feat(mcp): reference fragments + vault key naming schema + guard fixtures

README: add vault key naming schema (<server-name>-<verwendungszweck>,
kebab-case) and a key-exception example to the mcp/ guard rules.

Reference fragments in mcp/: zugferd-service.yaml (OAuth standard case,
no credential field) and az-zoll-service.yaml (documented key exception
using ${VAULT:az-zoll-service-api-key} placeholder) — neither contains
any secret.

Five invalid mcp fixtures under tests/fixtures/mcp/invalid/ covering all
README-documented failure modes: inline secret, missing server-name
fragment structure, missing url, missing type, wrong placeholder syntax.

Closes az-agent-defaults-95y
This commit is contained in:
m3ta-chiron
2026-08-22 10:26:56 +02:00
parent befb071fea
commit d428d53e9e
10 changed files with 67 additions and 3 deletions
+7
View File
@@ -0,0 +1,7 @@
# Testgegenstand: Platzhalter in falscher Syntax — erlaubt ist nur ${VAULT:...}.
falscher-platzhalter-service:
type: remote
url: https://mcp.example.az.local/alt
headers:
Authorization: Bearer ${SECRET:veraltete-syntax}
enabled: true