mirror of
https://github.com/jambonz/jambonz-feature-server.git
synced 2026-10-03 17:54:12 +00:00
This repo is public and held a long-lived AWS access key as repository secrets
(set 2023-11-22). It is replaced with short-lived credentials from the GitHub OIDC
provider; no AWS key and no account id remain in the repo.
create-test-db.js wrote {access_key_id, secret_access_key, aws_region} into the test
database as the aws speech credential, which sends speech-utils' getAwsAuthToken down
its access-key branch and calls GetSessionToken -- rejected by AWS for session
credentials. The role_arn branch calls AssumeRole instead, which accepts them, and is
already plumbed through db-utils.js, call-session.js and stt-task.js. The pinned
speech-utils 0.2.30 already supports it, so no dependency change is needed.
Fork pull requests receive neither secrets nor an OIDC token, so the credentials step
is guarded by a condition; the AWS tests then skip for forks exactly as they do today.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
84 lines
3.0 KiB
JavaScript
84 lines
3.0 KiB
JavaScript
const test = require('tape') ;
|
|
const exec = require('child_process').exec ;
|
|
const fs = require('fs');
|
|
const {encrypt} = require('../lib/utils/encrypt-decrypt');
|
|
const {
|
|
GCP_JSON_KEY,
|
|
AWS_ACCESS_KEY_ID,
|
|
AWS_ROLE_ARN,
|
|
AWS_SECRET_ACCESS_KEY,
|
|
AWS_REGION,
|
|
MICROSOFT_REGION,
|
|
MICROSOFT_API_KEY,
|
|
} = require('../lib/config');
|
|
|
|
test('creating jambones_test database', (t) => {
|
|
exec(`mysql -h 127.0.0.1 -u root --protocol=tcp --port=3360 < ${__dirname}/db/create_test_db.sql`, (err, stdout, stderr) => {
|
|
console.log(stdout);
|
|
console.log(stderr)
|
|
if (err) return t.end(err);
|
|
t.pass('database successfully created');
|
|
t.end();
|
|
});
|
|
});
|
|
|
|
test('creating schema', (t) => {
|
|
exec(`mysql -h 127.0.0.1 -u root --protocol=tcp --port=3360 -D jambones_test < ${__dirname}/db/create-and-populate-schema.sql`, (err, stdout, stderr) => {
|
|
if (err) return t.end(err);
|
|
t.pass('schema and test data successfully created');
|
|
|
|
const sql = [];
|
|
if (GCP_JSON_KEY) {
|
|
const google_credential = encrypt(GCP_JSON_KEY);
|
|
t.pass('adding google credentials');
|
|
sql.push(`UPDATE speech_credentials SET credential='${google_credential}' WHERE vendor='google';`);
|
|
}
|
|
// Prefer role_arn. Under GitHub OIDC the ambient credentials are temporary, and
|
|
// speech-utils' getAwsAuthToken calls GetSessionToken on its access-key branch --
|
|
// which AWS rejects for session credentials. The role_arn branch calls AssumeRole
|
|
// instead, which works with temporary credentials.
|
|
if (AWS_ROLE_ARN) {
|
|
const aws_credential = encrypt(JSON.stringify({
|
|
role_arn: AWS_ROLE_ARN,
|
|
aws_region: AWS_REGION
|
|
}));
|
|
t.pass('adding aws credentials (role_arn)');
|
|
sql.push(`UPDATE speech_credentials SET credential='${aws_credential}' WHERE vendor='aws';`);
|
|
}
|
|
else if (AWS_ACCESS_KEY_ID && AWS_SECRET_ACCESS_KEY) {
|
|
const aws_credential = encrypt(JSON.stringify({
|
|
access_key_id: AWS_ACCESS_KEY_ID,
|
|
secret_access_key: AWS_SECRET_ACCESS_KEY,
|
|
aws_region: AWS_REGION
|
|
}));
|
|
t.pass('adding aws credentials');
|
|
sql.push(`UPDATE speech_credentials SET credential='${aws_credential}' WHERE vendor='aws';`);
|
|
}
|
|
if (MICROSOFT_REGION && MICROSOFT_API_KEY) {
|
|
const microsoft_credential = encrypt(JSON.stringify({
|
|
region: MICROSOFT_REGION,
|
|
api_key: MICROSOFT_API_KEY
|
|
}));
|
|
t.pass('adding microsoft credentials');
|
|
sql.push(`UPDATE speech_credentials SET credential='${microsoft_credential}' WHERE vendor='microsoft';`);
|
|
}
|
|
if (sql.length > 0) {
|
|
const path = `${__dirname}/.creds.sql`;
|
|
const cmd = sql.join('\n');
|
|
fs.writeFileSync(path, sql.join('\n'));
|
|
exec(`mysql -h 127.0.0.1 -u root --protocol=tcp --port=3360 -D jambones_test < ${path}`, (err, stdout, stderr) => {
|
|
console.log(stdout);
|
|
console.log(stderr);
|
|
if (err) return t.end(err);
|
|
fs.unlinkSync(path)
|
|
t.pass('set account-level speech credentials');
|
|
t.end();
|
|
});
|
|
}
|
|
else {
|
|
t.end();
|
|
}
|
|
});
|
|
});
|
|
|