fix(backend): validate configured model provider pair

This commit is contained in:
User
2026-07-14 18:39:37 +02:00
parent c463de8da2
commit 3d23d0543c
5 changed files with 61 additions and 7 deletions
+27
View File
@@ -64,6 +64,33 @@ test("PUT /settings rejects an unknown model when a model list is available", as
}
});
test("PUT /settings validates provider and model as one composite identifier", async () => {
const { app, dir } = appWithTmpSettings({}, {
listModels: async () => [
{ provider: "provider-a", id: "shared-id", name: "A", reasoning: false },
],
});
try {
const wrongProvider = await app.inject({
method: "PUT", url: "/settings",
payload: {
workspace: "psd", provider: "provider-b", model: "shared-id", thinking: "low",
},
});
expect(wrongProvider.statusCode).toBe(400);
const exactPair = await app.inject({
method: "PUT", url: "/settings",
payload: {
workspace: "psd", provider: "provider-a", model: "shared-id", thinking: "low",
},
});
expect(exactPair.statusCode).toBe(200);
} finally {
rmSync(dir, { recursive: true, force: true });
}
});
test("PUT /settings allows any model when model list is empty (Pi unavailable)", async () => {
const { app, dir } = appWithTmpSettings({}, { listModels: async () => [] });
try {
+15 -1
View File
@@ -1,4 +1,4 @@
import { test, expect } from "vitest";
import { test, expect, vi } from "vitest";
import { buildApp } from "../src/app.js";
import { loadConfig } from "../src/config.js";
@@ -148,6 +148,20 @@ test("GET /models returns {models:[]} when listModels throws (graceful fallback)
expect(res.json()).toEqual({ models: [] });
});
test("GET /models logs a sanitized warning when listing fails", async () => {
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
thtRunner: {} as any,
listModels: async () => { throw new Error("credential-value-must-not-appear"); },
});
const warn = vi.spyOn(app.log, "warn");
const res = await app.inject({ method: "GET", url: "/models" });
expect(res.json()).toEqual({ models: [] });
expect(JSON.stringify(warn.mock.calls)).not.toContain("credential-value-must-not-appear");
expect(warn).toHaveBeenCalled();
});
test("GET /models with empty listModels stub returns empty array", async () => {
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
thtRunner: {} as any,