feat(backend): expose sanitized tool activity

This commit is contained in:
User
2026-07-14 22:46:22 +02:00
parent a3c7d6ba05
commit e0a97a01f3
2 changed files with 93 additions and 2 deletions
+63
View File
@@ -181,3 +181,66 @@ test("steer invia un comando steer e riattiva il turno", () => {
expect(sent.at(-1)).toEqual({ type: "steer", message: "considera solo il 2024" });
expect(bridge.turnState()).toBe("running");
});
test("tool execution emits only a sanitized correlated lifecycle", () => {
const { rpc, fire } = fakeRpc();
const bridge = new SessionBridge(rpc);
const seen: any[] = [];
bridge.onClientEvent((event) => seen.push(event));
fire({
type: "tool_execution_start",
toolCallId: "tool-1",
toolName: "bash",
args: { command: "curl https://secret.invalid/?token=DO_NOT_LEAK_ARGS" },
});
fire({
type: "tool_execution_update",
toolCallId: "tool-1",
toolName: "bash",
partialResult: { content: "DO_NOT_LEAK_PARTIAL" },
});
fire({
type: "tool_execution_end",
toolCallId: "tool-1",
toolName: "bash",
result: { content: "DO_NOT_LEAK_RESULT" },
isError: false,
});
expect(seen).toEqual([
{
type: "activity_event",
activity: { kind: "tool", toolCallId: "tool-1", toolName: "bash", status: "running" },
},
{
type: "activity_event",
activity: { kind: "tool", toolCallId: "tool-1", toolName: "bash", status: "completed" },
},
]);
expect(JSON.stringify(seen)).not.toMatch(/DO_NOT_LEAK|args|partialResult|result|command/);
});
test("failed tool completion is sanitized and invalid starts are ignored", () => {
const { rpc, fire } = fakeRpc();
const bridge = new SessionBridge(rpc);
const seen: any[] = [];
bridge.onClientEvent((event) => seen.push(event));
fire({ type: "tool_execution_start", toolName: "read", args: { path: "DO_NOT_LEAK_PATH" } });
fire({
type: "tool_execution_end",
toolCallId: "tool-2",
toolName: 42,
result: { error: "DO_NOT_LEAK_ERROR" },
isError: true,
});
expect(seen).toEqual([
{
type: "activity_event",
activity: { kind: "tool", toolCallId: "tool-2", toolName: "Tool", status: "failed" },
},
]);
expect(JSON.stringify(seen)).not.toMatch(/DO_NOT_LEAK|args|result|error|path/);
});