import { expect, test } from "vitest"; import { mkdtempSync, mkdirSync, rmSync, writeFileSync } from "node:fs"; import { tmpdir } from "node:os"; import { join } from "node:path"; import { buildInstallationContract, renderWorkspaceDocs } from "../src/workspaces/contracts.js"; import { type CanonicalWorkspace, parseWorkspaceYaml } from "../src/workspaces/schema.js"; const workspaceV3 = parseWorkspaceYaml(`workspace: schema_version: 3 id: psd-clinical name: Policlinico San Donato language: it dwh: engine: postgres database: postgres schema: datawarehouse supported_transports: [postgres_direct, rest_api, ssh_tunnel] semantic_index: vector_store: { engine: qdrant, collection: psd-clinical, dimensions: 1024, distance: cosine } embedding: { provider: ollama_internal, model: qwen3-embedding:0.6b, dimensions: 1024 } llm_policy: allowed: [zai/glm-5.2] `); test("schema-v3 installation contracts expose only DWH bindings and no semantic variables", () => { const contract = buildInstallationContract(workspaceV3); const names = contract.variables.map((variable) => variable.name); const docs = renderWorkspaceDocs(workspaceV3); expect(contract.workspaceId).toBe("psd-clinical"); expect(contract.namespace).toBe("PSD_CLINICAL"); expect(contract.variables.every((variable) => variable.role === "DWH")).toBe(true); expect(names).toContain("THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE"); expect(names.some((name) => /_VECTOR_|_EMBEDDING_/.test(name))).toBe(false); expect(docs.envExample).not.toContain("_VECTOR_"); expect(docs.markdown).toContain("Configurazione dell'installazione"); expect(docs.markdown).not.toContain("Vector store"); expect(docs.markdown).not.toContain("Embedding service"); }); test.each([ ["postgres_direct", "HOST", "BASE_URL"], ["rest_api", "BASE_URL", "HOST"], ["ssh_tunnel", "SSH_PRIVATE_KEY_FILE", "BASE_URL"], ] as const)("documents only the DWH fields for %s", (transport, included, excluded) => { const descriptor = parseWorkspaceYaml(renderWorkspaceWithoutEvidence() .replace("[postgres_direct]", `[${transport}]`)); const variables = buildInstallationContract(descriptor).variables; expect(variables.find(({ suffix }) => suffix === included)?.transports).toEqual([transport]); expect(variables.some(({ suffix }) => suffix === excluded)).toBe(false); expect(variables.filter(({ secret }) => secret).every(({ name }) => name.endsWith("_FILE"))) .toBe(true); }); test("validates public contract and documentation inputs at runtime", () => { const unsafeWorkspace = { ...workspaceV3, workspace: { ...workspaceV3.workspace, id: "psd\nclinical" }, } as CanonicalWorkspace; expect(() => buildInstallationContract(unsafeWorkspace)).toThrow(/id/i); expect(() => renderWorkspaceDocs(unsafeWorkspace)).toThrow(/id/i); }); test("v3 installation contract omits external vector and embedding bindings", () => { const contract = buildInstallationContract(workspaceV3); const names = contract.variables.map((variable) => variable.name); expect(names).toContain("THT_WS_PSD_CLINICAL_DWH_TRANSPORT"); expect(names.some((name) => name.includes("_VECTOR_"))).toBe(false); expect(names.some((name) => name.includes("_EMBEDDING_"))).toBe(false); expect(renderWorkspaceDocs(workspaceV3).markdown).not.toContain("Embedding service"); }); test.each([ { mode: "signed HTTP", source: { type: "http", uris: ["https://evidence.example.test/guide.md"], authentication: "signed_urls_file", }, expected: ["THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE"], }, { mode: "static S3", source: { type: "s3", uri: "s3://clinical-evidence/published/", credentials: "static_files" }, expected: [ "THT_WS_PSD_CLINICAL_EVIDENCE_ACCESS_KEY_FILE", "THT_WS_PSD_CLINICAL_EVIDENCE_SECRET_KEY_FILE", "THT_WS_PSD_CLINICAL_EVIDENCE_SESSION_TOKEN_FILE", ], }, ])("generates source-specific $mode Evidence file bindings", ({ source, expected }) => { const descriptor = parseWorkspaceYaml(`${renderWorkspaceWithoutEvidence()}evidence:\n source: ${JSON.stringify(source)}\n`); const contract = buildInstallationContract(descriptor); const evidence = contract.variables.filter((variable) => variable.role === "EVIDENCE"); expect(contract.namespace).toBe("PSD_CLINICAL"); expect(evidence.map((variable) => variable.name)).toEqual(expected); expect(evidence.every((variable) => variable.secret)).toBe(true); expect(renderWorkspaceDocs(descriptor).envExample).not.toContain("CANARY-SECRET"); }); test.each([ { type: "filesystem", uri: "workspace-content/psd-clinical/evidence" }, { type: "http", uris: ["https://evidence.example.test/guide.md"], authentication: "none" }, { type: "s3", uri: "s3://clinical-evidence/published/", credentials: "ambient" }, ])("omits Evidence installation variables for $type modes without file credentials", (source) => { const descriptor = parseWorkspaceYaml(`${renderWorkspaceWithoutEvidence()}evidence:\n source: ${JSON.stringify(source)}\n`); expect(buildInstallationContract(descriptor).variables.some((variable) => variable.role === "EVIDENCE")) .toBe(false); }); function renderWorkspaceWithoutEvidence(): string { return `workspace: schema_version: 3 id: psd-clinical name: Policlinico San Donato language: it dwh: engine: postgres database: postgres schema: datawarehouse supported_transports: [postgres_direct] semantic_index: vector_store: { engine: