Dev credentials — one file for every test
All credentials the test suites need live in a single gitignored file:
secrets/dev-credentials.local.json. Copy the committed template and fill in what you
have — every value is optional and the tests that need a missing value skip cleanly.
mkdir -p secrets
cp dev-credentials.example.json secrets/dev-credentials.local.json
# edit secrets/dev-credentials.local.json
What each test tier reads
| Tier | Needs | From |
|---|---|---|
Unit (tests/UnitTests) | nothing | — deterministic, no secrets, no network |
Integration (tests/IntegrationTests) | Postgres | Testcontainers (Docker) — auto |
Live copy (tests/IntegrationTests/CopyLive) | OpenAPI app + token cache | OpenApi.App, OpenApi.Tokens |
E2E onboarding (tests/E2ETests/CopyLive) | OpenAPI app + cID logins | OpenApi.App, OpenApi.Cids |
E2E real run/backtest (CBotRealRunBacktestTests) | a cID login + a demo account number | OpenApi.Cids[].{Username,Password,Accounts} |
| AI features | Anthropic key | Ai.ApiKey (unset ⇒ AI features return disabled, app still runs) |
Live economic-calendar sources (tests/IntegrationTests/Calendar/CalendarSourceLiveTests) | FRED / BLS API keys | Calendar.FredApiKey, Calendar.BlsApiKey (unset ⇒ that source's live test skips; the keyless central-bank schedule still works) |
Schema
See dev-credentials.example.json at the repo root. Sections:
-
OpenApi.App—{ ClientId, ClientSecret }of the cTrader Open API application. -
OpenApi.Cids— cTrader ID logins used by the headless OAuth onboarding. Each entry also carries anAccountsarray — the cTrader trading-account numbers (the login/account number, e.g.3635817) under that cID that the test infrastructure is allowed to link into the app and drive.CBotRealRunBacktestTestsreads the first entry that has a non-emptyAccountsarray, adds that cID + account to the app, then really runs and backtests a cBot on it. Put only demo account numbers here — never a live account; the run/backtest tests place real orders on whatever account you list. Empty/omittedAccounts⇒ the real run/backtest test skips cleanly. -
OpenApi.Tokens— the multi-cID token cache (one entry per authorized cID with its refresh/access token + account list). Written automatically by onboarding and by the token-refresh step; you rarely edit it by hand. -
Owner— seed owner login for the app under E2E. -
Database.ConnectionString— only when pointing tests at an external Postgres instead of Testcontainers. -
Ai.ApiKey— Anthropic API key for the AI features. -
Calendar.FredApiKey— FRED (St. Louis Fed) API key. The primary economic-calendar value source (interest rates, inflation, employment). -
Calendar.BlsApiKey— BLS (US Bureau of Labor Statistics) v2 registration key (CPI, PPI, employment, JOLTS). Absent ⇒ the low-quota public tier.Both feed the exact
FredSource/BlsSourcethe ingestion worker uses. With a key present,CalendarSourceLiveTestshits the real provider and asserts observations come back; absent, that source's test skips cleanly. The app also reads these at runtime viaApp:Calendar:FredApiKey/App:Calendar:BlsApiKey(environment variables override — e.g.FRED_API_KEY,BLS_API_KEY).
Precedence
- Environment variables override everything (e.g.
App__OwnerPassword,App:Ai:ApiKey). secrets/dev-credentials.local.json— the unified file (preferred).- Legacy split files —
openapi-test-app.local.json,openapi-cids.local.json,openapi-tokens.local.jsonare still read when the unified file is absent, so existing machines keep working. New setups should use the single file.
Safety
secrets/and*.local.jsonare gitignored — nothing here is ever committed.- Live copy tests refuse to run against non-demo accounts (
IsLiveaccounts are filtered out byLiveCopyFixture). Keep only demo accounts in the token cache. - In-cluster (Kubernetes) runs mount the file as a read-only Secret; token refreshes are kept in memory and the read-only write-back is a silent no-op.