Skip to content

ci(sdk): fail the export snapshot on secret-bearing symbols (#412) - #467

Open
Hustler490 wants to merge 1 commit into
Sub-Rosa-Issue:mainfrom
Hustler490:ci/sdk-export-secret-guard
Open

Hustler490 wants to merge 1 commit into
Sub-Rosa-Issue:mainfrom
Hustler490:ci/sdk-export-secret-guard

Conversation

@Hustler490

Copy link
Copy Markdown

Closes #412.

What

Hardens the SDK public-API snapshot test so an accidentally-exported secret-bearing symbol fails CI.

  • Static, source-based comparison. The test now parses packages/sdk/src/index.ts instead of importing the SDK, so it never constructs a network client (acceptance Add bounded retry and backoff policies to keeper RPC and Drand operations #4) and does not depend on the runtime module graph.
  • Extra/missing detection. Any export not in the committed EXPECTED_EXPORTS snapshot fails, and any snapshot entry no longer exported fails.
  • Secret-symbol guard. Any exported value or type whose name matches /(secret|seed|keypair|privatekey|privkey|mnemonic|rawkey|...)/i fails, even if it has been added to the snapshot - unless the name is on the explicit, reviewed ALLOWLISTED_SECRET_SYMBOLS set (empty today). This is the "fail even if added to the snapshot without the allowlist" criterion.
  • Snapshot updated to the current declared surface (10 legitimate exports - ROUND_PHASES, ROUND_PHASE_LABELS, isRoundPhase, roundPhaseLabel, ROUND_EVENT_*, expectedRoundEventSequence, diffContractErrorMapping, validatePasskeySession - were missing from the stale snapshot).

Focused base fixes (to make the declared surface match the snapshot)

  • Added the missing SubRosaPaginationError class to errors.ts (used by client.ts but previously undefined).
  • Re-exported networkPassphrasesMatch + SubRosaNetworkPassphraseMismatchError (from network.ts) and parseMicroStroops (from mainnet-readiness.ts) from index.ts, which the committed snapshot already expected.

Tests

node --import tsx --test src/public-api-snapshot.test.ts -> 12 passed (snapshot match, no secret-bearing value/type, extra/missing guards, value/type separation, source-level secret-type detection, allowlist).

Honest note on the base

This is a focused change per maintainer direction. main is independently broken: packages/sdk/src/errors.ts is missing the ROUND_CONTRACT_ERRORS mapping (getRoundContractError / isRoundContractErrorRetryable / diffContractErrorMapping / ROUND_CONTRACT_ERRORS_BY_NAME) that index.ts re-exports and errors.test.ts imports - so importing the SDK (and sdk:typecheck) still fails for reasons unrelated to this PR. The snapshot test no longer imports the SDK, so it runs and passes regardless. I can reconstruct the error mapping in a follow-up if you'd like #412 to also unblock the runtime import.

@drips-wave

drips-wave Bot commented Oct 1, 2026

Copy link
Copy Markdown

@Hustler490 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Hustler490
Hustler490 force-pushed the ci/sdk-export-secret-guard branch from 823de2c to d37f923 Compare October 4, 2026 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fail the SDK export snapshot when a secret-bearing symbol is public

2 participants