qdrant, collection: psd-clinical, dimensions: 1024, distance: cosine } embedding: { provider: ollama_internal, model: qwen3-embedding:0.6b, dimensions: 1024 } llm_policy: { allowed: [zai/glm-5.2] } `; } const evidenceSources = [ { label: "filesystem", source: { type: "filesystem", uri: "workspace-content/psd-clinical/evidence" }, variables: [], }, { label: "HTTP signed URL file", source: { type: "http", uris: ["https://evidence.example.test/guide.md", "http://public.example.test/policy.pdf"], authentication: "signed_urls_file", }, variables: ["THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE"], }, { label: "S3 static files", source: { type: "s3", uri: "s3://clinical-evidence/published/", credentials: "static_files", }, variables: [ "THT_WS_PSD_CLINICAL_EVIDENCE_ACCESS_KEY_FILE", "THT_WS_PSD_CLINICAL_EVIDENCE_SECRET_KEY_FILE", "THT_WS_PSD_CLINICAL_EVIDENCE_SESSION_TOKEN_FILE", ], }, ] as const; test.each(evidenceSources)("renders deterministic public Evidence docs for $label", ({ source, variables }) => { const descriptor = parseWorkspaceYaml( `${renderWorkspaceWithoutEvidence()}evidence:\n source: ${JSON.stringify(source)}\n`, ); const firstContract = buildInstallationContract(descriptor); const secondContract = buildInstallationContract(descriptor); const firstDocs = renderWorkspaceDocs(descriptor); const secondDocs = renderWorkspaceDocs(descriptor); expect(secondContract).toEqual(firstContract); expect(secondDocs).toEqual(firstDocs); expect(firstContract.variables.filter(({ role }) => role === "EVIDENCE").map(({ name }) => name)) .toEqual(variables); expect(firstDocs.markdown).toContain("## Evidence source"); expect(firstDocs.markdown).toContain(`- Type: \`${source.type}\``); for (const uri of "uris" in source ? source.uris : [source.uri]) { expect(firstDocs.markdown).toContain(`\`${uri}\``); } expect(firstDocs.markdown).toContain("- Maximum source bytes: `10485760`"); expect(firstDocs.markdown).toContain("- Maximum chunk characters: `4000`"); expect(firstDocs.markdown).toContain("- Retained published generations: `3`"); for (const variable of variables) { expect(firstDocs.markdown).toContain(`\`${variable}\``); expect(firstDocs.envExample).toContain(`${variable}=`); } }); test("documents the S3 session token file as optional", () => { const descriptor = parseWorkspaceYaml( `${renderWorkspaceWithoutEvidence()}evidence: source: { type: s3, uri: s3://clinical-evidence/published/, credentials: static_files } `, ); const markdown = renderWorkspaceDocs(descriptor).markdown; const required = markdown.slice( markdown.indexOf("- Required installation file variables:"), markdown.indexOf("- Optional installation file variables:"), ); const optional = markdown.slice(markdown.indexOf("- Optional installation file variables:")); expect(required).toContain("EVIDENCE_ACCESS_KEY_FILE"); expect(required).toContain("EVIDENCE_SECRET_KEY_FILE"); expect(required).not.toContain("EVIDENCE_SESSION_TOKEN_FILE"); expect(optional).toContain("EVIDENCE_SESSION_TOKEN_FILE"); }); test("documents same-revision filesystem ownership without claiming P1 materialization", () => { const descriptor = parseWorkspaceYaml( `${renderWorkspaceWithoutEvidence()}evidence:\n source: { type: filesystem, uri: workspace-content/psd-clinical/evidence }\n`, ); const docs = renderWorkspaceDocs(descriptor).markdown; expect(docs).toContain("`workspace-content/psd-clinical/evidence`"); expect(docs).toMatch(/same Git revision/i); expect(docs).toMatch(/P6.*materializ/i); expect(docs).toMatch(/containment.*symlink/i); expect(docs).toMatch(/does not include Evidence file bytes/i); }); test.each([ { source: { type: "http", uris: ["https://evidence.example.test/guide.md"], authentication: "none" }, expected: "No credential file is required", }, { source: { type: "http", uris: ["https://evidence.example.test/guide.md"], authentication: "signed_urls_file" }, expected: "signed URL file", }, { source: { type: "s3", uri: "s3://clinical-evidence/published/", credentials: "ambient" }, expected: "ambient credentials", }, { source: { type: "s3", uri: "s3://clinical-evidence/published/", credentials: "static_files" }, expected: "installation file variables", }, ])("documents $source.type credential mode without reading credential contents", ({ source, expected }) => { const root = mkdtempSync(join(tmpdir(), "thoth-evidence-doc-secret-")); const secrets = join(root, "secrets"); const canary = "CANARY-EVIDENCE-CREDENTIAL-DO-NOT-LEAK"; mkdirSync(secrets); const binding = join(secrets, "credential"); writeFileSync(binding, canary); const previous = process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE; process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE = binding; try { const descriptor = parseWorkspaceYaml( `${renderWorkspaceWithoutEvidence()}evidence:\n source: ${JSON.stringify(source)}\n`, ); const generated = JSON.stringify({ contract: buildInstallationContract(descriptor), docs: renderWorkspaceDocs(descriptor), }); expect(generated).toContain(expected); expect(generated).not.toContain(canary); } finally { if (previous === undefined) delete process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE; else process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE = previous; rmSync(root, { recursive: true, force: true }); } });