diff --git a/.gitignore b/.gitignore index ae69a1f..24c743c 100644 --- a/.gitignore +++ b/.gitignore @@ -22,3 +22,4 @@ evaluations/results/ # Installed locally from an exact source lock. Upstream redistribution permission is unresolved. skills/alibabacloud-resourcecenter-search/ venv/ +.venv/ diff --git a/src/titmas_action_gate/service.py b/src/titmas_action_gate/service.py index 90d7164..df6bc08 100644 --- a/src/titmas_action_gate/service.py +++ b/src/titmas_action_gate/service.py @@ -5,6 +5,7 @@ import hashlib import hmac import json +from dataclasses import dataclass from datetime import datetime, timedelta from pathlib import Path from typing import Any @@ -20,7 +21,6 @@ from .provider import GitHubProvider from .signing import HmacRecordSigner from .store import AppendOnlyStore -from dataclasses import dataclass @dataclass(frozen=True) diff --git a/tests/test_cloud_context_mcp.py b/tests/test_cloud_context_mcp.py index 18dddb2..2ce5fd7 100644 --- a/tests/test_cloud_context_mcp.py +++ b/tests/test_cloud_context_mcp.py @@ -2,6 +2,7 @@ import json import tempfile +import typing import unittest import warnings from datetime import UTC, datetime @@ -48,8 +49,8 @@ def credentials() -> dict[str, str]: class CloudContextMcpTests(unittest.TestCase): - def test_authenticated_cloud_worker_invokes_only_typed_tool(self) -> None: - values = credentials() + @staticmethod + def _create_test_request() -> dict[str, typing.Any]: request = { "schema_version": "0.1.0", "request_id": "aar-cloud-mcp-test-001", @@ -68,7 +69,11 @@ def test_authenticated_cloud_worker_invokes_only_typed_tool(self) -> None: "idempotency_key": "cloud-mcp-test-001", } request["parameters_sha256"] = sha256_json(request["parameters"]) - scope = { + return request + + @staticmethod + def _create_test_scope() -> dict[str, typing.Any]: + return { "schema_version": "0.1.0", "run_id": "run-cloud-mcp-test-001", "correlation_id": "corr-cloud-mcp-test-001", @@ -76,7 +81,10 @@ def test_authenticated_cloud_worker_invokes_only_typed_tool(self) -> None: "repository": "joy7758/action-gate-demo", "commit": "a" * 40, } - query = { + + @staticmethod + def _create_test_query() -> dict[str, typing.Any]: + return { "schema_version": "0.1.0", "operation": "resourcecenter.search-resources", "max_results": 1, @@ -85,7 +93,10 @@ def test_authenticated_cloud_worker_invokes_only_typed_tool(self) -> None: "parameters_confirmed_by_user": True, "confirmation_ref": "confirmation:" + "a" * 64, } - cloud_credential = CloudCredentialContext( + + @staticmethod + def _create_test_cloud_credential() -> CloudCredentialContext: + return CloudCredentialContext( profile_name="not-returned-profile", permission_identity="not-returned-identity", permission_role_ref="sha256:" + "c" * 64, @@ -95,6 +106,13 @@ def test_authenticated_cloud_worker_invokes_only_typed_tool(self) -> None: same_run_policy_readback_verified=True, policy_observation_observed_at=datetime.now(UTC), ) + + def test_authenticated_cloud_worker_invokes_only_typed_tool(self) -> None: + values = credentials() + request = self._create_test_request() + scope = self._create_test_scope() + query = self._create_test_query() + cloud_credential = self._create_test_cloud_credential() with tempfile.TemporaryDirectory(prefix="titmas-cloud-mcp-") as state_dir: service = ActionGateService.demo(state_dir) runtime = NativeRuntimeMcp( diff --git a/tests/test_security_argument_injection.py b/tests/test_security_argument_injection.py index 3990256..4d8bb42 100644 --- a/tests/test_security_argument_injection.py +++ b/tests/test_security_argument_injection.py @@ -1,9 +1,8 @@ import unittest -import subprocess -from unittest.mock import patch, MagicMock +from unittest.mock import MagicMock, patch from titmas_action_gate.provider import GhCliProvider -from titmas_action_gate.errors import ActionGateError + class ProviderSecurityTests(unittest.TestCase): @patch("subprocess.run") diff --git a/tests/test_workflow.py b/tests/test_workflow.py index 61c356d..461a3bf 100644 --- a/tests/test_workflow.py +++ b/tests/test_workflow.py @@ -1,8 +1,8 @@ +import json import tempfile import unittest from pathlib import Path -import json from titmas_action_gate.workflow import validate_agentteams_template, write_demo_report @@ -83,7 +83,7 @@ def test_write_demo_report(self): self.assertEqual(result_path, output_file) self.assertTrue(output_file.exists()) - with open(output_file, "r", encoding="utf-8") as f: + with open(output_file, encoding="utf-8") as f: content = json.load(f) self.assertEqual(content, report_data) @@ -95,7 +95,7 @@ def test_write_demo_report_creates_directories(self): write_demo_report(report_data, output_file) self.assertTrue(output_file.exists()) - with open(output_file, "r", encoding="utf-8") as f: + with open(output_file, encoding="utf-8") as f: content = json.load(f) self.assertEqual(content, report_data)