Make secret-file reading tolerate a missing file at the default path

A concurrent commit changed DB_PASSWORD_FILE/ENCRYPTION_KEY_FILE's
defaults from "" (opt-in) to fixed /run/secrets/... paths, so production
containers pick them up with zero extra config. But model_post_init reads
these unconditionally at Settings() construction for every process that
imports app.config — including local dev and the test suite, which don't
have that file — so it started crashing the entire test suite with
FileNotFoundError. A missing file now falls back to leaving DATABASE_URL/
ENCRYPTION_KEY untouched instead of crashing; an actual I/O error reading
an existing file still propagates. Added a regression test for exactly
this scenario. 171 backend tests passing.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Le
2026-07-04 12:45:21 +07:00
parent 7ed53050b7
commit b96139d66f
2 changed files with 44 additions and 9 deletions
+19
View File
@@ -33,6 +33,25 @@ def test_without_file_variants_plain_env_values_are_unchanged():
settings = Settings(
DATABASE_URL="postgresql+asyncpg://trading:plain@db:5432/trading_portal",
ENCRYPTION_KEY="plain-key",
DB_PASSWORD_FILE="", ENCRYPTION_KEY_FILE="",
)
assert settings.DATABASE_URL == "postgresql+asyncpg://trading:plain@db:5432/trading_portal"
assert settings.ENCRYPTION_KEY == "plain-key"
def test_missing_secret_file_at_default_path_does_not_crash():
"""DB_PASSWORD_FILE/ENCRYPTION_KEY_FILE default to fixed /run/secrets/...
paths so production containers pick them up with no extra config — but
that same default runs in every process that imports this module,
including local dev and CI, which don't have that file. A missing file
must be a no-op fallback, not a crash (regression: a teammate's commit
hardcoded non-empty defaults here and broke the whole test suite until
this fallback was added)."""
settings = Settings(
DATABASE_URL="postgresql+asyncpg://trading:plain@db:5432/trading_portal",
ENCRYPTION_KEY="plain-key",
DB_PASSWORD_FILE="/nonexistent/db_password_file_for_test.txt",
ENCRYPTION_KEY_FILE="/nonexistent/encryption_key_file_for_test.txt",
)
assert settings.DATABASE_URL == "postgresql+asyncpg://trading:plain@db:5432/trading_portal"
assert settings.ENCRYPTION_KEY == "plain-key"