package pi import ( "context" "path/filepath" "strings" "testing" ) func TestDoctorRequiresExternalEndpointAuthPiStateAndHealth(t *testing.T) { fake := newFakeRunner() if err := Doctor(context.Background(), fake); err != nil { t.Fatalf("Doctor() error = %v", err) } for _, command := range []string{"pi --version", "test -w /home/thoth/.pi", "test -r /home/thoth/.pi/agent/auth.json", "/health"} { assertCalled(t, fake.calls, command) } } func TestConfigureValidatesBackendModelOptionsAndWritesNoSecrets(t *testing.T) { fake := newFakeRunner() path := filepath.Join(t.TempDir(), "pi-defaults.json") if err := Configure(context.Background(), fake, path, Defaults{Provider: "provider", Model: "model", Thinking: "medium", LLMURL: "https://llm.example.invalid"}); err != nil { t.Fatal(err) } if got := string(readStateBytes(t, path)); strings.Contains(got, "secret") || !strings.Contains(got, "llm.example.invalid") { t.Fatalf("defaults=%q", got) } if err := Configure(context.Background(), fake, path, Defaults{Provider: "provider", Model: "unknown", Thinking: "medium", LLMURL: "https://llm.example.invalid"}); err == nil { t.Fatal("expected unknown model rejection") } } func TestTestUsesOnlySanitizedPiAndCoreProbes(t *testing.T) { fake := newFakeRunner() if err := Test(context.Background(), fake); err != nil { t.Fatalf("Test() error = %v", err) } for _, command := range []string{"pi --version", "/health", "/models", "/settings"} { assertCalled(t, fake.calls, command) } if got := strings.Join(fake.calls, "\n"); strings.Contains(got, "secret") { t.Fatalf("probe commands expose secret: %s", got) } }