feat: protect sensitive catalog samples
This commit is contained in:
@@ -141,6 +141,83 @@ async function waitForTerminalRun(app: ReturnType<typeof buildApp>, runId: strin
|
||||
throw new Error(`Description Generation Run ${runId} did not finish`);
|
||||
}
|
||||
|
||||
test("suggests sensitive flags from structural metadata without persisting them", async () => {
|
||||
const modelCompleter = {
|
||||
complete: vi.fn(async () => JSON.stringify({
|
||||
suggestions: [{ columnId: expect.any(String), sensitive: true }],
|
||||
})),
|
||||
};
|
||||
const { app, repository, database, column } = await setup(modelCompleter);
|
||||
modelCompleter.complete.mockResolvedValueOnce(JSON.stringify({
|
||||
suggestions: [{ columnId: column.id, sensitive: true }],
|
||||
}));
|
||||
|
||||
try {
|
||||
const response = await app.inject({
|
||||
method: "POST",
|
||||
url: `/catalog/databases/${database.id}/sensitive-data-suggestions`,
|
||||
payload: { modelId: configuredModel.id },
|
||||
});
|
||||
|
||||
expect(response.statusCode).toBe(200);
|
||||
expect(response.json()).toEqual({
|
||||
suggestions: [{ columnId: column.id, sensitive: true }],
|
||||
});
|
||||
expect(await repository.getColumn(database.id, column.tableId, column.id))
|
||||
.toMatchObject({ sensitive: false });
|
||||
|
||||
const request = modelCompleter.complete.mock.calls[0]![0] as ModelCompletionRequest;
|
||||
const prompt = request.messages.map((message) => message.content).join("\n");
|
||||
expect(prompt).toContain("patients");
|
||||
expect(prompt).toContain("birth_date");
|
||||
expect(prompt).toContain("date");
|
||||
expect(prompt).not.toContain("Patient date of birth");
|
||||
expect(prompt).not.toContain("test-provider-secret");
|
||||
} finally {
|
||||
await app.close();
|
||||
}
|
||||
});
|
||||
|
||||
test.each(["malformed", "incomplete", "duplicate"] as const)(
|
||||
"fails safely when sensitive-data suggestions are %s",
|
||||
async (kind) => {
|
||||
const modelCompleter: ModelCompleter = {
|
||||
complete: vi.fn(async () => "unused"),
|
||||
};
|
||||
const { app, repository, database, column } = await setup(modelCompleter);
|
||||
const rawResponse = kind === "malformed"
|
||||
? "RAW_PROVIDER_RESPONSE_DO_NOT_EXPOSE_{"
|
||||
: kind === "incomplete"
|
||||
? JSON.stringify({ suggestions: [] })
|
||||
: JSON.stringify({
|
||||
suggestions: [
|
||||
{ columnId: column.id, sensitive: true },
|
||||
{ columnId: column.id, sensitive: true },
|
||||
],
|
||||
});
|
||||
vi.mocked(modelCompleter.complete).mockResolvedValueOnce(rawResponse);
|
||||
|
||||
try {
|
||||
const response = await app.inject({
|
||||
method: "POST",
|
||||
url: `/catalog/databases/${database.id}/sensitive-data-suggestions`,
|
||||
payload: { modelId: configuredModel.id },
|
||||
});
|
||||
|
||||
expect(response.statusCode).toBe(502);
|
||||
expect(response.json()).toEqual({
|
||||
code: "sensitive_data_suggestion_failed",
|
||||
message: "Sensitive-data suggestions could not be prepared.",
|
||||
});
|
||||
expect(response.body).not.toContain(rawResponse);
|
||||
expect(await repository.getColumn(database.id, column.tableId, column.id))
|
||||
.toMatchObject({ sensitive: false });
|
||||
} finally {
|
||||
await app.close();
|
||||
}
|
||||
},
|
||||
);
|
||||
|
||||
interface SseFrame {
|
||||
id?: string;
|
||||
event?: string;
|
||||
@@ -398,6 +475,102 @@ test("keeps real source samples transient across the Fastify API and application
|
||||
}
|
||||
});
|
||||
|
||||
test("never exposes a protected source value to the model, persistence, logs, or browser APIs", async () => {
