feat: complete evidence restructuring worktree
This commit is contained in:
@@ -117,20 +117,41 @@ test("single-key providers scrub ambient compound companions before injecting th
|
||||
expect(env).not.toHaveProperty("CLOUDFLARE_GATEWAY_ID");
|
||||
});
|
||||
|
||||
test("local-qwen is an explicit local provider and needs no generic key", () => {
|
||||
test("a provider with a literal apiKey in models.json needs no code-level provider exception", () => {
|
||||
const env = buildPiChildEnv({
|
||||
ambient: {
|
||||
PI_PROVIDER_API_KEY: "must-not-leak",
|
||||
OPENAI_API_KEY: "must-not-leak",
|
||||
THT_MODEL_API_KEY_FILE: "/must/not/leak",
|
||||
},
|
||||
provider: "local-qwen",
|
||||
provider: "installation-local",
|
||||
configuredApiKey: "local",
|
||||
});
|
||||
expect(env).not.toHaveProperty("PI_PROVIDER_API_KEY");
|
||||
expect(env).not.toHaveProperty("OPENAI_API_KEY");
|
||||
expect(env).not.toHaveProperty("THT_MODEL_API_KEY_FILE");
|
||||
});
|
||||
|
||||
test.each(["$PRIVATE_PROVIDER_API_KEY", "${PRIVATE_PROVIDER_API_KEY}"])(
|
||||
"a custom provider credential target is derived from models.json: %s",
|
||||
(configuredApiKey) => {
|
||||
const env = buildPiChildEnv({
|
||||
ambient: { PRIVATE_PROVIDER_API_KEY: "stale" },
|
||||
provider: "private-provider",
|
||||
configuredApiKey,
|
||||
credentialValue: "selected-secret",
|
||||
});
|
||||
expect(env.PRIVATE_PROVIDER_API_KEY).toBe("selected-secret");
|
||||
},
|
||||
);
|
||||
|
||||
test("a custom provider cannot redirect a managed credential into a process-control variable", () => {
|
||||
expect(() => buildPiChildEnv({
|
||||
ambient: {}, provider: "private-provider", configuredApiKey: "$PATH",
|
||||
credentialValue: "selected-secret",
|
||||
})).toThrow("model provider credential is unavailable");
|
||||
});
|
||||
|
||||
test("credential status reports only present or missing without treating local providers as credentialed", () => {
|
||||
expect(piProviderCredentialStatus({
|
||||
provider: "deepseek",
|
||||
@@ -139,7 +160,8 @@ test("credential status reports only present or missing without treating local p
|
||||
})).toBe("present");
|
||||
expect(piProviderCredentialStatus({ provider: "deepseek" })).toBe("missing");
|
||||
expect(piProviderCredentialStatus({
|
||||
provider: "local-qwen",
|
||||
provider: "installation-local",
|
||||
configuredApiKey: "local",
|
||||
resolveCredentialValue: () => "must-not-be-returned",
|
||||
})).toBe("missing");
|
||||
});
|
||||
@@ -159,7 +181,8 @@ test("credential status never resolves the generic secret for auth-store or loca
|
||||
resolveCredentialValue: unreadableSecret,
|
||||
})).toBe("present");
|
||||
expect(piProviderCredentialStatus({
|
||||
provider: "local-qwen",
|
||||
provider: "installation-local",
|
||||
configuredApiKey: "local",
|
||||
resolveCredentialValue: unreadableSecret,
|
||||
})).toBe("missing");
|
||||
expect(secretReads).toBe(0);
|
||||
|
||||
Reference in New Issue
Block a user