CodeIssuesDiscussionsWikiPull RequestsProjectsCommitsActionsReleasesContributorsPulse● GatesSecuritySettingsDeploymentsPipelineInsightsAgents✨ Explain✨ Ask AI✨ Workspace✨ Spec✨ Tests▓ Debt Map✨ NL Search🏛 Archaeology
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 | /**
* Pure-helper tests for src/lib/workflow-secrets.ts substituteSecrets.
*
* loadSecretsContext / upsert / delete are DB-coupled so they're not
* exercised here — the crypto round-trip lives in
* workflow-secrets-crypto.test.ts. This file pins the pure substitution
* grammar so the runner's secret-injection contract can be relied on
* without instantiating Postgres.
*/
import { describe, it, expect } from "bun:test";
import { substituteSecrets } from "../lib/workflow-secrets";
describe("substituteSecrets — happy path", () => {
it("replaces a single token with the matching plaintext", () => {
const out = substituteSecrets(
'echo "$TOKEN_${{ secrets.TOKEN }}"',
{ TOKEN: "abc123" }
);
expect(out).toBe('echo "$TOKEN_abc123"');
});
it("replaces multiple tokens in one template", () => {
const out = substituteSecrets(
"DEPLOY_KEY=${{ secrets.DEPLOY_KEY }} REGION=${{ secrets.REGION }}",
{ DEPLOY_KEY: "k1", REGION: "us-east-1" }
);
expect(out).toBe("DEPLOY_KEY=k1 REGION=us-east-1");
});
it("tolerates whitespace variants inside the braces", () => {
const map = { X: "v" };
expect(substituteSecrets("${{secrets.X}}", map)).toBe("v");
expect(substituteSecrets("${{ secrets.X }}", map)).toBe("v");
expect(substituteSecrets("${{ secrets . X }}", map)).toBe("v");
});
it("repeats substitution when a name appears multiple times", () => {
const out = substituteSecrets(
"${{ secrets.X }} and again ${{ secrets.X }}",
{ X: "yes" }
);
expect(out).toBe("yes and again yes");
});
});
describe("substituteSecrets — leaves tokens intact when secret is missing", () => {
it("missing name → token unchanged (loud failure signal)", () => {
const tpl = "echo ${{ secrets.MISSING }}";
expect(substituteSecrets(tpl, {})).toBe(tpl);
expect(substituteSecrets(tpl, { OTHER: "x" })).toBe(tpl);
});
it("substitutes the matching tokens and leaves the missing ones", () => {
const out = substituteSecrets(
"${{ secrets.A }} / ${{ secrets.B }} / ${{ secrets.C }}",
{ A: "a", C: "c" }
);
expect(out).toBe("a / ${{ secrets.B }} / c");
});
});
describe("substituteSecrets — strict name grammar", () => {
it("rejects lowercase names (matches GitHub Actions grammar)", () => {
const tpl = "echo ${{ secrets.lower }}";
expect(substituteSecrets(tpl, { lower: "x" })).toBe(tpl);
});
it("rejects names starting with a digit", () => {
const tpl = "echo ${{ secrets.1ABC }}";
expect(substituteSecrets(tpl, { "1ABC": "x" })).toBe(tpl);
});
it("accepts underscore-only names + names with digits", () => {
expect(
substituteSecrets("${{ secrets.A_B_C }}", { A_B_C: "v" })
).toBe("v");
expect(
substituteSecrets("${{ secrets._UNDER }}", { _UNDER: "v" })
).toBe("v");
expect(
substituteSecrets("${{ secrets.X1Y2 }}", { X1Y2: "v" })
).toBe("v");
});
});
describe("substituteSecrets — defensive on bad input", () => {
it("returns '' for non-string template", () => {
expect(substituteSecrets(undefined as any, {})).toBe("");
expect(substituteSecrets(null as any, {})).toBe("");
expect(substituteSecrets(42 as any, {})).toBe("");
});
it("returns the template untouched when secrets is null/undefined", () => {
expect(substituteSecrets("hello", null as any)).toBe("hello");
expect(substituteSecrets("hello", undefined as any)).toBe("hello");
});
it("returns '' when both inputs are empty", () => {
expect(substituteSecrets("", {})).toBe("");
});
it("ignores prototype-pollution probes (uses hasOwnProperty)", () => {
const tpl = "${{ secrets.TO_STRING }}";
// {}.toString exists on the prototype; substitution must NOT pick it up.
expect(substituteSecrets(tpl, {} as any)).toBe(tpl);
});
it("does not alter unrelated `${{ ... }}` syntax (env, vars)", () => {
const tpl = "${{ env.FOO }} ${{ vars.BAR }}";
expect(substituteSecrets(tpl, { FOO: "v" })).toBe(tpl);
});
});
|