feat: bind evidence credentials through local files
This commit is contained in:
@@ -2797,3 +2797,99 @@ test("POST /sessions bootstrap failure emits only a fixed recovery message", asy
|
||||
expect(clientOutput).not.toContain("DO_NOT_LEAK");
|
||||
expect(clientOutput).not.toContain("/srv/private/model-key");
|
||||
});
|
||||
|
||||
|
||||
test.each([
|
||||
{ mode: "missing signed Evidence file", evidence: true, safe: false, expectedStatus: 409, reachesReadiness: false },
|
||||
{ mode: "safe signed Evidence file", evidence: true, safe: true, expectedStatus: 503, reachesReadiness: true },
|
||||
{ mode: "no Evidence descriptor", evidence: false, safe: false, expectedStatus: 503, reachesReadiness: true },
|
||||
])("real buildApp admission handles $mode before Pi spawn", async ({
|
||||
evidence, safe, expectedStatus, reachesReadiness,
|
||||
}) => {
|
||||
const root = mkdtempSync(path.join(tmpdir(), "thoth-evidence-admission-"));
|
||||
const signedFile = path.join(root, "signed-urls.json");
|
||||
writeFileSync(signedFile, '["CANARY-SIGNED-QUERY"]');
|
||||
const variable = "THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE";
|
||||
const previous = {
|
||||
transport: process.env.THT_WS_PSD_CLINICAL_DWH_TRANSPORT,
|
||||
baseUrl: process.env.THT_WS_PSD_CLINICAL_DWH_BASE_URL,
|
||||
signed: process.env[variable],
|
||||
};
|
||||
process.env.THT_WS_PSD_CLINICAL_DWH_TRANSPORT = "rest_api";
|
||||
process.env.THT_WS_PSD_CLINICAL_DWH_BASE_URL = "https://dwh.example.test";
|
||||
if (safe) process.env[variable] = signedFile;
|
||||
else delete process.env[variable];
|
||||
|
||||
const descriptor = {
|
||||
...operationalWorkspace("psd-clinical"),
|
||||
dwh: {
|
||||
...operationalWorkspace("psd-clinical").dwh,
|
||||
supported_transports: ["rest_api"],
|
||||
},
|
||||
diagnostics: {
|
||||
dwh_rest: {
|
||||
method: "GET", path: "/health", auth: "none",
|
||||
response: { database: "database", schema: "schema" },
|
||||
},
|
||||
},
|
||||
...(evidence ? {
|
||||
evidence: {
|
||||
source: {
|
||||
type: "http",
|
||||
uris: ["https://evidence.example.test/guide.md"],
|
||||
authentication: "signed_urls_file",
|
||||
connect_timeout_ms: 5_000,
|
||||
read_timeout_ms: 30_000,
|
||||
max_bytes: 10 * 1024 * 1024,
|
||||
max_redirects: 5,
|
||||
allow_private_hosts: false,
|
||||
max_cache_bytes: 64 * 1024 * 1024,
|
||||
},
|
||||
policy: { max_chunk_chars: 4_000, retain_published_generations: 3 },
|
||||
},
|
||||
} : {}),
|
||||
} as any;
|
||||
const canonicalBefore = JSON.stringify(descriptor);
|
||||
const ensure = vi.fn(async () => ({ ok: false, code: "workspace_not_activatable" as const }));
|
||||
const createFor = vi.fn();
|
||||
const abort = vi.fn(async () => {});
|
||||
const revision = {
|
||||
id: "psd-clinical", commit: "a".repeat(40), blob: "b".repeat(40),
|
||||
snapshotPath: `/data/workspace-registry/snapshots/${"a".repeat(40)}/psd-clinical.yaml`,
|
||||
state: "operational" as const,
|
||||
};
|
||||
|
||||
try {
|
||||
const app = buildRealApp(loadConfig({
|
||||
THT_HARNESS_DIR: "../harness",
|
||||
THT_WORKSPACE_SECRET_ROOTS: root,
|
||||
}), {
|
||||
thtRunner: { sessionNew: vi.fn(), searchPack: async () => {} } as any,
|
||||
readiness: { ensure } as any,
|
||||
mgr: { get: () => undefined, createFor } as any,
|
||||
getSettings: () => ({ workspace: "psd-clinical" }) as any,
|
||||
workspaceRegistry: {
|
||||
acquireSessionRevision: vi.fn(async () => ({
|
||||
workspace: descriptor, revision, abort, markPersisted: vi.fn(async () => {}),
|
||||
})),
|
||||
} as any,
|
||||
});
|
||||
const response = await app.inject({ method: "POST", url: "/sessions", payload: { question: "q" } });
|
||||
|
||||
expect(response.statusCode).toBe(expectedStatus);
|
||||
expect(ensure).toHaveBeenCalledTimes(reachesReadiness ? 1 : 0);
|
||||
expect(createFor).not.toHaveBeenCalled();
|
||||
expect(JSON.stringify(descriptor)).toBe(canonicalBefore);
|
||||
expect(revision.commit).toBe("a".repeat(40));
|
||||
expect(response.body).not.toContain("CANARY-SIGNED-QUERY");
|
||||
} finally {
|
||||
const restore = (name: string, value: string | undefined) => {
|
||||
if (value === undefined) delete process.env[name];
|
||||
else process.env[name] = value;
|
||||
};
|
||||
restore("THT_WS_PSD_CLINICAL_DWH_TRANSPORT", previous.transport);
|
||||
restore("THT_WS_PSD_CLINICAL_DWH_BASE_URL", previous.baseUrl);
|
||||
restore(variable, previous.signed);
|
||||
rmSync(root, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user