254 lines
10 KiB
TypeScript
254 lines
10 KiB
TypeScript
import { expect, test } from "vitest";
|
|
import { mkdtempSync, mkdirSync, rmSync, writeFileSync } from "node:fs";
|
|
import { tmpdir } from "node:os";
|
|
import { join } from "node:path";
|
|
import { buildInstallationContract, renderWorkspaceDocs } from "../src/workspaces/contracts.js";
|
|
import { type CanonicalWorkspace, parseWorkspaceYaml } from "../src/workspaces/schema.js";
|
|
|
|
const workspaceV4 = parseWorkspaceYaml(`workspace:
|
|
schema_version: 4
|
|
id: psd-clinical
|
|
name: Policlinico San Donato
|
|
language: it
|
|
dwh:
|
|
engine: postgres
|
|
database: postgres
|
|
schema: datawarehouse
|
|
supported_transports: [postgres_direct, rest_api, ssh_tunnel]
|
|
`);
|
|
|
|
test("workspace-v4 installation contracts expose only DWH bindings and no semantic variables", () => {
|
|
const contract = buildInstallationContract(workspaceV4);
|
|
const names = contract.variables.map((variable) => variable.name);
|
|
const docs = renderWorkspaceDocs(workspaceV4);
|
|
|
|
expect(contract.workspaceId).toBe("psd-clinical");
|
|
expect(contract.namespace).toBe("PSD_CLINICAL");
|
|
expect(contract.variables.every((variable) => variable.role === "DWH")).toBe(true);
|
|
expect(names).toContain("THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE");
|
|
expect(names.some((name) => /_VECTOR_|_EMBEDDING_/.test(name))).toBe(false);
|
|
expect(docs.envExample).not.toContain("_VECTOR_");
|
|
expect(docs.markdown).toContain("Configurazione dell'installazione");
|
|
expect(docs.markdown).not.toContain("Vector store");
|
|
expect(docs.markdown).not.toContain("Embedding service");
|
|
});
|
|
|
|
test.each([
|
|
["postgres_direct", "HOST", "BASE_URL"],
|
|
["rest_api", "BASE_URL", "HOST"],
|
|
["ssh_tunnel", "SSH_PRIVATE_KEY_FILE", "BASE_URL"],
|
|
] as const)("documents only the DWH fields for %s", (transport, included, excluded) => {
|
|
const descriptor = parseWorkspaceYaml(renderWorkspaceWithoutEvidence()
|
|
.replace("[postgres_direct]", `[${transport}]`));
|
|
const variables = buildInstallationContract(descriptor).variables;
|
|
expect(variables.find(({ suffix }) => suffix === included)?.transports).toEqual([transport]);
|
|
expect(variables.some(({ suffix }) => suffix === excluded)).toBe(false);
|
|
expect(variables.filter(({ secret }) => secret).every(({ name }) => name.endsWith("_FILE")))
|
|
.toBe(true);
|
|
});
|
|
|
|
test("validates public contract and documentation inputs at runtime", () => {
|
|
const unsafeWorkspace = {
|
|
...workspaceV4,
|
|
workspace: { ...workspaceV4.workspace, id: "psd\nclinical" },
|
|
} as CanonicalWorkspace;
|
|
|
|
expect(() => buildInstallationContract(unsafeWorkspace)).toThrow(/id/i);
|
|
expect(() => renderWorkspaceDocs(unsafeWorkspace)).toThrow(/id/i);
|
|
});
|
|
|
|
test("v4 installation contract omits external vector and embedding bindings", () => {
|
|
const contract = buildInstallationContract(workspaceV4);
|
|
const names = contract.variables.map((variable) => variable.name);
|
|
|
|
expect(names).toContain("THT_WS_PSD_CLINICAL_DWH_TRANSPORT");
|
|
expect(names.some((name) => name.includes("_VECTOR_"))).toBe(false);
|
|
expect(names.some((name) => name.includes("_EMBEDDING_"))).toBe(false);
|
|
expect(renderWorkspaceDocs(workspaceV4).markdown).not.toContain("Embedding service");
|
|
});
|
|
|
|
|
|
test.each([
|
|
{
|
|
mode: "signed HTTP",
|
|
source: {
|
|
type: "http", uris: ["https://evidence.example.test/guide.md"],
|
|
authentication: "signed_urls_file",
|
|
},
|
|
expected: ["THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE"],
|
|
},
|
|
{
|
|
mode: "static S3",
|
|
source: { type: "s3", uri: "s3://clinical-evidence/published/", credentials: "static_files" },
