Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions packages/cre-sdk-examples/.env.example
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,10 @@ CRE_ETH_PRIVATE_KEY=000000000000000000000000000000000000000000000000000000000000
CRE_TARGET=local-simulation
# This one will be used in PoR workflow
SECRET_ADDRESS_ALL=0x4700A50d858Cb281847ca4Ee0938F80DEfB3F1dd
# This one will be used in secrets workflow
SECRET_CHARACTER_ID=5
# These will be used in secrets workflow
SECRET_URL_VALUE="https://swapi.info/api/people/{characterId}"
SECRET_CHARACTER_ID1=5
SECRET_CHARACTER_ID2=6
SECRET_CHARACTER_ID3=7
# Secret header value for HTTP trigger
SECRET_HEADER_VALUE=abcd1234
3 changes: 2 additions & 1 deletion packages/cre-sdk-examples/.gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -2,4 +2,5 @@ node_modules
dist
.turbo
tmp.js
tmp.wasm
tmp.wasm
.cre_build_tmp.js
2 changes: 1 addition & 1 deletion packages/cre-sdk-examples/package.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "@chainlink/cre-sdk-examples",
"private": true,
"version": "1.6.0",
"version": "1.7.0-alpha.1",
"type": "module",
"author": "Ernest Nowacki",
"license": "BUSL-1.1",
Expand Down
10 changes: 8 additions & 2 deletions packages/cre-sdk-examples/secrets.yaml
Original file line number Diff line number Diff line change
@@ -1,7 +1,13 @@
secretsNames:
SECRET_ADDRESS:
- SECRET_ADDRESS_ALL
CHARACTER_ID:
- SECRET_CHARACTER_ID
SECRET_URL:
- SECRET_URL_VALUE
CHARACTER_ID1:
- SECRET_CHARACTER_ID1
CHARACTER_ID2:
- SECRET_CHARACTER_ID2
CHARACTER_ID3:
- SECRET_CHARACTER_ID3
SECRET_HEADER:
- SECRET_HEADER_VALUE
32 changes: 25 additions & 7 deletions packages/cre-sdk-examples/src/workflows/secrets/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -41,9 +41,10 @@ type StarWarsCharacter = z.infer<typeof responseSchema>
const fetchStarWarsCharacter = (
sendRequester: HTTPSendRequester,
config: Config,
url: string,
characterId: string,
): StarWarsCharacter => {
const url = config.url.replace('{characterId}', characterId)
url = config.url.replace('{characterId}', characterId)
const response = sendRequester.sendRequest({ url, method: 'GET' }).result()

// Check if the response is successful using the helper function
Expand All @@ -58,14 +59,31 @@ const fetchStarWarsCharacter = (

const onHTTPTrigger = async (runtime: Runtime<Config>) => {
const httpCapability = new HTTPClient()
const characterId = runtime.getSecret({ id: 'CHARACTER_ID' }).result().value
// Fetch a single secret
const secretUrlValue = runtime.getSecret({ id: 'SECRET_URL' }).result().value

// Fetch multiple secrets
const secretsToFetch = [{ id: 'CHARACTER_ID1' }, { id: 'CHARACTER_ID2' }, { id: 'CHARACTER_ID3' }]
const secretResponses = runtime.getSecrets(secretsToFetch).result()
const characterIds = secretResponses.flatMap((response) =>
response.response.case === 'secret' && response.response.value?.id
? [response.response.value.value]
: [],
)
if (characterIds.length === 0) {
throw new Error('No character ID secrets available')
}

// choose a random character id
// Math.random() is safe to use in the workflow
const characterId = characterIds[Math.floor(Math.random() * characterIds.length)]

const result: StarWarsCharacter = httpCapability
.sendRequest(
runtime,
fetchStarWarsCharacter,
consensusIdenticalAggregation(),
)(runtime.config, characterId)
.sendRequest(runtime, fetchStarWarsCharacter, consensusIdenticalAggregation())(
runtime.config,
secretUrlValue,
characterId,
)
.result()

return result
Expand Down
2 changes: 1 addition & 1 deletion packages/cre-sdk/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@chainlink/cre-sdk",
"version": "1.6.0",
"version": "1.7.0-alpha.1",
"type": "module",
"main": "dist/index.js",
"types": "dist/index.d.ts",
Expand Down
12 changes: 12 additions & 0 deletions packages/cre-sdk/src/sdk/errors.ts
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,18 @@ export class SecretsError extends Error {
}
}

export class SecretsBatchError extends Error {
constructor(
public readonly secretRequests: SecretRequest[],
public readonly error: string,
) {
super(
`batch secret retrieval failed for ${secretRequests.length} request(s): ${error}. Verify the host response is complete and that the workflow has access to the requested secrets`,
)
this.name = 'SecretsBatchError'
}
}

export class NullReportError extends Error {
constructor() {
super('null report')
Expand Down
154 changes: 153 additions & 1 deletion packages/cre-sdk/src/sdk/impl/runtime-impl.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ import {
Value,
} from '@cre/sdk/utils'
import { CapabilityError } from '@cre/sdk/utils/capabilities/capability-error'
import { DonModeError, NodeModeError, SecretsError } from '../errors'
import { DonModeError, NodeModeError, SecretsBatchError, SecretsError } from '../errors'
import { RESPONSE_BUFFER_TOO_SMALL } from '../testutils/test-runtime'
import { type RuntimeHelpers, RuntimeImpl } from './runtime-impl'

