fix: stop the RoleArn synth test printing AWS credentials into CI logs (#161)

With renderForCaching unset, synthPolly returns the mediajam streaming params
string, and lib/synth-audio.js:337-340 embeds accessKeyId, secretAccessKey and
sessionToken in it. The test interpolated that value into its assertion message,
so run 32995180996 printed live (1 hour) AWS credentials into a public build log.

Every other synth test in this file passes renderForCaching: true; this one was
the only exception. It now does the same, and the assertion no longer interpolates
opts.filePath at all, so the streaming params string cannot leak this way again.

Latent since the test was written -- it only surfaced once AWS_ROLE_ARN was wired
up and the test actually ran.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Dave Horton
2026-08-26 13:44:05 -04:00
committed by GitHub
co-authored by Claude Opus 5
parent b928820906
commit 89fe0b87e9
+7 -1
View File
@@ -722,8 +722,14 @@ test('AWS speech synth tests by RoleArn', async(t) => {
// the same vendor/voice/language, and identical text would hit that cache entry,
// making servedFromCache true and this assertion fail.
text: 'This is a roleArn test. This is only a roleArn test',
// Without this, synthPolly returns the mediajam streaming params string, which
// embeds accessKeyId/secretAccessKey/sessionToken (see lib/synth-audio.js).
// Every other synth test in this file renders for caching; this one did not,
// so it printed live credentials into a public CI log.
renderForCaching: true,
});
t.ok(!opts.servedFromCache, `successfully synthesized aws by roleArn audio to ${opts.filePath}`);
// Deliberately does not interpolate opts.filePath -- it can carry credentials.
t.ok(!opts.servedFromCache, 'successfully synthesized aws by roleArn audio');
} catch (err) {
console.error(err);
t.end(err);