122 lines
4.2 KiB
TypeScript
122 lines
4.2 KiB
TypeScript
import { mkdirSync, mkdtempSync, rmSync, writeFileSync } from "node:fs";
|
|
import { tmpdir } from "node:os";
|
|
import { join } from "node:path";
|
|
import { afterEach, expect, test } from "vitest";
|
|
import { resolveBinding } from "../src/workspaces/bindings.js";
|
|
import { parseWorkspaceYaml } from "../src/workspaces/schema.js";
|
|
|
|
const workspace = parseWorkspaceYaml(`workspace:
|
|
schema_version: 1
|
|
id: psd-clinical
|
|
name: Policlinico San Donato
|
|
language: it
|
|
dwh:
|
|
engine: postgres
|
|
database: postgres
|
|
schema: datawarehouse
|
|
supported_transports: [postgres_direct, rest_api, ssh_tunnel]
|
|
semantic_index:
|
|
vector_store:
|
|
engine: pgvector
|
|
collection: clinical_documents
|
|
dimensions: 768
|
|
distance: cosine
|
|
supported_transports: [pgvector_direct, rest_api, ssh_tunnel]
|
|
embedding:
|
|
provider: ollama_compatible
|
|
model: nomic-embed-text-v2-moe
|
|
dimensions: 768
|
|
llm_policy:
|
|
allowed: [zai/glm-5.2]
|
|
`);
|
|
const temporaryRoots: string[] = [];
|
|
|
|
afterEach(() => {
|
|
temporaryRoots.splice(0).forEach((root) => rmSync(root, { recursive: true, force: true }));
|
|
});
|
|
|
|
function secretPath(name: string): { root: string; path: string } {
|
|
const root = mkdtempSync(join(tmpdir(), "thoth-binding-"));
|
|
temporaryRoots.push(root);
|
|
const secrets = join(root, "secrets");
|
|
mkdirSync(secrets);
|
|
const path = join(secrets, name);
|
|
writeFileSync(path, "");
|
|
return { root: secrets, path };
|
|
}
|
|
|
|
test("marks a portable workspace non-activatable when its local REST key file is absent", () => {
|
|
const result = resolveBinding(workspace, "DWH", {
|
|
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api",
|
|
THT_WS_PSD_CLINICAL_DWH_BASE_URL: "https://dwh.example.test",
|
|
}, ["/run/secrets"]);
|
|
|
|
expect(result.missing).toContain("THT_WS_PSD_CLINICAL_DWH_API_KEY_FILE");
|
|
});
|
|
|
|
test("resolves direct bindings from the stable workspace namespace", () => {
|
|
const password = secretPath("dwh-password");
|
|
const result = resolveBinding(workspace, "DWH", {
|
|
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
|
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
|
|
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
|
|
THT_WS_PSD_CLINICAL_DWH_USER: "thoth_reader",
|
|
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: password.path,
|
|
}, [password.root]);
|
|
|
|
expect(result).toMatchObject({
|
|
transport: "postgres_direct",
|
|
missing: [],
|
|
values: {
|
|
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
|
|
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
|
|
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: password.path,
|
|
},
|
|
});
|
|
});
|
|
|
|
test("reports only a FILE variable name when a secret path is outside the configured roots", () => {
|
|
const outside = secretPath("outside-password");
|
|
const allowed = secretPath("allowed-password");
|
|
const result = resolveBinding(workspace, "DWH", {
|
|
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
|
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
|
|
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
|
|
THT_WS_PSD_CLINICAL_DWH_USER: "thoth_reader",
|
|
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: outside.path,
|
|
}, [allowed.root]);
|
|
|
|
expect(result.missing).toEqual(["THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE"]);
|
|
expect(result.missing.join("\n")).not.toContain(outside.path);
|
|
});
|
|
|
|
test("reports an invalid optional secret file instead of silently dropping it", () => {
|
|
const password = secretPath("dwh-password");
|
|
const result = resolveBinding(workspace, "DWH", {
|
|
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
|
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
|
|
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
|
|
THT_WS_PSD_CLINICAL_DWH_USER: "thoth_reader",
|
|
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: password.path,
|
|
THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE: "relative-ca.pem",
|
|
}, [password.root]);
|
|
|
|
expect(result.missing).toContain("THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE");
|
|
expect(result.values).not.toHaveProperty("THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE");
|
|
});
|
|
|
|
test("rejects a selected transport that the canonical workspace does not support", () => {
|
|
const directOnly = {
|
|
...workspace,
|
|
dwh: { ...workspace.dwh, supported_transports: ["postgres_direct"] },
|
|
};
|
|
const result = resolveBinding(directOnly, "DWH", {
|
|
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api",
|
|
}, ["/run/secrets"]);
|
|
|
|
expect(result).toMatchObject({
|
|
transport: "rest_api",
|
|
missing: ["THT_WS_PSD_CLINICAL_DWH_TRANSPORT"],
|
|
});
|
|
});
|