fix(docker): run real questions through trusted Pi gate
This commit is contained in:
@@ -44,6 +44,14 @@ export class PiProcessManager {
|
||||
credentialFile: this.cfg.modelApiKeyFile,
|
||||
additions: { THT_SESSION: sessionId, THT_AUTHOR: author },
|
||||
});
|
||||
// The Thoth gate executes the deterministic `tht` CLI as a Pi tool. Give only
|
||||
// this managed session process the adapter values already loaded by the core
|
||||
// entrypoint; the generic provider helper continues to scrub them by default.
|
||||
for (const name of [
|
||||
"THT_DWH_API_KEY", "THT_VEC_API_KEY", "THT_VEC_WRITE_API_KEY", "THT_SSL_CA",
|
||||
] as const) {
|
||||
if (process.env[name] !== undefined) env[name] = process.env[name];
|
||||
}
|
||||
delete env.THT_DATA_ROOT;
|
||||
if (this.cfg.dataRoot !== undefined) env.THT_DATA_ROOT = this.cfg.dataRoot;
|
||||
// pi 0.73 removed `--approve`: rpc mode is headless and its argv is intentionally minimal.
|
||||
@@ -62,7 +70,7 @@ export class PiProcessManager {
|
||||
|
||||
async spawnFor(
|
||||
sessionId: string,
|
||||
o: { provider?: string; model?: string; thinking?: string; author?: string; mode?: "new" | "resume" },
|
||||
o: { provider?: string; model?: string; thinking?: string; author?: string; question?: string; mode?: "new" | "resume" },
|
||||
): Promise<SessionRuntime> {
|
||||
// Idempotent per session id: tear down any existing runtime for this id
|
||||
// first (before the cap check) so a resume/respawn neither leaks the old
|
||||
@@ -110,7 +118,7 @@ export class PiProcessManager {
|
||||
|
||||
const message = o.mode === "resume"
|
||||
? `/riprendi-sessione ${sessionId}`
|
||||
: `/nuova-domanda "kickoff"`;
|
||||
: `/nuova-domanda ${JSON.stringify(o.question ?? "")}`;
|
||||
rpc.send({ type: "prompt", message });
|
||||
return rt;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user