Files
2026-09-30 20:30:56 +03:00

31 lines
2.1 KiB
Markdown

## ADDED Requirements
### Requirement: Alternative provider contexts execute independently
The custom detector policy SHALL detect supported Xai and ZAI/GLM credentials when provider context appears either before or after the credential, without requiring both context directions in one input chunk.
#### Scenario: Provider context appears before the credential
- **WHEN** an offline scan processes a bounded synthetic credential preceded by its supported provider context
- **THEN** the policy emits one corresponding custom provider finding
#### Scenario: Provider context appears after the credential
- **WHEN** an offline scan processes a bounded synthetic credential followed by its supported provider context
- **THEN** the policy emits one corresponding custom provider finding
### Requirement: Alternative detector names normalize canonically
The scanner MUST normalize all compatibility-only custom detector aliases to the existing canonical `Xai` or `ZaiGLM` detector identity before persistence and candidate extraction.
#### Scenario: Context-after alias is emitted
- **WHEN** TruffleHog emits `CustomRegex` with a context-after compatibility name in `ExtraData.name`
- **THEN** the scanner retains `CustomRegex` as the original detector and exposes the canonical provider detector name downstream
### Requirement: Compatibility is tested through the real CLI
The compatibility suite SHALL run the complete configured custom detector policy through an available TruffleHog executable using deterministic synthetic credentials, disabled verification, and disabled update checks.
#### Scenario: Compatible executable is available
- **WHEN** a configured Windows or Linux TruffleHog executable scans the compatibility fixtures
- **THEN** both context directions produce canonical findings and route to the expected keycheck candidate services without network verification
#### Scenario: Executable is unavailable
- **WHEN** no TruffleHog executable is available in a general unit-test environment
- **THEN** the real-CLI test is explicitly skipped while policy-structure and normalization unit tests still execute