"""Credential rotation must override stale inherited keys without printing them.""" import os import subprocess import sys import tempfile import unittest from pathlib import Path class CredentialTests(unittest.TestCase): def check_mode(self, mode, expected): with tempfile.TemporaryDirectory() as directory: root = Path(directory) (root / "cred.txt").write_text( "ghp_not_a_real_github_key\nWANDB_API_KEY=new_fake_key\n" ) environment = { **os.environ, "ROOT": str(root), "LOG_DIR": str(root / "logs"), "SPEC_PYTHON": sys.executable, "WANDB_API_KEY": "old_fake_key", "WANDB_MODE": mode, } result = subprocess.run( ["bash", "-c", 'source "$1" && [[ "$WANDB_API_KEY" == "$2" ]]', "bash", str(Path(__file__).with_name("ngram_runtime_env.sh")), expected], env=environment, capture_output=True, text=True, check=False, ) self.assertEqual(result.returncode, 0, result.stderr) self.assertNotIn("fake_key", result.stdout + result.stderr) def test_online_uses_updated_file_over_inherited_key(self): self.check_mode("online", "new_fake_key") def test_disabled_does_not_load_credentials(self): self.check_mode("disabled", "old_fake_key") if __name__ == "__main__": unittest.main()