From 9572bfc26274d1f811535dabbfa7e18b9b9a0c79 Mon Sep 17 00:00:00 2001 From: Roberto Iskandarani Date: Mon, 28 Sep 2026 18:03:07 -0500 Subject: [PATCH] chore: keep tests, examples and benches out of the published crates MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `core/tests/fixtures/` holds RSA and EC private keys that the unit tests and the DPoP example load through `include_str!`. They are test material — nothing in the SDK verifies against them — but `cargo package --list` showed all four shipping inside the `authplane-sdk` tarball, and a crates.io version is immutable: whatever 0.1.0 carries, it carries for good. Key-shaped files in a published tarball are permanent noise for every downstream secret scanner and SBOM, so the cheapest moment to keep them out is before the first publish. `examples/` is excluded alongside `tests/` rather than kept: the DPoP example reads `tests/fixtures/test-private.pem`, so shipping it without the fixture would leave it unbuildable from the tarball. Both stay in the repository, which is where anyone reading them is already looking. Packaging only — no source, no API and no test behaviour changes. The suites still run from a checkout, and `cargo package -p authplane-sdk` verifies clean with no `.pem` in the result. `authplane-mcp` and `authplane-fastmcp` cannot be packaged until `authplane-sdk` is on the index, which is the publish order RELEASE_SETUP.md already prescribes. --- core/Cargo.toml | 13 +++++++++++++ fastmcp/Cargo.toml | 13 +++++++++++++ mcp/Cargo.toml | 13 +++++++++++++ 3 files changed, 39 insertions(+) diff --git a/core/Cargo.toml b/core/Cargo.toml index c4427b7..c7f31be 100644 --- a/core/Cargo.toml +++ b/core/Cargo.toml @@ -10,6 +10,19 @@ readme = "README.md" keywords = ["oauth", "jwt", "security", "mcp", "authplane"] categories = ["authentication", "api-bindings"] +# Tests, examples and benches are not shipped in the published crate. They are +# not what a consumer compiles against, they are all readable in the repository, +# and `core/tests/fixtures/` holds RSA and EC private keys the unit tests and the +# DPoP example use. Those keys are test material — nothing verifies against them — +# but a crates.io version is immutable, so anything that ships stays shipped, and +# key-shaped files in a published tarball are permanent noise for every downstream +# secret scanner and SBOM. Keeping them out of the tarball costs nothing here. +# +# `examples/` goes with `tests/` rather than staying behind: the DPoP example +# reads `tests/fixtures/test-private.pem` through `include_str!`, so shipping the +# example without the fixture would leave it unbuildable from the tarball. +exclude = ["tests/", "examples/", "benches/"] + [dependencies] async-trait = "0.1" base64 = "0.22" diff --git a/fastmcp/Cargo.toml b/fastmcp/Cargo.toml index d18f29e..a687fa6 100644 --- a/fastmcp/Cargo.toml +++ b/fastmcp/Cargo.toml @@ -10,6 +10,19 @@ readme = "README.md" keywords = ["oauth", "jwt", "fastmcp", "adapter", "authplane"] categories = ["authentication", "api-bindings"] +# Tests, examples and benches are not shipped in the published crate. They are +# not what a consumer compiles against, they are all readable in the repository, +# and `core/tests/fixtures/` holds RSA and EC private keys the unit tests and the +# DPoP example use. Those keys are test material — nothing verifies against them — +# but a crates.io version is immutable, so anything that ships stays shipped, and +# key-shaped files in a published tarball are permanent noise for every downstream +# secret scanner and SBOM. Keeping them out of the tarball costs nothing here. +# +# `examples/` goes with `tests/` rather than staying behind: the DPoP example +# reads `tests/fixtures/test-private.pem` through `include_str!`, so shipping the +# example without the fixture would leave it unbuildable from the tarball. +exclude = ["tests/", "examples/", "benches/"] + [dependencies] authplane-sdk = { path = "../core", version = "0.1.0" } fastmcp-rust = "0.3.0" diff --git a/mcp/Cargo.toml b/mcp/Cargo.toml index ea551e5..4652384 100644 --- a/mcp/Cargo.toml +++ b/mcp/Cargo.toml @@ -10,6 +10,19 @@ readme = "README.md" keywords = ["oauth", "jwt", "mcp", "adapter", "authplane"] categories = ["authentication", "api-bindings"] +# Tests, examples and benches are not shipped in the published crate. They are +# not what a consumer compiles against, they are all readable in the repository, +# and `core/tests/fixtures/` holds RSA and EC private keys the unit tests and the +# DPoP example use. Those keys are test material — nothing verifies against them — +# but a crates.io version is immutable, so anything that ships stays shipped, and +# key-shaped files in a published tarball are permanent noise for every downstream +# secret scanner and SBOM. Keeping them out of the tarball costs nothing here. +# +# `examples/` goes with `tests/` rather than staying behind: the DPoP example +# reads `tests/fixtures/test-private.pem` through `include_str!`, so shipping the +# example without the fixture would leave it unbuildable from the tarball. +exclude = ["tests/", "examples/", "benches/"] + [dependencies] authplane-sdk = { path = "../core", version = "0.1.0" } axum = "0.8"