Files
ThothII/harness/tests/test_vector_dual_key.py
T
marcopan 796a39d893 feat(harness): port vectorstore dual-key + reader RPC (D11, §5.4)
Ports vectorstore/{rest_client,rest_writer,store,reader,embeddings,records},
evidence/model (leaf dep of records), and cli/_guards (require_vector_write_allowed
workstation write-guard). Renamed psdwp3->nsp, verbatim.

VectorRestClient gains an api_key property so reader/writer clients carry their
distinct keys visibly (spec D11: vector_reader / vector_writer on the same endpoint).

scripts/create_vector_reader_rpc.sql is NEW: the reader RPCs (search_similar,
list_tables) lived server-side in Supabase and were never versioned. Authored now
mirroring the writer allowlist pattern (table allowlist, security definer, revoke
from anon/authenticated, grant to vector_reader only). Writer RPC ported verbatim.

L1: test_vector_dual_key (7 tests) pins the dual-key construction + the workstation
write-guard (exit 4 without writer key).
2026-06-26 22:55:40 +02:00

65 lines
2.3 KiB
Python

"""L1: dual vector API key (spec D11, §5.4).
The reader (search_similar) and the writer (upsert_vector_records) use SEPARATE
API keys against the same pgvector REST endpoint, with distinct roles
(vector_reader / vector_writer). This test pins the dual-key construction and
the workstation write-guard.
"""
from nsp.cli._guards import has_vector_write_rest, require_vector_write_allowed
from nsp.config import Config, DatabaseConfig, RestConfig
from nsp.vectorstore.rest_client import VectorRestClient
def _minimal_config(**kw) -> Config:
base = dict(
database=DatabaseConfig(database="db", schema="dw", user="u", password="p"),
)
base.update(kw)
return Config(**base)
def test_reader_and_writer_use_separate_keys():
reader = VectorRestClient(RestConfig(base_url="https://v/", api_key="K-READ"))
writer = VectorRestClient(RestConfig(base_url="https://v/", api_key="K-WRITE"))
assert reader.api_key == "K-READ"
assert writer.api_key == "K-WRITE"
def test_has_vector_write_rest_false_for_empty_key():
cfg = _minimal_config(vector_write_rest=RestConfig(base_url="x", api_key=" "))
assert has_vector_write_rest(cfg) is False
def test_has_vector_write_rest_false_when_absent():
cfg = _minimal_config()
assert has_vector_write_rest(cfg) is False
def test_has_vector_write_rest_true_when_key_present():
cfg = _minimal_config(vector_write_rest=RestConfig(base_url="x", api_key="K-WRITE"))
assert has_vector_write_rest(cfg) is True
def test_require_vector_write_allowed_blocks_workstation_without_key():
import typer
cfg = _minimal_config(profile="workstation") # no vector_write_rest
try:
require_vector_write_allowed(cfg, "memory save-one")
assert False, "should have exited with code 4"
except typer.Exit as e:
assert e.exit_code == 4
def test_require_vector_write_allowed_allows_workstation_with_key():
cfg = _minimal_config(
profile="workstation",
vector_write_rest=RestConfig(base_url="x", api_key="K-WRITE"),
)
require_vector_write_allowed(cfg, "memory save-one") # no exit -> ok
def test_require_vector_write_allowed_allows_server_without_key():
# server profile can use direct vectordb; the REST write guard does not apply.
cfg = _minimal_config(profile="server")
require_vector_write_allowed(cfg, "memory save-one") # no exit -> ok