[vitest-plugin] Declare the adminSecretsStore() result as disposable - #15706
Merged
cjol merged 5 commits intoSep 22, 2026
Merged
Conversation
The admin API is backed by RPC stubs, and both the returned promise and the object it resolves to carry Symbol.dispose, but SecretsStoreSecretAdmin left it out and the example assigned the result with const. A test that followed the example leaked the stubs until the garbage collector ran, and workerd warned that an RPC stub was not disposed properly. Declare the disposer on the interface, the way WorkflowInstanceIntrospector declares Symbol.asyncDispose, show using in both examples, and pin it in the types test.
🦋 Changeset detectedLatest commit: f4dcf0d The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
workers-devprod
requested review from
a team and
cjol
and removed request for
a team
September 18, 2026 07:20
Contributor
|
Codeowners approval required for this PR:
Show detailed file reviewers |
The seeded integration test still assigned the adminSecretsStore() result with const, so disposal only ever ran through the types test. Declaring it with using makes the runtime test follow the documented example, and using throws at the start of the scope if the value is not disposable.
@cloudflare/autoconfig
@cloudflare/build-output-utils
@cloudflare/codemods
@cloudflare/config
@cloudflare/containers-shared
create-cloudflare
@cloudflare/deploy-helpers
@cloudflare/kv-asset-handler
miniflare
@cloudflare/pages-functions
@cloudflare/pages-shared
@cloudflare/unenv-preset
@cloudflare/vite-plugin
@cloudflare/vitest-plugin
@cloudflare/workers-auth
@cloudflare/workers-editor-shared
@cloudflare/workers-utils
wrangler
commit: |
…pose-secrets-admin
cjol
approved these changes
Sep 22, 2026
workers-devprod
approved these changes
Sep 22, 2026
workers-devprod
left a comment
Contributor
There was a problem hiding this comment.
Codeowners reviews satisfied
cjol
enabled auto-merge (squash)
September 22, 2026 16:25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #15696.
adminSecretsStore()returns the RPC promise from the binding's admin API, which workerd makes disposable. But theSecretsStoreSecretAdmintype incloudflare:testleft outSymbol.dispose, and the JSDoc example assigned the result withconst. So a test that followed the example leaked the stubs until the garbage collector ran, and workerd printed "An RPC stub was not disposed properly". The issue has a deterministic reproduction and shows thatusingon the result removes the warning.This declares
[Symbol.dispose](): voidonSecretsStoreSecretAdmin, the same wayWorkflowInstanceIntrospectoralready declares[Symbol.asyncDispose], and changes both examples tousing admin = adminSecretsStore(env.MY_SECRET). There's no runtime change.test/types.test.tsnow compiles ausingdeclaration of the result. With the previouscloudflare-test.d.tsit fails with TS2850, since the initializer of ausingdeclaration needs a[Symbol.dispose]()method. With this change it passes.oxfmtandoxlintare clean on the changed files.adminSecretsStore()is only documented in thecloudflare:testtype declarations, which this updates.