135 lines
4.9 KiB
TypeScript
135 lines
4.9 KiB
TypeScript
import { mkdtempSync, readFileSync, rmSync } from "node:fs";
|
|
import { tmpdir } from "node:os";
|
|
import { join } from "node:path";
|
|
import { afterEach, expect, test } from "vitest";
|
|
|
|
import {
|
|
discoverWorkspaceSecretRequirements,
|
|
resolveRuntimeBindingsWithWorkspaceSecrets,
|
|
} from "../src/workspaces/secret-requirements.js";
|
|
import { WorkspaceSecretStore } from "../src/workspaces/secret-store.js";
|
|
import { parseWorkspaceYaml } from "../src/workspaces/schema.js";
|
|
|
|
const roots: string[] = [];
|
|
|
|
function workspace(extra = "") {
|
|
return parseWorkspaceYaml(`workspace:
|
|
schema_version: 4
|
|
id: psd-clinical
|
|
name: Policlinico San Donato
|
|
language: en
|
|
dwh:
|
|
engine: postgres
|
|
database: postgres
|
|
schema: datawarehouse
|
|
supported_transports: [postgres_direct, rest_api, ssh_tunnel]
|
|
${extra}`);
|
|
}
|
|
|
|
function store() {
|
|
const root = mkdtempSync(join(tmpdir(), "thoth-requirement-vault-"));
|
|
const runtimeRoot = mkdtempSync(join(tmpdir(), "thoth-requirement-runtime-"));
|
|
roots.push(root, runtimeRoot);
|
|
return new WorkspaceSecretStore({ root, runtimeRoot, installationId: "test-installation" });
|
|
}
|
|
|
|
afterEach(() => {
|
|
for (const root of roots.splice(0)) rmSync(root, { recursive: true, force: true });
|
|
});
|
|
|
|
test("requirements follow the selected DWH transport", () => {
|
|
const descriptor = workspace();
|
|
const direct = discoverWorkspaceSecretRequirements(descriptor, {
|
|
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
|
});
|
|
expect(direct.map(({ id, required }) => ({ id, required }))).toEqual([
|
|
{ id: "dwh.password", required: true },
|
|
]);
|
|
|
|
const rest = discoverWorkspaceSecretRequirements(descriptor, {
|
|
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api",
|
|
});
|
|
expect(rest.map(({ id }) => id)).toEqual(["dwh.api_key"]);
|
|
|
|
const ssh = discoverWorkspaceSecretRequirements(descriptor, {
|
|
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "ssh_tunnel",
|
|
});
|
|
expect(ssh.map(({ id }) => id)).toEqual(["dwh.password", "dwh.ssh_private_key"]);
|
|
});
|
|
|
|
test("REST without authentication does not request an API key", () => {
|
|
const descriptor = workspace(`diagnostics:
|
|
dwh_rest:
|
|
method: GET
|
|
path: /health
|
|
auth: none
|
|
response: { database: database, schema: schema }
|
|
`);
|
|
expect(discoverWorkspaceSecretRequirements(descriptor, {
|
|
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api",
|
|
})).toEqual([]);
|
|
});
|
|
|
|
test("evidence requirements follow the descriptor authentication mechanism", () => {
|
|
const signed = workspace(`evidence:
|
|
source:
|
|
type: http
|
|
uris: [https://evidence.example.test/guide.md]
|
|
authentication: signed_urls_file
|
|
policy: { max_chunk_chars: 4000, retain_published_generations: 2 }
|
|
`);
|
|
expect(discoverWorkspaceSecretRequirements(signed, {
|
|
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
|
}).map(({ id, required }) => ({ id, required }))).toEqual([
|
|
{ id: "dwh.password", required: true },
|
|
{ id: "evidence.signed_urls", required: true },
|
|
]);
|
|
|
|
const s3 = workspace(`evidence:
|
|
source: { type: s3, uri: s3://clinical-evidence/published/, credentials: static_files }
|
|
policy: { max_chunk_chars: 4000, retain_published_generations: 2 }
|
|
`);
|
|
expect(discoverWorkspaceSecretRequirements(s3, {
|
|
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
|
}).map(({ id, required }) => ({ id, required }))).toEqual([
|
|
{ id: "dwh.password", required: true },
|
|
{ id: "evidence.access_key", required: true },
|
|
{ id: "evidence.secret_key", required: true },
|
|
{ id: "evidence.session_token", required: false },
|
|
]);
|
|
});
|
|
|
|
test("vault values are mapped to temporary file bindings and released", () => {
|
|
const descriptor = workspace();
|
|
const vault = store();
|
|
vault.put("psd-clinical", "dwh.password", "runtime-password");
|
|
const environment = {
|
|
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
|
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
|
|
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
|
|
THT_WS_PSD_CLINICAL_DWH_USER: "reader",
|
|
};
|
|
|
|
const lease = resolveRuntimeBindingsWithWorkspaceSecrets(descriptor, environment, [], vault);
|
|
expect(lease.bindings.dwh.missing).toEqual([]);
|
|
const secretPath = lease.bindings.dwh.values.THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE!;
|
|
expect(readFileSync(secretPath, "utf8")).toBe("runtime-password");
|
|
lease.release();
|
|
expect(() => readFileSync(secretPath, "utf8")).toThrow();
|
|
});
|
|
|
|
test("missing vault values remain missing and materialization never mutates the source environment", () => {
|
|
const descriptor = workspace();
|
|
const vault = store();
|
|
const environment = {
|
|
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
|
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
|
|
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
|
|
THT_WS_PSD_CLINICAL_DWH_USER: "reader",
|
|
};
|
|
const lease = resolveRuntimeBindingsWithWorkspaceSecrets(descriptor, environment, [], vault);
|
|
expect(lease.bindings.dwh.missing).toContain("THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE");
|
|
expect(environment).not.toHaveProperty("THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE");
|
|
lease.release();
|
|
});
|