feat: add fail-closed Hub access profile foundation
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
df39fd5f43
commit
3e386147fd
35 changed files with 2009 additions and 195 deletions
|
|
@ -69,3 +69,34 @@ def test_repository_navigation_mcp_tool_exposes_all_six_facets() -> None:
|
|||
"business_stake",
|
||||
"business_mechanic",
|
||||
} <= set(schema["properties"])
|
||||
|
||||
|
||||
def test_mcp_credentials_are_per_invocation_and_redirects_do_not_relay_them():
|
||||
from contextvars import ContextVar
|
||||
import pytest
|
||||
credential = ContextVar('hub_credential')
|
||||
server = HubCoreMCPServer(name='secure', api_base='https://hub.example', register_tools=False,
|
||||
token_provider=credential.get, require_credentials=True)
|
||||
async def invoke(token):
|
||||
credential.set(token)
|
||||
await asyncio.sleep(0)
|
||||
with server._client() as client:
|
||||
assert client.headers['authorization'] == f'Bearer {token}'
|
||||
assert not client.follow_redirects
|
||||
async def run():
|
||||
await asyncio.gather(invoke('caller-a'), invoke('caller-b'))
|
||||
asyncio.run(run())
|
||||
with pytest.raises(LookupError):
|
||||
server._client()
|
||||
missing = HubCoreMCPServer(name='missing', api_base='https://hub.example', register_tools=False,
|
||||
require_credentials=True)
|
||||
with pytest.raises(ValueError, match='current Hub credential'):
|
||||
missing._client()
|
||||
|
||||
|
||||
def test_mcp_provider_errors_do_not_echo_credentials():
|
||||
def failed_provider():
|
||||
raise RuntimeError('secret-value-must-not-escape')
|
||||
server = HubCoreMCPServer(name='failing', api_base='https://hub.example', register_tools=False,
|
||||
token_provider=failed_provider, require_credentials=True)
|
||||
assert server._get('/docs') == {'error': 'Request failed'}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue