fix: align workspace diagnostic contracts
This commit is contained in:
@@ -10,6 +10,13 @@ import {
|
||||
type WorkspaceDescriptor,
|
||||
} from "./schema.js";
|
||||
|
||||
export interface RuntimeBindings {
|
||||
dwh: ResolvedBinding;
|
||||
vector: ResolvedBinding;
|
||||
vectorWriter: ResolvedBinding;
|
||||
embedding: ResolvedBinding;
|
||||
}
|
||||
|
||||
export interface ResolvedBinding {
|
||||
transport: DwhTransport | VectorTransport;
|
||||
values: Record<string, string>;
|
||||
@@ -63,12 +70,19 @@ function isSafeSecretFile(path: string, secretRoots: readonly string[]): boolean
|
||||
}
|
||||
|
||||
function requiredSuffixes(
|
||||
workspace: WorkspaceDescriptor,
|
||||
role: InstallationRole,
|
||||
transport: DwhTransport | VectorTransport,
|
||||
): readonly InstallationSuffix[] {
|
||||
if (role === "EMBEDDING") return EMBEDDING_REQUIRED_SUFFIXES;
|
||||
if (role === "VECTOR_WRITER") return ["API_KEY_FILE"];
|
||||
return REQUIRED_SUFFIXES[role][transport] ?? [];
|
||||
const required = REQUIRED_SUFFIXES[role][transport] ?? [];
|
||||
const diagnostic = role === "DWH"
|
||||
? workspace.diagnostics?.dwh_rest
|
||||
: workspace.diagnostics?.vector_rest?.metadata;
|
||||
return transport === "rest_api" && diagnostic?.auth === "none"
|
||||
? required.filter((suffix) => suffix !== "API_KEY_FILE")
|
||||
: required;
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -98,7 +112,7 @@ export function resolveBinding(
|
||||
missing.push(transportVariable.name);
|
||||
}
|
||||
|
||||
const required = new Set(requiredSuffixes(role, selectedTransport));
|
||||
const required = new Set(requiredSuffixes(canonical, role, selectedTransport));
|
||||
const values: Record<string, string> = {};
|
||||
for (const variable of variables) {
|
||||
if (variable.suffix === "TRANSPORT") continue;
|
||||
@@ -115,3 +129,17 @@ export function resolveBinding(
|
||||
|
||||
return { transport: selectedTransport, values, missing };
|
||||
}
|
||||
|
||||
/** Resolve all runtime roles together so optional writer credentials cannot be smuggled into reader bindings. */
|
||||
export function resolveRuntimeBindings(
|
||||
workspace: WorkspaceDescriptor,
|
||||
env: NodeJS.ProcessEnv,
|
||||
secretRoots: readonly string[],
|
||||
): RuntimeBindings {
|
||||
return {
|
||||
dwh: resolveBinding(workspace, "DWH", env, secretRoots),
|
||||
vector: resolveBinding(workspace, "VECTOR", env, secretRoots),
|
||||
vectorWriter: resolveBinding(workspace, "VECTOR_WRITER", env, secretRoots),
|
||||
embedding: resolveBinding(workspace, "EMBEDDING", env, secretRoots),
|
||||
};
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user