5a581c78a2
Build / build (push) Has been cancelled
Docker / build (push) Has been cancelled
Lint / ruff (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.11) (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.12) (push) Has been cancelled
Test / pytest (windows-latest, 3.11) (push) Has been cancelled
Test / pytest (windows-latest, 3.12) (push) Has been cancelled
Introduce provider, model, and invocation contracts with encrypted configuration persistence. Add web runtime fencing, route fallback, recovery middleware, workspace scoping, and comprehensive tests.
49 lines
1.8 KiB
Python
49 lines
1.8 KiB
Python
from __future__ import annotations
|
|
|
|
import pytest
|
|
|
|
from EvoScientist.llm.contracts import EvoRuntimeError
|
|
from EvoScientist.llm.model_config import SecretReference
|
|
from EvoScientist.llm.secret_store import EncryptedModelSecretStore
|
|
|
|
|
|
def test_secret_store_versions_masks_and_resolves(tmp_path):
|
|
store = EncryptedModelSecretStore(
|
|
tmp_path / "secrets.sqlite",
|
|
master_secret="test-master-secret-that-is-at-least-32-bytes",
|
|
)
|
|
|
|
first = store.put("dashscope/primary", "sk-first-secret-value", created_by="admin")
|
|
second = store.put(
|
|
"dashscope/primary", "sk-second-secret-value", created_by="admin"
|
|
)
|
|
|
|
assert first.version == 1
|
|
assert second.version == 2
|
|
assert "second-secret" not in second.masked_value
|
|
assert second.ref == "secret://dashscope/primary#2"
|
|
metadata = store.list_metadata()
|
|
assert [item.version for item in metadata] == [2, 1]
|
|
resolved = store.resolve(SecretReference(second.ref, second.version))
|
|
assert resolved.value == "sk-second-secret-value"
|
|
assert resolved.authoritative_version == "2"
|
|
|
|
|
|
def test_secret_store_rejects_wrong_revision_and_master_key(tmp_path):
|
|
path = tmp_path / "secrets.sqlite"
|
|
store = EncryptedModelSecretStore(
|
|
path,
|
|
master_secret="test-master-secret-that-is-at-least-32-bytes",
|
|
)
|
|
item = store.put("openai/primary", "sk-secret", created_by="admin")
|
|
|
|
with pytest.raises(EvoRuntimeError, match="ROUTE_SECRET_UNAVAILABLE"):
|
|
store.resolve(SecretReference(item.ref, item.version + 1))
|
|
|
|
wrong_key = EncryptedModelSecretStore(
|
|
path,
|
|
master_secret="different-master-secret-that-is-at-least-32-bytes",
|
|
)
|
|
with pytest.raises(EvoRuntimeError, match="ROUTE_SECRET_UNAVAILABLE"):
|
|
wrong_key.resolve(SecretReference(item.ref, item.version))
|