Files
pi-extensions/packages/pi-permission-ai-judge/test/review.test.ts
T
SikongJueluo 99e953664d refactor(ai-judge): group src modules into domain directories
- move evidence.ts and conversation.ts into evidence/ as bash.ts and conversation.ts
- move prompt.ts and model.ts into judge/
- move highrisk.ts and judge.ts into authority/, renaming judge.ts to enforce.ts to avoid clashing with the judge/ directory
- move review.ts and audit.ts into telemetry/
- move config.ts and catalog.ts into config/ as judge.ts and catalog.ts
- rewrite static and dynamic imports across src, tools, and tests to the new paths
- fix the models-catalog.json relative URL broken by the move (caught by fallow unresolved-import)
- update the PIEXTENSIO-12 module map in the ADR to the new paths
- add editorconfig for 4-space ts indentation
2026-08-22 01:34:29 +08:00

80 lines
2.9 KiB
TypeScript

import { describe, expect, it } from "vitest";
import { createReviewSink, type ReviewSinkDeps } from "../src/telemetry/review";
import type { AuthorizerLog } from "@gotgenes/pi-permission-system";
function fakeLog(): AuthorizerLog & {
reviews: Array<{ event: string; details: Record<string, unknown> }>;
debugs: Array<{ event: string; details?: Record<string, unknown> }>;
} {
const reviews: Array<{ event: string; details: Record<string, unknown> }> = [];
const debugs: Array<{ event: string; details?: Record<string, unknown> }> = [];
return {
reviews,
debugs,
review: (event, details = {}) => reviews.push({ event, details }),
debug: (event, details) => debugs.push({ event, details }),
};
}
describe("createReviewSink — telemetry health", () => {
it("marks the runtime disabled when the review log toggle is off", () => {
const log = fakeLog();
const deps: ReviewSinkDeps = { log, reviewLogEnabled: false };
const sink = createReviewSink(deps);
expect(sink.health()).toBe("disabled");
});
it("reports healthy when the toggle is on", () => {
const sink = createReviewSink({ log: fakeLog(), reviewLogEnabled: true });
expect(sink.health()).toBe("healthy");
});
});
describe("createReviewSink — privacy denylist at the sink", () => {
it("strips keys matching forbidden patterns before delegation", () => {
const log = fakeLog();
const sink = createReviewSink({ log, reviewLogEnabled: true });
sink.review("ai_bash_judge.result", {
requestId: "req-1",
apiToken: "leak",
sshKey: "leak",
secrets: "leak",
password: "leak",
credentials: "leak",
outputUsage: 10,
});
expect(log.reviews).toEqual([
{
event: "ai_bash_judge.result",
details: { requestId: "req-1", outputUsage: 10 },
},
]);
});
it("passes metadata-only events through unchanged", () => {
const log = fakeLog();
const sink = createReviewSink({ log, reviewLogEnabled: true });
sink.review("ai_bash_judge.result", {
schemaVersion: 1,
requestId: "req-1",
judgeRuntimeId: "abc",
mode: "shadow",
resultKind: "judgment",
});
expect(log.reviews[0]?.details).toEqual({
schemaVersion: 1,
requestId: "req-1",
judgeRuntimeId: "abc",
mode: "shadow",
resultKind: "judgment",
});
});
it("delegates debug writes without stripping", () => {
const log = fakeLog();
const sink = createReviewSink({ log, reviewLogEnabled: true });
sink.debug("ai_bash_judge.exception");
expect(log.debugs).toEqual([{ event: "ai_bash_judge.exception" }]);
});
});