TestBuildConfigSecretEmitsHTTPWhenProxySet asserts the SQL produced by buildConfigSecret contains URL_STYLE 'path' / USE_SSL false when an HTTP proxy is in front, and the org's preferred values otherwise.
(t *testing.T)
| 68 | // buildConfigSecret contains URL_STYLE 'path' / USE_SSL false when an |
| 69 | // HTTP proxy is in front, and the org's preferred values otherwise. |
| 70 | func TestBuildConfigSecretEmitsHTTPWhenProxySet(t *testing.T) { |
| 71 | withProxy := buildConfigSecret(DuckLakeConfig{ |
| 72 | S3AccessKey: "AKIA", |
| 73 | S3SecretKey: "secret", |
| 74 | S3Region: "us-east-1", |
| 75 | S3Endpoint: "s3.us-east-1.amazonaws.com", |
| 76 | S3URLStyle: "vhost", |
| 77 | S3UseSSL: true, |
| 78 | HTTPProxy: "http://10.0.0.1:8080", |
| 79 | }) |
| 80 | if !strings.Contains(withProxy, "URL_STYLE 'path'") { |
| 81 | t.Errorf("expected URL_STYLE 'path' with proxy set, got:\n%s", withProxy) |
| 82 | } |
| 83 | if !strings.Contains(withProxy, "USE_SSL false") { |
| 84 | t.Errorf("expected USE_SSL false with proxy set, got:\n%s", withProxy) |
| 85 | } |
| 86 | |
| 87 | withoutProxy := buildConfigSecret(DuckLakeConfig{ |
| 88 | S3AccessKey: "AKIA", |
| 89 | S3SecretKey: "secret", |
| 90 | S3Region: "us-east-1", |
| 91 | S3Endpoint: "s3.us-east-1.amazonaws.com", |
| 92 | S3URLStyle: "vhost", |
| 93 | S3UseSSL: true, |
| 94 | }) |
| 95 | if !strings.Contains(withoutProxy, "URL_STYLE 'vhost'") { |
| 96 | t.Errorf("expected URL_STYLE 'vhost' without proxy, got:\n%s", withoutProxy) |
| 97 | } |
| 98 | if !strings.Contains(withoutProxy, "USE_SSL true") { |
| 99 | t.Errorf("expected USE_SSL true without proxy, got:\n%s", withoutProxy) |
| 100 | } |
| 101 | } |
| 102 | |
| 103 | // Regression for the env-inheritance hazard: a PROVIDER config secret that |
| 104 | // omits SESSION_TOKEN silently inherits a host AWS_SESSION_TOKEN env var |
nothing calls this directly
no test coverage detected