Scope workspace roots per account
This commit is contained in:
@@ -2,6 +2,7 @@ from __future__ import annotations
|
||||
|
||||
import base64
|
||||
import hashlib
|
||||
import json
|
||||
import os
|
||||
import tempfile
|
||||
import unittest
|
||||
@@ -25,6 +26,10 @@ class KnowledgeIndexTests(unittest.TestCase):
|
||||
def setUp(self) -> None:
|
||||
self.temp = tempfile.TemporaryDirectory()
|
||||
self.base = Path(self.temp.name)
|
||||
self.workspace_environment = patch.dict(
|
||||
os.environ, {"SOVEREIGNAI_ALLOWED_WORKSPACES": str(self.base)}
|
||||
)
|
||||
self.workspace_environment.start()
|
||||
self.database = self.base / "knowledge.sqlite3"
|
||||
self.workspace = self.base / "project"
|
||||
self.workspace.mkdir()
|
||||
@@ -34,6 +39,7 @@ class KnowledgeIndexTests(unittest.TestCase):
|
||||
knowledge.initialize()
|
||||
|
||||
def tearDown(self) -> None:
|
||||
self.workspace_environment.stop()
|
||||
self.temp.cleanup()
|
||||
|
||||
def _index(self, text: str, root: Path | None = None) -> None:
|
||||
@@ -167,11 +173,14 @@ class KnowledgeIndexTests(unittest.TestCase):
|
||||
def test_api_knowledge_index_isolated_between_account_sessions(self) -> None:
|
||||
marker = "OwnerScopedKnowledgeMarker"
|
||||
(self.workspace / "private.md").write_text(marker, encoding="utf-8")
|
||||
(self.other_workspace / "private.md").write_text(marker, encoding="utf-8")
|
||||
first_email = f"{uuid4().hex}@example.test"
|
||||
second_email = f"{uuid4().hex}@example.test"
|
||||
owner_id = auth.create_account(
|
||||
f"{uuid4().hex}@example.test", "account one secure passphrase"
|
||||
first_email, "account one secure passphrase"
|
||||
)
|
||||
other_id = auth.create_account(
|
||||
f"{uuid4().hex}@example.test", "account two secure passphrase"
|
||||
second_email, "account two secure passphrase"
|
||||
)
|
||||
self.addCleanup(self._delete_test_users, owner_id, other_id)
|
||||
owner_token, _ = auth.issue_session(owner_id)
|
||||
@@ -182,20 +191,29 @@ class KnowledgeIndexTests(unittest.TestCase):
|
||||
other_client = TestClient(
|
||||
app, headers={"Authorization": f"Bearer {other_token}"}
|
||||
)
|
||||
payload = {
|
||||
"workspace_path": str(self.workspace),
|
||||
"files": ["private.md"],
|
||||
}
|
||||
|
||||
indexed = owner_client.post("/v1/agent/knowledge/index", json=payload)
|
||||
owner_results = owner_client.post(
|
||||
"/v1/agent/knowledge/search",
|
||||
json={"workspace_path": str(self.workspace), "task": marker},
|
||||
)
|
||||
other_results = other_client.post(
|
||||
"/v1/agent/knowledge/search",
|
||||
json={"workspace_path": str(self.workspace), "task": marker},
|
||||
)
|
||||
with patch.dict(
|
||||
os.environ,
|
||||
{
|
||||
"SOVEREIGNAI_USER_WORKSPACES": json.dumps(
|
||||
{
|
||||
first_email: [str(self.workspace)],
|
||||
second_email: [str(self.other_workspace)],
|
||||
}
|
||||
),
|
||||
},
|
||||
):
|
||||
indexed = owner_client.post(
|
||||
"/v1/agent/knowledge/index",
|
||||
json={"workspace_path": str(self.workspace), "files": ["private.md"]},
|
||||
)
|
||||
owner_results = owner_client.post(
|
||||
"/v1/agent/knowledge/search",
|
||||
json={"workspace_path": str(self.workspace), "task": marker},
|
||||
)
|
||||
other_results = other_client.post(
|
||||
"/v1/agent/knowledge/search",
|
||||
json={"workspace_path": str(self.other_workspace), "task": marker},
|
||||
)
|
||||
|
||||
self.assertEqual(indexed.status_code, 200, indexed.text)
|
||||
self.assertEqual(owner_results.status_code, 200, owner_results.text)
|
||||
@@ -207,6 +225,7 @@ class KnowledgeIndexTests(unittest.TestCase):
|
||||
workspace_path=self.workspace,
|
||||
relative_path="private.md",
|
||||
)
|
||||
(self.other_workspace / "private.md").unlink(missing_ok=True)
|
||||
|
||||
@staticmethod
|
||||
def _delete_test_users(*user_ids: str) -> None:
|
||||
|
||||
Reference in New Issue
Block a user