Expand Down Expand Up @@ -358,6 +358,158 @@ describe('test now converts to date', () => {
})

describe('test getSecret', () => {
test('getSecrets returns ordered batched responses', () => {
const helpers = createRuntimeHelpersMock({
getSecrets: mock((request) => {
expect(request.callbackId).toEqual(1)
expect(request.requests.length).toEqual(2)
expect(request.requests[0].id).toEqual('secret-1')
expect(request.requests[1].id).toEqual('secret-2')
}),
awaitSecrets: mock((request) => {
expect(request.ids.length).toEqual(1)
expect(request.ids[0]).toEqual(1)
return create(AwaitSecretsResponseSchema, {
responses: {
1: create(SecretResponsesSchema, {
responses: [
create(SecretResponseSchema, {
response: {
case: 'secret',
value: {
id: 'secret-1',
namespace: 'ns',
owner: 'owner-1',
value: 'value-1',
},
},
}),
create(SecretResponseSchema, {
response: {
case: 'secret',
value: {
id: 'secret-2',
namespace: 'ns',
owner: 'owner-2',
value: 'value-2',
},
},
}),
],
}),
},
})
}),
})

const runtime = new RuntimeImpl<unknown>({}, 1, helpers, anyMaxSize)
const responses = runtime
.getSecrets([
{ id: 'secret-1', namespace: 'ns' },
{ id: 'secret-2', namespace: 'ns' },
])
.result()

expect(responses.length).toEqual(2)
expect(responses[0].response.case).toEqual('secret')
expect(responses[1].response.case).toEqual('secret')
if (responses[0].response.case === 'secret') {
expect(responses[0].response.value.id).toEqual('secret-1')
}
if (responses[1].response.case === 'secret') {
expect(responses[1].response.value.id).toEqual('secret-2')
}
})

test('getSecrets returns mixed success and error responses without throwing', () => {
const helpers = createRuntimeHelpersMock({
getSecrets: mock(() => undefined),
awaitSecrets: mock(() => {
return create(AwaitSecretsResponseSchema, {
responses: {
1: create(SecretResponsesSchema, {
responses: [
create(SecretResponseSchema, {
response: {
case: 'secret',
value: {
id: 'ok-secret',
namespace: 'ns',
owner: 'owner',
value: 'ok-value',
},
},
}),
create(SecretResponseSchema, {
response: {
case: 'error',
value: {
id: 'missing-secret',
namespace: 'ns',
owner: 'owner',
error: 'secret not found',
},
},
}),
],
}),
},
})
}),
})

const runtime = new RuntimeImpl<unknown>({}, 1, helpers, anyMaxSize)
const responses = runtime
.getSecrets([
{ id: 'ok-secret', namespace: 'ns' },
{ id: 'missing-secret', namespace: 'ns' },
])
.result()

expect(responses.length).toEqual(2)
expect(responses[0].response.case).toEqual('secret')
expect(responses[1].response.case).toEqual('error')
})

test('getSecrets throws SecretsBatchError when host getSecrets call fails', () => {
const helpers = createRuntimeHelpersMock({
getSecrets: mock(() => {
throw new Error('vault: signer unreachable')
}),
})

const runtime = new RuntimeImpl<unknown>({}, 1, helpers, anyMaxSize)
expect(() =>
runtime
.getSecrets([
{ id: 'secret-a', namespace: 'ns' },
{ id: 'secret-b', namespace: 'ns' },
])
.result(),
).toThrow(SecretsBatchError)
})

test('getSecrets throws SecretsBatchError for malformed batched response envelope', () => {
const helpers = createRuntimeHelpersMock({
getSecrets: mock(() => undefined),
awaitSecrets: mock(() =>
create(AwaitSecretsResponseSchema, {
responses: {},
}),
),
})

const runtime = new RuntimeImpl<unknown>({}, 1, helpers, anyMaxSize)
expect(() =>
runtime
.getSecrets([
{ id: 'secret-a', namespace: 'ns' },
{ id: 'secret-b', namespace: 'ns' },
])
.result(),
).toThrow(SecretsBatchError)
})

test('successfully gets secret with SecretRequest (proto message)', () => {
const secretRequest = create(SecretRequestSchema, {
id: 'my-secret',
Expand Down
Loading
Loading