|
||||
let selectedColumnId = "";
|
||||
const protectedValue = "PROTECTED_SOURCE_VALUE_8f4c2a";
|
||||
const modelCompleter: ModelCompleter = {
|
||||
complete: vi.fn(async () => JSON.stringify({
|
||||
results: [{
|
||||
targetId: selectedColumnId,
|
||||
outcome: "generated",
|
||||
description: "Data di nascita del paziente.",
|
||||
}],
|
||||
})),
|
||||
};
|
||||
const descriptionSourceSampler: DescriptionSourceSampler = {
|
||||
sample: vi.fn(async (_database, targets) => [{
|
||||
targetId: targets[0]!.targetId,
|
||||
tableName: targets[0]!.tableName,
|
||||
rows: [{ fields: [{ name: "birth_date", value: protectedValue }] }],
|
||||
representativeValues: [{ column: "birth_date", values: [protectedValue] }],
|
||||
}]),
|
||||
};
|
||||
const { app, repository, database, table, column } = await setup(
|
||||
modelCompleter,
|
||||
{},
|
||||
"it",
|
||||
descriptionSourceSampler,
|
||||
);
|
||||
selectedColumnId = column.id;
|
||||
await repository.updateColumnMetadata(
|
||||
database.id,
|
||||
table.id,
|
||||
column.id,
|
||||
column.version,
|
||||
column.description,
|
||||
column.generatedDescription,
|
||||
true,
|
||||
);
|
||||
const logSpies = [
|
||||
vi.spyOn(app.log, "info"),
|
||||
vi.spyOn(app.log, "warn"),
|
||||
vi.spyOn(app.log, "error"),
|
||||
];
|
||||
|
||||
try {
|
||||
const start = await app.inject({
|
||||
method: "POST",
|
||||
url: `/catalog/databases/${database.id}/description-generation-runs`,
|
||||
payload: {
|
||||
modelId: configuredModel.id,
|
||||
scope: "selected_columns",
|
||||
targetIds: [column.id],
|
||||
},
|
||||
});
|
||||
expect(start.statusCode).toBe(202);
|
||||
await waitForTerminalRun(app, start.json().id);
|
||||
|
||||
expect(descriptionSourceSampler.sample).toHaveBeenCalledWith(
|
||||
expect.anything(),
|
||||
[expect.objectContaining({ targetId: column.id, columnNames: [] })],
|
||||
expect.any(AbortSignal),
|
||||
);
|
||||
const completionRequest = vi.mocked(modelCompleter.complete).mock.calls[0]![0];
|
||||
const providerPayload = JSON.stringify(completionRequest.messages);
|
||||
expect(providerPayload).not.toContain(protectedValue);
|
||||
expect(providerPayload).toContain("1981-01-01");
|
||||
|
||||
const apiResponses = await Promise.all([
|
||||
app.inject({ method: "GET", url: `/catalog/description-generation-runs/${start.json().id}` }),
|
||||
app.inject({
|
||||
method: "GET",
|
||||
url: `/catalog/description-generation-runs/${start.json().id}/events-list`,
|
||||
}),
|
||||
app.inject({ method: "GET", url: `/catalog/databases/${database.id}` }),
|
||||
app.inject({ method: "GET", url: `/catalog/databases/${database.id}/tables` }),
|
||||
app.inject({
|
||||
method: "GET",
|
||||
url: `/catalog/databases/${database.id}/tables/${table.id}/columns`,
|
||||
}),
|
||||
]);
|
||||
expect(apiResponses.every((response) => response.statusCode === 200)).toBe(true);
|
||||
expect(apiResponses.map((response) => response.body).join("\n")).not.toContain(protectedValue);
|
||||
|
||||
const persisted = JSON.stringify({
|
||||
run: await repository.getDescriptionGenerationRun(start.json().id),
|
||||
events: await repository.listDescriptionGenerationEvents(start.json().id),
|
||||
database: await repository.get(database.id),
|
||||
table: await repository.getTable(database.id, table.id),
|
||||
column: await repository.getColumn(database.id, table.id, column.id),
|
||||
});
|
||||
expect(persisted).not.toContain(protectedValue);
|
||||
expect(JSON.stringify(logSpies.flatMap((spy) => spy.mock.calls))).not.toContain(protectedValue);
|
||||
} finally {
|
||||
