Skip to content

fix(SDK-7770): warn when Test Reporting and session credentials point to different accounts - #238

Merged
Dalwin-Barnard merged 2 commits into
mainfrom
fix/SDK-7770-credential-mismatch
Sep 29, 2026
Merged

Dalwin-Barnard merged 2 commits into
mainfrom
fix/SDK-7770-credential-mismatch

Conversation

@anish353

Copy link
Copy Markdown
Collaborator

What is this about?

When BROWSERSTACK_USERNAME / BROWSERSTACK_USER_NAME (or testObservabilityOptions.user) points to a different BrowserStack account than the WebdriverIO user, a single run gets split across two accounts:

  • the device session is created with the WebdriverIO user/key (WebdriverIO never reads the env vars);
  • the Test Reporting & Analytics build is created with the env credentials (the CLI binary gives env precedence over the config the SDK sends; the legacy path's getObservabilityUser does the same);
  • the session is still stamped with that build's testhubBuildUuid.

The customer sees the session in the App Automate dashboard, but the test results land in the other account, and nothing warns them.

This PR adds a warning, logged once from onPrepare and only for runs on BrowserStack, whenever the Test Reporting credentials differ from the WebdriverIO user. The message names the conflicting source (the env var or testObservabilityOptions.user) and never includes credential values. Credential precedence and routing are unchanged.

Reproduced with two valid accounts on 9.33.1 and 9.36.2, on both Automate and App Automate. In the split runs the Test Reporting build's JWT sub was account B, while the session stayed on account A (the session owner was confirmed on the dashboard for Automate). With a local build of this branch, the split run logs the warning exactly once and the control run logs nothing. Both tests pass.

Related Jira task/s

https://browserstack.atlassian.net/browse/SDK-7770

Release (mandatory for every PR — required for the ready-for-review label)

Version bump: (required — tick exactly one)

  • minor (backwards-compatible feature)
  • patch (bug fix or other small change)

Release notes type: (optional)

  • New Feature
  • Bug Fix
  • Other Improvement

Release notes (customer-facing): (optional but encouraged)

  • Added a warning when BROWSERSTACK_USERNAME/BROWSERSTACK_ACCESS_KEY or testObservabilityOptions.user point to a different BrowserStack account than the WebdriverIO user/key. Such runs send test results to a different account than their sessions.

Release notes (internal): (required — engineer-facing; what actually changed / why)

  • SDK-7770: new getCredentialMismatchWarning in util.ts. launcher.onPrepare calls it and logs BStackLogger.warn when isBrowserstackInfra. The env var (BROWSERSTACK_USERNAME, then BROWSERSTACK_USER_NAME) or testObservabilityOptions.user is compared against config.user. Warning only; credential precedence is unchanged.

Checklist

  • Ready to review
  • Has it been tested locally?

PR Validations

Run Tests: Comment RUN_TESTS to trigger sanity tests.

🤖 Generated with Claude Code

… to different accounts

Sessions authenticate with the WebdriverIO config user/key, while the CLI /
Test Reporting build prefers BROWSERSTACK_USERNAME (or BROWSERSTACK_USER_NAME),
then testObservabilityOptions.user. When these differ, one run is silently split
across two accounts and results never show up next to the sessions. Log a clear
warning (no credential values) from onPrepare when running on BrowserStack.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@anish353
anish353 requested a review from a team as a code owner September 28, 2026 07:28
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited), Workspace UI (inherited)

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: 1bee4fbc-95fb-43b3-b4f3-35282eb7435b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

🔴 SDK PR Review gate is red. Pending:

  • The SDK PR Review Agent has not been run on the current head commit yet — run the SDK PR Review Agent (its verdict is advisory; this gate only requires that it ran on the latest commit).

It turns green once the SDK PR Review Agent has run on the current head commit (any verdict — the gate only requires that the review ran). A native reviewer approval is separately required by branch protection before merge.

@anish353

Copy link
Copy Markdown
Collaborator Author

RUN_TESTS

@anish353

anish353 commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator Author

🔴 Blocking findings — fix required

See the SDK PR Review Agent's report from your local run.

Change map (generated deterministically from the diff)

graph LR
  subgraph nwdio_service["wdio-service"]
    npackages_browserstack_service_src_util_ts["util.ts<br/>~38 lines"]
    npackages_browserstack_service_tests_util_test_ts["util.test.ts<br/>~38 lines"]
    npackages_browserstack_service_src_launcher_ts["launcher.ts<br/>~18 lines"]
    npackages_browserstack_service_tests_launcher_test_ts["launcher.test.ts<br/>~18 lines"]
    n_changeset_pr_238_md["pr-238.md<br/>~5 lines"]
  end
Loading

↻ This verdict comment is the review anchor — it's updated in place on each run (the gate posts its status separately).

— SDK PR Review Agent

@github-actions

Copy link
Copy Markdown
Contributor

🟢 SDK PR Review gate is green — the SDK PR Review Agent has run on the current head commit (verdict: pending).

This gate confirms a review ran on the latest commit. The verdict itself is advisory — read the findings and use your judgement; it does not block merge. A native GitHub reviewer approval is still separately required by branch protection before this PR can merge.

@github-actions

Copy link
Copy Markdown
Contributor

🟢 SDK PR Review gate is green — the SDK PR Review Agent has run on the current head commit (verdict: failure).

This gate confirms a review ran on the latest commit. The verdict itself is advisory — read the findings and use your judgement; it does not block merge. A native GitHub reviewer approval is still separately required by branch protection before this PR can merge.

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

🟢 SDK PR Review gate is green — the SDK PR Review Agent has run on the current head commit (verdict: failure).

This gate confirms a review ran on the latest commit. The verdict itself is advisory — read the findings and use your judgement; it does not block merge. A native GitHub reviewer approval is still separately required by branch protection before this PR can merge.

Comment on lines +1453 to +1454
// Sessions authenticate with config.user, but the CLI / Test Reporting build prefers the
// env credentials, then testObservabilityOptions.user — a mismatch splits one run across two accounts.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

if creds are present in the env vars then why are we using the creds from the config file? shouldn't we follow this order of picking up the properties: cli > env > yml

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checked the history. Device-session creds have always come from the wdio config: WebdriverIO core builds the /session Basic auth from config.user/config.key and never reads BROWSERSTACK_USERNAME. See webdriver 8.40.0 build/request/index.js:121 and 9.32.0 build/node.js:2230; there are no env refs in any core package. No @wdio/browserstack-service release from 6.12.1 to 9.36.2 copies the env creds into config.user/key.

The cli > env > yml order only ever applied to the service's own calls: Test Reporting (getObservabilityUser, and since 9.21.0 the CLI binary's setFinalCaps), Percy and the log upload. So the service and WebdriverIO have always resolved credentials differently. Making the session follow env too would mean overwriting config.user/key in onPrepare. That silently moves sessions to another account for anyone with a stray env var today, which is why this PR only warns.

@github-actions

Copy link
Copy Markdown
Contributor

🟢 SDK PR Review gate is green — the SDK PR Review Agent has run on the current head commit (verdict: failure).

This gate confirms a review ran on the latest commit. The verdict itself is advisory — read the findings and use your judgement; it does not block merge. A native GitHub reviewer approval is still separately required by branch protection before this PR can merge.

@Dalwin-Barnard
Dalwin-Barnard merged commit 6bd7aba into main Sep 29, 2026
20 of 24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants