import { mkdtempSync, readFileSync, rmSync } from "node:fs"; import { tmpdir } from "node:os"; import { join } from "node:path"; import { afterEach, expect, test } from "vitest"; import { discoverWorkspaceSecretRequirements, resolveRuntimeBindingsWithWorkspaceSecrets, } from "../src/workspaces/secret-requirements.js"; import { WorkspaceSecretStore } from "../src/workspaces/secret-store.js"; import { parseWorkspaceYaml } from "../src/workspaces/schema.js"; const roots: string[] = []; function workspace(extra = "") { return parseWorkspaceYaml(`workspace: schema_version: 4 id: psd-clinical name: Policlinico San Donato language: en dwh: engine: postgres database: postgres schema: datawarehouse supported_transports: [postgres_direct, rest_api, ssh_tunnel] ${extra}`); } function store() { const root = mkdtempSync(join(tmpdir(), "thoth-requirement-vault-")); const runtimeRoot = mkdtempSync(join(tmpdir(), "thoth-requirement-runtime-")); roots.push(root, runtimeRoot); return new WorkspaceSecretStore({ root, runtimeRoot, installationId: "test-installation" }); } afterEach(() => { for (const root of roots.splice(0)) rmSync(root, { recursive: true, force: true }); }); test("requirements follow the selected DWH transport", () => { const descriptor = workspace(); const direct = discoverWorkspaceSecretRequirements(descriptor, { THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct", }); expect(direct.map(({ id, required }) => ({ id, required }))).toEqual([ { id: "dwh.password", required: true }, ]); const rest = discoverWorkspaceSecretRequirements(descriptor, { THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api", }); expect(rest.map(({ id }) => id)).toEqual(["dwh.api_key"]); const ssh = discoverWorkspaceSecretRequirements(descriptor, { THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "ssh_tunnel", }); expect(ssh.map(({ id }) => id)).toEqual(["dwh.password", "dwh.ssh_private_key"]); }); test("REST without authentication does not request an API key", () => { const descriptor = workspace(`diagnostics: dwh_rest: method: GET path: /health auth: none response: { database: database, schema: schema } `); expect(discoverWorkspaceSecretRequirements(descriptor, { THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api", })).toEqual([]); }); test("evidence requirements follow the descriptor authentication mechanism", () => { const signed = workspace(`evidence: source: type: http uris: [https://evidence.example.test/guide.md] authentication: signed_urls_file policy: { max_chunk_chars: 4000, retain_published_generations: 2 } `); expect(discoverWorkspaceSecretRequirements(signed, { THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct", }).map(({ id, required }) => ({ id, required }))).toEqual([ { id: "dwh.password", required: true }, { id: "evidence.signed_urls", required: true }, ]); const s3 = workspace(`evidence: source: { type: s3, uri: s3://clinical-evidence/published/, credentials: static_files } policy: { max_chunk_chars: 4000, retain_published_generations: 2 } `); expect(discoverWorkspaceSecretRequirements(s3, { THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct", }).map(({ id, required }) => ({ id, required }))).toEqual([ { id: "dwh.password", required: true }, { id: "evidence.access_key", required: true }, { id: "evidence.secret_key", required: true }, { id: "evidence.session_token", required: false }, ]); }); test("vault values are mapped to temporary file bindings and released", () => { const descriptor = workspace(); const vault = store(); vault.put("psd-clinical", "dwh.password", "runtime-password"); const environment = { THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct", THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal", THT_WS_PSD_CLINICAL_DWH_PORT: "5432", THT_WS_PSD_CLINICAL_DWH_USER: "reader", }; const lease = resolveRuntimeBindingsWithWorkspaceSecrets(descriptor, environment, [], vault); expect(lease.bindings.dwh.missing).toEqual([]); const secretPath = lease.bindings.dwh.values.THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE!; expect(readFileSync(secretPath, "utf8")).toBe("runtime-password"); lease.release(); expect(() => readFileSync(secretPath, "utf8")).toThrow(); }); test("missing vault values remain missing and materialization never mutates the source environment", () => { const descriptor = workspace(); const vault = store(); const environment = { THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct", THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal", THT_WS_PSD_CLINICAL_DWH_PORT: "5432", THT_WS_PSD_CLINICAL_DWH_USER: "reader", }; const lease = resolveRuntimeBindingsWithWorkspaceSecrets(descriptor, environment, [], vault); expect(lease.bindings.dwh.missing).toContain("THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE"); expect(environment).not.toHaveProperty("THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE"); lease.release(); });