CB-189: cover every remote, both URLs, and any non-SSH scheme in the credential check #195
Reference in New Issue
Block a user
Delete Branch "worker/cb-189-remote-url-coverage-4692f3-1"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes #189.
GitWorktrees's credential check only ever inspected origin's HTTPS fetch URL. Four gaps closed, additively (the existing origin/https strip-and-refuse behaviour is unchanged):
Both hard constraints from the issue are honored: the new reportRemoteUrlsWithUserInfo check is wrapped end-to-end so it can never abort a provision (git calls inside it can throw), and on any failure it logs only the exception's class, never its message — the enumerating git remote call is not redacted, and its stderr can itself hold the URL.
Tests added in GitWorktreesTest (all real git, TempDir-based, matching the existing style):
Each uses a logback ListAppender on GitWorktrees's own logger and asserts both that the expected report fires and that no captured log message contains the URL, user, password, or host. The existing origin strip-and-refuse tests are untouched and still pass.
I proved each of the four checks by temporarily disabling it and watching its test fail, then reverted (see PR description / worker report for the exact failure text); all sabotage has been reverted before this commit.
Build: mvn clean install — Tests run: 1016, Failures: 0, Errors: 0, Skipped: 0. BUILD SUCCESS. GitWorktreesTest: 29/29.