for (const spy of logSpies) spy.mockRestore();
|
||||
await app.close();
|
||||
}
|
||||
});
|
||||
|
||||
test("wires the production sampler to the same injected CatalogPostgresAccess instance", async () => {
|
||||
let selectedColumnId = "";
|
||||
const sampleSecret = "PRODUCTION_WIRING_SAMPLE_f2986a";
|
||||
|
||||
@@ -222,7 +222,7 @@ test("adds only bounded transient source samples to the model request", async ()
|
||||
tables: [{ name: "patients", sourceComment: null }],
|
||||
columns: [{
|
||||
tableName: "patients",
|
||||
name: "status",
|
||||
name: "patient_email",
|
||||
ordinalPosition: 1,
|
||||
dataType: "text",
|
||||
isNullable: true,
|
||||
@@ -243,9 +243,18 @@ test("adds only bounded transient source samples to the model request", async ()
|
||||
});
|
||||
const table = (await repository.listTables(database.id))[0]!;
|
||||
const columns = await repository.listColumns(database.id, table.id);
|
||||
const column = columns.find((candidate) => candidate.name === "status")!;
|
||||
const column = columns.find((candidate) => candidate.name === "patient_email")!;
|
||||
const ward = columns.find((candidate) => candidate.name === "ward")!;
|
||||
const sampleSecret = "ONLY_IN_TRANSIENT_SAMPLE_7f29c8";
|
||||
await repository.updateColumnMetadata(
|
||||
database.id,
|
||||
table.id,
|
||||
column.id,
|
||||
column.version,
|
||||
column.description,
|
||||
column.generatedDescription,
|
||||
true,
|
||||
);
|
||||
const sampleSecret = "real.patient@hospital.invalid";
|
||||
const sourceSampler: DescriptionSourceSampler = {
|
||||
sample: vi.fn(async () => [{
|
||||
targetId: column.id,
|
||||
@@ -265,11 +274,14 @@ test("adds only bounded transient source samples to the model request", async ()
|
||||
rows: [
|
||||
{ fields: [{ name: ward.name, value: "row-4" }] },
|
||||
{ fields: [{ name: ward.name, value: "row-5" }] },
|
||||
{ fields: [{ name: ward.name, value: "row-6-must-be-omitted" }] },
|
||||
{ fields: [{ name: ward.name, value: "row-6" }] },
|
||||
{ fields: [{ name: ward.name, value: "row-7" }] },
|
||||
{ fields: [{ name: ward.name, value: "row-8" }] },
|
||||
{ fields: [{ name: ward.name, value: "row-9-must-be-omitted" }] },
|
||||
],
|
||||
representativeValues: [{
|
||||
column: ward.name,
|
||||
values: ["ward-1", "ward-2", "ward-3-must-be-omitted"],
|
||||
values: ["ward-1", "ward-2", "ward-3", "ward-4", "ward-5", "ward-6-must-be-omitted"],
|
||||
}],
|
||||
}]),
|
||||
};
|
||||
@@ -321,7 +333,7 @@ test("adds only bounded transient source samples to the model request", async ()
|
||||
expect(sourceSampler.sample).toHaveBeenCalledWith(
|
||||
expect.objectContaining({ id: database.id, binding: database.binding }),
|
||||
[
|
||||
{ targetId: column.id, tableName: table.name, columnNames: [column.name] },
|
||||
{ targetId: column.id, tableName: table.name, columnNames: [] },
|
||||
{ targetId: ward.id, tableName: table.name, columnNames: [ward.name] },
|
||||
],
|
||||
expect.any(AbortSignal),
|
||||
@@ -338,21 +350,29 @@ test("adds only bounded transient source samples to the model request", async ()
|
||||
targetContext.sourceSample?.representativeValues.flatMap((entry) => entry.values) ?? []
|
||||
),
|
||||
);
|
||||
expect(sampledRows).toHaveLength(5);
|
||||
expect(representativeValues).toHaveLength(5);
|
||||
expect(context.targets[0].sourceSample.rows).toHaveLength(3);
|
||||
expect(context.targets[1].sourceSample.rows).toHaveLength(2);
|
||||
expect(sampledRows).toHaveLength(10);
|
||||
expect(representativeValues).toHaveLength(10);
|
||||
expect(context.targets[0].sourceSample.rows).toHaveLength(5);
