426e9eeabd
Voice Workbench / headless workbench (mocked backends) (push) Has been cancelled
Voice Workbench / real acoustic lane (nightly, provisioned only) (push) Has been cancelled
ci / test (push) Has been cancelled
ci / lint-and-format (push) Has been cancelled
ci / build (push) Has been cancelled
ci / dev-startup (push) Has been cancelled
gitleaks / gitleaks (push) Has been cancelled
Markdown Links / Relative Markdown Links (push) Has been cancelled
Quality (Extended) / Homepage Build (PR smoke) (push) Has been cancelled
Quality (Extended) / Comment-only diff guard (push) Has been cancelled
Quality (Extended) / Format + Type Safety Ratchet (push) Has been cancelled
Quality (Extended) / Develop Gate (secret scan + UI determinism) (push) Has been cancelled
Quality (Extended) / Develop Gate (lint) (push) Has been cancelled
Chat shell gestures / Chat shell gesture + parity e2e (push) Has been cancelled
Cloud Gateway Discord / Test (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx @biomejs/biome check packages/lifeops-bench/src, benchmark-lint) (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx vitest run --config packages/lifeops-bench/vitest.config.ts --root packages/lifeops-bench --passWithNoTests, benchmark-tests) (push) Has been cancelled
Build Agent Image / build-and-push (push) Has been cancelled
Dev Smoke / bun run dev onboarding chat (push) Has been cancelled
Dev Smoke / Vite HMR dependency-level smoke (push) Has been cancelled
Electrobun Submodule Guard / electrobun gitlink is fetchable (push) Has been cancelled
Publish @elizaos/example-code / check_npm (push) Has been cancelled
Publish @elizaos/example-code / publish_npm (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / verify_version (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / publish_npm (push) Has been cancelled
Sandbox Live Smoke / Sandbox live smoke (push) Has been cancelled
Snap Build & Test / Build Snap (amd64) (push) Has been cancelled
Snap Build & Test / Build Snap (arm64) (push) Has been cancelled
Test Packaging / elizaos CLI global-install smoke (node + bun) (push) Has been cancelled
Cloud Gateway Webhook / Test (push) Has been cancelled
Cloud Tests / lint-and-types (push) Has been cancelled
Cloud Tests / unit-tests (push) Has been cancelled
Cloud Tests / integration-tests (push) Has been cancelled
Cloud Tests / e2e-tests (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Deploy Apps Worker (Product 2) / Determine environment (push) Has been cancelled
Deploy Apps Worker (Product 2) / Deploy apps worker to apps-control host (${{ needs.determine-env.outputs.environment }}) (push) Has been cancelled
Deploy Eliza Provisioning Worker / Determine environment (push) Has been cancelled
Deploy Eliza Provisioning Worker / Deploy worker to Hetzner host (${{ needs.determine-env.outputs.environment }} @ ${{ needs.determine-env.outputs.deployment_sha }}) (push) Has been cancelled
Dev Smoke / Classify changed paths (push) Has been cancelled
supply-chain / sbom (push) Has been cancelled
supply-chain / vulnerability-scan (push) Has been cancelled
Build, Push & Deploy to Phala Cloud / build-and-push (push) Has been cancelled
Test Packaging / Validate Packaging Configs (push) Has been cancelled
Test Packaging / Build & Test PyPI Package (push) Has been cancelled
Test Packaging / PyPI on Python ${{ matrix.python }} (push) Has been cancelled
Test Packaging / Pack & Test JS Tarballs (push) Has been cancelled
UI Fixture E2E / ui-fixture-e2e (push) Has been cancelled
UI Fixture E2E / fixture-e2e (push) Has been cancelled
UI Story Gate / story-gate (push) Has been cancelled
vault-ci / test (macos-latest) (push) Has been cancelled
vault-ci / test (ubuntu-latest) (push) Has been cancelled
vault-ci / test (windows-latest) (push) Has been cancelled
vault-ci / app-core wiring tests (push) Has been cancelled
verify-patches / verify patches/CHECKSUMS.sha256 (push) Has been cancelled
Voice Benchmark Smoke / voice-emotion fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voiceagentbench fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench-quality unit smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench TypeScript unit (no audio) (push) Has been cancelled
Voice Benchmark Smoke / voice bench smoke summary (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/app-core test bun run --cwd packages/elizaos test bun run --cwd packages/cloud/shared test], app-and-cli) (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/scenario-runner test bun run --cwd packages/vault test bun run --cwd packages/security test bun run --cwd plugins/plugin-coding-tools test], framework-packages) (push) Has been cancelled
Windows CI / windows ([bun run --cwd plugins/plugin-elizacloud test bun run --cwd plugins/plugin-discord test bun run --cwd plugins/plugin-anthropic test bun run --cwd plugins/plugin-openai test bun run --cwd plugins/plugin-app-control test bun run --cwd plugins/pl… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run build --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/agent --concurrency=4 node packages/scripts/run-bash-linux-only.mjs scripts/verify-riscv64-buildpaths.sh node packages/scripts/run… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run typecheck --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/cloud-shared --concurrency=4 bun run --cwd packages/core test bun run --cwd packages/shared test], core-runtime, 75) (push) Has been cancelled
165 lines
5.7 KiB
TypeScript
165 lines
5.7 KiB
TypeScript
/**
|
|
* Covers the hasLifeOpsAccess owner gate: denying on a missing runtime/agentId or message
|
|
* entityId, and otherwise delegating to hasOwnerAccess. Deterministic, mocked owner-access.
