fix(SDK-7770): warn when Test Reporting and session credentials point to different accounts - #238
Conversation
… to different accounts Sessions authenticate with the WebdriverIO config user/key, while the CLI / Test Reporting build prefers BROWSERSTACK_USERNAME (or BROWSERSTACK_USER_NAME), then testObservabilityOptions.user. When these differ, one run is silently split across two accounts and results never show up next to the sessions. Log a clear warning (no credential values) from onPrepare when running on BrowserStack. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Central YAML (base), Organization UI (inherited), Workspace UI (inherited) Review profile: ASSERTIVE Plan: Enterprise Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
🔴 SDK PR Review gate is red. Pending:
It turns green once the SDK PR Review Agent has run on the current head commit (any verdict — the gate only requires that the review ran). A native reviewer approval is separately required by branch protection before merge. |
|
RUN_TESTS |
|
🔴 Blocking findings — fix required See the SDK PR Review Agent's report from your local run. Change map (generated deterministically from the diff)graph LR
subgraph nwdio_service["wdio-service"]
npackages_browserstack_service_src_util_ts["util.ts<br/>~38 lines"]
npackages_browserstack_service_tests_util_test_ts["util.test.ts<br/>~38 lines"]
npackages_browserstack_service_src_launcher_ts["launcher.ts<br/>~18 lines"]
npackages_browserstack_service_tests_launcher_test_ts["launcher.test.ts<br/>~18 lines"]
n_changeset_pr_238_md["pr-238.md<br/>~5 lines"]
end
↻ This verdict comment is the review anchor — it's updated in place on each run (the gate posts its status separately). — SDK PR Review Agent |
|
🟢 SDK PR Review gate is green — the SDK PR Review Agent has run on the current head commit (verdict: This gate confirms a review ran on the latest commit. The verdict itself is advisory — read the findings and use your judgement; it does not block merge. A native GitHub reviewer approval is still separately required by branch protection before this PR can merge. |
|
🟢 SDK PR Review gate is green — the SDK PR Review Agent has run on the current head commit (verdict: This gate confirms a review ran on the latest commit. The verdict itself is advisory — read the findings and use your judgement; it does not block merge. A native GitHub reviewer approval is still separately required by branch protection before this PR can merge. |
1 similar comment
|
🟢 SDK PR Review gate is green — the SDK PR Review Agent has run on the current head commit (verdict: This gate confirms a review ran on the latest commit. The verdict itself is advisory — read the findings and use your judgement; it does not block merge. A native GitHub reviewer approval is still separately required by branch protection before this PR can merge. |
| // Sessions authenticate with config.user, but the CLI / Test Reporting build prefers the | ||
| // env credentials, then testObservabilityOptions.user — a mismatch splits one run across two accounts. |
There was a problem hiding this comment.
if creds are present in the env vars then why are we using the creds from the config file? shouldn't we follow this order of picking up the properties: cli > env > yml
There was a problem hiding this comment.
Checked the history. Device-session creds have always come from the wdio config: WebdriverIO core builds the /session Basic auth from config.user/config.key and never reads BROWSERSTACK_USERNAME. See webdriver 8.40.0 build/request/index.js:121 and 9.32.0 build/node.js:2230; there are no env refs in any core package. No @wdio/browserstack-service release from 6.12.1 to 9.36.2 copies the env creds into config.user/key.
The cli > env > yml order only ever applied to the service's own calls: Test Reporting (getObservabilityUser, and since 9.21.0 the CLI binary's setFinalCaps), Percy and the log upload. So the service and WebdriverIO have always resolved credentials differently. Making the session follow env too would mean overwriting config.user/key in onPrepare. That silently moves sessions to another account for anyone with a stray env var today, which is why this PR only warns.
|
🟢 SDK PR Review gate is green — the SDK PR Review Agent has run on the current head commit (verdict: This gate confirms a review ran on the latest commit. The verdict itself is advisory — read the findings and use your judgement; it does not block merge. A native GitHub reviewer approval is still separately required by branch protection before this PR can merge. |
What is this about?
When
BROWSERSTACK_USERNAME/BROWSERSTACK_USER_NAME(ortestObservabilityOptions.user) points to a different BrowserStack account than the WebdriverIOuser, a single run gets split across two accounts:user/key(WebdriverIO never reads the env vars);getObservabilityUserdoes the same);testhubBuildUuid.The customer sees the session in the App Automate dashboard, but the test results land in the other account, and nothing warns them.
This PR adds a warning, logged once from
onPrepareand only for runs on BrowserStack, whenever the Test Reporting credentials differ from the WebdriverIOuser. The message names the conflicting source (the env var ortestObservabilityOptions.user) and never includes credential values. Credential precedence and routing are unchanged.Reproduced with two valid accounts on 9.33.1 and 9.36.2, on both Automate and App Automate. In the split runs the Test Reporting build's JWT
subwas account B, while the session stayed on account A (the session owner was confirmed on the dashboard for Automate). With a local build of this branch, the split run logs the warning exactly once and the control run logs nothing. Both tests pass.Related Jira task/s
https://browserstack.atlassian.net/browse/SDK-7770
Release (mandatory for every PR — required for the
ready-for-reviewlabel)Version bump: (required — tick exactly one)
Release notes type: (optional)
Release notes (customer-facing): (optional but encouraged)
BROWSERSTACK_USERNAME/BROWSERSTACK_ACCESS_KEYortestObservabilityOptions.userpoint to a different BrowserStack account than the WebdriverIOuser/key. Such runs send test results to a different account than their sessions.Release notes (internal): (required — engineer-facing; what actually changed / why)
getCredentialMismatchWarninginutil.ts.launcher.onPreparecalls it and logsBStackLogger.warnwhenisBrowserstackInfra. The env var (BROWSERSTACK_USERNAME, thenBROWSERSTACK_USER_NAME) ortestObservabilityOptions.useris compared againstconfig.user. Warning only; credential precedence is unchanged.Checklist
PR Validations
Run Tests: Comment RUN_TESTS to trigger sanity tests.
🤖 Generated with Claude Code