Regression for the env-inheritance hazard: a PROVIDER config secret that omits SESSION_TOKEN silently inherits a host AWS_SESSION_TOKEN env var (httpfs copies it into the global s3_session_token setting at load, and secret lookup falls back to settings for keys the secret omits) and signs with a mis
(t *testing.T)
| 107 | // with a mismatched (key, token) pair. buildConfigSecret must always pin the |
| 108 | // token explicitly — empty means "no token". |
| 109 | func TestBuildConfigSecretAlwaysEmitsSessionToken(t *testing.T) { |
| 110 | noToken := buildConfigSecret(DuckLakeConfig{ |
| 111 | S3AccessKey: "AKIA", |
| 112 | S3SecretKey: "sk", |
| 113 | }) |
| 114 | if !strings.Contains(noToken, "SESSION_TOKEN ''") { |
| 115 | t.Errorf("config secret without a token must pin SESSION_TOKEN '':\n%s", noToken) |
| 116 | } |
| 117 | withToken := buildConfigSecret(DuckLakeConfig{ |
| 118 | S3AccessKey: "ASIA", |
| 119 | S3SecretKey: "sk", |
| 120 | S3SessionToken: "tok", |
| 121 | }) |
| 122 | if !strings.Contains(withToken, "SESSION_TOKEN 'tok'") { |
| 123 | t.Errorf("config secret must carry the explicit token:\n%s", withToken) |
| 124 | } |
| 125 | } |
| 126 | |
| 127 | // TestBuildCredentialChainSecretEmitsHTTPWhenProxySet covers the |
| 128 | // credential-chain branch, which previously only emitted USE_SSL / |
nothing calls this directly
no test coverage detected