fix: harden Pi management readiness

This commit is contained in:
2026-08-05 06:20:25 +02:00
parent 7a8bcacbfe
commit 7df21b5f21
24 changed files with 577 additions and 274 deletions
+32
View File
@@ -38,12 +38,14 @@ test("status parses only a Pi version from a fixed execFile argument array", asy
execute: successfulExec(calls),
listModels: async () => supportedModels,
readSettings: () => ({ provider: "zai", model: "glm-5.2", thinking: "medium" }),
credentialStatus: () => "missing",
now: () => new Date("2026-08-05T10:00:00.000Z"),
});
await expect(service.status()).resolves.toEqual({
version: "0.80.3",
ready: true,
credentials: "missing",
config: { provider: "zai", model: "glm-5.2", reasoning: "medium" },
checkedAt: "2026-08-05T10:00:00.000Z",
});
@@ -53,6 +55,36 @@ test("status parses only a Pi version from a fixed execFile argument array", asy
expect(calls[0].timeout).toBeLessThanOrEqual(750);
});
// Catches credential presence being inferred from smoke success/failure or exposing any
// credential material instead of the installation's explicit sanitized presence state.
test.each(["present", "missing"] as const)(
"status reports configured-provider credentials only as %s",
async (credentials) => {
const checkedProviders: Array<string | undefined> = [];
const service = createPiManagement(configFor(), {
execute: successfulExec([]),
listModels: async () => supportedModels,
readSettings: () => ({ provider: "zai", model: "glm-5.2", thinking: "medium" }),
credentialStatus: (provider) => {
checkedProviders.push(provider);
return credentials;
},
now: () => new Date("2026-08-05T10:00:00.000Z"),
});
const status = await service.status();
expect(status).toEqual({
version: "0.80.3",
ready: true,
credentials,
config: { provider: "zai", model: "glm-5.2", reasoning: "medium" },
checkedAt: "2026-08-05T10:00:00.000Z",
});
expect(checkedProviders).toEqual(["zai"]);
expect(JSON.stringify(status)).not.toMatch(/api.?key|token|password|secret/i);
},
);
// Catches an options response that leaks provider metadata or lets callers choose model IDs that
// Pi did not explicitly enable for this installation.
test("options expose only closed provider, model, and reasoning choices", async () => {
+14
View File
@@ -5,6 +5,7 @@ import {
PI_0803_CREDENTIAL_ENV_NAMES,
buildPiChildEnv,
canonicalPiProvider,
piProviderCredentialStatus,
} from "../src/pi/provider-credentials.js";
test("canonical provider aliases resolve to packaged Pi 0.80.3 IDs", () => {
@@ -130,6 +131,19 @@ test("local-qwen is an explicit local provider and needs no generic key", () =>
expect(env).not.toHaveProperty("THT_MODEL_API_KEY_FILE");
});
test("credential status reports only present or missing without treating local providers as credentialed", () => {
expect(piProviderCredentialStatus({
provider: "deepseek",
authProviders: new Set(["deepseek"]),
credentialValue: "must-not-be-returned",
})).toBe("present");
expect(piProviderCredentialStatus({ provider: "deepseek" })).toBe("missing");
expect(piProviderCredentialStatus({
provider: "local-qwen",
credentialValue: "must-not-be-returned",
})).toBe("missing");
});
test("bundle value is injected without exposing bundle metadata to Pi", () => {
const env = buildPiChildEnv({
ambient: {
@@ -10,6 +10,7 @@ function fakeService(): PiManagementService {
return {
status: vi.fn(async () => ({
version: "0.80.3", ready: true,
credentials: "present",
config: { provider: "zai", model: "glm-5.2", reasoning: "medium" },
checkedAt: "2026-08-05T10:00:00.000Z",
})),
@@ -77,6 +78,7 @@ test("loopback-only AUTH_MODE=none may read the sanitized Pi status", async () =
expect(response.statusCode).toBe(200);
expect(response.json()).toEqual({
version: "0.80.3", ready: true,
credentials: "present",
config: { provider: "zai", model: "glm-5.2", reasoning: "medium" },
checkedAt: "2026-08-05T10:00:00.000Z",
});