import assert from "node:assert/strict"; import { inspect } from "node:util"; import { test } from "node:test"; import { loadCustomerConfig, loadCustomerSecrets, parseInstallationConfig, serializeInstallationConfig, } from "../configuration/customer.ts"; import { loadControlPlaneConfig, loadControlPlaneSecrets, serializeControlPlaneConfig, } from "../configuration/control-plane.ts"; import { ConfigurationError } from "../configuration/validation.ts"; import { customerBindings, installation } from "./fixtures/config.mjs"; const secret = "sentinel-private-credential-do-not-disclose"; const controlPlane = { schemaVersion: 1, publicOrigin: "https://control.example.com", oauthClientId: "registered-flarebot-client", oauthRedirectUri: "https://control.example.com/auth/callback", oauthScopes: ["openid", "account.read", "workers-platform.write"], }; const controlBindings = { FLAREBOT_MODE: "control-plane", FLAREBOT_CONTROL_PLANE: JSON.stringify(controlPlane), FLAREBOT_SESSION_SECRET: secret, FLAREBOT_CREDENTIAL_ENCRYPTION_KEY: Buffer.alloc(32, 7).toString("base64url"), FLAREBOT_OAUTH_CLIENT_SECRET: secret, }; function rejectsSafely(action, field) { assert.throws(action, (error) => { assert.ok(error instanceof ConfigurationError); assert.ok(error.message.includes(field), error.message); assert.ok(!inspect(error).includes(secret)); assert.ok(!JSON.stringify(error).includes(secret)); return true; }); } test("production installation configuration round-trips separately from runtime secrets", () => { const config = loadCustomerConfig({ ...customerBindings, FLAREBOT_ENV: undefined, }); assert.equal(config.environment, "production"); assert.equal(config.mode, "customer-runtime"); assert.deepEqual( JSON.parse(serializeInstallationConfig(config.installation)), installation, ); assert.ok(Object.isFrozen(config.installation)); assert.ok( !JSON.stringify(config).includes(customerBindings.FLAREBOT_SESSION_SECRET), ); assert.equal( loadCustomerSecrets(customerBindings).sessionSecret.reveal(), customerBindings.FLAREBOT_SESSION_SECRET, ); }); test("missing settings, malformed JSON and invalid identities fail with safe recovery guidance", () => { for (const [key, value] of [ ["FLAREBOT_MODE", undefined], ["FLAREBOT_ENV", secret], ["FLAREBOT_INSTALLATION", undefined], ["FLAREBOT_INSTALLATION", `{${secret}`], ]) rejectsSafely( () => loadCustomerConfig({ ...customerBindings, [key]: value }), key, ); for (const [key, value] of [ ["schemaVersion", 2], ["installationId", secret], ["ownerSubject", ""], ["ownerSubject", { token: secret }], ]) { rejectsSafely( () => parseInstallationConfig({ ...installation, [key]: value }), key, ); } rejectsSafely( () => loadCustomerSecrets({ ...customerBindings, FLAREBOT_SESSION_SECRET: undefined, }), "FLAREBOT_SESSION_SECRET", ); rejectsSafely( () => loadCustomerSecrets({ ...customerBindings, FLAREBOT_SESSION_SECRET: "short", }), "wrangler secret put", ); }); test("nonsecret persistence rejects raw secrets, wrappers, nested fields and whole environments", () => { for (const extra of [ { apiKey: secret }, { sessionSecret: loadCustomerSecrets(customerBindings).sessionSecret }, { secrets: { token: secret } }, { [secret]: secret }, ]) { rejectsSafely( () => serializeInstallationConfig({ ...installation, ...extra }), "FLAREBOT_INSTALLATION", ); rejectsSafely( () => serializeControlPlaneConfig({ ...controlPlane, ...extra }), "FLAREBOT_CONTROL_PLANE", ); } rejectsSafely( () => serializeInstallationConfig(customerBindings), "FLAREBOT_INSTALLATION", ); rejectsSafely( () => serializeInstallationConfig(loadCustomerConfig(customerBindings)), "FLAREBOT_INSTALLATION", ); rejectsSafely( () => serializeInstallationConfig({ ...installation, ownerSubject: { secret }, }), "ownerSubject", ); }); test("secret wrappers redact JSON, interpolation, inspection and spread diagnostics", () => { const secrets = loadControlPlaneSecrets(controlBindings); assert.equal(secrets.oauthClientSecret.reveal(), secret); for (const output of [ JSON.stringify(secrets), inspect(secrets), `${secrets.sessionSecret}`, JSON.stringify({ ...secrets.sessionSecret }), ]) { assert.ok(!output.includes(secret)); assert.ok( !output.includes(controlBindings.FLAREBOT_CREDENTIAL_ENCRYPTION_KEY), ); } rejectsSafely( () => loadControlPlaneSecrets({ ...controlBindings, FLAREBOT_CREDENTIAL_ENCRYPTION_KEY: secret, }), "FLAREBOT_CREDENTIAL_ENCRYPTION_KEY", ); assert.equal( loadControlPlaneSecrets({ ...controlBindings, FLAREBOT_OAUTH_CLIENT_SECRET: undefined, }).oauthClientSecret, undefined, ); }); test("customer and control-plane modes, config keys and credentials cannot cross boundaries", () => { rejectsSafely(() => loadCustomerConfig(controlBindings), "FLAREBOT_MODE"); rejectsSafely(() => loadCustomerSecrets(controlBindings), "FLAREBOT_MODE"); rejectsSafely( () => loadControlPlaneSecrets(customerBindings), "FLAREBOT_MODE", ); rejectsSafely( () => loadControlPlaneConfig(customerBindings), "FLAREBOT_MODE", ); for (const key of [ "FLAREBOT_CONTROL_PLANE", "FLAREBOT_OAUTH_CLIENT_SECRET", "FLAREBOT_CREDENTIAL_ENCRYPTION_KEY", "FLAREBOT_UNKNOWN", ]) { rejectsSafely( () => loadCustomerConfig({ ...customerBindings, [key]: secret }), "Worker bindings", ); } rejectsSafely( () => loadControlPlaneConfig({ ...controlBindings, FLAREBOT_INSTALLATION: secret, }), "Worker bindings", ); // Platform bindings are outside the namespaced application config contract. assert.equal( loadCustomerConfig({ ...customerBindings, AI: {}, ASSETS: {} }).mode, "customer-runtime", ); const config = loadControlPlaneConfig(controlBindings); assert.equal(config.mode, "control-plane"); assert.deepEqual( JSON.parse(serializeControlPlaneConfig(config.config)), controlPlane, ); assert.ok(!JSON.stringify(config).includes(secret)); }); test("origins reject unsafe URLs and production cannot opt into development overrides", () => { for (const runtimeOrigin of [ "http://localhost:8787", "http://example.com", `https://${secret}@example.com`, "https://example.com/path", "https://example.com/", "https://example.com?q=1", "https://example.com#fragment", "javascript:alert(1)", ]) { rejectsSafely( () => parseInstallationConfig({ ...installation, runtimeOrigin }), "runtimeOrigin", ); } rejectsSafely( () => loadCustomerConfig({ ...customerBindings, FLAREBOT_DEV_OVERRIDES: "{}" }), "FLAREBOT_DEV_OVERRIDES", ); const dev = { ...customerBindings, FLAREBOT_ENV: "development", FLAREBOT_DEV_OVERRIDES: JSON.stringify({ runtimeOrigin: "http://localhost:8787", controlPlaneOrigin: "http://127.0.0.1:8788", }), }; const config = loadCustomerConfig(dev); assert.deepEqual(config.installation, installation); assert.equal( config.effectiveInstallation.runtimeOrigin, "http://localhost:8787", ); assert.equal( config.effectiveInstallation.ownerSubject, installation.ownerSubject, ); assert.equal( config.effectiveInstallation.installationId, installation.installationId, ); for (const overrides of [ { ownerSubject: secret }, { installationId: secret }, { runtimeOrigin: "http://remote.example.com" }, { sessionSecret: secret }, ]) { rejectsSafely( () => loadCustomerConfig({ ...dev, FLAREBOT_DEV_OVERRIDES: JSON.stringify(overrides), }), overrides.runtimeOrigin ? "runtimeOrigin" : "FLAREBOT_DEV_OVERRIDES", ); } }); test("OAuth redirect is bound to the configured origin and scope syntax accepts documented IDs", () => { for (const oauthRedirectUri of [ "https://evil.example.com/callback", `https://${secret}@control.example.com/callback`, "https://control.example.com/callback?token=secret", "https://control.example.com/callback#secret", ]) { rejectsSafely( () => loadControlPlaneConfig({ ...controlBindings, FLAREBOT_CONTROL_PLANE: JSON.stringify({ ...controlPlane, oauthRedirectUri, }), }), "oauthRedirectUri", ); } for (const oauthScopes of [[], ["workers:write"], [secret + " "]]) { rejectsSafely( () => loadControlPlaneConfig({ ...controlBindings, FLAREBOT_CONTROL_PLANE: JSON.stringify({ ...controlPlane, oauthScopes, }), }), "oauthScopes", ); } });