fix: harden evidence secret file handoff

This commit is contained in:
2026-08-09 19:27:52 +02:00
parent e50aad7e41
commit 3b9681a63a
4 changed files with 83 additions and 24 deletions
+22 -6
View File
@@ -1,4 +1,4 @@
import { chmodSync, mkdirSync, mkdtempSync, rmSync, symlinkSync, writeFileSync } from "node:fs";
import { chmodSync, mkdirSync, mkdtempSync, realpathSync, rmSync, symlinkSync, writeFileSync } from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { afterEach, expect, test } from "vitest";
@@ -153,7 +153,7 @@ test("resolves direct bindings from the stable workspace namespace", () => {
values: {
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: password.path,
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: realpathSync(password.path),
},
});
});
@@ -304,10 +304,26 @@ test("requires only a safe HTTP signed-URL file and never reads its contents", (
[variable]: signed.path,
[evidenceVariable("ACCESS_KEY_FILE")]: signed.path,
}, [signed.root]);
expect(resolved).toEqual({ values: { [variable]: signed.path }, missing: [] });
expect(resolved).toEqual({ values: { [variable]: realpathSync(signed.path) }, missing: [] });
expect(JSON.stringify(resolved)).not.toContain("CANARY-SIGNED-URL-CONTENT");
});
test("canonicalizes an in-root Evidence symlink before passing it to the harness", () => {
const signed = secretPath("evidence-signed-target");
const link = join(signed.root, "signed-urls-link");
symlinkSync(signed.path, link);
const source = withEvidence({
type: "http",
uris: ["https://evidence.example.test/guide.md"],
authentication: "signed_urls_file",
});
const variable = evidenceVariable("SIGNED_URLS_FILE");
expect(resolveEvidenceBinding(source, { [variable]: link }, [signed.root])).toEqual({
values: { [variable]: realpathSync(signed.path) }, missing: [],
});
});
test("requires S3 access and secret files together while accepting an optional safe session token", () => {
const access = secretPath("evidence-access");
const secret = secretPath("evidence-secret");
@@ -327,9 +343,9 @@ test("requires S3 access and secret files together while accepting an optional s
}, [access.root]).missing).toEqual([evidenceVariable("SECRET_KEY_FILE")]);
expect(resolveEvidenceBinding(source, env, [access.root, secret.root, token.root])).toEqual({
values: {
[evidenceVariable("ACCESS_KEY_FILE")]: access.path,
[evidenceVariable("SECRET_KEY_FILE")]: secret.path,
[evidenceVariable("SESSION_TOKEN_FILE")]: token.path,
[evidenceVariable("ACCESS_KEY_FILE")]: realpathSync(access.path),
[evidenceVariable("SECRET_KEY_FILE")]: realpathSync(secret.path),
[evidenceVariable("SESSION_TOKEN_FILE")]: realpathSync(token.path),
},
missing: [],
});