docs: replace JWT-like Bearer placeholder with <license-token> #191
No reviewers
Labels
No labels
autopilot:pending-human
source:analyste
source:defenseur
source:human
source:medic
status:approved
status:blocked
status:in-progress
status:needs-clarification
status:needs-fix
status:ready
status:review
status:triage
type:bug
type:feature
type:infra
type:refactor
type:schema
type:security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: maximus/Simpl-Resultat#191
Loading…
Reference in a new issue
No description provided.
Delete branch "issue-181-doc-bearer-token-placeholder"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes #181
Diagnostic
Defenseur run du 2026-04-30 a flag
docs/api-contract-prices.md:471(HIGH, categoriesecrets) sur le patternBearer Token. La chaine est un exemple JWT tronque (...final), pas un secret reel — l'entropie suffit pour faire match le scanner.Fix
1 ligne dans
docs/api-contract-prices.md. Pas de changement de comportement utilisateur, donc pas d'entree CHANGELOG.Verification
grep -rn 'Bearer eyJ' docs/ src/: 0 hit apres le fix.Note
L'autre faux positif mentionne dans le body (
balance.service.ts:1332surauth: "balance.priceFetching.errors.authFailed") est explicitement hors scope ici — issue separee coteagent-defenseurspour durcir la regexGeneric Token Assignment.Review — APPROVE
Summary: Fix doc-only minimal qui remplace un JWT-exemple tronque par un placeholder
<license-token>plus explicite. Resout le faux positifsecrets/HIGHdu Defenseur sans introduire de regression.Notes positives
<license-token>est plus parlant queeyJ...pour le lecteur de la docbalance.service.ts:1332) explicitement reporte hors scope dans le PR body : bonne hygienegrep 'Bearer eyJ'etgrep 'eyJ'dansdocs/+src/retournent zero hitChecklist
docs:conformeFixes #181Mergeable.