Files
ThothII/harness/nsp/cli/_guards.py
T
marcopan 796a39d893 feat(harness): port vectorstore dual-key + reader RPC (D11, §5.4)
Ports vectorstore/{rest_client,rest_writer,store,reader,embeddings,records},
evidence/model (leaf dep of records), and cli/_guards (require_vector_write_allowed
workstation write-guard). Renamed psdwp3->nsp, verbatim.

VectorRestClient gains an api_key property so reader/writer clients carry their
distinct keys visibly (spec D11: vector_reader / vector_writer on the same endpoint).

scripts/create_vector_reader_rpc.sql is NEW: the reader RPCs (search_similar,
list_tables) lived server-side in Supabase and were never versioned. Authored now
mirroring the writer allowlist pattern (table allowlist, security definer, revoke
from anon/authenticated, grant to vector_reader only). Writer RPC ported verbatim.

L1: test_vector_dual_key (7 tests) pins the dual-key construction + the workstation
write-guard (exit 4 without writer key).
2026-06-26 22:55:40 +02:00

41 lines
1.7 KiB
Python

import typer
def require_server_profile(cfg, command: str) -> None:
"""Rifiuta i comandi di scrittura vectordb sul profilo workstation (exit 4).
Va chiamata subito dopo il caricamento della config e PRIMA di aprire qualunque
connessione, cosi' su workstation non si tenta mai la connessione diretta al vectordb.
"""
if cfg.profile == "workstation":
typer.secho(
f"ERRORE: `{command}` e' un comando solo-server (scrive nel vectordb centrale). "
f"Sulla postazione locale (profile: workstation) il vectordb si LEGGE via REST, "
f"non si ricostruisce. Esegui questo comando sul server di produzione "
f"(profile: server).",
fg=typer.colors.RED, err=True,
)
raise typer.Exit(code=4)
def has_vector_write_rest(cfg) -> bool:
return cfg.vector_write_rest is not None and bool(cfg.vector_write_rest.api_key.strip())
def require_vector_write_allowed(cfg, command: str) -> None:
"""Permette scritture vectordb da workstation solo con API key REST writer.
Senza `vector_write_rest`, la workstation resta read-only e i comandi di indexing sono
eseguibili solo sul server con connessione diretta al vectordb.
"""
if cfg.profile == "workstation" and not has_vector_write_rest(cfg):
typer.secho(
f"ERRORE: `{command}` e' un comando solo-server se manca `vector_write_rest`: "
f"scrive nel vectordb centrale. Sulla postazione locale serve la sezione "
f"`vector_write_rest` con una API key di upsert; in alternativa esegui il "
f"comando sul server di produzione (profile: server).",
fg=typer.colors.RED, err=True,
)
raise typer.Exit(code=4)