//nolint:testpackage // white-box test of unexported internals package secret import ( "testing" ) func TestValidateGPGKeyID(t *testing.T) { t.Parallel() tests := []struct { name string keyID string wantErr bool }{ // Valid cases {"valid email address", "test@example.com", false}, {"valid email with dots and hyphens", "test.user-name@example-domain.co.uk", false}, {"valid email with plus", "test+tag@example.com", false}, {"valid short key ID (8 hex chars)", "ABCDEF12", false}, {"valid long key ID (16 hex chars)", "ABCDEF1234567890", false}, { "valid fingerprint (40 hex chars)", "ABCDEF1234567890ABCDEF1234567890ABCDEF12", false, }, { "valid lowercase hex fingerprint", "abcdef1234567890abcdef1234567890abcdef12", false, }, {"valid mixed case hex", "AbCdEf1234567890", false}, // Invalid cases {"empty key ID", "", true}, {"key ID with spaces", "test user@example.com", true}, {"key ID with semicolon (command injection)", "test@example.com; rm -rf /", true}, { "key ID with pipe (command injection)", "test@example.com | cat /etc/passwd", true, }, {"key ID with backticks (command injection)", "test@example.com`whoami`", true}, { "key ID with dollar sign (command injection)", "test@example.com$(whoami)", true, }, {"key ID with quotes", "test\"@example.com", true}, {"key ID with single quotes", "test'@example.com", true}, {"key ID with backslash", "test\\@example.com", true}, {"key ID with newline", "test@example.com\nrm -rf /", true}, {"key ID with carriage return", "test@example.com\rrm -rf /", true}, {"hex with invalid length (7 chars)", "ABCDEF1", true}, {"hex with invalid length (9 chars)", "ABCDEF123", true}, {"hex with non-hex characters", "ABCDEFGH", true}, {"mixed format (email with hex)", "test@ABCDEF12", true}, {"key ID with ampersand", "test@example.com & echo test", true}, {"key ID with redirect", "test@example.com > /tmp/test", true}, {"key ID with null byte", "test@example.com\x00", true}, } for _, tt := range tests { t.Run(tt.name, func(t *testing.T) { t.Parallel() err := validateGPGKeyID(tt.keyID) if (err != nil) != tt.wantErr { t.Errorf("validateGPGKeyID() error = %v, wantErr %v", err, tt.wantErr) } }) } }