fix: harden Pi management readiness
This commit is contained in:
@@ -38,12 +38,14 @@ test("status parses only a Pi version from a fixed execFile argument array", asy
|
||||
execute: successfulExec(calls),
|
||||
listModels: async () => supportedModels,
|
||||
readSettings: () => ({ provider: "zai", model: "glm-5.2", thinking: "medium" }),
|
||||
credentialStatus: () => "missing",
|
||||
now: () => new Date("2026-08-05T10:00:00.000Z"),
|
||||
});
|
||||
|
||||
await expect(service.status()).resolves.toEqual({
|
||||
version: "0.80.3",
|
||||
ready: true,
|
||||
credentials: "missing",
|
||||
config: { provider: "zai", model: "glm-5.2", reasoning: "medium" },
|
||||
checkedAt: "2026-08-05T10:00:00.000Z",
|
||||
});
|
||||
@@ -53,6 +55,36 @@ test("status parses only a Pi version from a fixed execFile argument array", asy
|
||||
expect(calls[0].timeout).toBeLessThanOrEqual(750);
|
||||
});
|
||||
|
||||
// Catches credential presence being inferred from smoke success/failure or exposing any
|
||||
// credential material instead of the installation's explicit sanitized presence state.
|
||||
test.each(["present", "missing"] as const)(
|
||||
"status reports configured-provider credentials only as %s",
|
||||
async (credentials) => {
|
||||
const checkedProviders: Array<string | undefined> = [];
|
||||
const service = createPiManagement(configFor(), {
|
||||
execute: successfulExec([]),
|
||||
listModels: async () => supportedModels,
|
||||
readSettings: () => ({ provider: "zai", model: "glm-5.2", thinking: "medium" }),
|
||||
credentialStatus: (provider) => {
|
||||
checkedProviders.push(provider);
|
||||
return credentials;
|
||||
},
|
||||
now: () => new Date("2026-08-05T10:00:00.000Z"),
|
||||
});
|
||||
|
||||
const status = await service.status();
|
||||
expect(status).toEqual({
|
||||
version: "0.80.3",
|
||||
ready: true,
|
||||
credentials,
|
||||
config: { provider: "zai", model: "glm-5.2", reasoning: "medium" },
|
||||
checkedAt: "2026-08-05T10:00:00.000Z",
|
||||
});
|
||||
expect(checkedProviders).toEqual(["zai"]);
|
||||
expect(JSON.stringify(status)).not.toMatch(/api.?key|token|password|secret/i);
|
||||
},
|
||||
);
|
||||
|
||||
// Catches an options response that leaks provider metadata or lets callers choose model IDs that
|
||||
// Pi did not explicitly enable for this installation.
|
||||
test("options expose only closed provider, model, and reasoning choices", async () => {
|
||||
|
||||
@@ -5,6 +5,7 @@ import {
|
||||
PI_0803_CREDENTIAL_ENV_NAMES,
|
||||
buildPiChildEnv,
|
||||
canonicalPiProvider,
|
||||
piProviderCredentialStatus,
|
||||
} from "../src/pi/provider-credentials.js";
|
||||
|
||||
test("canonical provider aliases resolve to packaged Pi 0.80.3 IDs", () => {
|
||||
@@ -130,6 +131,19 @@ test("local-qwen is an explicit local provider and needs no generic key", () =>
|
||||
expect(env).not.toHaveProperty("THT_MODEL_API_KEY_FILE");
|
||||
});
|
||||
|
||||
test("credential status reports only present or missing without treating local providers as credentialed", () => {
|
||||
expect(piProviderCredentialStatus({
|
||||
provider: "deepseek",
|
||||
authProviders: new Set(["deepseek"]),
|
||||
credentialValue: "must-not-be-returned",
|
||||
})).toBe("present");
|
||||
expect(piProviderCredentialStatus({ provider: "deepseek" })).toBe("missing");
|
||||
expect(piProviderCredentialStatus({
|
||||
provider: "local-qwen",
|
||||
credentialValue: "must-not-be-returned",
|
||||
})).toBe("missing");
|
||||
});
|
||||
|
||||
test("bundle value is injected without exposing bundle metadata to Pi", () => {
|
||||
const env = buildPiChildEnv({
|
||||
ambient: {
|
||||
|
||||
@@ -10,6 +10,7 @@ function fakeService(): PiManagementService {
|
||||
return {
|
||||
status: vi.fn(async () => ({
|
||||
version: "0.80.3", ready: true,
|
||||
credentials: "present",
|
||||
config: { provider: "zai", model: "glm-5.2", reasoning: "medium" },
|
||||
checkedAt: "2026-08-05T10:00:00.000Z",
|
||||
})),
|
||||
@@ -77,6 +78,7 @@ test("loopback-only AUTH_MODE=none may read the sanitized Pi status", async () =
|
||||
expect(response.statusCode).toBe(200);
|
||||
expect(response.json()).toEqual({
|
||||
version: "0.80.3", ready: true,
|
||||
credentials: "present",
|
||||
config: { provider: "zai", model: "glm-5.2", reasoning: "medium" },
|
||||
checkedAt: "2026-08-05T10:00:00.000Z",
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user