From 89fe0b87e971a7d6e7367dac67ad95655cdb107a Mon Sep 17 00:00:00 2001 From: Dave Horton Date: Wed, 26 Aug 2026 13:44:05 -0400 Subject: [PATCH] fix: stop the RoleArn synth test printing AWS credentials into CI logs (#161) With renderForCaching unset, synthPolly returns the mediajam streaming params string, and lib/synth-audio.js:337-340 embeds accessKeyId, secretAccessKey and sessionToken in it. The test interpolated that value into its assertion message, so run 32995180996 printed live (1 hour) AWS credentials into a public build log. Every other synth test in this file passes renderForCaching: true; this one was the only exception. It now does the same, and the assertion no longer interpolates opts.filePath at all, so the streaming params string cannot leak this way again. Latent since the test was written -- it only surfaced once AWS_ROLE_ARN was wired up and the test actually ran. Co-authored-by: Claude Opus 5 --- test/synth.js | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/test/synth.js b/test/synth.js index e0cb486..c2d1ef6 100644 --- a/test/synth.js +++ b/test/synth.js @@ -722,8 +722,14 @@ test('AWS speech synth tests by RoleArn', async(t) => { // the same vendor/voice/language, and identical text would hit that cache entry, // making servedFromCache true and this assertion fail. text: 'This is a roleArn test. This is only a roleArn test', + // Without this, synthPolly returns the mediajam streaming params string, which + // embeds accessKeyId/secretAccessKey/sessionToken (see lib/synth-audio.js). + // Every other synth test in this file renders for caching; this one did not, + // so it printed live credentials into a public CI log. + renderForCaching: true, }); - t.ok(!opts.servedFromCache, `successfully synthesized aws by roleArn audio to ${opts.filePath}`); + // Deliberately does not interpolate opts.filePath -- it can carry credentials. + t.ok(!opts.servedFromCache, 'successfully synthesized aws by roleArn audio'); } catch (err) { console.error(err); t.end(err);