feat(backend): expose sanitized tool activity
This commit is contained in:
@@ -181,3 +181,66 @@ test("steer invia un comando steer e riattiva il turno", () => {
|
||||
expect(sent.at(-1)).toEqual({ type: "steer", message: "considera solo il 2024" });
|
||||
expect(bridge.turnState()).toBe("running");
|
||||
});
|
||||
|
||||
test("tool execution emits only a sanitized correlated lifecycle", () => {
|
||||
const { rpc, fire } = fakeRpc();
|
||||
const bridge = new SessionBridge(rpc);
|
||||
const seen: any[] = [];
|
||||
bridge.onClientEvent((event) => seen.push(event));
|
||||
|
||||
fire({
|
||||
type: "tool_execution_start",
|
||||
toolCallId: "tool-1",
|
||||
toolName: "bash",
|
||||
args: { command: "curl https://secret.invalid/?token=DO_NOT_LEAK_ARGS" },
|
||||
});
|
||||
fire({
|
||||
type: "tool_execution_update",
|
||||
toolCallId: "tool-1",
|
||||
toolName: "bash",
|
||||
partialResult: { content: "DO_NOT_LEAK_PARTIAL" },
|
||||
});
|
||||
fire({
|
||||
type: "tool_execution_end",
|
||||
toolCallId: "tool-1",
|
||||
toolName: "bash",
|
||||
result: { content: "DO_NOT_LEAK_RESULT" },
|
||||
isError: false,
|
||||
});
|
||||
|
||||
expect(seen).toEqual([
|
||||
{
|
||||
type: "activity_event",
|
||||
activity: { kind: "tool", toolCallId: "tool-1", toolName: "bash", status: "running" },
|
||||
},
|
||||
{
|
||||
type: "activity_event",
|
||||
activity: { kind: "tool", toolCallId: "tool-1", toolName: "bash", status: "completed" },
|
||||
},
|
||||
]);
|
||||
expect(JSON.stringify(seen)).not.toMatch(/DO_NOT_LEAK|args|partialResult|result|command/);
|
||||
});
|
||||
|
||||
test("failed tool completion is sanitized and invalid starts are ignored", () => {
|
||||
const { rpc, fire } = fakeRpc();
|
||||
const bridge = new SessionBridge(rpc);
|
||||
const seen: any[] = [];
|
||||
bridge.onClientEvent((event) => seen.push(event));
|
||||
|
||||
fire({ type: "tool_execution_start", toolName: "read", args: { path: "DO_NOT_LEAK_PATH" } });
|
||||
fire({
|
||||
type: "tool_execution_end",
|
||||
toolCallId: "tool-2",
|
||||
toolName: 42,
|
||||
result: { error: "DO_NOT_LEAK_ERROR" },
|
||||
isError: true,
|
||||
});
|
||||
|
||||
expect(seen).toEqual([
|
||||
{
|
||||
type: "activity_event",
|
||||
activity: { kind: "tool", toolCallId: "tool-2", toolName: "Tool", status: "failed" },
|
||||
},
|
||||
]);
|
||||
expect(JSON.stringify(seen)).not.toMatch(/DO_NOT_LEAK|args|result|error|path/);
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user