fix(pi): resolve packaged proxy token lazily

This commit is contained in:
brother7 committed 2026-08-24 21:41:29 +08:00
1 parent fa510c4976
commit f902edefd0
13 files changed
+934 -30

No files matched your search

+64 -2
View File
@@ -1,9 +1,9 @@
// @vitest-environment node
import { mkdtemp, rm } from 'node:fs/promises';
import { mkdtemp, readFile, rm } from 'node:fs/promises';
import { tmpdir } from 'node:os';
import path from 'node:path';
import { afterEach, describe, expect, it } from 'vitest';
import { afterEach, describe, expect, it, vi } from 'vitest';
import { createCodingProjectAgent } from '../../electron/coding-projects/project-config';
import {
createCodingProjectStore,
@@ -152,4 +152,66 @@ describe('managed Pi subagent child opener', () => {
expect(processes.every(({ stopped }) => stopped)).toBe(true);
await host.close();
});
it('reads the current local-proxy credential for every ephemeral child open', async () => {
const root = await mkdtemp(path.join(tmpdir(), 'makelore-pi-proxy-child-'));
roots.push(root);
const projectPath = path.join(root, 'project');
const userDataDir = path.join(root, 'user-data');
const projectStore = createCodingProjectStore(createMemoryCodingProjectStorage(), {
createId: () => 'project-proxy', now: () => NOW,
});
await createLocalCodingProject({ projectPath, now: NOW }, projectStore);
await createCodingProjectAgent(projectPath, {
id: 'agent-proxy', avatarId: 'avatar-01', roleName: 'Reviewer', name: 'Proxy Agent',
model: { accountId: 'account-proxy', modelId: 'model-proxy', thinkingLevel: 'medium' },
modelResolution: 'resolved',
responsibility: { mission: 'Review', owns: [], boundaries: [], collaborators: [], principles: [] },
}, { now: NOW });
const account: ProviderAccount = {
id: 'account-proxy', vendorId: 'custom', label: 'Proxy account', authMode: 'api_key',
apiProtocol: 'openai-completions', baseUrl: 'http://127.0.0.1:43123/api/ai-proxy/v1',
model: 'model-proxy', enabled: true, isDefault: true, createdAt: NOW, updatedAt: NOW,
metadata: { worksSquareCredentialMode: 'works_square_ai_gateway_proxy' },
};
const host = new PiManagedExtensionHost();
const processOptions: PiWorkerProcessOptions[] = [];
let currentToken = 'host-token-child-first';
const getLocalProxyCredential = vi.fn(async () => currentToken);
const opener = createPiManagedSubagentChildOpener({
projectStore,
executablePath: 'electron.exe',
cliPath: 'pi-cli.js',
userDataDir,
bundledSkillsDir: path.resolve('resources/coding-skills'),
extensionHost: host,
loadProviderInput: async () => ({ accounts: [account], modelSummaries: [] }),
resolveCredential: vi.fn(async () => 'stale-secret-store-token'),
getRevision: () => ({ provider: 1, resources: 1 }),
getLocalProxyCredential,
createProcess: (options) => {
processOptions.push(options);
return new FakeChildProcess();
},
});
const identity = {
conversationId: 'conversation-proxy', workerGeneration: 1, runId: 'run-proxy',
projectId: 'project-proxy', dispatchId: 'dispatch-proxy', agentId: 'agent-proxy',
};
const first = await opener({ ...identity, taskId: 'task-child-first', toolProfile: 'read-only' });
currentToken = 'host-token-child-second';
const second = await opener({ ...identity, taskId: 'task-child-second', toolProfile: 'coding' });
expect(getLocalProxyCredential).toHaveBeenCalledTimes(2);
expect(processOptions.map(({ env }) => Object.values(env ?? {}).find((value) => value.startsWith('host-token-'))))
.toEqual(['host-token-child-first', 'host-token-child-second']);
expect(JSON.stringify(processOptions.map(({ additionalArgs }) => additionalArgs))).not.toContain('host-token-');
expect(await readFile(path.join(userDataDir, 'coding-runtime', 'pi', 'config', 'models.json'), 'utf8'))
.not.toContain('host-token-');
await first.stop();
await second.stop();
await host.close();
});
});