fix(backend): reject compound provider credentials
This commit is contained in:
@@ -262,6 +262,25 @@ test("local providers spawn without a model key and scrub ambient generic creden
|
||||
}
|
||||
});
|
||||
|
||||
test.each(["amazon-bedrock", "azure-openai-responses", "cloudflare-workers-ai", "cloudflare-ai-gateway"])(
|
||||
"session spawn rejects compound provider %s before spawning Pi", async (provider) => {
|
||||
const secret = path.resolve(__dirname, `.compound-key-${process.pid}-${provider}`);
|
||||
writeFileSync(secret, "provider-secret", { mode: 0o600 });
|
||||
let spawns = 0;
|
||||
const mgr = new PiProcessManager(loadConfig({ THT_MODEL_API_KEY_FILE: secret }), {
|
||||
spawnFn: () => { spawns += 1; throw new Error("must not spawn"); },
|
||||
});
|
||||
try {
|
||||
await expect(mgr.spawnFor("compound-provider", { provider })).rejects.toThrow(
|
||||
"compound credential bundles are unsupported by THT_MODEL_API_KEY_FILE; dedicated provider configuration is required",
|
||||
);
|
||||
expect(spawns).toBe(0);
|
||||
} finally {
|
||||
await import("node:fs/promises").then((fs) => fs.unlink(secret));
|
||||
}
|
||||
},
|
||||
);
|
||||
|
||||
test.each(["missing", "permissive", "unreadable", "directory", "symlink", "unsupported"])(
|
||||
"hosted provider credential failure is sanitized: %s", async (kind) => {
|
||||
const target = path.resolve(__dirname, `.bad-model-key-${process.pid}-${kind}`);
|
||||
|
||||
Reference in New Issue
Block a user