `Fixes #<issue number>`. ## Summary <!-- Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context. List any dependencies that are required for this change. --> ## Screenshots | Before | After | |--------|-------| | ... | ... | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:47:48 -05:00
yindo closed this issue 2026-02-21 20:47:48 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#30570