Something went wrong. Try again.
This repository has no description
Something went wrong. Try again.
JavaScript
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307import assert from "node:assert/strict";import { inspect } from "node:util";import { test } from "node:test";import { loadCustomerConfig, loadCustomerSecrets, parseInstallationConfig, serializeInstallationConfig,} from "../configuration/customer.ts";import { loadControlPlaneConfig, loadControlPlaneSecrets, serializeControlPlaneConfig,} from "../configuration/control-plane.ts";import { ConfigurationError } from "../configuration/validation.ts";import { customerBindings, installation } from "./fixtures/config.mjs";
const secret = "sentinel-private-credential-do-not-disclose";const controlPlane = { schemaVersion: 1, publicOrigin: "https://control.example.com", oauthClientId: "registered-flarebot-client", oauthRedirectUri: "https://control.example.com/auth/callback", oauthScopes: ["openid", "account.read", "workers-platform.write"],};const controlBindings = { FLAREBOT_MODE: "control-plane", FLAREBOT_CONTROL_PLANE: JSON.stringify(controlPlane), FLAREBOT_SESSION_SECRET: secret, FLAREBOT_CREDENTIAL_ENCRYPTION_KEY: Buffer.alloc(32, 7).toString("base64url"), FLAREBOT_OAUTH_CLIENT_SECRET: secret,};
function rejectsSafely(action, field) { assert.throws(action, (error) => { assert.ok(error instanceof ConfigurationError); assert.ok(error.message.includes(field), error.message); assert.ok(!inspect(error).includes(secret)); assert.ok(!JSON.stringify(error).includes(secret)); return true; });}
test("production installation configuration round-trips separately from runtime secrets", () => { const config = loadCustomerConfig({ ...customerBindings, FLAREBOT_ENV: undefined, }); assert.equal(config.environment, "production"); assert.equal(config.mode, "customer-runtime"); assert.deepEqual( JSON.parse(serializeInstallationConfig(config.installation)), installation, ); assert.ok(Object.isFrozen(config.installation)); assert.ok( !JSON.stringify(config).includes(customerBindings.FLAREBOT_SESSION_SECRET), ); assert.equal( loadCustomerSecrets(customerBindings).sessionSecret.reveal(), customerBindings.FLAREBOT_SESSION_SECRET, );});
test("missing settings, malformed JSON and invalid identities fail with safe recovery guidance", () => { for (const [key, value] of [ ["FLAREBOT_MODE", undefined], ["FLAREBOT_ENV", secret], ["FLAREBOT_INSTALLATION", undefined], ["FLAREBOT_INSTALLATION", `{${secret}`], ]) rejectsSafely( () => loadCustomerConfig({ ...customerBindings, [key]: value }), key, ); for (const [key, value] of [ ["schemaVersion", 2], ["installationId", secret], ["ownerSubject", ""], ["ownerSubject", { token: secret }], ]) { rejectsSafely( () => parseInstallationConfig({ ...installation, [key]: value }), key, ); } rejectsSafely( () => loadCustomerSecrets({ ...customerBindings, FLAREBOT_SESSION_SECRET: undefined, }), "FLAREBOT_SESSION_SECRET", ); rejectsSafely( () => loadCustomerSecrets({ ...customerBindings, FLAREBOT_SESSION_SECRET: "short", }), "wrangler secret put", );});
test("nonsecret persistence rejects raw secrets, wrappers, nested fields and whole environments", () => { for (const extra of [ { apiKey: secret }, { sessionSecret: loadCustomerSecrets(customerBindings).sessionSecret }, { secrets: { token: secret } }, { [secret]: secret }, ]) { rejectsSafely( () => serializeInstallationConfig({ ...installation, ...extra }), "FLAREBOT_INSTALLATION", ); rejectsSafely( () => serializeControlPlaneConfig({ ...controlPlane, ...extra }), "FLAREBOT_CONTROL_PLANE", ); } rejectsSafely( () => serializeInstallationConfig(customerBindings), "FLAREBOT_INSTALLATION", ); rejectsSafely( () => serializeInstallationConfig(loadCustomerConfig(customerBindings)), "FLAREBOT_INSTALLATION", ); rejectsSafely( () => serializeInstallationConfig({ ...installation, ownerSubject: { secret }, }), "ownerSubject", );});
