feat: add scoped model runtime configuration
Build / build (push) Has been cancelled
Docker / build (push) Has been cancelled
Lint / ruff (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.11) (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.12) (push) Has been cancelled
Test / pytest (windows-latest, 3.11) (push) Has been cancelled
Test / pytest (windows-latest, 3.12) (push) Has been cancelled

Introduce provider, model, and invocation contracts with encrypted configuration persistence. Add web runtime fencing, route fallback, recovery middleware, workspace scoping, and comprehensive tests.
This commit is contained in:
m4
2026-08-14 22:03:04 +08:00
parent 3ce5614254
commit 5a581c78a2
97 changed files with 26670 additions and 454 deletions
+54
View File
@@ -6,7 +6,9 @@ langgraph dev.
from __future__ import annotations
from unittest.mock import patch
from uuid import uuid4
import pytest
from starlette.testclient import TestClient
from EvoScientist.config import EvoScientistConfig
@@ -161,3 +163,55 @@ def test_ollama_discovery_skipped_when_base_url_absent():
{"name": n, "model_id": m, "provider": p}
for n, m, p in list_models_by_provider()
]
def test_recoverable_capabilities_include_resume_and_workspace(monkeypatch):
monkeypatch.setenv("EVOSCIENTIST_DEPLOY_MODE", "full")
response = client.get("/api/ai4sci/recoverable-runs/capabilities")
assert response.status_code == 200
body = response.json()
assert body["interrupt_resume"] is True
assert body["pending_interrupt_state"] is True
assert body["workspace_scope_v1"] is True
def test_recoverable_capabilities_fail_closed_without_full_deploy(monkeypatch):
monkeypatch.delenv("EVOSCIENTIST_DEPLOY_MODE", raising=False)
response = client.get("/api/ai4sci/recoverable-runs/capabilities")
assert response.status_code == 200
assert response.json()["workspace_scope_v1"] is False
def test_recoverable_resume_rejects_human_input(monkeypatch):
run_id = str(uuid4())
response = client.post(
"/api/ai4sci/recoverable-runs/create",
headers={"x-auth-scheme": "langsmith"},
json={
"operation": "resume",
"thread_id": str(uuid4()),
"run_id": run_id,
"run_request_id": run_id,
"request_hash": "a" * 64,
"assistant_id": "EvoScientist",
"input": {"messages": [{"role": "user", "content": "continue"}]},
"command": {"resume": {"decisions": [{"type": "approve"}]}},
},
)
assert response.status_code == 400
assert response.json()["code"] == "INVALID_RESUME_REQUEST"
def test_workspace_scope_routes_require_service_token():
response = client.post(
"/internal/workspace-scopes/provision",
json={"thread_id": str(uuid4())},
)
assert response.status_code == 401
def test_workspace_materialize_rejects_path_escape():
from EvoScientist.langgraph_dev.http import _materialize_target
with pytest.raises(ValueError, match="uploads"):
_materialize_target(str(uuid4()), "../secret.txt")