From 276717005da928ef70d7bf163a87b0c99169814f Mon Sep 17 00:00:00 2001 From: mptyl Date: Sat, 27 Jun 2026 06:45:00 +0200 Subject: [PATCH] fix(harness): drop THOTH_SSL_CA from REQUIRED_L2 + isolate profile in workspace test Two fixes found while unblocking the L2 setup: 1. conftest: THOTH_SSL_CA is NOT an L2 prerequisite. The DWH endpoint presents a public cert (*.policlinicosandonato.it, signed by GoDaddy), already in the certifi bundle, so the REST clients validate TLS with verify=True -- no CA file needed. The ssl_ca line was commented out in ChironeWp3's nsp.yaml too. 2. test_workspace: the profile-default assertion collided with the operator's real harness/.env once load_dotenv (D3) started injecting THOTH_PROFILE into the process env. The test now dels THOTH_PROFILE to assert the actual *default* (server), regardless of what the operator set in .env. Suite: 109 passed. --- harness/tests/conftest.py | 5 ++++- harness/tests/test_workspace.py | 4 ++++ 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/harness/tests/conftest.py b/harness/tests/conftest.py index 81081d1f..cb6e904d 100644 --- a/harness/tests/conftest.py +++ b/harness/tests/conftest.py @@ -23,7 +23,10 @@ load_dotenv(_ROOT / ".env") # L2 connection prerequisites (spec Testing Strategy). If any is missing/empty, L2 # tests are SKIPPED (not failed) so the default run (pytest = L0+L1) stays green. -REQUIRED_L2 = ["THOTH_DWH_API_KEY", "THOTH_VEC_API_KEY", "THOTH_VEC_WRITE_API_KEY", "THOTH_SSL_CA"] +# NOTE: THOTH_SSL_CA is NOT required -- the DWH endpoint presents a public cert +# (*.policlinicosandonato.it signed by GoDaddy), already in the certifi bundle, so +# the clients fall back to verify=True and TLS validates without a CA file. +REQUIRED_L2 = ["THOTH_DWH_API_KEY", "THOTH_VEC_API_KEY", "THOTH_VEC_WRITE_API_KEY"] @pytest.fixture(scope="session") diff --git a/harness/tests/test_workspace.py b/harness/tests/test_workspace.py index 3285e5fb..4332f8fa 100644 --- a/harness/tests/test_workspace.py +++ b/harness/tests/test_workspace.py @@ -4,6 +4,10 @@ from nsp.workspace import load_workspace, WorkspaceError def test_load_workspace_expands_env_vars(monkeypatch, tmp_path): + # Isolate profile: load_dotenv (conftest D3) injects THOTH_PROFILE from the real + # harness/.env into os.environ; this test asserts the *default* (server), so it + # must del THOTH_PROFILE rather than inherit whatever the operator set. + monkeypatch.delenv("THOTH_PROFILE", raising=False) monkeypatch.setenv("THOTH_VEC_API_KEY", "secret-reader") monkeypatch.setenv("THOTH_VEC_WRITE_API_KEY", "secret-writer") monkeypatch.setenv("THOTH_VEC_REST_URL", "https://example/vector/v1/")