test(redact): pin Supabase provider-token length and hyphen boundaries

main

Commit

suhaanthayyil2mo ago

The {20,} length floor on both sb_secret_ and sbp_ patterns was only accidentally pinned by unrelated fixtures, and the body charset's hyphen (present in real base64url key bodies) had no test coverage at all. Add explicit boundary cases (exactly 20 chars redacts, 19 is preserved) and hyphen-bearing fixtures for both prefixes so a regex tightening or charset "tidy-up" fails a test instead of silently under-redacting real keys.

Also correct two inaccurate comments verified against the vendored betterleaks v1.5.0 rule source: the sbp_ rule (unlike sb_secret_) fires standalone and only misses tokens via its exact-40-char body regex, entropy filter, and digit-minimum filter, not because it requires a companion URL; and the over-redaction example used a body shorter than the {20,} floor so it didn't actually demonstrate the pattern.