fix: reject executable pi configuration
This commit is contained in:
@@ -73,6 +73,32 @@ test("options expose only closed provider, model, and reasoning choices", async
|
||||
});
|
||||
});
|
||||
|
||||
// Catches raw managed models.json validation details being collapsed into an ambiguous model-list
|
||||
// failure or escaping through the Pi Management options API.
|
||||
test("options report invalid managed model configuration with a stable sanitized error", async () => {
|
||||
const service = createPiManagement(configFor(), {
|
||||
execute: successfulExec([]),
|
||||
listModels: async () => {
|
||||
throw Object.assign(
|
||||
new Error("!sensitive-command /private/models.json raw-secret"),
|
||||
{ code: "PI_MANAGED_CONFIG_INVALID" },
|
||||
);
|
||||
},
|
||||
});
|
||||
|
||||
let caught: unknown;
|
||||
try {
|
||||
await service.options();
|
||||
} catch (error) {
|
||||
caught = error;
|
||||
}
|
||||
expect(caught).toMatchObject<PiManagementError>({
|
||||
code: "pi_management_unavailable",
|
||||
message: "Pi provider/model configuration is invalid",
|
||||
});
|
||||
expect(String(caught)).not.toMatch(/sensitive|private|models\.json|secret/i);
|
||||
});
|
||||
|
||||
// Catches configuration writes that accept whitespace, unknown choices, or extra free-form fields
|
||||
// before reaching the durable installation settings file.
|
||||
test("config rejects invalid free-form values before writing settings", async () => {
|
||||
@@ -186,6 +212,31 @@ test("smoke fails closed and sanitizes configured-provider authentication errors
|
||||
expect(JSON.stringify(result)).not.toMatch(/raw-expired-token|raw-provider-output/);
|
||||
});
|
||||
|
||||
// Catches selected auth/models validation failures being downgraded to a generic provider error
|
||||
// or exposing the rejected command, path, or secret through POST /pi-management/test.
|
||||
test("smoke reports invalid managed provider configuration with a stable sanitized error", async () => {
|
||||
const service = createPiManagement(configFor(), {
|
||||
execute: successfulExec([]),
|
||||
listModels: async () => supportedModels,
|
||||
readSettings: () => ({ provider: "zai", model: "glm-5.2", thinking: "medium" }),
|
||||
smokeProvider: async () => {
|
||||
throw Object.assign(
|
||||
new Error("!sensitive-command /private/models.json raw-secret"),
|
||||
{ code: "PI_MANAGED_CONFIG_INVALID" },
|
||||
);
|
||||
},
|
||||
now: () => new Date("2026-08-05T10:00:00.000Z"),
|
||||
});
|
||||
|
||||
const result = await service.test();
|
||||
expect(result).toEqual({
|
||||
ready: false,
|
||||
message: "Pi provider/model configuration is invalid",
|
||||
checkedAt: "2026-08-05T10:00:00.000Z",
|
||||
});
|
||||
expect(JSON.stringify(result)).not.toMatch(/sensitive|private|models\.json|secret/i);
|
||||
});
|
||||
|
||||
// Catches separate per-phase timeouts that allow a later provider turn to exceed the one
|
||||
// end-to-end Pi Management smoke budget.
|
||||
test("smoke applies one deadline across version and a hung provider turn", async () => {
|
||||
|
||||
Reference in New Issue
Block a user