fix: harden Pi management readiness
This commit is contained in:
@@ -38,12 +38,14 @@ test("status parses only a Pi version from a fixed execFile argument array", asy
|
||||
execute: successfulExec(calls),
|
||||
listModels: async () => supportedModels,
|
||||
readSettings: () => ({ provider: "zai", model: "glm-5.2", thinking: "medium" }),
|
||||
credentialStatus: () => "missing",
|
||||
now: () => new Date("2026-08-05T10:00:00.000Z"),
|
||||
});
|
||||
|
||||
await expect(service.status()).resolves.toEqual({
|
||||
version: "0.80.3",
|
||||
ready: true,
|
||||
credentials: "missing",
|
||||
config: { provider: "zai", model: "glm-5.2", reasoning: "medium" },
|
||||
checkedAt: "2026-08-05T10:00:00.000Z",
|
||||
});
|
||||
@@ -53,6 +55,36 @@ test("status parses only a Pi version from a fixed execFile argument array", asy
|
||||
expect(calls[0].timeout).toBeLessThanOrEqual(750);
|
||||
});
|
||||
|
||||
// Catches credential presence being inferred from smoke success/failure or exposing any
|
||||
// credential material instead of the installation's explicit sanitized presence state.
|
||||
test.each(["present", "missing"] as const)(
|
||||
"status reports configured-provider credentials only as %s",
|
||||
async (credentials) => {
|
||||
const checkedProviders: Array<string | undefined> = [];
|
||||
const service = createPiManagement(configFor(), {
|
||||
execute: successfulExec([]),
|
||||
listModels: async () => supportedModels,
|
||||
readSettings: () => ({ provider: "zai", model: "glm-5.2", thinking: "medium" }),
|
||||
credentialStatus: (provider) => {
|
||||
checkedProviders.push(provider);
|
||||
return credentials;
|
||||
},
|
||||
now: () => new Date("2026-08-05T10:00:00.000Z"),
|
||||
});
|
||||
|
||||
const status = await service.status();
|
||||
expect(status).toEqual({
|
||||
version: "0.80.3",
|
||||
ready: true,
|
||||
credentials,
|
||||
config: { provider: "zai", model: "glm-5.2", reasoning: "medium" },
|
||||
checkedAt: "2026-08-05T10:00:00.000Z",
|
||||
});
|
||||
expect(checkedProviders).toEqual(["zai"]);
|
||||
expect(JSON.stringify(status)).not.toMatch(/api.?key|token|password|secret/i);
|
||||
},
|
||||
);
|
||||
|
||||
// Catches an options response that leaks provider metadata or lets callers choose model IDs that
|
||||
// Pi did not explicitly enable for this installation.
|
||||
test("options expose only closed provider, model, and reasoning choices", async () => {
|
||||
|
||||
Reference in New Issue
Block a user