feat(config): load one validated secret bundle

This commit is contained in:
2026-07-12 11:06:19 +02:00
parent b539303002
commit 5fe74612fb
9 changed files with 255 additions and 2 deletions
+22
View File
@@ -142,6 +142,28 @@ test("model-list spawn loads only the selected canonical provider credential", a
}
});
test("model-list spawn uses the same single secret bundle as sessions", async () => {
const script = scriptWith([]);
const bundle = join(path.dirname(script), "bundle");
writeFileSync(bundle, "THT_MODEL_API_KEY=selected-bundle-secret\n", { mode: 0o600 });
const calls: any[][] = [];
const lister = createPiModelLister(loadConfig({
PI_PROVIDER: "openai", THT_SECRETS_FILE: bundle,
}), {
spawnFn: (...args: any[]) => {
calls.push(args);
return spawn("node", [FAKE, script]) as any;
},
});
try {
await lister();
expect(calls[0][2].env.OPENAI_API_KEY).toBe("selected-bundle-secret");
expect(calls[0][2].env).not.toHaveProperty("THT_SECRETS_FILE");
} finally {
rmSync(path.dirname(script), { recursive: true, force: true });
}
});
test.each(["amazon-bedrock", "azure-openai-responses", "cloudflare-workers-ai", "cloudflare-ai-gateway"])(
"model listing rejects compound provider %s before spawning Pi", async (provider) => {
const script = scriptWith([]);