Skip to content

fix(auth-server): set SESSION_TOKEN_HANDLE_KEY in prod jwksUri config tests - #21360

Merged
nshirley merged 1 commit into
mainfrom
fix/jwks-config-test-main
Oct 1, 2026
Merged

nshirley merged 1 commit into
mainfrom
fix/jwks-config-test-main

Conversation

@nshirley

@nshirley nshirley commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Because

  • The prod GOOGLE/APPLE_AUTH_JWKS_URI config tests fail on main: FXA-14056 made sessionTokenHandle.key a required production secret, so they hit the secret check first.

This pull request

  • Sets SESSION_TOKEN_HANDLE_KEY in the two prod jwksUri config tests.

Issue that this pull request solves

Closes: N/A

Checklist

Put an x in the boxes that apply

  • My commit is GPG signed.
  • If applicable, I have modified or added tests which pass locally.
  • I have added necessary documentation (if appropriate).
  • I have verified that my changes render correctly in RTL (if appropriate).
  • I have manually reviewed all AI generated code.

How to review (Optional)

  • Key files/areas to focus on:
  • Suggested review order:
  • Risky or complex parts:

Screenshots (Optional)

Please attach the screenshots of the changes made in case of change in user interface.

Other information (Optional)

Cherry-pick of f07b134 from train-346, which isn't on main yet. Follows FXA-14056. No separate review: one-line test fix, and config/index.spec.ts passes 6/6 locally.

… tests

Because:

- The FXA-14056 cherry-pick added sessionTokenHandle.key to SECRET_SETTINGS, so the prod jwksUri tests failed on the secret check before the jwksUri check.

This commit:

- Sets SESSION_TOKEN_HANDLE_KEY in the GOOGLE/APPLE_AUTH_JWKS_URI prod config tests.

(cherry picked from commit f07b134)
@nshirley
nshirley marked this pull request as ready for review October 1, 2026 15:40
@nshirley
nshirley requested a review from a team as a code owner October 1, 2026 15:40
Copilot AI lite review requested due to automatic review settings October 1, 2026 15:40

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review comments; the required secret is supplied in the production JWKS tests.

Review effort: Lite
Findings: None

What changed in this PR

Updates production JWKS URI configuration tests to provide the required session token handle secret.

Changes:

  • Adds SESSION_TOKEN_HANDLE_KEY to the Google/Apple production JWKS tests.
File Description
packages/​fxa-auth-server/​config/​index.spec.ts Supplies the required production secret in JWKS URI validation tests.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@nshirley
nshirley merged commit 30836e6 into main Oct 1, 2026
21 checks passed
@nshirley
nshirley deleted the fix/jwks-config-test-main branch October 1, 2026 16:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants