fix(evidence): make result summaries safe
This commit is contained in:
@@ -5,7 +5,7 @@ import pytest
|
||||
from tht.corpus.chunk import ChunkPolicy
|
||||
from tht.corpus.pipeline import CorpusPipeline, PipelineError, PipelineResult
|
||||
from tht.corpus.store import CorpusStore
|
||||
from tht.corpus.models import CanonicalChunk, CorpusManifest
|
||||
from tht.corpus.models import CanonicalChunk, CanonicalDocument, CorpusManifest
|
||||
from tht.ports.evidence import AcquiredDocument, SourceObject
|
||||
from tht.ports.vector import VectorCapabilities, VectorHealth
|
||||
|
||||
@@ -362,6 +362,30 @@ def test_pipeline_result_public_dump_is_bounded_and_excludes_evidence_content(tm
|
||||
assert len(json.dumps(large)) < 25_000
|
||||
|
||||
|
||||
def test_pipeline_result_repr_is_bounded_and_excludes_manifest_secrets():
|
||||
secret = "TOP_SECRET_CONTENT"
|
||||
manifest = CorpusManifest.model_construct(
|
||||
manifest_id="gen:" + "a" * 64,
|
||||
documents=tuple(CanonicalDocument.model_construct(content=secret) for _ in range(1000)),
|
||||
chunks=tuple(CanonicalChunk.model_construct(content=secret) for _ in range(1000)),
|
||||
metadata={"password": secret, "credential": "Bearer " + secret},
|
||||
)
|
||||
result = PipelineResult(
|
||||
"succeeded", "gen:" + "a" * 64, True, (), (), (), manifest,
|
||||
run_id="b" * 32,
|
||||
)
|
||||
|
||||
rendered = repr(result)
|
||||
assert str(result) == rendered
|
||||
assert len(rendered) < 1000
|
||||
assert secret not in rendered
|
||||
assert "password" not in rendered
|
||||
assert "credential" not in rendered
|
||||
assert "manifest" not in rendered.lower()
|
||||
assert "documents" not in rendered
|
||||
assert "chunks" not in rendered
|
||||
|
||||
|
||||
def test_reused_corpus_root_rejects_workspace_rename_before_any_mutation(tmp_path):
|
||||
vectors = Vectors()
|
||||
first = pipeline(tmp_path, Source([(item("one", "a"), "stable")]), vectors=vectors)
|
||||
|
||||
@@ -72,6 +72,27 @@ def test_preprocess_real_failed_stage_result_exits_nonzero(monkeypatch, tmp_path
|
||||
assert "secret" not in response.output
|
||||
|
||||
|
||||
def test_preprocess_evidence_text_uses_uncapped_result_counts(monkeypatch, tmp_path):
|
||||
import tht.cli.preprocess_cmd as command
|
||||
|
||||
result = SimpleNamespace(model_dump=lambda mode=None: {
|
||||
"status": "succeeded", "run_id": "a" * 32,
|
||||
"generation": "gen:" + "b" * 64, "published": True,
|
||||
"changed": ["fs:item"] * 100,
|
||||
"unchanged": ["fs:item"] * 100,
|
||||
"removed": ["fs:item"] * 100,
|
||||
"counts": {"changed": 1001, "unchanged": 902, "removed": 803},
|
||||
})
|
||||
monkeypatch.setattr(command, "run_from_config", lambda *args, **kwargs: result)
|
||||
|
||||
response = CliRunner().invoke(
|
||||
app, ["preprocess", "evidence", "-c", str(tmp_path / "workspace.yaml")]
|
||||
)
|
||||
|
||||
assert response.exit_code == 0, response.output
|
||||
assert "changed=1001 unchanged=902 removed=803" in response.output
|
||||
|
||||
|
||||
def test_preprocess_resume_rejects_generation_id_before_configuration(monkeypatch, tmp_path):
|
||||
import tht.cli.preprocess_cmd as command
|
||||
|
||||
|
||||
Reference in New Issue
Block a user