feat(mcp): reference fragments + vault key naming schema + guard fixtures
README: add vault key naming schema (<server-name>-<verwendungszweck>,
kebab-case) and a key-exception example to the mcp/ guard rules.
Reference fragments in mcp/: zugferd-service.yaml (OAuth standard case,
no credential field) and az-zoll-service.yaml (documented key exception
using ${VAULT:az-zoll-service-api-key} placeholder) — neither contains
any secret.
Five invalid mcp fixtures under tests/fixtures/mcp/invalid/ covering all
README-documented failure modes: inline secret, missing server-name
fragment structure, missing url, missing type, wrong placeholder syntax.
Closes az-agent-defaults-95y
This commit is contained in:
@@ -0,0 +1,7 @@
|
||||
# Testgegenstand: Platzhalter in falscher Syntax — erlaubt ist nur ${VAULT:...}.
|
||||
falscher-platzhalter-service:
|
||||
type: remote
|
||||
url: https://mcp.example.az.local/alt
|
||||
headers:
|
||||
Authorization: Bearer ${SECRET:veraltete-syntax}
|
||||
enabled: true
|
||||
@@ -0,0 +1,8 @@
|
||||
# Testgegenstand: statischer Key im Klartext statt ${VAULT:...}-Platzhalter.
|
||||
# Der Guard muss rot abbrechen — auch Beispiel-/Fake-Werte zählen als Secret.
|
||||
wetter-service:
|
||||
type: remote
|
||||
url: https://mcp.example.az.local/wetter
|
||||
headers:
|
||||
Authorization: Bearer sk-live-a1b2c3d4e5f6
|
||||
enabled: true
|
||||
@@ -0,0 +1,5 @@
|
||||
# Testgegenstand: keine Fragment-Struktur — der Server-Name fehlt als Schlüssel,
|
||||
# die Felder stehen auf Root-Ebene statt unter genau einem Server-Namen.
|
||||
type: remote
|
||||
url: https://mcp.example.az.local/ohne-namen
|
||||
enabled: true
|
||||
+4
@@ -0,0 +1,4 @@
|
||||
# Testgegenstand: remote-Server ohne type-Feld.
|
||||
az-ohne-type-service:
|
||||
url: https://mcp.example.az.local/ohne-type
|
||||
enabled: true
|
||||
+4
@@ -0,0 +1,4 @@
|
||||
# Testgegenstand: remote-Server ohne Pflichtfeld url.
|
||||
az-ohne-url-service:
|
||||
type: remote
|
||||
enabled: true
|
||||
Reference in New Issue
Block a user