|
||||
expect(context.targets[1].sourceSample.rows).toHaveLength(5);
|
||||
expect(context.targets[0].sourceSample.representativeValues).toEqual([{
|
||||
column: column.name,
|
||||
values: [sampleSecret, "two", "three"],
|
||||
values: [
|
||||
"marta.rossi@example.com",
|
||||
"luca.bianchi@example.com",
|
||||
"elena.conti@example.com",
|
||||
"paolo.romano@example.com",
|
||||
"giulia.ferrari@example.com",
|
||||
],
|
||||
}]);
|
||||
expect(context.targets[1].sourceSample.representativeValues).toEqual([{
|
||||
column: ward.name,
|
||||
values: ["ward-1", "ward-2"],
|
||||
values: ["ward-1", "ward-2", "ward-3", "ward-4", "ward-5"],
|
||||
}]);
|
||||
expect(userMessage).toContain(sampleSecret);
|
||||
expect(userMessage).not.toContain(sampleSecret);
|
||||
expect(userMessage).not.toMatch(/synthetic|fake|fittizi/i);
|
||||
expect(userMessage).toContain("marta.rossi@example.com");
|
||||
expect(userMessage).not.toMatch(
|
||||
/row-6-must-be-omitted|ward-3-must-be-omitted/,
|
||||
/row-9-must-be-omitted|ward-6-must-be-omitted/,
|
||||
);
|
||||
|
||||
const persisted = JSON.stringify({
|
||||
@@ -366,6 +386,173 @@ test("adds only bounded transient source samples to the model request", async ()
|
||||
expect(persisted).not.toContain(sampleSecret);
|
||||
});
|
||||
|
||||
test("gives every sensitive column synthetic context without consuming the real sample budget", async () => {
|
||||
const repository = new MemoryCatalogRepository();
|
||||
const database = await repository.create({
|
||||
workspaceId: "psd-clinical",
|
||||
engine: "postgres",
|
||||
databaseName: "warehouse",
|
||||
schema: "datawarehouse",
|
||||
binding: { transport: "postgres_direct", host: "db.internal", port: 5432, username: "reader" },
|
||||
});
|
||||
await repository.applySchemaSync(database.id, database.version, "all", [], {
|
||||
schemaVersion: 1,
|
||||
capabilities: { tables: "available", columns: "available", relationships: "available" },
|
||||
tables: [{ name: "patients", sourceComment: null }],
|
||||
columns: [{
|
||||
tableName: "patients",
|
||||
name: "patient_email",
|
||||
ordinalPosition: 1,
|
||||
dataType: "text",
|
||||
isNullable: true,
|
||||
defaultExpression: null,
|
||||
primaryKeyPosition: null,
|
||||
sourceComment: null,
|
||||
}, {
|
||||
tableName: "patients",
|
||||
name: "patient_phone",
|
||||
ordinalPosition: 2,
|
||||
dataType: "text",
|
||||
isNullable: true,
|
||||
defaultExpression: null,
|
||||
primaryKeyPosition: null,
|
||||
sourceComment: null,
|
||||
}, {
|
||||
tableName: "patients",
|
||||
name: "ward",
|
||||
ordinalPosition: 3,
|
||||
dataType: "text",
|
||||
isNullable: true,
|
||||
defaultExpression: null,
|
||||
primaryKeyPosition: null,
|
||||
sourceComment: null,
|
||||
}],
|
||||
relationships: [],
|
||||
});
|
||||
const table = (await repository.listTables(database.id))[0]!;
|
||||
const columns = await repository.listColumns(database.id, table.id);
|
||||
const email = columns.find((column) => column.name === "patient_email")!;
|
||||
const phone = columns.find((column) => column.name === "patient_phone")!;
|
||||
const ward = columns.find((column) => column.name === "ward")!;
|
||||
for (const column of [email, phone]) {
|
||||
await repository.updateColumnMetadata(
|
||||
database.id,
|
||||
table.id,
|
||||
column.id,
|
||||
column.version,
|
||||
column.description,
|
||||
column.generatedDescription,
|
||||
true,
|
||||
);
|
||||
}
|
||||
const wardValues = ["ward-a", "ward-b", "ward-c", "ward-d", "ward-e"];
|
||||
const sourceSampler: DescriptionSourceSampler = {
|
||||
