From 062d44bba7973aa911d086be2be495c8db980744 Mon Sep 17 00:00:00 2001 From: Ray Date: Sun, 2 Aug 2026 00:53:16 -0700 Subject: [PATCH] =?UTF-8?q?fix(xai):=20fail=20closed=20in=20xai=5Fhttp.get?= =?UTF-8?q?=5Fenv=5Fvalue=20=E2=80=94=20honor=20get=5Fsecret's=20verdict?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Salvaged from #56982 (@rayjun): the live piece of the PR. The hermes_cli/config.py get_env_value scope-honoring change and its test_env_load_cache.py tests were already merged via ed1170cd8b (#76462) and are dropped here. tools/xai_http.py::get_env_value wrapped the scope-aware hermes_cli.config.get_env_value in except Exception + a raw os.environ fallback — swallowing UnscopedSecretError and borrowing the process env, so a multiplexed xAI credential read could silently pick up another profile's XAI_API_KEY. Narrow the except to ImportError (the only legitimate degraded case) so get_secret's verdict propagates: an unscoped multiplexed read fails closed, and a scoped miss returns the default instead of the foreign environ value. Co-authored-by: rayjun --- tests/tools/test_xai_http_credentials.py | 57 ++++++++++++++++++++++++ tools/xai_http.py | 10 ++--- 2 files changed, 61 insertions(+), 6 deletions(-) create mode 100644 tests/tools/test_xai_http_credentials.py diff --git a/tests/tools/test_xai_http_credentials.py b/tests/tools/test_xai_http_credentials.py new file mode 100644 index 0000000000..4217823f8c --- /dev/null +++ b/tests/tools/test_xai_http_credentials.py @@ -0,0 +1,57 @@ +import pytest + + +def _set_xai_oauth_unavailable(monkeypatch): + from hermes_cli import auth + + monkeypatch.setattr(auth, "resolve_xai_oauth_runtime_credentials", lambda **_: {}) + + +def test_xai_credentials_fail_closed_without_profile_scope(tmp_path, monkeypatch): + from agent import secret_scope + from hermes_cli.config import invalidate_env_cache + from tools.xai_http import resolve_xai_http_credentials + + monkeypatch.setenv("HERMES_HOME", str(tmp_path)) + monkeypatch.setenv("XAI_API_KEY", "foreign-xai-key") + monkeypatch.setenv("XAI_BASE_URL", "https://foreign.example/v1") + _set_xai_oauth_unavailable(monkeypatch) + invalidate_env_cache() + previous_multiplex = secret_scope.is_multiplex_active() + token = secret_scope.set_secret_scope(None) + secret_scope.set_multiplex_active(True) + try: + with pytest.raises(secret_scope.UnscopedSecretError): + resolve_xai_http_credentials(force_refresh=True) + finally: + secret_scope.reset_secret_scope(token) + secret_scope.set_multiplex_active(previous_multiplex) + invalidate_env_cache() + + +def test_xai_credentials_do_not_fall_back_to_environ_when_scope_has_no_key( + tmp_path, monkeypatch +): + from agent import secret_scope + from hermes_cli.config import invalidate_env_cache + from tools.xai_http import resolve_xai_http_credentials + + monkeypatch.setenv("HERMES_HOME", str(tmp_path)) + monkeypatch.setenv("XAI_API_KEY", "foreign-xai-key") + monkeypatch.setenv("XAI_BASE_URL", "https://foreign.example/v1") + _set_xai_oauth_unavailable(monkeypatch) + invalidate_env_cache() + previous_multiplex = secret_scope.is_multiplex_active() + token = secret_scope.set_secret_scope({}) + secret_scope.set_multiplex_active(True) + try: + credentials = resolve_xai_http_credentials(force_refresh=True) + assert credentials == { + "provider": "xai", + "api_key": "", + "base_url": "https://api.x.ai/v1", + } + finally: + secret_scope.reset_secret_scope(token) + secret_scope.set_multiplex_active(previous_multiplex) + invalidate_env_cache() diff --git a/tools/xai_http.py b/tools/xai_http.py index 8ef0b85630..1e4f72a7fb 100644 --- a/tools/xai_http.py +++ b/tools/xai_http.py @@ -79,13 +79,11 @@ def get_env_value(name: str, default=None): """ try: from hermes_cli.config import get_env_value as _hermes_get_env_value + except ImportError: + return os.environ.get(name, default) - value = _hermes_get_env_value(name) - if value is not None: - return value - except Exception: - pass - return os.environ.get(name, default) + value = _hermes_get_env_value(name) + return value if value is not None else default def hermes_xai_user_agent() -> str: