fix: harden workspace registry deployment
This commit is contained in:
@@ -39,6 +39,24 @@ test("loadConfig keeps local development defaults", () => {
|
||||
expect(loadConfig({}).dataRoot).toBeUndefined();
|
||||
});
|
||||
|
||||
test("loadConfig enables the legacy workspace request only through explicit local mode", () => {
|
||||
expect(loadConfig({ THT_LEGACY_WORKSPACE_MODE: "local" }).legacyWorkspaceMode).toBe(true);
|
||||
|
||||
expect(() => loadConfig({
|
||||
THT_LEGACY_WORKSPACE_MODE: "local",
|
||||
AUTH_MODE: "upstream",
|
||||
THT_SESSION_STORAGE: "postgres",
|
||||
THT_SESSION_DB_HOST: "db.internal",
|
||||
THT_SESSION_DB_NAME: "thoth",
|
||||
THT_SESSION_RUNTIME_USER: "thoth_sessions_app",
|
||||
THT_SESSION_RUNTIME_PASSWORD_FILE: "/run/secrets/session_runtime_password",
|
||||
THT_SESSION_DB_SSLMODE: "verify-full",
|
||||
THT_SESSION_DB_SSLROOTCERT: "/run/secrets/session_ca.pem",
|
||||
})).toThrow(/legacy workspace mode requires local session storage/);
|
||||
expect(() => loadConfig({ THT_LEGACY_WORKSPACE_MODE: "true" }))
|
||||
.toThrow(/legacy workspace mode configuration is invalid/);
|
||||
});
|
||||
|
||||
test("loadConfig rejects unauthenticated public exposure", () => {
|
||||
expect(() => loadConfig({
|
||||
THOTH_PUBLIC_EXPOSURE: "true",
|
||||
|
||||
@@ -29,7 +29,9 @@ async function readUntil(
|
||||
}
|
||||
|
||||
test("loop F1: crea sessione → SSE riceve il widget → risponde → il modello riparte (follow-up)", async () => {
|
||||
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
|
||||
const app = buildApp(loadConfig({
|
||||
THT_HARNESS_DIR: "../harness", THT_LEGACY_WORKSPACE_MODE: "local",
|
||||
}), {
|
||||
thtRunner: {
|
||||
ollamaEnsure: async () => ({ ok: true }),
|
||||
searchPack: async () => {},
|
||||
|
||||
@@ -173,6 +173,45 @@ test("new sessions are created through the authenticated principal, not a client
|
||||
expect(principal).toMatchObject({ issuer: "portal", subject: "alice" });
|
||||
});
|
||||
|
||||
test("new sessions reject the client legacy workspace field unless local legacy mode is explicit", async () => {
|
||||
const sessionNew = vi.fn(async () => ({ id: "legacy" }));
|
||||
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
|
||||
thtRunner: { sessionNew, searchPack: async () => {} } as any,
|
||||
readiness: { ensure: async () => ({ ok: true }) } as any,
|
||||
mgr: { get: () => undefined, createFor: () => ({ bridge: { onClientEvent: () => {} } }), configure: async () => {}, start: () => {} } as any,
|
||||
getSettings: () => ({}) as any,
|
||||
});
|
||||
|
||||
const response = await app.inject({
|
||||
method: "POST", url: "/sessions", payload: { question: "q", workspace: "legacy" },
|
||||
});
|
||||
|
||||
expect(response.statusCode).toBe(409);
|
||||
expect(response.json()).toMatchObject({ code: "workspace_revision_unavailable" });
|
||||
expect(sessionNew).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
test("explicit local legacy mode permits the unpinned client workspace request", async () => {
|
||||
const sessionNew = vi.fn(async () => ({ id: "legacy" }));
|
||||
const app = buildApp(loadConfig({
|
||||
THT_HARNESS_DIR: "../harness", THT_LEGACY_WORKSPACE_MODE: "local",
|
||||
}), {
|
||||
thtRunner: { sessionNew, searchPack: async () => {} } as any,
|
||||
readiness: { ensure: async () => ({ ok: true }) } as any,
|
||||
mgr: { get: () => undefined, createFor: () => ({ bridge: { onClientEvent: () => {} } }), configure: async () => {}, start: () => {} } as any,
|
||||