|
|
expected: [
|
|
"THT_WS_PSD_CLINICAL_EVIDENCE_ACCESS_KEY_FILE",
|
|
"THT_WS_PSD_CLINICAL_EVIDENCE_SECRET_KEY_FILE",
|
|
"THT_WS_PSD_CLINICAL_EVIDENCE_SESSION_TOKEN_FILE",
|
|
],
|
|
},
|
|
])("generates source-specific $mode Evidence file bindings", ({ source, expected }) => {
|
|
const descriptor = parseWorkspaceYaml(`${renderWorkspaceWithoutEvidence()}evidence:\n source: ${JSON.stringify(source)}\n`);
|
|
const contract = buildInstallationContract(descriptor);
|
|
const evidence = contract.variables.filter((variable) => variable.role === "EVIDENCE");
|
|
|
|
expect(contract.namespace).toBe("PSD_CLINICAL");
|
|
expect(evidence.map((variable) => variable.name)).toEqual(expected);
|
|
expect(evidence.every((variable) => variable.secret)).toBe(true);
|
|
expect(renderWorkspaceDocs(descriptor).envExample).not.toContain("CANARY-SECRET");
|
|
});
|
|
|
|
test.each([
|
|
{ type: "filesystem", uri: "psd-clinical/evidence" },
|
|
{ type: "http", uris: ["https://evidence.example.test/guide.md"], authentication: "none" },
|
|
{ type: "s3", uri: "s3://clinical-evidence/published/", credentials: "ambient" },
|
|
])("omits Evidence installation variables for $type modes without file credentials", (source) => {
|
|
const descriptor = parseWorkspaceYaml(`${renderWorkspaceWithoutEvidence()}evidence:\n source: ${JSON.stringify(source)}\n`);
|
|
expect(buildInstallationContract(descriptor).variables.some((variable) => variable.role === "EVIDENCE"))
|
|
.toBe(false);
|
|
});
|
|
|
|
function renderWorkspaceWithoutEvidence(): string {
|
|
return `workspace:
|
|
schema_version: 4
|
|
id: psd-clinical
|
|
name: Policlinico San Donato
|
|
language: it
|
|
dwh:
|
|
engine: postgres
|
|
database: postgres
|
|
schema: datawarehouse
|
|
supported_transports: [postgres_direct]
|
|
`;
|
|
}
|
|
|
|
|
|
const evidenceSources = [
|
|
{
|
|
label: "filesystem",
|
|
source: { type: "filesystem", uri: "psd-clinical/evidence" },
|
|
variables: [],
|
|
},
|
|
{
|
|
label: "HTTP signed URL file",
|
|
source: {
|
|
type: "http",
|
|
uris: ["https://evidence.example.test/guide.md", "http://public.example.test/policy.pdf"],
|
|
authentication: "signed_urls_file",
|
|
},
|
|
variables: ["THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE"],
|
|
},
|
|
{
|
|
label: "S3 static files",
|
|
source: {
|
|
type: "s3", uri: "s3://clinical-evidence/published/", credentials: "static_files",
|
|
},
|
|
variables: [
|
|
"THT_WS_PSD_CLINICAL_EVIDENCE_ACCESS_KEY_FILE",
|
|
"THT_WS_PSD_CLINICAL_EVIDENCE_SECRET_KEY_FILE",
|
|
"THT_WS_PSD_CLINICAL_EVIDENCE_SESSION_TOKEN_FILE",
|
|
],
|
|
},
|
|
] as const;
|
|
|
|
test.each(evidenceSources)("renders deterministic public Evidence docs for $label", ({ source, variables }) => {
|
|
const descriptor = parseWorkspaceYaml(
|
|
`${renderWorkspaceWithoutEvidence()}evidence:\n source: ${JSON.stringify(source)}\n`,
|
|
);
|
|
const firstContract = buildInstallationContract(descriptor);
|
|
const secondContract = buildInstallationContract(descriptor);
|
|
const firstDocs = renderWorkspaceDocs(descriptor);
|
|
const secondDocs = renderWorkspaceDocs(descriptor);
|
|
|
|
expect(secondContract).toEqual(firstContract);
|
|
expect(secondDocs).toEqual(firstDocs);
|
|
expect(firstContract.variables.filter(({ role }) => role === "EVIDENCE").map(({ name }) => name))
|
|
.toEqual(variables);
|
|
expect(firstDocs.markdown).toContain("## Evidence source");
|
|
expect(firstDocs.markdown).toContain(`- Type: \`${source.type}\``);
|
|
for (const uri of "uris" in source ? source.uris : [source.uri]) {
|
|
expect(firstDocs.markdown).toContain(`\`${uri}\``);
|
|
}
|
|
expect(firstDocs.markdown).toContain("- Maximum source bytes: `10485760`");
