fix: complete diagnostic extension remediation
This commit is contained in:
@@ -10,7 +10,7 @@ import {
|
||||
type DiagnosticAdapters,
|
||||
} from "../src/workspaces/diagnostics.js";
|
||||
import { resolveRuntimeBindings } from "../src/workspaces/bindings.js";
|
||||
import type { RuntimeBindings } from "../src/workspaces/runtime-renderer.js";
|
||||
import { renderRuntimeConfig, type RuntimeBindings } from "../src/workspaces/runtime-renderer.js";
|
||||
import { parseWorkspaceYaml } from "../src/workspaces/schema.js";
|
||||
|
||||
const workspace = parseWorkspaceYaml(`workspace:
|
||||
@@ -268,6 +268,74 @@ test("checks direct and REST resolution, TLS, authentication, and resource metad
|
||||
expect(JSON.stringify(result)).not.toContain("/run/secrets/dwh-api-key");
|
||||
});
|
||||
|
||||
test("carries auth-none REST bindings from resolver through runtime rendering to diagnostics without a key", async () => {
|
||||
const unauthenticatedWorkspace = parseWorkspaceYaml(`workspace:
|
||||
schema_version: 2
|
||||
id: psd-clinical
|
||||
name: Policlinico San Donato
|
||||
language: it
|
||||
dwh:
|
||||
engine: postgres
|
||||
database: warehouse
|
||||
schema: datawarehouse
|
||||
supported_transports: [rest_api]
|
||||
semantic_index:
|
||||
vector_store:
|
||||
engine: pgvector
|
||||
database: postgres
|
||||
schema: vectors
|
||||
collection: clinical_documents
|
||||
dimensions: 768
|
||||
distance: cosine
|
||||
supported_transports: [rest_api]
|
||||
embedding:
|
||||
provider: ollama_compatible
|
||||
model: nomic-embed-text-v2-moe
|
||||
dimensions: 768
|
||||
diagnostics:
|
||||
dwh_rest:
|
||||
method: POST
|
||||
path: /rpc/ping
|
||||
auth: none
|
||||
response: { database: database, schema: schema }
|
||||
vector_rest:
|
||||
metadata:
|
||||
method: GET
|
||||
path: /vector/metadata
|
||||
auth: none
|
||||
response: { collection: collection, dimensions: dimensions, distance: distance }
|
||||
embedding:
|
||||
method: GET
|
||||
path: /models
|
||||
auth: none
|
||||
response: { model: model, dimensions: dimensions }
|
||||
llm_policy:
|
||||
allowed: [zai/glm-5.2]
|
||||
`);
|
||||
const resolved = resolveRuntimeBindings(unauthenticatedWorkspace, {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api",
|
||||
THT_WS_PSD_CLINICAL_DWH_BASE_URL: "https://dwh.example.test",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_TRANSPORT: "rest_api",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_BASE_URL: "https://vector.example.test",
|
||||
THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL: "https://embedding.example.test",
|
||||
}, ["/run/secrets"]);
|
||||
const adapters = successfulAdapters();
|
||||
|
||||
const runtime = renderRuntimeConfig(unauthenticatedWorkspace, resolved, {
|
||||
sessions: "/data/sessions", artifacts: "/data/artifacts", indexes: "/data/indexes",
|
||||
});
|
||||
const result = await diagnose(adapters)(unauthenticatedWorkspace, resolved, { writeProbe: false });
|
||||
|
||||
expect(runtime).not.toContain("api_key_file");
|
||||
expect(result.activatable).toBe(true);
|
||||
expect(adapters.probeConnector).toHaveBeenCalledWith(expect.objectContaining({
|
||||
role: "dwh", credentialFile: undefined,
|
||||
}));
|
||||
expect(adapters.probeConnector).toHaveBeenCalledWith(expect.objectContaining({
|
||||
