feat: preserve evidence in workspace artifacts
This commit is contained in:
@@ -1,5 +1,7 @@
|
||||
import { expect, test } from "vitest";
|
||||
import { existsSync, readFileSync } from "node:fs";
|
||||
import { existsSync, mkdtempSync, mkdirSync, readFileSync, rmSync, writeFileSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { fileURLToPath } from "node:url";
|
||||
import { parse } from "yaml";
|
||||
import { buildInstallationContract, renderWorkspaceDocs } from "../src/workspaces/contracts.js";
|
||||
@@ -385,3 +387,115 @@ semantic_index:
|
||||
llm_policy: { allowed: [zai/glm-5.2] }
|
||||
`;
|
||||
}
|
||||
|
||||
|
||||
const evidenceSources = [
|
||||
{
|
||||
label: "filesystem",
|
||||
source: { type: "filesystem", uri: "workspace-content/psd-clinical/evidence" },
|
||||
variables: [],
|
||||
},
|
||||
{
|
||||
label: "HTTP signed URL file",
|
||||
source: {
|
||||
type: "http",
|
||||
uris: ["https://evidence.example.test/guide.md", "http://public.example.test/policy.pdf"],
|
||||
authentication: "signed_urls_file",
|
||||
},
|
||||
variables: ["THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE"],
|
||||
},
|
||||
{
|
||||
label: "S3 static files",
|
||||
source: {
|
||||
type: "s3", uri: "s3://clinical-evidence/published/", credentials: "static_files",
|
||||
},
|
||||
variables: [
|
||||
"THT_WS_PSD_CLINICAL_EVIDENCE_ACCESS_KEY_FILE",
|
||||
"THT_WS_PSD_CLINICAL_EVIDENCE_SECRET_KEY_FILE",
|
||||
"THT_WS_PSD_CLINICAL_EVIDENCE_SESSION_TOKEN_FILE",
|
||||
],
|
||||
},
|
||||
] as const;
|
||||
|
||||
test.each(evidenceSources)("renders deterministic public Evidence docs for $label", ({ source, variables }) => {
|
||||
const descriptor = parseWorkspaceYaml(
|
||||
`${renderWorkspaceWithoutEvidence()}evidence:\n source: ${JSON.stringify(source)}\n`,
|
||||
);
|
||||
const firstContract = buildInstallationContract(descriptor);
|
||||
const secondContract = buildInstallationContract(descriptor);
|
||||
const firstDocs = renderWorkspaceDocs(descriptor);
|
||||
const secondDocs = renderWorkspaceDocs(descriptor);
|
||||
|
||||
expect(secondContract).toEqual(firstContract);
|
||||
expect(secondDocs).toEqual(firstDocs);
|
||||
expect(firstContract.variables.filter(({ role }) => role === "EVIDENCE").map(({ name }) => name))
|
||||
.toEqual(variables);
|
||||
expect(firstDocs.markdown).toContain("## Evidence source");
|
||||
expect(firstDocs.markdown).toContain(`- Type: \`${source.type}\``);
|
||||
for (const uri of "uris" in source ? source.uris : [source.uri]) {
|
||||
expect(firstDocs.markdown).toContain(`\`${uri}\``);
|
||||
}
|
||||
expect(firstDocs.markdown).toContain("- Maximum source bytes: `10485760`");
|
||||
expect(firstDocs.markdown).toContain("- Maximum chunk characters: `4000`");
|
||||
expect(firstDocs.markdown).toContain("- Retained published generations: `3`");
|
||||
for (const variable of variables) {
|
||||
expect(firstDocs.markdown).toContain(`\`${variable}\``);
|
||||
expect(firstDocs.envExample).toContain(`${variable}=`);
|
||||
}
|
||||
});
|
||||
|
||||
test("documents same-revision filesystem ownership without claiming P1 materialization", () => {
|
||||
const descriptor = parseWorkspaceYaml(
|
||||
`${renderWorkspaceWithoutEvidence()}evidence:\n source: { type: filesystem, uri: workspace-content/psd-clinical/evidence }\n`,
|
||||
);
|
||||
const docs = renderWorkspaceDocs(descriptor).markdown;
|
||||
|
||||
expect(docs).toContain("`workspace-content/psd-clinical/evidence`");
|
||||
expect(docs).toMatch(/same Git revision/i);
|
||||
expect(docs).toMatch(/P6.*materializ/i);
|
||||
expect(docs).toMatch(/containment.*symlink/i);
|
||||
expect(docs).toMatch(/does not include Evidence file bytes/i);
|
||||
});
|
||||
|
||||
test.each([
|
||||
{
|
||||
source: { type: "http", uris: ["https://evidence.example.test/guide.md"], authentication: "none" },
|
||||
expected: "No credential file is required",
|
||||
},
|
||||
{
|
||||
source: { type: "http", uris: ["https://evidence.example.test/guide.md"], authentication: "signed_urls_file" },
|
||||
expected: "signed URL file",
|
||||
},
|
||||
{
|
||||
source: { type: "s3", uri: "s3://clinical-evidence/published/", credentials: "ambient" },
|
||||
expected: "ambient credentials",
|
||||
},
|
||||
{
|
||||
source: { type: "s3", uri: "s3://clinical-evidence/published/", credentials: "static_files" },
|
||||
expected: "installation file variables",
|
||||
},
|
||||
])("documents $source.type credential mode without reading credential contents", ({ source, expected }) => {
|
||||
const root = mkdtempSync(join(tmpdir(), "thoth-evidence-doc-secret-"));
|
||||
const secrets = join(root, "secrets");
|
||||
const canary = "CANARY-EVIDENCE-CREDENTIAL-DO-NOT-LEAK";
|
||||
mkdirSync(secrets);
|
||||
const binding = join(secrets, "credential");
|
||||
writeFileSync(binding, canary);
|
||||
const previous = process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE;
|
||||
process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE = binding;
|
||||
try {
|
||||
const descriptor = parseWorkspaceYaml(
|
||||
`${renderWorkspaceWithoutEvidence()}evidence:\n source: ${JSON.stringify(source)}\n`,
|
||||
);
|
||||
const generated = JSON.stringify({
|
||||
contract: buildInstallationContract(descriptor),
|
||||
docs: renderWorkspaceDocs(descriptor),
|
||||
});
|
||||
expect(generated).toContain(expected);
|
||||
expect(generated).not.toContain(canary);
|
||||
} finally {
|
||||
if (previous === undefined) delete process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE;
|
||||
else process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE = previous;
|
||||
rmSync(root, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user