getSettings: () => ({}) as any,
|
||||
});
|
||||
|
||||
const response = await app.inject({
|
||||
method: "POST", url: "/sessions", payload: { question: "q", workspace: "legacy" },
|
||||
});
|
||||
|
||||
expect(response.statusCode).toBe(200);
|
||||
expect(sessionNew).toHaveBeenCalledWith(expect.objectContaining({
|
||||
workspaceConfigPath: undefined, workspaceId: undefined, workspaceRevision: undefined,
|
||||
}));
|
||||
});
|
||||
|
||||
test("creates a session from the active immutable workspace revision", async () => {
|
||||
const sessionNew = vi.fn(async () => ({ id: "pinned" }));
|
||||
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
|
||||
|
||||
@@ -1,9 +1,10 @@
|
||||
import { existsSync, readFileSync, rmSync } from "node:fs";
|
||||
import { existsSync, readFileSync, rmSync, writeFileSync } from "node:fs";
|
||||
import { mkdtemp } from "node:fs/promises";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { afterEach, expect, test } from "vitest";
|
||||
import {
|
||||
main,
|
||||
migrateLegacyWorkspace,
|
||||
writeMigratedWorkspace,
|
||||
} from "../src/workspaces/migrate-legacy.js";
|
||||
@@ -48,13 +49,29 @@ test("writes versioned repository artifacts atomically without replacing a prior
|
||||
expect(existsSync(destination)).toBe(true);
|
||||
});
|
||||
|
||||
test("CLI accepts an explicit valid ID when a legacy filename contains dots", async () => {
|
||||
const root = await mkdtemp(join(tmpdir(), "thoth-workspace-migrate-"));
|
||||
temporaryRoots.push(root);
|
||||
const input = join(root, "psd.clinical.yaml");
|
||||
writeFileSync(input, readFixture("local.yaml"));
|
||||
|
||||
await main(["--input", input, "--output", root, "--id", "psd-clinical"]);
|
||||
|
||||
const destination = join(root, "workspaces", "psd-clinical.yaml");
|
||||
expect(parseWorkspaceYaml(readFileSync(destination, "utf8"))).toMatchObject({
|
||||
workspace: { id: "psd-clinical", schema_version: 1 },
|
||||
});
|
||||
});
|
||||
|
||||
test("declares a durable isolated registry volume and only read-only Git credential mounts", () => {
|
||||
const compose = readFileSync(new URL("../../compose.yaml", import.meta.url), "utf8");
|
||||
const development = readFileSync(new URL("../../docker-compose.dev.yml", import.meta.url), "utf8");
|
||||
const dockerfile = readFileSync(new URL("../../docker/core.Dockerfile", import.meta.url), "utf8");
|
||||
const smoke = readFileSync(new URL("../../scripts/workspace-registry-smoke.sh", import.meta.url), "utf8");
|
||||
|
||||
for (const source of [compose, development]) {
|
||||
expect(source).toContain("THT_WORKSPACE_REGISTRY_ROOT: /data/workspace-registry");
|
||||
expect(source).toContain("THT_WORKSPACE_GIT_REMOTE: ${THT_WORKSPACE_GIT_REMOTE:?set THT_WORKSPACE_GIT_REMOTE}");
|
||||
expect(source).toContain("workspace-registry:/data/workspace-registry");
|
||||
expect(source).toMatch(/workspace-registry-git-credentials:ro/);
|
||||
expect(source).toMatch(/workspace-registry-git-ca:ro/);
|
||||
@@ -62,4 +79,7 @@ test("declares a durable isolated registry volume and only read-only Git credent
|
||||
expect(source).toMatch(/workspace-registry-git-known-hosts:ro/);
|
||||
}
|
||||
expect(dockerfile).toMatch(/mkdir -p \/data\/workspace-registry && chown -R thoth:thoth \/data\/workspace-registry/);
|
||||
expect(smoke).toContain('core_remote="/fixtures/offline.git"');
|
||||
expect(smoke).toContain('"degraded":true');
|
||||
expect(smoke).toContain('core_remote="/fixtures/remote.git"');
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user