|
|
*/
|
|
import type { Memory } from "@elizaos/core";
|
|
import { beforeEach, describe, expect, it, vi } from "vitest";
|
|
|
|
// Mirrors the @elizaos/agent owner-access mock other PA action tests use.
|
|
// `vi.hoisted` so the mock fn exists when the hoisted `vi.mock` factory runs.
|
|
const mocks = vi.hoisted(() => ({
|
|
hasOwnerAccess: vi.fn(async () => true),
|
|
}));
|
|
vi.mock("@elizaos/agent", () => ({
|
|
hasOwnerAccess: mocks.hasOwnerAccess,
|
|
}));
|
|
|
|
import {
|
|
calendarReadUnavailableMessage,
|
|
calendarWriteUnavailableMessage,
|
|
getGoogleCapabilityStatus,
|
|
gmailReadUnavailableMessage,
|
|
gmailSendUnavailableMessage,
|
|
hasLifeOpsAccess,
|
|
} from "../src/lifeops/access.js";
|
|
import type { LifeOpsService } from "../src/lifeops/service.js";
|
|
|
|
type RuntimeArg = Parameters<typeof hasLifeOpsAccess>[0];
|
|
|
|
// No default params: passing `undefined` must set the field to undefined (a
|
|
// default would mask the missing-field guard the tests exercise).
|
|
function runtime(agentId: unknown): RuntimeArg {
|
|
return { agentId } as unknown as RuntimeArg;
|
|
}
|
|
function message(entityId: unknown): Memory {
|
|
return { entityId } as unknown as Memory;
|
|
}
|
|
|
|
function serviceWith(
|
|
connected: boolean,
|
|
grantedCapabilities: string[],
|
|
): LifeOpsService {
|
|
return {
|
|
getGoogleConnectorStatus: async () =>
|
|
({ connected, grantedCapabilities }) as never,
|
|
} as unknown as LifeOpsService;
|
|
}
|
|
|
|
function throwingService(): LifeOpsService {
|
|
return {
|
|
getGoogleConnectorStatus: async () => {
|
|
throw new Error("connector unavailable");
|
|
},
|
|
} as unknown as LifeOpsService;
|
|
}
|
|
|
|
beforeEach(() => {
|
|
mocks.hasOwnerAccess.mockReset().mockResolvedValue(true);
|
|
});
|
|
|
|
describe("hasLifeOpsAccess — owner gate", () => {
|
|
it("denies when runtime/agentId is missing", async () => {
|
|
expect(
|
|
await hasLifeOpsAccess(null as unknown as RuntimeArg, message("owner-1")),
|
|
).toBe(false);
|
|
expect(await hasLifeOpsAccess(runtime(undefined), message("owner-1"))).toBe(
|
|
false,
|
|
);
|
|
expect(mocks.hasOwnerAccess).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("denies when the message entityId is missing or empty", async () => {
|
|
expect(await hasLifeOpsAccess(runtime("agent-1"), message(undefined))).toBe(
|
|
false,
|
|
);
|
|
expect(await hasLifeOpsAccess(runtime("agent-1"), message(""))).toBe(false);
|
|
expect(mocks.hasOwnerAccess).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("delegates to hasOwnerAccess for a well-formed owner request", async () => {
|
|
mocks.hasOwnerAccess.mockResolvedValueOnce(true);
|
|
expect(await hasLifeOpsAccess(runtime("agent-1"), message("owner-1"))).toBe(
|
|
true,
|
|
);
|
|
mocks.hasOwnerAccess.mockResolvedValueOnce(false);
|
|
expect(await hasLifeOpsAccess(runtime("agent-1"), message("owner-1"))).toBe(
|
|
false,
|
|
);
|
|
