import { createHash } from "node:crypto"; import { expect, test } from "vitest"; import { buildCanonicalEffectiveConfig, canonicalEffectiveConfigJson, configFingerprint, effectiveConfigIdentity, inputFingerprint, } from "../src/workspaces/effective-config.js"; const semanticRuntime = { internalQdrantUrl: "http://qdrant:6333", internalEmbeddingUrl: "http://embedding:11434", internalEmbeddingId: "ollama/qwen3-embedding:0.6b", internalEmbeddingModel: "qwen3-embedding:0.6b", internalEmbeddingDimensions: 1024, }; function directRendered(): Record { return { runtime_identity: { workspace_id: "psd-clinical", workspace_revision: "a".repeat(40), source_identity: "workspace://psd-clinical", }, session_storage: { mode: "local" }, profile: "server", language: "it", database: { host: "dwh.internal", port: 5432, database: "postgres", schema: "datawarehouse", user: "thoth_reader", password_file: "/run/secrets/dwh-password", ssl_ca_file: "/run/secrets/dwh-ca.pem", transport: "direct", }, dwh: { type: "postgres_direct" }, resources: { vector: { engine: "qdrant", base_url: "http://qdrant:6333", collection: "psd-clinical", dimensions: 1024, distance: "cosine", collection_lifecycle: "require_existing", }, embeddings: { provider: "ollama_internal", base_url: "http://embedding:11434", model: "qwen3-embedding:0.6b", dimensions: 1024, }, }, roots: { sessions: "/data/sessions/psd-clinical/sessions", artifacts: "/data/sessions/psd-clinical/artifacts", indexes: "/data/sessions/psd-clinical/indexes", }, paths: { sessions: "/data/sessions/psd-clinical/sessions", artifacts: "/data/sessions/psd-clinical/artifacts", indexes: "/data/sessions/psd-clinical/indexes", memory: "/data/sessions/psd-clinical/memory", }, evidence: { sources: [{ type: "filesystem", root: "/srv/registry/snapshots/rev/psd-clinical/evidence", patterns: ["**/*.md"], max_bytes: 10_485_760, }], }, }; } function restRendered(): Record { return { ...directRendered(), database: { host: "localhost", port: 5432, database: "postgres", schema: "datawarehouse", user: "rest", password: "", transport: "rest", }, dwh: { type: "thoth_rest", database: { database: "postgres", schema: "datawarehouse" }, endpoint: { base_url: "https://dwh.example.test", api_key_file: "/run/secrets/dwh-api-key", }, }, rest: { base_url: "https://dwh.example.test", api_key_file: "/run/secrets/dwh-api-key", }, }; } const directCanonical = `{"schemaVersion":2,"dwh":{` + `"engine":"postgres","database":"postgres","schema":"datawarehouse",` + `"transport":"postgres_direct","host":"dwh.internal","port":5432,"user":"thoth_reader"},` + `"vector":{"collection":"psd-clinical","dimensions":1024,"distance":"cosine"},` + `"embedding":{"id":"ollama/qwen3-embedding:0.6b","model":"qwen3-embedding:0.6b","dimensions":1024},` + `"roots":{"artifacts":"/data/sessions/psd-clinical/artifacts",` + `"indexes":"/data/sessions/psd-clinical/indexes"}}`; test("canonical effective config is deterministic and contains the expected key order", () => { const rendered = directRendered(); const canonical = buildCanonicalEffectiveConfig(rendered); expect(canonicalEffectiveConfigJson(canonical)).toBe(directCanonical); expect(buildCanonicalEffectiveConfig(rendered)).toEqual(canonical); }); test("canonical effective config excludes secrets, evidence, session storage, and runtime identity", () => { const json = canonicalEffectiveConfigJson(buildCanonicalEffectiveConfig(directRendered())); expect(json).not.toContain("password_file"); expect(json).not.toContain("ssl_ca_file"); expect(json).not.toContain("session_storage"); expect(json).not.toContain("runtime_identity"); expect(json).not.toContain("evidence"); expect(json).not.toContain("sources"); expect(json).not.toContain("collection_lifecycle"); expect(json).not.toContain("base_url"); // vector/embedding service URLs are not identity expect(json).not.toContain("memory"); expect(json).not.toContain('"sessions"'); }); test("REST transport canonicalizes to transport rest_api with baseUrl and no host/port", () => { const canonical = buildCanonicalEffectiveConfig(restRendered()); const json = canonicalEffectiveConfigJson(canonical); expect(json).toContain(`"transport":"rest_api"`); expect(json).toContain(`"baseUrl":"https://dwh.example.test"`); expect(json).not.toContain(`"host":`); expect(json).not.toContain(`"port":`); expect(json).not.toContain("api_key_file"); }); test("identity and fingerprint helpers produce stable prefixed hex values", () => { const rendered = directRendered(); const identity = effectiveConfigIdentity("psd-clinical", rendered); const cfg = configFingerprint(rendered); const input = inputFingerprint("psd-clinical", rendered); expect(identity).toMatch(/^workspace:\/\/psd-clinical@v1:[0-9a-f]{64}$/); expect(cfg).toBe("sha256:" + createHash("sha256").update(directCanonical).digest("hex")); expect(input).toBe("sha256:" + createHash("sha256").update(identity).digest("hex")); expect(input).not.toBe(cfg); }); test("content-only or session_storage changes keep the same effective config identity", () => { const base = directRendered(); const identityBefore = effectiveConfigIdentity("psd-clinical", base); const fingerprintBefore = configFingerprint(base); const contentOnly = { ...base, runtime_identity: { ...base.runtime_identity, workspace_revision: "b".repeat(40), }, session_storage: { mode: "remote", url: "http://example.test" }, evidence: { sources: [{ type: "filesystem", root: "/srv/registry/snapshots/other/psd-clinical/evidence", patterns: ["**/*.txt"], max_bytes: 999, }], }, }; expect(effectiveConfigIdentity("psd-clinical", contentOnly)).toBe(identityBefore); expect(configFingerprint(contentOnly)).toBe(fingerprintBefore); }); test("DWH-affecting changes alter the effective config identity", () => { const base = directRendered(); const identityBefore = effectiveConfigIdentity("psd-clinical", base); const changedHost = { ...base, database: { ...(base.database as object), host: "dwh-two.internal" } }; expect(effectiveConfigIdentity("psd-clinical", changedHost)).not.toBe(identityBefore); const changedDatabase = { ...base, database: { ...(base.database as object), database: "analytics" } }; expect(effectiveConfigIdentity("psd-clinical", changedDatabase)).not.toBe(identityBefore); const changedCollection = { ...base, resources: { ...base.resources, vector: { ...(base.resources as Record).vector, collection: "other" } } }; expect(effectiveConfigIdentity("psd-clinical", changedCollection)).not.toBe(identityBefore); const changedEmbeddingIdentity = { ...base, resources: { ...base.resources, embeddings: { ...(base.resources as Record).embeddings, model: "other-embedding" } } }; expect(effectiveConfigIdentity("psd-clinical", changedEmbeddingIdentity)).not.toBe(identityBefore); const changedTransport = restRendered(); expect(effectiveConfigIdentity("psd-clinical", changedTransport)).not.toBe(identityBefore); });