@@ -515,6 +515,94 @@ describe("/datasources", () => {
515515 )
516516 } )
517517
518+ it ( "detects embedded env var references" , async ( ) => {
519+ const ds = await config . api . datasource . create ( {
520+ type : "datasource" ,
521+ name : "REST embedded env var" ,
522+ source : SourceName . REST ,
523+ config : {
524+ url : "https://{{ env.HOST }}/api" ,
525+ } ,
526+ } )
527+
528+ expect ( ds . usesEnvironmentVariables ) . toBe ( true )
529+ } )
530+
531+ it ( "scrubs secrets containing mixed literals and env var references" , async ( ) => {
532+ const ds = await config . api . datasource . create ( {
533+ type : "datasource" ,
534+ name : "REST mixed env secret" ,
535+ source : SourceName . REST ,
536+ config : {
537+ authConfigs : [
538+ {
539+ _id : generator . guid ( ) ,
540+ name : "Mixed Env Auth" ,
541+ type : RestAuthType . BASIC ,
542+ config : {
543+ username : "{{ env.USERNAME }}" ,
544+ password : "prefix {{ env.PASSWORD }}" ,
545+ } ,
546+ } ,
547+ ] ,
548+ } ,
549+ } )
550+
551+ expect ( ds . usesEnvironmentVariables ) . toBe ( true )
552+ expect ( ds . config ! . authConfigs [ 0 ] . config . password ) . toBe (
553+ PASSWORD_REPLACEMENT
554+ )
555+ } )
556+
557+ it ( "preserves secrets composed of adjacent env var references" , async ( ) => {
558+ const password = "{{ env.PASSWORD_PREFIX }}{{ env.PASSWORD_SUFFIX }}"
559+ const ds = await config . api . datasource . create ( {
560+ type : "datasource" ,
561+ name : "REST adjacent env secrets" ,
562+ source : SourceName . REST ,
563+ config : {
564+ authConfigs : [
565+ {
566+ _id : generator . guid ( ) ,
567+ name : "Adjacent Env Auth" ,
568+ type : RestAuthType . BASIC ,
569+ config : {
570+ username : "{{ env.USERNAME }}" ,
571+ password,
572+ } ,
573+ } ,
574+ ] ,
575+ } ,
576+ } )
577+
578+ expect ( ds . config ! . authConfigs [ 0 ] . config . password ) . toBe ( password )
579+ } )
580+
581+ it ( "scrubs secrets combining env and non-env bindings" , async ( ) => {
582+ const ds = await config . api . datasource . create ( {
583+ type : "datasource" ,
584+ name : "REST mixed binding secret" ,
585+ source : SourceName . REST ,
586+ config : {
587+ authConfigs : [
588+ {
589+ _id : generator . guid ( ) ,
590+ name : "Mixed Binding Auth" ,
591+ type : RestAuthType . BASIC ,
592+ config : {
593+ username : "{{ env.USERNAME }}" ,
594+ password : "{{ env.PASSWORD }}{{ user.password }}" ,
595+ } ,
596+ } ,
597+ ] ,
598+ } ,
599+ } )
600+
601+ expect ( ds . config ! . authConfigs [ 0 ] . config . password ) . toBe (
602+ PASSWORD_REPLACEMENT
603+ )
604+ } )
605+
518606 it ( "scrubs sensitive longform fields in get response" , async ( ) => {
519607 const privateKey = [
520608 "-----BEGIN PRIVATE KEY-----" ,
0 commit comments