sample: vi.fn(async (_database, targets) => targets.map((target) => {
|
||||
if (target.columnNames.length === 0) {
|
||||
return {
|
||||
targetId: target.targetId,
|
||||
tableName: target.tableName,
|
||||
rows: [],
|
||||
representativeValues: [],
|
||||
};
|
||||
}
|
||||
const columnName = target.columnNames[0]!;
|
||||
return {
|
||||
targetId: target.targetId,
|
||||
tableName: target.tableName,
|
||||
rows: wardValues.map((value) => ({ fields: [{ name: columnName, value }] })),
|
||||
representativeValues: [{ column: columnName, values: wardValues }],
|
||||
};
|
||||
})),
|
||||
};
|
||||
const completer: ModelCompleter = {
|
||||
complete: vi.fn(async (request) => {
|
||||
const context = JSON.parse(request.messages[1]!.content.split("\n").slice(1).join("\n"));
|
||||
return JSON.stringify({
|
||||
results: context.targets.map((target: { targetId: string }) => ({
|
||||
targetId: target.targetId,
|
||||
outcome: "generated",
|
||||
description: "Descrizione generata.",
|
||||
})),
|
||||
});
|
||||
}),
|
||||
};
|
||||
const models: MetadataGenerationModels = {
|
||||
catalog: () => ({ models: [{ id: "openai-mini", label: "OpenAI Mini" }], default: "openai-mini" }),
|
||||
resolve: () => ({
|
||||
id: "openai-mini",
|
||||
provider: "openai",
|
||||
model: "gpt-4.1-mini",
|
||||
apiKeyEnv: "OPENAI_API_KEY",
|
||||
apiKey: "test-provider-secret",
|
||||
}),
|
||||
};
|
||||
const worker = new DescriptionGenerationWorker(
|
||||
repository,
|
||||
{
|
||||
read: vi.fn(async () => ({
|
||||
workspace: { workspace: { language: "it" } },
|
||||
revision: {},
|
||||
})),
|
||||
} as unknown as WorkspaceRegistry,
|
||||
models,
|
||||
completer,
|
||||
new CatalogOperationCoordinator(),
|
||||
sourceSampler,
|
||||
);
|
||||
|
||||
const run = await worker.start(
|
||||
database.id,
|
||||
"openai-mini",
|
||||
"selected_columns",
|
||||
[email.id, phone.id, ward.id],
|
||||
);
|
||||
await worker.waitForRun(run.id);
|
||||
|
||||
expect(sourceSampler.sample).toHaveBeenCalledWith(
|
||||
expect.objectContaining({ id: database.id }),
|
||||
[
|
||||
{ targetId: email.id, tableName: table.name, columnNames: [] },
|
||||
{ targetId: phone.id, tableName: table.name, columnNames: [] },
|
||||
{ targetId: ward.id, tableName: table.name, columnNames: [ward.name] },
|
||||
],
|
||||
expect.any(AbortSignal),
|
||||
);
|
||||
const request = vi.mocked(completer.complete).mock.calls[0]![0] as ModelCompletionRequest;
|
||||
const context = JSON.parse(request.messages[1]!.content.split("\n").slice(1).join("\n"));
|
||||
const targets = new Map(
|
||||
context.targets.map((target: { targetId: string }) => [target.targetId, target]),
|
||||
);
|
||||
expect(targets.get(email.id)).toMatchObject({
|
||||
sourceSample: {
|
||||
rows: expect.arrayContaining([
|
||||
{ fields: [{ name: email.name, value: "marta.rossi@example.com" }] },
|
||||
]),
|
||||
representativeValues: [{
|
||||
column: email.name,
|
||||
values: expect.arrayContaining(["marta.rossi@example.com"]),
|
||||
}],
|
||||
},
|
||||
});
|
||||
expect(targets.get(phone.id)).toMatchObject({
|
||||
sourceSample: {
|
||||
rows: expect.arrayContaining([
|
||||
{ fields: [{ name: phone.name, value: "+39 02 5550 1001" }] },
|
||||
]),
|
||||
representativeValues: [{
|
||||
column: phone.name,
|
||||
values: expect.arrayContaining(["+39 02 5550 1001"]),
|
||||
}],
|
||||
},
|
||||
});
|
||||
expect(targets.get(ward.id)).toMatchObject({
|
||||
sourceSample: {
|
||||
rows: wardValues.map((value) => ({ fields: [{ name: ward.name, value }] })),
|
||||
representativeValues: [{ column: ward.name, values: wardValues }],