test("secret wrappers redact JSON, interpolation, inspection and spread diagnostics", () => { const secrets = loadControlPlaneSecrets(controlBindings); assert.equal(secrets.oauthClientSecret.reveal(), secret); for (const output of [ JSON.stringify(secrets), inspect(secrets), `${secrets.sessionSecret}`, JSON.stringify({ ...secrets.sessionSecret }), ]) { assert.ok(!output.includes(secret)); assert.ok( !output.includes(controlBindings.FLAREBOT_CREDENTIAL_ENCRYPTION_KEY), ); } rejectsSafely( () => loadControlPlaneSecrets({ ...controlBindings, FLAREBOT_CREDENTIAL_ENCRYPTION_KEY: secret, }), "FLAREBOT_CREDENTIAL_ENCRYPTION_KEY", ); assert.equal( loadControlPlaneSecrets({ ...controlBindings, FLAREBOT_OAUTH_CLIENT_SECRET: undefined, }).oauthClientSecret, undefined, );});
test("customer and control-plane modes, config keys and credentials cannot cross boundaries", () => { rejectsSafely(() => loadCustomerConfig(controlBindings), "FLAREBOT_MODE"); rejectsSafely(() => loadCustomerSecrets(controlBindings), "FLAREBOT_MODE"); rejectsSafely( () => loadControlPlaneSecrets(customerBindings), "FLAREBOT_MODE", ); rejectsSafely( () => loadControlPlaneConfig(customerBindings), "FLAREBOT_MODE", ); for (const key of [ "FLAREBOT_CONTROL_PLANE", "FLAREBOT_OAUTH_CLIENT_SECRET", "FLAREBOT_CREDENTIAL_ENCRYPTION_KEY", "FLAREBOT_UNKNOWN", ]) { rejectsSafely( () => loadCustomerConfig({ ...customerBindings, [key]: secret }), "Worker bindings", ); } rejectsSafely( () => loadControlPlaneConfig({ ...controlBindings, FLAREBOT_INSTALLATION: secret, }), "Worker bindings", ); // Platform bindings are outside the namespaced application config contract. assert.equal( loadCustomerConfig({ ...customerBindings, AI: {}, ASSETS: {} }).mode, "customer-runtime", ); const config = loadControlPlaneConfig(controlBindings); assert.equal(config.mode, "control-plane"); assert.deepEqual( JSON.parse(serializeControlPlaneConfig(config.config)), controlPlane, ); assert.ok(!JSON.stringify(config).includes(secret));});
test("origins reject unsafe URLs and production cannot opt into development overrides", () => { for (const runtimeOrigin of [ "http://localhost:8787", "http://example.com", `https://${secret}@example.com`, "https://example.com/path", "https://example.com/", "https://example.com?q=1", "https://example.com#fragment", "javascript:alert(1)", ]) { rejectsSafely( () => parseInstallationConfig({ ...installation, runtimeOrigin }), "runtimeOrigin", ); } rejectsSafely( () => loadCustomerConfig({ ...customerBindings, FLAREBOT_DEV_OVERRIDES: "{}" }), "FLAREBOT_DEV_OVERRIDES", ); const dev = { ...customerBindings, FLAREBOT_ENV: "development", FLAREBOT_DEV_OVERRIDES: JSON.stringify({ runtimeOrigin: "http://localhost:8787", controlPlaneOrigin: "http://127.0.0.1:8788", }), }; const config = loadCustomerConfig(dev); assert.deepEqual(config.installation, installation); assert.equal( config.effectiveInstallation.runtimeOrigin, "http://localhost:8787", ); assert.equal( config.effectiveInstallation.ownerSubject, installation.ownerSubject, ); assert.equal( config.effectiveInstallation.installationId, installation.installationId, ); for (const overrides of [ { ownerSubject: secret }, { installationId: secret }, { runtimeOrigin: "http://remote.example.com" }, { sessionSecret: secret }, ]) { rejectsSafely( () => loadCustomerConfig({ ...dev, FLAREBOT_DEV_OVERRIDES: JSON.stringify(overrides), }), overrides.runtimeOrigin ? "runtimeOrigin" : "FLAREBOT_DEV_OVERRIDES", ); }});
test("OAuth redirect is bound to the configured origin and scope syntax accepts documented IDs", () => { for (const oauthRedirectUri of [ "https://evil.example.com/callback", `https://${secret}@control.example.com/callback`, "https://control.example.com/callback?token=secret", "https://control.example.com/callback#secret", ]) { rejectsSafely( () => loadControlPlaneConfig({ ...controlBindings, FLAREBOT_CONTROL_PLANE: JSON.stringify({ ...controlPlane, oauthRedirectUri, }), }), "oauthRedirectUri", ); } for (const oauthScopes of [[], ["workers:write"], [secret + " "]]) { rejectsSafely( () => loadControlPlaneConfig({ ...controlBindings, FLAREBOT_CONTROL_PLANE: JSON.stringify({ ...controlPlane, oauthScopes, }), }), "oauthScopes", ); }});