feat(config): load one validated secret bundle

This commit is contained in:
2026-07-12 11:06:19 +02:00
parent b539303002
commit 5fe74612fb
9 changed files with 255 additions and 2 deletions
+20
View File
@@ -212,6 +212,26 @@ test.each([
}
});
test("session Pi spawn reads the single secret bundle and scrubs its path", async () => {
const secret = path.resolve(__dirname, `.bundle-${process.pid}`);
writeFileSync(secret, "THT_MODEL_API_KEY=bundle-secret\n", { mode: 0o600 });
chmodSync(secret, 0o600);
const calls: any[][] = [];
const child = recordingChild();
child.stderr.resume = () => {};
const mgr = new PiProcessManager(loadConfig({
PI_BIN: "/usr/local/bin/pi", THT_SECRETS_FILE: secret,
}), { spawnFn: (...args: any[]) => { calls.push(args); return child as any; } });
try {
await mgr.spawnFor("bundle-session", { provider: "openai" });
expect(calls[0][2].env.OPENAI_API_KEY).toBe("bundle-secret");
expect(calls[0][2].env).not.toHaveProperty("THT_SECRETS_FILE");
} finally {
mgr.teardown("bundle-session");
await import("node:fs/promises").then((fs) => fs.unlink(secret));
}
});
test.each([["OpenAI", "openai"], ["gemini", "google"]])(
"set_model uses canonical packaged provider ID for %s", async (provider, canonical) => {
const secret = path.resolve(__dirname, `.canonical-key-${process.pid}-${provider}`);