|
||||
},
|
||||
});
|
||||
});
|
||||
|
||||
test("continues metadata-only with one safe warning when source sampling is unavailable", async () => {
|
||||
const repository = new MemoryCatalogRepository();
|
||||
const database = await repository.create({
|
||||
|
||||
@@ -11,6 +11,7 @@ import { up as upDatabases } from "../src/catalog/migrations/001_workspace_datab
|
||||
import { up as upTables } from "../src/catalog/migrations/002_catalog_tables.js";
|
||||
import { up as upSchemaSync } from "../src/catalog/migrations/003_catalog_schema_sync.js";
|
||||
import { up as upDescriptionGeneration } from "../src/catalog/migrations/005_description_generation_runs.js";
|
||||
import { up as upSensitiveDataFlag } from "../src/catalog/migrations/006_sensitive_data_flag.js";
|
||||
import { KyselyCatalogRepository, type CatalogDatabase } from "../src/catalog/repository.js";
|
||||
import { loadConfig } from "../src/config.js";
|
||||
import type { WorkspaceRegistry } from "../src/workspaces/registry.js";
|
||||
@@ -43,6 +44,7 @@ test.skipIf(!dockerAvailable)("Fastify persists Description Generation success a
|
||||
await upDatabases(db);
|
||||
await upTables(db);
|
||||
await upSchemaSync(db);
|
||||
await upSensitiveDataFlag(db);
|
||||
await upDescriptionGeneration(db);
|
||||
const repository = new KyselyCatalogRepository(db);
|
||||
const database = await repository.create({
|
||||
|
||||
@@ -92,6 +92,34 @@ test("samples at most five source rows and five distinct non-null examples in a
|
||||
expect(end).toHaveBeenCalledOnce();
|
||||
});
|
||||
|
||||
test("does not issue a SELECT when a protected target has no source columns", async () => {
|
||||
const query = vi.fn(async () => ({ rows: [] }));
|
||||
const end = vi.fn(async () => undefined);
|
||||
const access: CatalogPostgresAccess = {
|
||||
connect: vi.fn(async () => ({ query, end }) as CatalogDatabaseClient),
|
||||
};
|
||||
const sampler = new PostgresDescriptionSourceSampler(access);
|
||||
|
||||
const samples = await sampler.sample(database, [{
|
||||
targetId: target.targetId,
|
||||
tableName: target.tableName,
|
||||
columnNames: [],
|
||||
}], new AbortController().signal);
|
||||
|
||||
expect(samples).toEqual([{
|
||||
targetId: target.targetId,
|
||||
tableName: target.tableName,
|
||||
rows: [],
|
||||
representativeValues: [],
|
||||
}]);
|
||||
expect(query.mock.calls).toEqual([
|
||||
["BEGIN TRANSACTION READ ONLY", []],
|
||||
["ROLLBACK", []],
|
||||
]);
|
||||
expect(query.mock.calls.some(([sql]) => String(sql).startsWith("SELECT"))).toBe(false);
|
||||
expect(end).toHaveBeenCalledOnce();
|
||||
});
|
||||
|
||||
test("rolls back and closes the source connection when sampling fails", async () => {
|
||||
const query = vi.fn(async (sql: string) => {
|
||||
if (sql.startsWith("SELECT")) throw new Error("distinctive-source-secret");
|
||||
|
||||
@@ -10,6 +10,7 @@ import { up as upTables } from "../src/catalog/migrations/002_catalog_tables.js"
|
||||
import { up as upSchemaSync } from "../src/catalog/migrations/003_catalog_schema_sync.js";
|
||||
import { up as upRuntimeSequencePrivileges } from "../src/catalog/migrations/004_catalog_runtime_sequence_privileges.js";
|
||||
import { up as upDescriptionGeneration } from "../src/catalog/migrations/005_description_generation_runs.js";
|
||||
import { up as upSensitiveDataFlag } from "../src/catalog/migrations/006_sensitive_data_flag.js";
|
||||
|
||||
const dockerAvailable = spawnSync("docker", ["info"], { stdio: "ignore" }).status === 0;
|
||||
|
||||
