Skip to content

fix: stop the RoleArn synth test printing AWS credentials into CI logs - #161

Merged
davehorton merged 1 commit into
mainfrom
fix/roleArn-test-credential-leak
Aug 26, 2026
Merged

davehorton merged 1 commit into
mainfrom
fix/roleArn-test-credential-leak

Conversation

@davehorton

@davehorton davehorton commented Aug 26, 2026 •

Copy link
Copy Markdown
Collaborator

Urgent

Run 32995180996 printed
live AWS credentials into a public build log:

ok 60 successfully synthesized aws by roleArn audio to say:{...
  accessKeyId=ASIA...,secretAccessKey=...,sessionToken=IQoJ...

They are temporary (role chaining caps at 1 hour) and the role is scoped to
Polly/Transcribe only, so blast radius is limited - but they were valid when logged.
Delete that run's logs independently of merging this.

Cause

With renderForCaching unset, synthPolly returns the mediajam streaming params string,
and lib/synth-audio.js:337-340 embeds the credentials into it:

params += `,accessKeyId=${cred.accessKeyId}`;
params += `,secretAccessKey=${cred.secretAccessKey}`;
params += `,sessionToken=${cred.sessionToken}`;

The test interpolated that return value into its assertion message via opts.filePath.

Every other synth test in test/synth.js passes renderForCaching: true - twelve of them.
The RoleArn test was the sole exception, so it alone took the streaming path.

Latent from the day the test was written; it surfaced only once AWS_ROLE_ARN was
supplied and the test ran for the first time.

Fix

  • add renderForCaching: true, matching every other synth test in the file
  • stop interpolating opts.filePath into the assertion message, so the params string
    cannot leak this way again even if the flag changes

No library code is touched.

Generated with Claude Code

With renderForCaching unset, synthPolly returns the mediajam streaming params
string, and lib/synth-audio.js:337-340 embeds accessKeyId, secretAccessKey and
sessionToken in it. The test interpolated that value into its assertion message,
so run 32995180996 printed live (1 hour) AWS credentials into a public build log.

Every other synth test in this file passes renderForCaching: true; this one was
the only exception. It now does the same, and the assertion no longer interpolates
opts.filePath at all, so the streaming params string cannot leak this way again.

Latent since the test was written -- it only surfaced once AWS_ROLE_ARN was wired
up and the test actually ran.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@davehorton
davehorton merged commit 89fe0b8 into main Aug 26, 2026
1 check passed
@davehorton
davehorton deleted the fix/roleArn-test-credential-leak branch August 26, 2026 17:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant