feat(harness): port vectorstore dual-key + reader RPC (D11, §5.4)
Ports vectorstore/{rest_client,rest_writer,store,reader,embeddings,records},
evidence/model (leaf dep of records), and cli/_guards (require_vector_write_allowed
workstation write-guard). Renamed psdwp3->nsp, verbatim.
VectorRestClient gains an api_key property so reader/writer clients carry their
distinct keys visibly (spec D11: vector_reader / vector_writer on the same endpoint).
scripts/create_vector_reader_rpc.sql is NEW: the reader RPCs (search_similar,
list_tables) lived server-side in Supabase and were never versioned. Authored now
mirroring the writer allowlist pattern (table allowlist, security definer, revoke
from anon/authenticated, grant to vector_reader only). Writer RPC ported verbatim.
L1: test_vector_dual_key (7 tests) pins the dual-key construction + the workstation
write-guard (exit 4 without writer key).
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
import typer
|
||||
|
||||
|
||||
def require_server_profile(cfg, command: str) -> None:
|
||||
"""Rifiuta i comandi di scrittura vectordb sul profilo workstation (exit 4).
|
||||
|
||||
Va chiamata subito dopo il caricamento della config e PRIMA di aprire qualunque
|
||||
connessione, cosi' su workstation non si tenta mai la connessione diretta al vectordb.
|
||||
"""
|
||||
if cfg.profile == "workstation":
|
||||
typer.secho(
|
||||
f"ERRORE: `{command}` e' un comando solo-server (scrive nel vectordb centrale). "
|
||||
f"Sulla postazione locale (profile: workstation) il vectordb si LEGGE via REST, "
|
||||
f"non si ricostruisce. Esegui questo comando sul server di produzione "
|
||||
f"(profile: server).",
|
||||
fg=typer.colors.RED, err=True,
|
||||
)
|
||||
raise typer.Exit(code=4)
|
||||
|
||||
|
||||
|
||||
def has_vector_write_rest(cfg) -> bool:
|
||||
return cfg.vector_write_rest is not None and bool(cfg.vector_write_rest.api_key.strip())
|
||||
|
||||
|
||||
def require_vector_write_allowed(cfg, command: str) -> None:
|
||||
"""Permette scritture vectordb da workstation solo con API key REST writer.
|
||||
|
||||
Senza `vector_write_rest`, la workstation resta read-only e i comandi di indexing sono
|
||||
eseguibili solo sul server con connessione diretta al vectordb.
|
||||
"""
|
||||
if cfg.profile == "workstation" and not has_vector_write_rest(cfg):
|
||||
typer.secho(
|
||||
f"ERRORE: `{command}` e' un comando solo-server se manca `vector_write_rest`: "
|
||||
f"scrive nel vectordb centrale. Sulla postazione locale serve la sezione "
|
||||
f"`vector_write_rest` con una API key di upsert; in alternativa esegui il "
|
||||
f"comando sul server di produzione (profile: server).",
|
||||
fg=typer.colors.RED, err=True,
|
||||
)
|
||||
raise typer.Exit(code=4)
|
||||
Reference in New Issue
Block a user