fix(backend): allow configured local Qwen provider

This commit is contained in:
User
2026-07-14 18:44:12 +02:00
parent 3d23d0543c
commit 0cf86e3540
3 changed files with 40 additions and 21 deletions
+23 -20
View File
@@ -289,26 +289,29 @@ test.each([["OpenAI", "openai"], ["gemini", "google"]])(
},
);
test("local providers spawn without a model key and scrub ambient generic credentials", async () => {
vi.stubEnv("PI_PROVIDER_API_KEY", "ambient-secret");
vi.stubEnv("THT_MODEL_API_KEY_FILE", "/ambient/secret-path");
vi.stubEnv("OPENAI_API_KEY", "unselected-provider-secret");
const calls: any[][] = [];
const child = recordingChild();
child.stderr.resume = () => {};
const mgr = new PiProcessManager(loadConfig({ PI_BIN: "/usr/local/bin/pi" }), {
spawnFn: (...args: any[]) => { calls.push(args); return child as any; },
});
try {
await mgr.spawnFor("local-session", { provider: "ollama" });
expect(calls[0][2].env).not.toHaveProperty("PI_PROVIDER_API_KEY");
expect(calls[0][2].env).not.toHaveProperty("THT_MODEL_API_KEY_FILE");
expect(calls[0][2].env).not.toHaveProperty("OPENAI_API_KEY");
} finally {
mgr.teardown("local-session");
vi.unstubAllEnvs();
}
});
test.each(["ollama", "local-qwen"])(
"local provider %s spawns without a model key and scrubs ambient credentials",
async (provider) => {
vi.stubEnv("PI_PROVIDER_API_KEY", "ambient-secret");
vi.stubEnv("THT_MODEL_API_KEY_FILE", "/ambient/secret-path");
vi.stubEnv("OPENAI_API_KEY", "unselected-provider-secret");
const calls: any[][] = [];
const child = recordingChild();
child.stderr.resume = () => {};
const mgr = new PiProcessManager(loadConfig({ PI_BIN: "/usr/local/bin/pi" }), {
spawnFn: (...args: any[]) => { calls.push(args); return child as any; },
});
try {
await mgr.spawnFor(`local-session-${provider}`, { provider });
expect(calls[0][2].env).not.toHaveProperty("PI_PROVIDER_API_KEY");
expect(calls[0][2].env).not.toHaveProperty("THT_MODEL_API_KEY_FILE");
expect(calls[0][2].env).not.toHaveProperty("OPENAI_API_KEY");
} finally {
mgr.teardown(`local-session-${provider}`);
vi.unstubAllEnvs();
}
},
);
test.each(["amazon-bedrock", "azure-openai-responses", "cloudflare-workers-ai", "cloudflare-ai-gateway"])(
"session spawn rejects compound provider %s before spawning Pi", async (provider) => {
+14
View File
@@ -116,6 +116,20 @@ test("single-key providers scrub ambient compound companions before injecting th
expect(env).not.toHaveProperty("CLOUDFLARE_GATEWAY_ID");
});
test("local-qwen is an explicit local provider and needs no generic key", () => {
const env = buildPiChildEnv({
ambient: {
PI_PROVIDER_API_KEY: "must-not-leak",
OPENAI_API_KEY: "must-not-leak",
THT_MODEL_API_KEY_FILE: "/must/not/leak",
},
provider: "local-qwen",
});
expect(env).not.toHaveProperty("PI_PROVIDER_API_KEY");
expect(env).not.toHaveProperty("OPENAI_API_KEY");
expect(env).not.toHaveProperty("THT_MODEL_API_KEY_FILE");
});
test("bundle value is injected without exposing bundle metadata to Pi", () => {
const env = buildPiChildEnv({
ambient: {