MCPcopy Create free account
hub / github.com/PostHog/duckgres / TestBuildConfigSecretAlwaysEmitsSessionToken

Function TestBuildConfigSecretAlwaysEmitsSessionToken

server/s3_secret_test.go:109–125  ·  view source on GitHub ↗

Regression for the env-inheritance hazard: a PROVIDER config secret that omits SESSION_TOKEN silently inherits a host AWS_SESSION_TOKEN env var (httpfs copies it into the global s3_session_token setting at load, and secret lookup falls back to settings for keys the secret omits) and signs with a mis

(t *testing.T)

Source from the content-addressed store, hash-verified

107// with a mismatched (key, token) pair. buildConfigSecret must always pin the
108// token explicitly — empty means "no token".
109func TestBuildConfigSecretAlwaysEmitsSessionToken(t *testing.T) {
110 noToken := buildConfigSecret(DuckLakeConfig{
111 S3AccessKey: "AKIA",
112 S3SecretKey: "sk",
113 })
114 if !strings.Contains(noToken, "SESSION_TOKEN ''") {
115 t.Errorf("config secret without a token must pin SESSION_TOKEN '':\n%s", noToken)
116 }
117 withToken := buildConfigSecret(DuckLakeConfig{
118 S3AccessKey: "ASIA",
119 S3SecretKey: "sk",
120 S3SessionToken: "tok",
121 })
122 if !strings.Contains(withToken, "SESSION_TOKEN 'tok'") {
123 t.Errorf("config secret must carry the explicit token:\n%s", withToken)
124 }
125}
126
127// TestBuildCredentialChainSecretEmitsHTTPWhenProxySet covers the
128// credential-chain branch, which previously only emitted USE_SSL /

Callers

nothing calls this directly

Calls 1

buildConfigSecretFunction · 0.85

Tested by

no test coverage detected