fix(backend): harden provider credential isolation
This commit is contained in:
@@ -212,6 +212,35 @@ test.each([
|
||||
}
|
||||
});
|
||||
|
||||
test.each([["OpenAI", "openai"], ["gemini", "google"]])(
|
||||
"set_model uses canonical packaged provider ID for %s", async (provider, canonical) => {
|
||||
const secret = path.resolve(__dirname, `.canonical-key-${process.pid}-${provider}`);
|
||||
writeFileSync(secret, "provider-secret", { mode: 0o600 });
|
||||
const child = recordingChild();
|
||||
child.stderr.resume = () => {};
|
||||
child.stdin.write = (data: unknown) => {
|
||||
const request = JSON.parse(String(data));
|
||||
child._writes.push(String(data));
|
||||
if (request.id) {
|
||||
queueMicrotask(() => child.stdout.emit("data", `${JSON.stringify({
|
||||
type: "response", id: request.id, success: true,
|
||||
})}\n`));
|
||||
}
|
||||
return true;
|
||||
};
|
||||
const mgr = new PiProcessManager(loadConfig({ THT_MODEL_API_KEY_FILE: secret }), {
|
||||
spawnFn: () => child as any,
|
||||
});
|
||||
try {
|
||||
await mgr.spawnFor("canonical-provider", { provider, model: "model-id" });
|
||||
expect(child._writes.join("")).toContain(`\"provider\":\"${canonical}\"`);
|
||||
} finally {
|
||||
mgr.teardown("canonical-provider");
|
||||
await import("node:fs/promises").then((fs) => fs.unlink(secret));
|
||||
}
|
||||
},
|
||||
);
|
||||
|
||||
test("local providers spawn without a model key and scrub ambient generic credentials", async () => {
|
||||
vi.stubEnv("PI_PROVIDER_API_KEY", "ambient-secret");
|
||||
vi.stubEnv("THT_MODEL_API_KEY_FILE", "/ambient/secret-path");
|
||||
|
||||
Reference in New Issue
Block a user