@@ -23,6 +24,7 @@ test.skipIf(!dockerAvailable)("PostgreSQL migration enforces one database per wo
|
||||
await upDatabases(db);
|
||||
await upTables(db);
|
||||
await upSchemaSync(db);
|
||||
await upSensitiveDataFlag(db);
|
||||
await sql`CREATE ROLE thothii_catalog_runtime`.execute(db);
|
||||
await upRuntimeSequencePrivileges(db);
|
||||
const sequencePrivilege = await sql<{ allowed: boolean }>`
|
||||
@@ -75,11 +77,47 @@ test.skipIf(!dockerAvailable)("PostgreSQL migration enforces one database per wo
|
||||
};
|
||||
expect(await repository.applySchemaSync(created.id, 1, "columns", [], fullColumnsSnapshot))
|
||||
.toMatchObject({ created: 4, deleted: 0 });
|
||||
expect((await repository.listColumns(created.id, patients.id)).map((column) => column.name))
|
||||
.toEqual(["id", "name"]);
|
||||
expect((await repository.listColumns(created.id, patients.id)).map((column) => ({
|
||||
name: column.name,
|
||||
sensitive: column.sensitive,
|
||||
}))).toEqual([
|
||||
{ name: "id", sensitive: false },
|
||||
{ name: "name", sensitive: false },
|
||||
]);
|
||||
expect((await repository.listColumns(created.id, visits.id)).map((column) => column.name))
|
||||
.toEqual(["id", "patient_id"]);
|
||||
|
||||
const patientName = (await repository.listColumns(created.id, patients.id))
|
||||
.find((column) => column.name === "name")!;
|
||||
expect(await repository.updateColumnMetadata(
|
||||
created.id,
|
||||
patients.id,
|
||||
patientName.id,
|
||||
patientName.version,
|
||||
patientName.description,
|
||||
patientName.generatedDescription,
|
||||
true,
|
||||
)).toMatchObject({ sensitive: true });
|
||||
const refreshedColumnsSnapshot: ObservedSchemaSnapshot = {
|
||||
...fullColumnsSnapshot,
|
||||
schemaVersion: 2,
|
||||
columns: fullColumnsSnapshot.columns.map((column) => column.tableName === "patients"
|
||||
&& column.name === "name"
|
||||
? { ...column, sourceComment: "Sensitive patient name" }
|
||||
: column),
|
||||
};
|
||||
expect(await repository.applySchemaSync(
|
||||
created.id,
|
||||
1,
|
||||
"columns",
|
||||
[patients.id],
|
||||
refreshedColumnsSnapshot,
|
||||
)).toMatchObject({ updated: 1 });
|
||||
expect(await repository.getColumn(created.id, patients.id, patientName.id)).toMatchObject({
|
||||
sensitive: true,
|
||||
sourceComment: "Sensitive patient name",
|
||||
});
|
||||
|
||||
const reducedColumnsSnapshot: ObservedSchemaSnapshot = {
|
||||
...fullColumnsSnapshot,
|
||||
columns: fullColumnsSnapshot.columns.filter((column) => column.name === "id"),
|
||||
@@ -135,6 +173,7 @@ test.skipIf(!dockerAvailable)("PostgreSQL repository performs scoped metadata cl
|
||||
await upDatabases(db);
|
||||
await upTables(db);
|
||||
await upSchemaSync(db);
|
||||
await upSensitiveDataFlag(db);
|
||||
const repository = new KyselyCatalogRepository(db);
|
||||
const database = await repository.create({
|
||||
workspaceId: "cleanup-test",
|
||||
@@ -212,6 +251,7 @@ test.skipIf(!dockerAvailable)("PostgreSQL repository atomically consolidates sel
|
||||
await upDatabases(db);
|
||||
await upTables(db);
|
||||
await upSchemaSync(db);
|
||||
await upSensitiveDataFlag(db);
|
||||
const repository = new KyselyCatalogRepository(db);
|
||||
const database = await repository.create({
|
||||
workspaceId: "consolidation-test",
|
||||
@@ -310,6 +350,7 @@ test.skipIf(!dockerAvailable)("PostgreSQL repository persists globally exclusive
|
||||
await upDatabases(db);
|
||||
await upTables(db);
|
||||
await upSchemaSync(db);
|
||||
await upSensitiveDataFlag(db);
|
||||
await upDescriptionGeneration(db);
|
||||
const repository = new KyselyCatalogRepository(db);
|