role: "vector", credentialFile: undefined,
|
||||
}));
|
||||
});
|
||||
|
||||
test("uses a loopback-only SSH tunnel for the bounded connector probe", async () => {
|
||||
const adapters = successfulAdapters();
|
||||
const sshBindings: RuntimeBindings = {
|
||||
@@ -305,6 +373,35 @@ test("uses a loopback-only SSH tunnel for the bounded connector probe", async ()
|
||||
}));
|
||||
});
|
||||
|
||||
test("retains the SSH target hostname for forwarded PostgreSQL TLS validation", async () => {
|
||||
const adapters = successfulAdapters();
|
||||
const sshBindings: RuntimeBindings = {
|
||||
...bindings,
|
||||
dwh: {
|
||||
transport: "ssh_tunnel",
|
||||
missing: [],
|
||||
values: {
|
||||
THT_WS_PSD_CLINICAL_DWH_USER: "reader",
|
||||
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: "/run/secrets/dwh-password",
|
||||
THT_WS_PSD_CLINICAL_DWH_SSH_HOST: "bastion.example.test",
|
||||
THT_WS_PSD_CLINICAL_DWH_SSH_PORT: "22",
|
||||
THT_WS_PSD_CLINICAL_DWH_SSH_USER: "tunnel",
|
||||
THT_WS_PSD_CLINICAL_DWH_SSH_PRIVATE_KEY_FILE: "/run/secrets/ssh-key",
|
||||
THT_WS_PSD_CLINICAL_DWH_SSH_KNOWN_HOSTS_FILE: "/run/secrets/known-hosts",
|
||||
THT_WS_PSD_CLINICAL_DWH_SSH_TARGET_HOST: "dwh.internal",
|
||||
THT_WS_PSD_CLINICAL_DWH_SSH_TARGET_PORT: "5432",
|
||||
},
|
||||
},
|
||||
};
|
||||
|
||||
await diagnose(adapters)(workspace, sshBindings, { writeProbe: false });
|
||||
|
||||
expect(adapters.probeConnector).toHaveBeenCalledWith(expect.objectContaining({
|
||||
host: "127.0.0.1",
|
||||
tlsServername: "dwh.internal",
|
||||
}));
|
||||
});
|
||||
|
||||
test("passes the declared vector database and schema to direct diagnostics", async () => {
|
||||
const adapters = successfulAdapters();
|
||||
|
||||
@@ -622,6 +719,31 @@ test("uses system trust for direct and SSH PostgreSQL diagnostics when no CA bin
|
||||
}
|
||||
});
|
||||
|
||||
test("passes the original target hostname to the PostgreSQL TLS client", async () => {
|
||||
const directory = await mkdtemp(join(tmpdir(), "thothii-diagnostic-"));
|
||||
const passwordFile = join(directory, "password");
|
||||
await writeFile(passwordFile, "password\n", { mode: 0o600 });
|
||||
const connect = vi.fn(async () => ({
|
||||
query: vi.fn(async () => ({ rows: [{ database: "warehouse", schema: "datawarehouse" }] })),
|
||||
end: vi.fn(async () => undefined),
|
||||
}));
|
||||
try {
|
||||
await createConcreteDiagnosticAdapters({ databaseClient: { connect } } as any).probeConnector({
|
||||
role: "dwh", transport: "ssh_tunnel", host: "127.0.0.1", port: 5432, user: "reader",
|
||||
credentialFile: passwordFile, tlsServername: "dwh.internal",
|
||||
resource: { database: "warehouse", schema: "datawarehouse" }, timeoutMs: 5000,
|
||||
signal: new AbortController().signal,
|
||||
});
|
||||
|
||||
expect(connect).toHaveBeenCalledWith(expect.objectContaining({
|
||||
host: "127.0.0.1",
|
||||
tlsServername: "dwh.internal",
|
||||
}));
|
||||
} finally {
|
||||
await rm(directory, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test("selects the vector index containing the declared vector column for direct metadata", async () => {
|
||||
const directory = await mkdtemp(join(tmpdir(), "thothii-diagnostic-"));
|
||||
const passwordFile = join(directory, "password");
|
||||
|
||||
Reference in New Issue
Block a user