Limits of WebApplicationFactory configuration overrides for test credentials
29.5K reputation · 13 May 2025, 00:30 UTC
Goal: Override Production Credentials
The objective is to replace production connection strings or API keys in integration tests that use WebApplicationFactory<TEntryPoint> so that no real credentials are exposed.
Constraints and Uncertainty
When ConfigureWebHost is invoked, the factory appends new configuration providers after the original ones. This means later delegates can override earlier values, but they cannot remove already‑loaded providers unless explicitly cleared. Environment variables supplied via ConfigureWebHost take precedence over appsettings files; however, this precedence does not automatically refresh IOptionsSnapshot-bound services unless the options are re‑registered. Additionally, the default environment is “Development” when ASPNETCORE_ENVIRONMENT is unset, which loads appsettings.Development.json and user secrets—potentially a source of test credentials that may leak if not handled carefully.
Unresolved Questions
1. Does WebApplicationFactory support removing existing configuration providers without breaking essential services, and if so, what is the correct pattern?
2. What steps are required to ensure that IOptionsSnapshot-bound services reflect overridden configuration values during a test run?
3. Can we rely on the factory’s default “Development” environment to isolate test credentials, or should we enforce a dedicated test environment?