||||
const firstDatabase = await repository.create({
|
||||
|
||||
@@ -234,16 +234,30 @@ test("keeps generated descriptions editable and preserves them across synchroniz
|
||||
});
|
||||
expect(editedTable.json()).toMatchObject({ description: null, generatedDescription: "Generated table draft" });
|
||||
const idColumn = (await repository.listColumns(database.id, patients.id))[0];
|
||||
expect(idColumn.sensitive).toBe(false);
|
||||
const editedColumn = await app.inject({
|
||||
method: "PATCH", url: `/catalog/databases/${database.id}/tables/${patients.id}/columns/${idColumn.id}`,
|
||||
payload: { version: idColumn.version, description: "Reviewed key", generatedDescription: "Generated key draft" },
|
||||
payload: {
|
||||
version: idColumn.version,
|
||||
description: "Reviewed key",
|
||||
generatedDescription: "Generated key draft",
|
||||
sensitive: true,
|
||||
},
|
||||
});
|
||||
expect(editedColumn.json()).toMatchObject({
|
||||
description: "Reviewed key",
|
||||
generatedDescription: "Generated key draft",
|
||||
sensitive: true,
|
||||
});
|
||||
expect(editedColumn.json()).toMatchObject({ description: "Reviewed key", generatedDescription: "Generated key draft" });
|
||||
|
||||
const second = await app.inject({ method: "POST", url: `/catalog/databases/${database.id}/sync-runs`, payload: { version: database.version, scope: "all", tableIds: [] } });
|
||||
await waitFor(repository, second.json().id, "succeeded");
|
||||
expect(await repository.getTable(database.id, patients.id)).toMatchObject({ generatedDescription: "Generated table draft" });
|
||||
expect(await repository.getColumn(database.id, patients.id, idColumn.id)).toMatchObject({ description: "Reviewed key", generatedDescription: "Generated key draft" });
|
||||
expect(await repository.getColumn(database.id, patients.id, idColumn.id)).toMatchObject({
|
||||
description: "Reviewed key",
|
||||
generatedDescription: "Generated key draft",
|
||||
sensitive: true,
|
||||
});
|
||||
});
|
||||
|
||||
test("consolidates non-empty generated table descriptions and reports skipped selections", async () => {
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
import { expect, test } from "vitest";
|
||||
import { syntheticSampleValue } from "../src/catalog/synthetic-sample-value.js";
|
||||
|
||||
test.each([
|
||||
["text[]", "tags", 1, "{tags_001,tags_002}"],
|
||||
["json", "payload", 2, '{"example":"payload_002","sequence":2}'],
|
||||
["jsonb", "attributes", 3, '{"example":"attributes_003","sequence":3}'],
|
||||
["inet", "client_ip", 4, "192.0.2.4"],
|
||||
["cidr", "network", 5, "192.0.2.0/24"],
|
||||
["time without time zone", "opening_time", 6, "10:30:06"],
|
||||
["interval", "duration", 7, "7 days 07:00:00"],
|
||||
["bytea", "digest", 8, "\\x00000008"],
|
||||
] as const)(
|
||||
"creates a deterministic PostgreSQL-shaped value for %s",
|
||||
(dataType, name, index, expected) => {
|
||||
const column = { name, dataType };
|
||||
|
||||
expect(syntheticSampleValue(column, index)).toBe(expected);
|
||||
expect(syntheticSampleValue(column, index)).toBe(expected);
|
||||
},
|
||||
);
|
||||
|
||||
test("uses the PostgreSQL type before birth-related name hints", () => {
|
||||
expect(syntheticSampleValue({ name: "birth_year", dataType: "integer" }, 2)).toBe(1002);
|
||||
expect(syntheticSampleValue({ name: "birth_date", dataType: "date" }, 2))
|
||||
.toBe("1982-01-02");
|
||||
expect(syntheticSampleValue({ name: "birth_recorded_at", dataType: "timestamp" }, 2))
|
||||
.toBe("2024-01-02T10:30:00.000Z");
|
||||
});
|
||||
Reference in New Issue
Block a user