fix: stop the RoleArn synth test printing AWS credentials into CI logs - #161
Merged
Merged
Conversation
With renderForCaching unset, synthPolly returns the mediajam streaming params string, and lib/synth-audio.js:337-340 embeds accessKeyId, secretAccessKey and sessionToken in it. The test interpolated that value into its assertion message, so run 32995180996 printed live (1 hour) AWS credentials into a public build log. Every other synth test in this file passes renderForCaching: true; this one was the only exception. It now does the same, and the assertion no longer interpolates opts.filePath at all, so the streaming params string cannot leak this way again. Latent since the test was written -- it only surfaced once AWS_ROLE_ARN was wired up and the test actually ran. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Urgent
Run 32995180996 printed
live AWS credentials into a public build log:
They are temporary (role chaining caps at 1 hour) and the role is scoped to
Polly/Transcribe only, so blast radius is limited - but they were valid when logged.
Delete that run's logs independently of merging this.
Cause
With
renderForCachingunset,synthPollyreturns the mediajam streaming params string,and
lib/synth-audio.js:337-340embeds the credentials into it:The test interpolated that return value into its assertion message via
opts.filePath.Every other synth test in
test/synth.jspassesrenderForCaching: true- twelve of them.The RoleArn test was the sole exception, so it alone took the streaming path.
Latent from the day the test was written; it surfaced only once
AWS_ROLE_ARNwassupplied and the test ran for the first time.
Fix
renderForCaching: true, matching every other synth test in the fileopts.filePathinto the assertion message, so the params stringcannot leak this way again even if the flag changes
No library code is touched.
Generated with Claude Code