feat: add privacy-safe server diagnostics
This commit is contained in:
1 parent
2360506607
commit
a3963ad0f6
27 files changed
+1305
-112
No files matched your search
@@ -5,6 +5,7 @@ import { sha256Bytes } from '../src/crypto.js';
|
||||
import {
|
||||
InputAttachmentError,
|
||||
decodeInlineInputAttachment,
|
||||
downloadAgentBusInputAttachment,
|
||||
isPrivateOrReservedIp,
|
||||
parseAgentBusInputAttachment,
|
||||
validateAgentBusAttachmentUrl
|
||||
@@ -80,6 +81,23 @@ test('AgentBus attachment metadata is normalized without exposing URL credential
|
||||
assert.equal(reference.sha256, 'a'.repeat(64));
|
||||
});
|
||||
|
||||
test('AgentBus attachment diagnostics expose stages and codes without URL data', async () => {
|
||||
const events: Array<{ event: string; metadata: Record<string, unknown> }> = [];
|
||||
await assert.rejects(
|
||||
() => downloadAgentBusInputAttachment({
|
||||
name: 'synthetic.xls',
|
||||
contentType: 'application/vnd.ms-excel',
|
||||
size: 128,
|
||||
url: 'https://127.0.0.1/private-roster.xls?token=secret'
|
||||
}, 1_000, (event, metadata) => events.push({ event, metadata })),
|
||||
(error: unknown) => error instanceof InputAttachmentError
|
||||
&& error.code === 'roster_attachment_url_unsafe'
|
||||
);
|
||||
assert.deepEqual(events.map((event) => event.event), ['download_started', 'download_failed']);
|
||||
assert.equal(events[1].metadata.error_code, 'roster_attachment_url_unsafe');
|
||||
assert.doesNotMatch(JSON.stringify(events), /127\.0\.0\.1|private-roster|token|secret/u);
|
||||
});
|
||||
|
||||
test('input attachment migration stores only encrypted normalized data and waiting-task index', async () => {
|
||||
const sql = await readFile(new URL('../migrations/014_task_input_attachments.sql', import.meta.url), 'utf8');
|
||||
assert.match(sql, /CREATE TABLE IF NOT EXISTS task_input_attachments/);
|
||||
|
||||
Reference in new issue
Block a user