test: verify read-only workspace secret flow
This commit is contained in:
@@ -34,9 +34,9 @@ test("loadConfig keeps local development defaults", () => {
|
||||
workspaceRegistry: {
|
||||
root: "/data/workspace-registry",
|
||||
branch: "main",
|
||||
maxImportBytes: 10 * 1024 * 1024,
|
||||
maxImportEntries: 32,
|
||||
},
|
||||
workspaceSecretStoreRoot: "/data/workspace-secrets",
|
||||
workspaceSecretRuntimeRoot: "/tmp/thothii-workspace-secrets",
|
||||
internalQdrantUrl: "http://qdrant:6333",
|
||||
internalEmbeddingUrl: "http://embedding:11434",
|
||||
internalEmbeddingModel: "qwen3-embedding:0.6b",
|
||||
|
||||
@@ -238,7 +238,7 @@ test("constructs diagnostic URLs only when the resolved URL remains on the servi
|
||||
|
||||
expect(resolveDiagnosticUrl).toBeTypeOf("function");
|
||||
expect((resolveDiagnosticUrl as (baseUrl: string, path: string) => URL)("https://service.example/base", "/rpc/ping"))
|
||||
.toMatchObject({ href: "https://service.example/rpc/ping" });
|
||||
.toMatchObject({ href: "https://service.example/base/rpc/ping" });
|
||||
expect(() => (resolveDiagnosticUrl as (baseUrl: string, path: string) => URL)(
|
||||
"https://service.example/base", "//diagnostic.invalid/rpc",
|
||||
)).toThrow(/origin/i);
|
||||
|
||||
Reference in New Issue
Block a user