mirror of
https://github.com/jambonz/speech-utils.git
synced 2026-10-03 23:33:59 +00:00
b9288209066e4535e86c42bba1fc550e703fdadf
* ci: authenticate to AWS via GitHub OIDC instead of stored access keys CI held a long-lived AWS access key as repository secrets. This replaces it with a short-lived credential obtained through the GitHub OIDC provider, so no AWS key is stored in the repo at all. The tests could not simply inherit the OIDC credentials. They passed AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY explicitly, which routes lib/get-aws-sts-token.js down its accessKeyId branch and calls GetSessionToken -- and AWS rejects GetSessionToken when it is called with session credentials. test/aws-credentials.js centralises the decision. When AWS_SESSION_TOKEN is present the credentials are temporary and only the region is passed, so the SDK's default credential provider chain is used. Static keys still work unchanged, which keeps local run-tests.sh working and also lets it run off an 'aws sso login' session with no credentials in the file. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * test: supply a cache key when AWS credentials come from the default chain getAwsAuthToken derives its cache key as roleArn || accessKeyId || speech_credential_sid. With temporary credentials the test passes none of those, so makeAwsKey received undefined and hash.update() threw ERR_INVALID_ARG_TYPE. Production never hits this: the instance-profile path always carries a speech_credential_sid from the database, which is exactly what the comment above that line describes. The test now supplies one the same way. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * ci: reference the CI role via secret rather than inlining the account id speech-utils is public, so the role ARN (and with it the AWS account id) should not be committed. It now comes from the AWS_ROLE_ARN secret, which also feeds the 'AWS speech synth tests by RoleArn' test -- previously always skipped, so the AssumeRole credential path had no coverage here. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * test: give the AWS RoleArn synth test its own cache key The RoleArn test synthesized the same vendor/voice/language/text as the plain AWS synth test that runs before it, so it hit that test's cache entry, servedFromCache came back true and the !servedFromCache assertion failed. Latent since the test was written -- it never ran, because AWS_ROLE_ARN was never supplied. Wiring the secret in activated it and exposed the collision. Distinct text makes the test independent of execution order. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Languages
JavaScript
99.8%
Dockerfile
0.2%