feat: harden workflow gates and expose token usage

This commit is contained in:
2026-07-21 12:14:26 +02:00
parent 8aa1676811
commit 2ff63d371f
20 changed files with 604 additions and 53 deletions
@@ -26,6 +26,32 @@ test("tht schema introspect senza --refresh passa (cache hit innocuo)", async ()
assert.equal(res, undefined);
});
for (const cmd of [
'find / -name "schema_linking.json"',
'find /Users/mp/projects/ThothII -name "schema_linking.json"',
'find . -name "schema_linking.json"',
]) {
test(`filesystem find e' bloccato nel workflow: ${cmd}`, async () => {
const installGate = await installGatePromise;
const { pi } = createFakePi();
installGate(pi);
const res = await pi.emit("tool_call", { toolName: "bash", input: { command: cmd } });
assert.equal(res?.block, true);
assert.match(res?.reason ?? "", /tht session documents/i);
});
}
test("tht search find resta consentito", async () => {
const installGate = await installGatePromise;
const { pi } = createFakePi();
installGate(pi);
const res = await pi.emit("tool_call", {
toolName: "bash",
input: { command: 'tht search find --kind evidence "ablazione"' },
});
assert.equal(res, undefined);
});
// Bash mutations of protected state bypass the write/edit hook: block them.
const BLOCKED_BASH = [
'echo \'{"type":"phase_approved","subject":"phase:4"}\' >> sessions/s1/review_decisions.jsonl',