|
|
expect(firstDocs.markdown).toContain("- Maximum chunk characters: `4000`");
|
|
expect(firstDocs.markdown).toContain("- Retained published generations: `3`");
|
|
for (const variable of variables) {
|
|
expect(firstDocs.markdown).toContain(`\`${variable}\``);
|
|
expect(firstDocs.envExample).toContain(`${variable}=`);
|
|
}
|
|
});
|
|
|
|
test("documents the S3 session token file as optional", () => {
|
|
const descriptor = parseWorkspaceYaml(
|
|
`${renderWorkspaceWithoutEvidence()}evidence:
|
|
source: { type: s3, uri: s3://clinical-evidence/published/, credentials: static_files }
|
|
`,
|
|
);
|
|
const markdown = renderWorkspaceDocs(descriptor).markdown;
|
|
const required = markdown.slice(
|
|
markdown.indexOf("- Required installation file variables:"),
|
|
markdown.indexOf("- Optional installation file variables:"),
|
|
);
|
|
const optional = markdown.slice(markdown.indexOf("- Optional installation file variables:"));
|
|
|
|
expect(required).toContain("EVIDENCE_ACCESS_KEY_FILE");
|
|
expect(required).toContain("EVIDENCE_SECRET_KEY_FILE");
|
|
expect(required).not.toContain("EVIDENCE_SESSION_TOKEN_FILE");
|
|
expect(optional).toContain("EVIDENCE_SESSION_TOKEN_FILE");
|
|
});
|
|
|
|
test("documents same-revision filesystem ownership without claiming P1 materialization", () => {
|
|
const descriptor = parseWorkspaceYaml(
|
|
`${renderWorkspaceWithoutEvidence()}evidence:\n source: { type: filesystem, uri: psd-clinical/evidence }\n`,
|
|
);
|
|
const docs = renderWorkspaceDocs(descriptor).markdown;
|
|
|
|
expect(docs).toContain("`psd-clinical/evidence`");
|
|
expect(docs).toMatch(/same Git revision/i);
|
|
expect(docs).toMatch(/P6.*materializ/i);
|
|
expect(docs).toMatch(/containment.*symlink/i);
|
|
expect(docs).toMatch(/does not include Evidence file bytes/i);
|
|
});
|
|
|
|
test.each([
|
|
{
|
|
source: { type: "http", uris: ["https://evidence.example.test/guide.md"], authentication: "none" },
|
|
expected: "No credential file is required",
|
|
},
|
|
{
|
|
source: { type: "http", uris: ["https://evidence.example.test/guide.md"], authentication: "signed_urls_file" },
|
|
expected: "signed URL file",
|
|
},
|
|
{
|
|
source: { type: "s3", uri: "s3://clinical-evidence/published/", credentials: "ambient" },
|
|
expected: "ambient credentials",
|
|
},
|
|
{
|
|
source: { type: "s3", uri: "s3://clinical-evidence/published/", credentials: "static_files" },
|
|
expected: "installation file variables",
|
|
},
|
|
])("documents $source.type credential mode without reading credential contents", ({ source, expected }) => {
|
|
const root = mkdtempSync(join(tmpdir(), "thoth-evidence-doc-secret-"));
|
|
const secrets = join(root, "secrets");
|
|
const canary = "CANARY-EVIDENCE-CREDENTIAL-DO-NOT-LEAK";
|
|
mkdirSync(secrets);
|
|
const binding = join(secrets, "credential");
|
|
writeFileSync(binding, canary);
|
|
const previous = process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE;
|
|
process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE = binding;
|
|
try {
|
|
const descriptor = parseWorkspaceYaml(
|
|
`${renderWorkspaceWithoutEvidence()}evidence:\n source: ${JSON.stringify(source)}\n`,
|
|
);
|
|
const generated = JSON.stringify({
|
|
contract: buildInstallationContract(descriptor),
|
|
docs: renderWorkspaceDocs(descriptor),
|
|
});
|
|
expect(generated).toContain(expected);
|
|
expect(generated).not.toContain(canary);
|
|
} finally {
|
|
if (previous === undefined) delete process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE;
|
|
else process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE = previous;
|
|
rmSync(root, { recursive: true, force: true });
|
|
}
|
|
});
|