fix: preserve deterministic runtime secret leases

This commit is contained in:
2026-08-14 17:47:17 +02:00
parent fd3b62ce6f
commit a94df262f4
4 changed files with 82 additions and 16 deletions
@@ -34,6 +34,23 @@ afterEach(() => {
});
describe("WorkspaceSecretStore", () => {
test("reuses stable materialized paths and removes them after the last lease", () => {
const { store } = fixture();
store.put("north-star", "dwh.password", "correct horse battery staple");
const first = store.materialize("north-star", ["dwh.password"]);
const second = store.materialize("north-star", ["dwh.password"]);
const firstPath = first.files.get("dwh.password")!;
const secondPath = second.files.get("dwh.password")!;
expect(secondPath).toBe(firstPath);
expect(readFileSync(firstPath, "utf8")).toBe("correct horse battery staple");
first.release();
expect(readFileSync(secondPath, "utf8")).toBe("correct horse battery staple");
second.release();
expect(existsSync(secondPath)).toBe(false);
});
test("persists ciphertext and exposes status without exposing plaintext", () => {
const { root, store } = fixture();
const secret = "correct horse battery staple";