Skip to content

test(candidate): add regression coverage proving password hash is never returned - #167

Merged
datvt243 merged 1 commit into
stagingfrom
152-password-hash-leaked
Sep 27, 2026
Merged

datvt243 merged 1 commit into
stagingfrom
152-password-hash-leaked

Conversation

@datvt243

Copy link
Copy Markdown
Owner

Summary

Closes #152. The production fix was already live on staging since commit f355e2f (2026-08-21) — handlerGetInformationByEmail/handlerGetInformationById already exclude the password field correctly — but no regression test ever covered it and the diagram node was never backfilled.

  • src/__tests__/candidate/candidate.service.test.ts — 3 tests proving both handlers exclude password by default, and that a given whitelisted select string is no longer silently dropped (the old double-wrap no-op bug).
  • agent-hub/: backfilled evidence (implementer + verifier) and sealed node fix-candidate-password-leak.

Commits

  • fd5a958 test(candidate): add regression coverage proving password hash is never returned

Test plan

  • npm test — 143 passed, 143 total
  • npm run build — clean

🤖 Generated with Claude Code

…er returned

Closes #152. The production fix was already live on `staging` since
commit f355e2f (2026-08-21) — handlerGetInformationByEmail/
handlerGetInformationById already exclude the password field correctly
— but no regression test ever covered it and the diagram node was
never backfilled.

- src/__tests__/candidate/candidate.service.test.ts: 3 tests proving
  both handlers exclude password by default, and that a given
  whitelisted select string is no longer silently dropped (the old
  double-wrap no-op bug).
- agent-hub: backfill evidence (implementer + verifier) and seal node
  fix-candidate-password-leak.

npm test: 143 passed, 143 total. npm run build: clean.

Node: fix-candidate-password-leak (SEALED)
Evidence: agent-hub/evidence/implementer/2026-09-28/fix-candidate-password-leak-plan.md,
agent-hub/evidence/verifier/2026-09-28/fix-candidate-password-leak-seal.md

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@datvt243
datvt243 merged commit a2ec824 into staging Sep 27, 2026
3 checks passed
@datvt243
datvt243 deleted the 152-password-hash-leaked branch September 27, 2026 18:22
@datvt243 datvt243 mentioned this pull request Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant