Remove redundant pattern checks from validity checks partner clients
What does this MR do and why?
Each partner token verifier re-matched the detected secret against its own copy of the detection rule's regex before calling the vendor. Since routing already happens on the exact rule id, the registry maps each one to a verifier class. Therefore, the check asserted nothing and made the client a second source of truth for a shape the default ruleset owns.
A pattern narrower than its rule also dropped findings silently, because the early return records no metric.
Removed from: postman, github, openai, anthropic, heroku, stripe, datadog and sendgrid.
Follows ADR 006 and addresses !248110 (comment 3658223808). It's a follow-up from #614186 (closed).
Kept on purpose
Two clients were kept on purpose as discussed below.
AWS
The AWS rule id matches AKIA, ASIA and A3T in one regex, and the dummy-secret STS test only reads correctly for AKIA. We leave this one around because pattern check picks the credential kind rather than re-checking the ruleset.
GCP
Currently, GCP client has three rule IDs that route to one client that can verify none of them. The check keeps them off tokeninfo, which rejects them with a 400 whether or not they are live and would have them reported inactive. This stays around until each type gets its own verifier as part of https://gitlab.com/gitlab-org/gitlab/-/issues/588454.
Issue
MR acceptance checklist
I have evaluated this MR against the MR acceptance checklist.