SC005_secret_redaction.json (1884B)
1 { 2 "fixture_format_version": 1, 3 "case_id": "SC005_secret_redaction", 4 "requirements": [ 5 "HYF-SEC-005", 6 "HYF-RUN-008" 7 ], 8 "family": "security", 9 "boundary": "security", 10 "operation": "security.boundary", 11 "purpose": "Failures do not disclose configuration secrets.", 12 "implementation_status": "planned", 13 "required_from_step": "S116", 14 "mandatory": true, 15 "context": { 16 "source_time": "2026-09-21T09:00:00-07:00", 17 "evaluated_at": "2026-09-21T10:00:00-07:00", 18 "timezone": "America/Vancouver", 19 "locale": "en-CA", 20 "tenant": "test-tenant-1", 21 "seed": 101, 22 "versions": { 23 "schema": "test-projection-1", 24 "taxonomy": "test-only-produce-1", 25 "normalization": "test-only-norm-1", 26 "review_policy": "test-only-review-1", 27 "ranking_policy": "test-only-ranking-1", 28 "question_bundle": "test-only-questions-1", 29 "model": "jev-1.13.0" 30 } 31 }, 32 "given": { 33 "inert_secret_marker": "NOT_A_REAL_SECRET_HYF_TEST", 34 "provider_failure": "authentication" 35 }, 36 "provider_script": [], 37 "then": [ 38 { 39 "operator": "equals", 40 "path": "/security/secret_in_stdout", 41 "value": false 42 }, 43 { 44 "operator": "equals", 45 "path": "/security/secret_in_stderr", 46 "value": false 47 }, 48 { 49 "operator": "equals", 50 "path": "/security/secret_in_logs", 51 "value": false 52 } 53 ], 54 "prohibited": [ 55 "No authoritative business mutation or reservation is performed by Hyf." 56 ], 57 "provenance": { 58 "kind": "synthetic", 59 "author": "hyf_v1_jev handoff", 60 "review_status": "implementation/domain review required; not a live-model label" 61 }, 62 "assumptions": [ 63 "This is a semantic test projection, not an already implemented public wire payload.", 64 "Test-only rules and scripted model outputs do not define production thresholds or certify model quality." 65 ] 66 }