fix(xai): fail closed in xai_http.get_env_value — honor get_secret's verdict
Salvaged from #56982 (@rayjun): the live piece of the PR. The
hermes_cli/config.py get_env_value scope-honoring change and its
test_env_load_cache.py tests were already merged via ed1170cd8b
(#76462) and are dropped here.
tools/xai_http.py::get_env_value wrapped the scope-aware
hermes_cli.config.get_env_value in except Exception + a raw os.environ
fallback — swallowing UnscopedSecretError and borrowing the process
env, so a multiplexed xAI credential read could silently pick up
another profile's XAI_API_KEY. Narrow the except to ImportError (the
only legitimate degraded case) so get_secret's verdict propagates: an
unscoped multiplexed read fails closed, and a scoped miss returns the
default instead of the foreign environ value.
Co-authored-by: rayjun <rayjun0412@gmail.com>
This commit is contained in:
57
tests/tools/test_xai_http_credentials.py
Normal file
57
tests/tools/test_xai_http_credentials.py
Normal file
@@ -0,0 +1,57 @@
|
||||
import pytest
|
||||
|
||||
|
||||
def _set_xai_oauth_unavailable(monkeypatch):
|
||||
from hermes_cli import auth
|
||||
|
||||
monkeypatch.setattr(auth, "resolve_xai_oauth_runtime_credentials", lambda **_: {})
|
||||
|
||||
|
||||
def test_xai_credentials_fail_closed_without_profile_scope(tmp_path, monkeypatch):
|
||||
from agent import secret_scope
|
||||
from hermes_cli.config import invalidate_env_cache
|
||||
from tools.xai_http import resolve_xai_http_credentials
|
||||
|
||||
monkeypatch.setenv("HERMES_HOME", str(tmp_path))
|
||||
monkeypatch.setenv("XAI_API_KEY", "foreign-xai-key")
|
||||
monkeypatch.setenv("XAI_BASE_URL", "https://foreign.example/v1")
|
||||
_set_xai_oauth_unavailable(monkeypatch)
|
||||
invalidate_env_cache()
|
||||
previous_multiplex = secret_scope.is_multiplex_active()
|
||||
token = secret_scope.set_secret_scope(None)
|
||||
secret_scope.set_multiplex_active(True)
|
||||
try:
|
||||
with pytest.raises(secret_scope.UnscopedSecretError):
|
||||
resolve_xai_http_credentials(force_refresh=True)
|
||||
finally:
|
||||
secret_scope.reset_secret_scope(token)
|
||||
secret_scope.set_multiplex_active(previous_multiplex)
|
||||
invalidate_env_cache()
|
||||
|
||||
|
||||
def test_xai_credentials_do_not_fall_back_to_environ_when_scope_has_no_key(
|
||||
tmp_path, monkeypatch
|
||||
):
|
||||
from agent import secret_scope
|
||||
from hermes_cli.config import invalidate_env_cache
|
||||
from tools.xai_http import resolve_xai_http_credentials
|
||||
|
||||
monkeypatch.setenv("HERMES_HOME", str(tmp_path))
|
||||
monkeypatch.setenv("XAI_API_KEY", "foreign-xai-key")
|
||||
monkeypatch.setenv("XAI_BASE_URL", "https://foreign.example/v1")
|
||||
_set_xai_oauth_unavailable(monkeypatch)
|
||||
invalidate_env_cache()
|
||||
previous_multiplex = secret_scope.is_multiplex_active()
|
||||
token = secret_scope.set_secret_scope({})
|
||||
secret_scope.set_multiplex_active(True)
|
||||
try:
|
||||
credentials = resolve_xai_http_credentials(force_refresh=True)
|
||||
assert credentials == {
|
||||
"provider": "xai",
|
||||
"api_key": "",
|
||||
"base_url": "https://api.x.ai/v1",
|
||||
}
|
||||
finally:
|
||||
secret_scope.reset_secret_scope(token)
|
||||
secret_scope.set_multiplex_active(previous_multiplex)
|
||||
invalidate_env_cache()
|
||||
@@ -79,13 +79,11 @@ def get_env_value(name: str, default=None):
|
||||
"""
|
||||
try:
|
||||
from hermes_cli.config import get_env_value as _hermes_get_env_value
|
||||
except ImportError:
|
||||
return os.environ.get(name, default)
|
||||
|
||||
value = _hermes_get_env_value(name)
|
||||
if value is not None:
|
||||
return value
|
||||
except Exception:
|
||||
pass
|
||||
return os.environ.get(name, default)
|
||||
value = _hermes_get_env_value(name)
|
||||
return value if value is not None else default
|
||||
|
||||
|
||||
def hermes_xai_user_agent() -> str:
|
||||
|
||||
Reference in New Issue
Block a user