feat: add fail-closed Hub access profile foundation
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 11:44:50 +02:00
parent df39fd5f43
commit 3e386147fd
35 changed files with 2009 additions and 195 deletions

View file

@ -69,3 +69,34 @@ def test_repository_navigation_mcp_tool_exposes_all_six_facets() -> None:
"business_stake",
"business_mechanic",
} <= set(schema["properties"])
def test_mcp_credentials_are_per_invocation_and_redirects_do_not_relay_them():
from contextvars import ContextVar
import pytest
credential = ContextVar('hub_credential')
server = HubCoreMCPServer(name='secure', api_base='https://hub.example', register_tools=False,
token_provider=credential.get, require_credentials=True)
async def invoke(token):
credential.set(token)
await asyncio.sleep(0)
with server._client() as client:
assert client.headers['authorization'] == f'Bearer {token}'
assert not client.follow_redirects
async def run():
await asyncio.gather(invoke('caller-a'), invoke('caller-b'))
asyncio.run(run())
with pytest.raises(LookupError):
server._client()
missing = HubCoreMCPServer(name='missing', api_base='https://hub.example', register_tools=False,
require_credentials=True)
with pytest.raises(ValueError, match='current Hub credential'):
missing._client()
def test_mcp_provider_errors_do_not_echo_credentials():
def failed_provider():
raise RuntimeError('secret-value-must-not-escape')
server = HubCoreMCPServer(name='failing', api_base='https://hub.example', register_tools=False,
token_provider=failed_provider, require_credentials=True)
assert server._get('/docs') == {'error': 'Request failed'}