fix(backend): reject compound provider credentials

This commit is contained in:
2026-07-12 08:10:47 +02:00
parent f064daef09
commit 2302286ea1
6 changed files with 115 additions and 4 deletions
+41
View File
@@ -74,3 +74,44 @@ test("Docker secrets require a secure root-owned /run/secrets parent and 0444 fi
},
})).toThrow("model provider credential is unavailable");
});
test.each(["amazon-bedrock", "azure-openai-responses", "cloudflare-workers-ai", "cloudflare-ai-gateway"])(
"compound provider %s fails closed before opening the generic secret", (provider) => {
let opens = 0;
expect(() => buildPiChildEnv({
ambient: {}, provider, credentialFile: "/unused",
fsOps: {
lstat: () => { throw new Error("must not inspect file"); },
open: () => { opens += 1; return 9; },
fstat: () => { throw new Error("must not inspect file"); },
read: () => "secret", close: () => undefined,
},
})).toThrow(
"compound credential bundles are unsupported by THT_MODEL_API_KEY_FILE; dedicated provider configuration is required",
);
expect(opens).toBe(0);
},
);
test("single-key providers scrub ambient compound companions before injecting their key", () => {
const stat = {
dev: 7, ino: 1, uid: process.getuid?.() ?? 0, mode: 0o100600, nlink: 1, size: 6,
isFile: () => true, isDirectory: () => false, isSymbolicLink: () => false,
};
const env = buildPiChildEnv({
ambient: {
AWS_ACCESS_KEY_ID: "ambient", AWS_SECRET_ACCESS_KEY: "ambient",
CLOUDFLARE_ACCOUNT_ID: "ambient", CLOUDFLARE_GATEWAY_ID: "ambient",
},
provider: "openai", credentialFile: "/safe/key",
fsOps: {
lstat: () => stat as any, open: () => 9, fstat: () => stat as any,
read: () => "secret", close: () => undefined,
},
});
expect(env.OPENAI_API_KEY).toBe("secret");
expect(env).not.toHaveProperty("AWS_ACCESS_KEY_ID");
expect(env).not.toHaveProperty("AWS_SECRET_ACCESS_KEY");
expect(env).not.toHaveProperty("CLOUDFLARE_ACCOUNT_ID");
expect(env).not.toHaveProperty("CLOUDFLARE_GATEWAY_ID");
});