expect(mocks.hasOwnerAccess).toHaveBeenCalledTimes(2);
|
|
});
|
|
});
|
|
|
|
describe("getGoogleCapabilityStatus — OAuth grant/scope matrix", () => {
|
|
it("maps calendar write as also granting read", async () => {
|
|
const g = await getGoogleCapabilityStatus(
|
|
serviceWith(true, ["google.calendar.write"]),
|
|
);
|
|
expect(g.connected).toBe(true);
|
|
expect(g.hasCalendarWrite).toBe(true);
|
|
expect(g.hasCalendarRead).toBe(true);
|
|
});
|
|
|
|
it("grants read without write when only the read scope is present", async () => {
|
|
const g = await getGoogleCapabilityStatus(
|
|
serviceWith(true, ["google.calendar.read"]),
|
|
);
|
|
expect(g.hasCalendarRead).toBe(true);
|
|
expect(g.hasCalendarWrite).toBe(false);
|
|
});
|
|
|
|
it("denies every capability when no scopes are granted", async () => {
|
|
const g = await getGoogleCapabilityStatus(serviceWith(true, []));
|
|
expect(g.hasCalendarRead).toBe(false);
|
|
expect(g.hasCalendarWrite).toBe(false);
|
|
expect(g.hasGmailTriage).toBe(false);
|
|
expect(g.hasGmailSend).toBe(false);
|
|
expect(g.hasGmailManage).toBe(false);
|
|
});
|
|
|
|
it("maps each gmail scope independently", async () => {
|
|
const g = await getGoogleCapabilityStatus(
|
|
serviceWith(true, ["google.gmail.triage", "google.gmail.send"]),
|
|
);
|
|
expect(g.hasGmailTriage).toBe(true);
|
|
expect(g.hasGmailSend).toBe(true);
|
|
expect(g.hasGmailManage).toBe(false);
|
|
});
|
|
|
|
it("returns a fully-denied snapshot when the connector errors (revoked/unavailable)", async () => {
|
|
const g = await getGoogleCapabilityStatus(throwingService());
|
|
expect(g.status).toBeNull();
|
|
expect(g.connected).toBe(false);
|
|
expect(g.hasCalendarRead).toBe(false);
|
|
expect(g.hasGmailSend).toBe(false);
|
|
});
|
|
|
|
it("reflects the connector's connected flag", async () => {
|
|
const g = await getGoogleCapabilityStatus(serviceWith(false, []));
|
|
expect(g.connected).toBe(false);
|
|
});
|
|
});
|
|
|
|
describe("unavailable-message helpers", () => {
|
|
const connected = {
|
|
connected: true,
|
|
} as Parameters<typeof calendarReadUnavailableMessage>[0];
|
|
const disconnected = {
|
|
connected: false,
|
|
} as Parameters<typeof calendarReadUnavailableMessage>[0];
|
|
|
|
it("distinguishes limited-access from not-connected wording", () => {
|
|
expect(calendarReadUnavailableMessage(connected)).toMatch(/limited/i);
|
|
expect(calendarReadUnavailableMessage(disconnected)).toMatch(
|
|
/not connected/i,
|
|
);
|
|
expect(calendarWriteUnavailableMessage(connected)).toMatch(/not granted/i);
|
|
expect(calendarWriteUnavailableMessage(disconnected)).toMatch(
|
|
/not connected/i,
|
|
);
|
|
expect(gmailReadUnavailableMessage(connected)).toMatch(/limited/i);
|
|
expect(gmailReadUnavailableMessage(disconnected)).toMatch(/not connected/i);
|
|
expect(gmailSendUnavailableMessage(connected)).toMatch(/not granted/i);
|
|
expect(gmailSendUnavailableMessage(disconnected)).toMatch(/not connected/i);
|
|
});
|
|
});
|