Dev credentials — ένα αρχείο για κάθε test
Όλα τα credentials που χρειάζονται τα test suites βρίσκονται σε ένα μόνο gitignored αρχείο:
secrets/dev-credentials.local.json. Αντιγράψτε το committed template και συμπληρώστε ό,τι
έχετε — κάθε τιμή είναι προαιρετικό και τα tests που χρειάζονται ένα missing value
παραλείπονται gracefully.
mkdir -p secrets
cp dev-credentials.example.json secrets/dev-credentials.local.json
# edit secrets/dev-credentials.local.json
Τι διαβάζει κάθε test tier
| Tier | Χρειάζεται | Από |
|---|---|---|
Unit (tests/UnitTests) | τίποτα | — deterministic, χωρίς secrets, χωρίς δίκτυο |
Integration (tests/IntegrationTests) | Postgres | Testcontainers (Docker) — auto |
Live copy (tests/IntegrationTests/CopyLive) | OpenAPI app + token cache | OpenApi.App, OpenApi.Tokens |
E2E onboarding (tests/E2ETests/CopyLive) | OpenAPI app + cID logins | OpenApi.App, OpenApi.Cids |
E2E real run/backtest (CBotRealRunBacktestTests) | ένα cID login + ένας demo account number | OpenApi.Cids[].{Username,Password,Accounts} |
| AI features | Anthropic key | Ai.ApiKey (unset ⇒ AI features return disabled, η app εξακολουθεί να τρέχει) |
Live economic-calendar sources (tests/IntegrationTests/Calendar/CalendarSourceLiveTests) | FRED / BLS API keys | Calendar.FredApiKey, Calendar.BlsApiKey (unset ⇒ that source's live test skips; the keyless central-bank schedule still works) |
Schema
Δείτε dev-credentials.example.json στο repo root. Sections:
-
OpenApi.App—{ ClientId, ClientSecret }της cTrader Open API εφαρμογής. -
OpenApi.Cids— cTrader ID logins που χρησιμοποιούνται από το headless OAuth onboarding. Κάθε entry επίσης φέρει έναAccountsarray — τα cTrader trading-account numbers (το login/account number, π.χ.3635817) κάτω από εκείνο το cID που η test infrastructure επιτρέπεται να συνδέσει στην app και να οδηγήσει. ΤοCBotRealRunBacktestTestsδιαβάζει το πρώτο entry που έχει non-emptyAccountsarray, προσθέτει εκείνο το cID + account στην app, μετά πραγματικά εκτελεί και backtest ένα cBot σε αυτό. Βάλτε μόνο demo account numbers εδώ — ποτέ live account· τα run/backtest tests τοποθετούν πραγματικές εντολές σε ό,τι account λίσταρετε. Empty/omittedAccounts⇒ το real run/backtest test παραλείπεται gracefully. -
OpenApi.Tokens— το multi-cID token cache (μία entry ανά authorized cID με το refresh/access token + account list). Γράφεται αυτόματα από onboarding και από το token-refresh step· σπάνια επεξεργάζεται με το χέρι. -
Owner— seed owner login για την app under E2E. -
Database.ConnectionString— μόνο όταν τα tests στοχεύουν σε external Postgres αντί για Testcontainers. -
Ai.ApiKey— Anthropic API key για τα AI features. -
Calendar.FredApiKey— FRED (St. Louis Fed) API key. The primary economic-calendar value source (interest rates, inflation, employment). -
Calendar.BlsApiKey— BLS (US Bureau of Labor Statistics) v2 registration key (CPI, PPI, employment, JOLTS). Absent ⇒ the low-quota public tier.Both feed the exact
FredSource/BlsSourcethe ingestion worker uses. With a key present,CalendarSourceLiveTestshits the real provider and asserts observations come back; absent, that source's test skips cleanly. The app also reads these at runtime viaApp:Calendar:FredApiKey/App:Calendar:BlsApiKey(environment variables override — e.g.FRED_API_KEY,BLS_API_KEY).
Προτεραιότητα
- Περιβαλλοντικές μεταβλητές override όλα (π.χ.
App__OwnerPassword,App:Ai:ApiKey). secrets/dev-credentials.local.json— το ενοποιημένο αρχείο (προτιμάται).- Legacy split files —
openapi-test-app.local.json,openapi-cids.local.json,openapi-tokens.local.jsonεξακολουθούν να διαβάζονται όταν το ενοποιημένο αρχείο απουσιάζει, οπότε τα υπάρχοντα machines συνεχίζουν να δουλεύουν. Τα νέα setups πρέπει να χρησιμοποιούν το single file.
Ασφάλεια
secrets/και*.local.jsonείναι gitignored — τίποτα εδώ δεν commitάρεται ποτέ.- Τα live copy tests αρνούνται να τρέξουν ενάντια σε non-demo accounts (τα
IsLiveaccounts φιλτράρονται απόLiveCopyFixture). Κρατήστε μόνο demo accounts στο token cache. - In-cluster (Kubernetes) runs mount το αρχείο ως read-only Secret· τα token refreshes κρατούνται in memory και το read-only write-back είναι silent no-op.