1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
|
import { describe, it, expect } from "bun:test";
import { substituteSecrets } from "../lib/workflow-secrets";
describe("substituteSecrets — happy path", () => {
it("replaces a single token with the matching plaintext", () => {
const out = substituteSecrets(
'echo "$TOKEN_${{ secrets.TOKEN }}"',
{ TOKEN: "abc123" }
);
expect(out).toBe('echo "$TOKEN_abc123"');
});
it("replaces multiple tokens in one template", () => {
const out = substituteSecrets(
"DEPLOY_KEY=${{ secrets.DEPLOY_KEY }} REGION=${{ secrets.REGION }}",
{ DEPLOY_KEY: "k1", REGION: "us-east-1" }
);
expect(out).toBe("DEPLOY_KEY=k1 REGION=us-east-1");
});
it("tolerates whitespace variants inside the braces", () => {
const map = { X: "v" };
expect(substituteSecrets("${{secrets.X}}", map)).toBe("v");
expect(substituteSecrets("${{ secrets.X }}", map)).toBe("v");
expect(substituteSecrets("${{ secrets . X }}", map)).toBe("v");
});
it("repeats substitution when a name appears multiple times", () => {
const out = substituteSecrets(
"${{ secrets.X }} and again ${{ secrets.X }}",
{ X: "yes" }
);
expect(out).toBe("yes and again yes");
});
});
describe("substituteSecrets — leaves tokens intact when secret is missing", () => {
it("missing name → token unchanged (loud failure signal)", () => {
const tpl = "echo ${{ secrets.MISSING }}";
expect(substituteSecrets(tpl, {})).toBe(tpl);
expect(substituteSecrets(tpl, { OTHER: "x" })).toBe(tpl);
});
it("substitutes the matching tokens and leaves the missing ones", () => {
const out = substituteSecrets(
"${{ secrets.A }} / ${{ secrets.B }} / ${{ secrets.C }}",
{ A: "a", C: "c" }
);
expect(out).toBe("a / ${{ secrets.B }} / c");
});
});
describe("substituteSecrets — strict name grammar", () => {
it("rejects lowercase names (matches GitHub Actions grammar)", () => {
const tpl = "echo ${{ secrets.lower }}";
expect(substituteSecrets(tpl, { lower: "x" })).toBe(tpl);
});
it("rejects names starting with a digit", () => {
const tpl = "echo ${{ secrets.1ABC }}";
expect(substituteSecrets(tpl, { "1ABC": "x" })).toBe(tpl);
});
it("accepts underscore-only names + names with digits", () => {
expect(
substituteSecrets("${{ secrets.A_B_C }}", { A_B_C: "v" })
).toBe("v");
expect(
substituteSecrets("${{ secrets._UNDER }}", { _UNDER: "v" })
).toBe("v");
expect(
substituteSecrets("${{ secrets.X1Y2 }}", { X1Y2: "v" })
).toBe("v");
});
});
describe("substituteSecrets — defensive on bad input", () => {
it("returns '' for non-string template", () => {
expect(substituteSecrets(undefined as any, {})).toBe("");
expect(substituteSecrets(null as any, {})).toBe("");
expect(substituteSecrets(42 as any, {})).toBe("");
});
it("returns the template untouched when secrets is null/undefined", () => {
expect(substituteSecrets("hello", null as any)).toBe("hello");
expect(substituteSecrets("hello", undefined as any)).toBe("hello");
});
it("returns '' when both inputs are empty", () => {
expect(substituteSecrets("", {})).toBe("");
});
it("ignores prototype-pollution probes (uses hasOwnProperty)", () => {
const tpl = "${{ secrets.TO_STRING }}";
expect(substituteSecrets(tpl, {} as any)).toBe(tpl);
});
it("does not alter unrelated `${{ ... }}` syntax (env, vars)", () => {
const tpl = "${{ env.FOO }} ${{ vars.BAR }}";
expect(substituteSecrets(tpl, { FOO: "v" })).toBe(tpl);
});
});
|