fix: harden workspace diagnostic protocols

This commit is contained in:
2026-08-03 23:59:46 +02:00
parent 9e2eafb66c
commit ca97bbb9c2
5 changed files with 371 additions and 17 deletions
@@ -366,6 +366,31 @@ test("does not substitute the reader credential for a declared vector writer", a
expect(adapters.writeDiagnosticRecord).not.toHaveBeenCalled();
});
test("rejects a writer credential that aliases the reader credential", async () => {
const directory = await mkdtemp(join(tmpdir(), "thothii-diagnostic-"));
const readerKey = join(directory, "reader-key");
const writerAlias = join(directory, "writer-key");
await writeFile(readerKey, "same-secret\n", { mode: 0o600 });
await (await import("node:fs/promises")).symlink(readerKey, writerAlias);
const adapters = successfulAdapters();
const aliasedBindings: RuntimeBindings = {
...writerBindings,
vector: { ...writerBindings.vector, values: {
...writerBindings.vector.values,
THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE: readerKey,
THT_WS_PSD_CLINICAL_VECTOR_WRITER_API_KEY_FILE: writerAlias,
} },
};
try {
const result = await diagnose(adapters)(writerWorkspace, aliasedBindings, { writeProbe: true });
expect(result.activatable).toBe(false);
expect(adapters.writeDiagnosticRecord).not.toHaveBeenCalled();
} finally {
await rm(directory, { recursive: true, force: true });
}
});
test("uses the declared POST DWH ping endpoint without exposing its local credential", async () => {
const directory = await mkdtemp(join(tmpdir(), "thothii-diagnostic-"));
const credentialFile = join(directory, "dwh-api-key");
@@ -403,6 +428,50 @@ test("uses the declared POST DWH ping endpoint without exposing its local creden
}
});
test("requires an authenticated TLS database query before direct diagnostics succeed", async () => {
const directory = await mkdtemp(join(tmpdir(), "thothii-diagnostic-"));
const passwordFile = join(directory, "password");
const caFile = join(directory, "ca.pem");
await Promise.all([writeFile(passwordFile, "password\n", { mode: 0o600 }), writeFile(caFile, "test-ca\n")]);
const query = vi.fn(async () => ({ rows: [{ database: "warehouse", schema: "datawarehouse" }] }));
const end = vi.fn(async () => undefined);
const connect = vi.fn(async () => ({ query, end }));
try {
const result = await createConcreteDiagnosticAdapters({ databaseClient: { connect } } as any).probeConnector({
role: "dwh", transport: "postgres_direct", host: "127.0.0.1", port: 5432, user: "reader",
credentialFile: passwordFile, tlsCaFile: caFile,
resource: { database: "warehouse", schema: "datawarehouse" }, timeoutMs: 5000,
signal: new AbortController().signal,
});
expect(connect).toHaveBeenCalledWith(expect.objectContaining({ database: "warehouse", tlsCaFile: caFile }));
expect(query).toHaveBeenCalledWith(expect.stringContaining("current_database"), []);
expect(end).toHaveBeenCalledOnce();
expect(result).toMatchObject({ authenticated: true, tlsVerified: true });
} finally {
await rm(directory, { recursive: true, force: true });
}
});
test("honors a declared unauthenticated REST diagnostic without reading a credential", async () => {
const fetchSpy = vi.fn(async () => new Response(JSON.stringify({ database: "warehouse", schema: "datawarehouse" }), {
status: 200, headers: { "content-type": "application/json" },
}));
vi.stubGlobal("fetch", fetchSpy);
try {
await expect(createConcreteDiagnosticAdapters().probeConnector({
role: "dwh", transport: "rest_api", baseUrl: "https://dwh.example.test",
resource: { database: "warehouse", schema: "datawarehouse" }, timeoutMs: 5000,
signal: new AbortController().signal,
diagnostic: { method: "POST", path: "/rpc/ping", auth: "none", response: { database: "database", schema: "schema" } } as any,
})).resolves.toMatchObject({ authenticated: true });
expect(fetchSpy.mock.calls[0]?.[1]).not.toMatchObject({ headers: expect.objectContaining({ authorization: expect.anything() }) });
} finally {
vi.unstubAllGlobals();
}
});
test("constructs the production diagnoser with the configured timeout and injected adapters", async () => {
const adapters = successfulAdapters();
@@ -430,3 +499,16 @@ test("retries bounded cleanup after a write-probe removal times out", async () =
expect(result).toMatchObject({ activatable: false });
expect(JSON.stringify(result)).not.toContain("timeout");
});
test("attempts bounded cleanup when a timed-out write may already have created the record", async () => {
const adapters = successfulAdapters({
writeDiagnosticRecord: vi.fn(() => new Promise<void>(() => undefined)),
});
const diagnoseWithShortTimeout = createWorkspaceDiagnoser(adapters, { timeoutMs: 10 });
const result = await diagnoseWithShortTimeout(writerWorkspace, writerBindings, { writeProbe: true });
expect(adapters.writeDiagnosticRecord).toHaveBeenCalledOnce();
expect(adapters.removeDiagnosticRecord).toHaveBeenCalledOnce();
expect(result.activatable).toBe(false);
});