Skip to content

Extract GTM container IDs from audit evidence - #1220

Open
ChristianPavilonis wants to merge 1 commit into
mainfrom
fix/audit-gtm-container-id-1219
Open

ChristianPavilonis wants to merge 1 commit into
mainfrom
fix/audit-gtm-container-id-1219

Conversation

@ChristianPavilonis

Copy link
Copy Markdown
Collaborator

Summary

  • Fix audit-generated GTM configuration being rejected when detection evidence contains a script URL rather than a bare container ID.
  • Return only the regex match from integration evidence, matching the existing asset fallback. Keep runtime validation unchanged.

Changes

File Change
crates/trusted-server-cli/src/commands/audit/generate/analyzer.rs Extract only the container ID; cover bare-ID evidence and URLs with and without trailing query parameters.
crates/trusted-server-cli/src/commands/audit/generate/mod.rs Verify generated TOML enables GTM and writes only the container ID from URL evidence.

Closes

Closes #1219

Test plan

Both new regression tests failed before the fix by returning the full URL instead of GTM-ABC123, then passed after the fix.

  • cargo test --package trusted-server-cli --target x86_64-unknown-linux-gnu gtm_container_id
  • ./scripts/test-cli.sh, including opt-in browser fixtures
  • cargo test-fastly && cargo test-axum && cargo test-cloudflare && cargo test-spin
  • cargo test --manifest-path crates/trusted-server-integration-tests/Cargo.toml --test parity, 14 passed
  • cargo clippy-fastly && cargo clippy-axum && cargo clippy-cloudflare && cargo clippy-cloudflare-wasm && cargo clippy-spin-native && cargo clippy-spin-wasm && cargo clippy-cli && cargo clippy-codegen
  • cargo fmt --all -- --check
  • JS build: cd crates/trusted-server-js/lib && node build-all.mjs
  • JS tests: cd crates/trusted-server-js/lib && npx vitest run, 1,155 passed
  • JS format: cd crates/trusted-server-js/lib && npm run format
  • Docs format: cd docs && npm run format

No deployment or manual Fastly smoke test performed. This changes only CLI extraction logic and its tests.

Checklist

  • Changes follow repository conventions
  • No new production unwrap() or logging changes
  • New code has regression tests
  • No secrets or credentials committed

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ts audit writes the full GTM script URL into container_id

1 participant