From 8c6e41a4ded6b684f82859cbc0f911fc5aff3419 Mon Sep 17 00:00:00 2001 From: Dave Horton Date: Wed, 26 Aug 2026 13:40:06 -0400 Subject: [PATCH] fix: stop the RoleArn synth test printing AWS credentials into CI logs With renderForCaching unset, synthPolly returns the mediajam streaming params string, and lib/synth-audio.js:337-340 embeds accessKeyId, secretAccessKey and sessionToken in it. The test interpolated that value into its assertion message, so run 32995180996 printed live (1 hour) AWS credentials into a public build log. Every other synth test in this file passes renderForCaching: true; this one was the only exception. It now does the same, and the assertion no longer interpolates opts.filePath at all, so the streaming params string cannot leak this way again. Latent since the test was written -- it only surfaced once AWS_ROLE_ARN was wired up and the test actually ran. Co-Authored-By: Claude Opus 5 --- test/synth.js | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/test/synth.js b/test/synth.js index e0cb486..c2d1ef6 100644 --- a/test/synth.js +++ b/test/synth.js @@ -722,8 +722,14 @@ test('AWS speech synth tests by RoleArn', async(t) => { // the same vendor/voice/language, and identical text would hit that cache entry, // making servedFromCache true and this assertion fail. text: 'This is a roleArn test. This is only a roleArn test', + // Without this, synthPolly returns the mediajam streaming params string, which + // embeds accessKeyId/secretAccessKey/sessionToken (see lib/synth-audio.js). + // Every other synth test in this file renders for caching; this one did not, + // so it printed live credentials into a public CI log. + renderForCaching: true, }); - t.ok(!opts.servedFromCache, `successfully synthesized aws by roleArn audio to ${opts.filePath}`); + // Deliberately does not interpolate opts.filePath -- it can carry credentials. + t.ok(!opts.servedFromCache, 'successfully synthesized aws by roleArn audio'); } catch (err) { console.error(err); t.end(err);