mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: make sure creds are always masked (#24241)
## Summary Adds a `sanitizeCredentialHint` safety check in the db-to-SDK conversion layer to ensure credential hints are always masked before being exposed in the API. Also adds `credential_kind` and `credential_hint` assertions to the session threads API test.
This commit is contained in:
@@ -1836,10 +1836,12 @@ func TestAIBridgeGetSessionThreads(t *testing.T) {
|
||||
now := dbtime.Now()
|
||||
endedAt := now.Add(time.Minute)
|
||||
i1 := dbgen.AIBridgeInterception(t, db, database.InsertAIBridgeInterceptionParams{
|
||||
InitiatorID: firstUser.UserID,
|
||||
Provider: "openai",
|
||||
Model: "gpt-4",
|
||||
StartedAt: now,
|
||||
InitiatorID: firstUser.UserID,
|
||||
Provider: "openai",
|
||||
Model: "gpt-4",
|
||||
StartedAt: now,
|
||||
CredentialKind: database.CredentialKindByok,
|
||||
CredentialHint: "sk-a...efgh",
|
||||
}, &endedAt)
|
||||
|
||||
// When no client session ID is set, the interception ID becomes the session identifier.
|
||||
@@ -1847,6 +1849,8 @@ func TestAIBridgeGetSessionThreads(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
require.Equal(t, i1.ID.String(), res.ID)
|
||||
require.Len(t, res.Threads, 1)
|
||||
require.Equal(t, "byok", res.Threads[0].CredentialKind)
|
||||
require.Equal(t, "sk-a...efgh", res.Threads[0].CredentialHint)
|
||||
})
|
||||
|
||||
t.Run("ThreadsWithAgenticActions", func(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user