feat: complete evidence restructuring worktree

This commit is contained in:
Codex
2026-08-26 11:39:02 +02:00
parent a54d4769dd
commit 38f02cfd08
56 changed files with 1981 additions and 1801 deletions
+28
View File
@@ -0,0 +1,28 @@
import { expect, test } from "vitest";
import {
PI_MANAGED_CONFIG_ERROR_MESSAGE,
configuredPiProviderApiKey,
} from "../src/pi/managed-config.js";
test("provider credential declarations are selected from models.json by provider ID", () => {
const raw = JSON.stringify({
providers: {
hosted: { apiKey: "$HOSTED_API_KEY", models: [{ id: "one" }] },
local: { apiKey: "local", models: [{ id: "two" }] },
},
});
expect(configuredPiProviderApiKey(raw, "HOSTED")).toBe("$HOSTED_API_KEY");
expect(configuredPiProviderApiKey(raw, "local")).toBe("local");
expect(configuredPiProviderApiKey(raw, "missing")).toBeUndefined();
});
test.each([
JSON.stringify({ providers: [] }),
JSON.stringify({ providers: { local: "invalid" } }),
JSON.stringify({ providers: { local: { apiKey: 42 } } }),
JSON.stringify({ providers: { local: { apiKey: "!must-not-run" } } }),
])("invalid declarative provider credential configuration fails closed", (raw) => {
expect(() => configuredPiProviderApiKey(raw, "local"))
.toThrow(PI_MANAGED_CONFIG_ERROR_MESSAGE);
});
+17 -3
View File
@@ -22,7 +22,7 @@ const SAFE_AUTH = '{"deepseek":{"type":"api_key","key":"safe-token"}}\n';
const SAFE_MODELS = [
"{",
' "providers": {',
' "local-qwen": {"baseUrl":"http://model.invalid/v1","models":[{"id":"qwen"}]}',
' "local-qwen": {"baseUrl":"http://model.invalid/v1","apiKey":"local","models":[{"id":"qwen"}]}',
" }",
"}",
"",
@@ -670,9 +670,22 @@ test.each([["OpenAI", "openai"], ["gemini", "google"]])(
},
);
test.each(["ollama", "local-qwen"])(
"local provider %s spawns without a model key and scrubs ambient credentials",
test.each(["installation-local", "private-compatible"])(
"provider %s configured with a literal apiKey spawns without a managed key",
async (provider) => {
const root = mkdtempSync(path.join(tmpdir(), "tht-local-provider-"));
const agentDir = path.join(root, "agent");
mkdirSync(agentDir, { mode: 0o700 });
writeFileSync(path.join(agentDir, "models.json"), JSON.stringify({
providers: {
[provider]: {
baseUrl: "http://model.invalid/v1",
apiKey: "local",
models: [{ id: "model" }],
},
},
}), { mode: 0o600 });
vi.stubEnv("PI_CODING_AGENT_DIR", agentDir);
vi.stubEnv("PI_PROVIDER_API_KEY", "ambient-secret");
vi.stubEnv("THT_MODEL_API_KEY_FILE", "/ambient/secret-path");
vi.stubEnv("OPENAI_API_KEY", "unselected-provider-secret");
@@ -690,6 +703,7 @@ test.each(["ollama", "local-qwen"])(
} finally {
mgr.teardown(`local-session-${provider}`);
vi.unstubAllEnvs();
rmSync(root, { recursive: true, force: true });
}
},
);
+27 -4
View File
@@ -117,20 +117,41 @@ test("single-key providers scrub ambient compound companions before injecting th
expect(env).not.toHaveProperty("CLOUDFLARE_GATEWAY_ID");
});
test("local-qwen is an explicit local provider and needs no generic key", () => {
test("a provider with a literal apiKey in models.json needs no code-level provider exception", () => {
const env = buildPiChildEnv({
ambient: {
PI_PROVIDER_API_KEY: "must-not-leak",
OPENAI_API_KEY: "must-not-leak",
THT_MODEL_API_KEY_FILE: "/must/not/leak",
},
provider: "local-qwen",
provider: "installation-local",
configuredApiKey: "local",
});
expect(env).not.toHaveProperty("PI_PROVIDER_API_KEY");
expect(env).not.toHaveProperty("OPENAI_API_KEY");
expect(env).not.toHaveProperty("THT_MODEL_API_KEY_FILE");
});
test.each(["$PRIVATE_PROVIDER_API_KEY", "${PRIVATE_PROVIDER_API_KEY}"])(
"a custom provider credential target is derived from models.json: %s",
(configuredApiKey) => {
const env = buildPiChildEnv({
ambient: { PRIVATE_PROVIDER_API_KEY: "stale" },
provider: "private-provider",
configuredApiKey,
credentialValue: "selected-secret",
});
expect(env.PRIVATE_PROVIDER_API_KEY).toBe("selected-secret");
},
);
test("a custom provider cannot redirect a managed credential into a process-control variable", () => {
expect(() => buildPiChildEnv({
ambient: {}, provider: "private-provider", configuredApiKey: "$PATH",
credentialValue: "selected-secret",
})).toThrow("model provider credential is unavailable");
});
test("credential status reports only present or missing without treating local providers as credentialed", () => {
expect(piProviderCredentialStatus({
provider: "deepseek",
@@ -139,7 +160,8 @@ test("credential status reports only present or missing without treating local p
})).toBe("present");
expect(piProviderCredentialStatus({ provider: "deepseek" })).toBe("missing");
expect(piProviderCredentialStatus({
provider: "local-qwen",
provider: "installation-local",
configuredApiKey: "local",
resolveCredentialValue: () => "must-not-be-returned",
})).toBe("missing");
});
@@ -159,7 +181,8 @@ test("credential status never resolves the generic secret for auth-store or loca
resolveCredentialValue: unreadableSecret,
})).toBe("present");
expect(piProviderCredentialStatus({
provider: "local-qwen",
provider: "installation-local",
configuredApiKey: "local",
resolveCredentialValue: unreadableSecret,
})).toBe("missing");
expect(secretReads).toBe(0);