agent build
This commit is contained in:
@@ -1,8 +1,10 @@
|
||||
package httpserver_test
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"net/http"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
)
|
||||
@@ -846,3 +848,38 @@ pages:
|
||||
t.Errorf("get after delete: got %d, want 404", getAfterDel.code)
|
||||
}
|
||||
}
|
||||
|
||||
/* ── Tool names are checked at publish ────────────────────────────────────── */
|
||||
|
||||
// §3: an unknown tool name fails validation at PUBLISH. Before this, the name
|
||||
// was accepted, stored, and dropped by the runtime at resolve time — so an
|
||||
// author got an agent that was silently missing a capability they believed they
|
||||
// had chosen, and found out by watching it fail to answer.
|
||||
func TestAgentCreateRejectsAnUnknownToolName(t *testing.T) {
|
||||
r := newRBAC(t)
|
||||
|
||||
withTools := func(names string) string {
|
||||
return strings.Replace(validAgentMD, "pages:\n - candidates",
|
||||
"tools:\n"+names+"pages:\n - candidates", 1)
|
||||
}
|
||||
|
||||
res := r.as(r.talA, "POST", "/api/v1/agent-definitions", map[string]any{
|
||||
"markdown": withTools(" - not_a_real_tool\n"),
|
||||
"visibility": "personal",
|
||||
})
|
||||
if res.code != http.StatusBadRequest && res.code != http.StatusUnprocessableEntity {
|
||||
t.Fatalf("unknown tool accepted: status %d (%v)", res.code, res.body)
|
||||
}
|
||||
if body, _ := json.Marshal(res.body); !strings.Contains(string(body), "not_a_real_tool") {
|
||||
t.Errorf("the error does not name the offending tool: %s", body)
|
||||
}
|
||||
|
||||
// A real tool is accepted, so the check is not simply refusing everything.
|
||||
ok := r.as(r.talA, "POST", "/api/v1/agent-definitions", map[string]any{
|
||||
"markdown": withTools(" - candidates_awaiting\n"),
|
||||
"visibility": "personal",
|
||||
})
|
||||
if ok.code != http.StatusCreated {
|
||||
t.Fatalf("a real tool was refused: status %d (%v)", ok.code, ok.body)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user