fix(evidence): make result summaries safe
This commit is contained in:
@@ -5,7 +5,7 @@ import pytest
|
||||
from tht.corpus.chunk import ChunkPolicy
|
||||
from tht.corpus.pipeline import CorpusPipeline, PipelineError, PipelineResult
|
||||
from tht.corpus.store import CorpusStore
|
||||
from tht.corpus.models import CanonicalChunk, CorpusManifest
|
||||
from tht.corpus.models import CanonicalChunk, CanonicalDocument, CorpusManifest
|
||||
from tht.ports.evidence import AcquiredDocument, SourceObject
|
||||
from tht.ports.vector import VectorCapabilities, VectorHealth
|
||||
|
||||
@@ -362,6 +362,30 @@ def test_pipeline_result_public_dump_is_bounded_and_excludes_evidence_content(tm
|
||||
assert len(json.dumps(large)) < 25_000
|
||||
|
||||
|
||||
def test_pipeline_result_repr_is_bounded_and_excludes_manifest_secrets():
|
||||
secret = "TOP_SECRET_CONTENT"
|
||||
manifest = CorpusManifest.model_construct(
|
||||
manifest_id="gen:" + "a" * 64,
|
||||
documents=tuple(CanonicalDocument.model_construct(content=secret) for _ in range(1000)),
|
||||
chunks=tuple(CanonicalChunk.model_construct(content=secret) for _ in range(1000)),
|
||||
metadata={"password": secret, "credential": "Bearer " + secret},
|
||||
)
|
||||
result = PipelineResult(
|
||||
"succeeded", "gen:" + "a" * 64, True, (), (), (), manifest,
|
||||
run_id="b" * 32,
|
||||
)
|
||||
|
||||
rendered = repr(result)
|
||||
assert str(result) == rendered
|
||||
assert len(rendered) < 1000
|
||||
assert secret not in rendered
|
||||
assert "password" not in rendered
|
||||
assert "credential" not in rendered
|
||||
assert "manifest" not in rendered.lower()
|
||||
assert "documents" not in rendered
|
||||
assert "chunks" not in rendered
|
||||
|
||||
|
||||
def test_reused_corpus_root_rejects_workspace_rename_before_any_mutation(tmp_path):
|
||||
vectors = Vectors()
|
||||
first = pipeline(tmp_path, Source([(item("one", "a"), "stable")]), vectors=vectors)
|
||||
|
||||
Reference in New Issue
Block a user