hermes-agent/tests/run_agent/test_credential_rotation_route_settings.py
Teknium 6b81590c55
test: prune low-value tests suite-wide (wave 1) — 46,820 → 28,106 test functions
Systematic prune per AGENTS.md test policy, one pass over every major
test tree (gateway, hermes_cli, tools, agent, run_agent, plugins, cli,
cron, tui_gateway, honcho/openviking, root-level):

- DELETE: source-reading tests (read_text/getsource on prod files),
  change-detector tests (exact catalog counts, model-name snapshots,
  config version literals), mock-echo tests (assert a mock returns what
  it was told), assertion-free/trivial tests, near-duplicate
  parametrizations (boundaries + one representative kept), async/sync
  twin duplicates, cosmetic within-file variations.
- KEEP (mandatory): security/redaction/approval guards, message-role
  alternation invariants, prompt-caching/deterministic-call-id
  invariants, issue-number regression tests (deduped), E2E tests.
- 6 test files deleted outright (script-style/no-assert or fully
  redundant); conftest.py, fakes/, fixtures/ untouched.
- tests/acp/conftest.py added: autouse fixture stubs the live
  models.dev/GitHub/Copilot/Anthropic inventory fetches that ACP server
  tests performed on every session create — test_server.py 147s → 3.4s,
  and the tests are now genuinely hermetic.
- Sleep-based slowness shrunk where safe (codex_ttfb_watchdog,
  compression_concurrent_fork, etc.); no wall-clock assertion tightened.

Verification: full hermetic suite via scripts/run_tests.sh —
2439 files, 31,130 tests passed, 0 failed, 0 flaky retries, 315s wall
(baseline: 583s wall, 13,564s subprocess CPU).
2026-07-29 13:10:23 -07:00

105 lines
3.1 KiB
Python

"""Credential rotation must not carry route-scoped TLS policy."""
from types import MethodType, SimpleNamespace
from unittest.mock import MagicMock, patch
from run_agent import AIAgent
def test_credential_rotation_replaces_route_scoped_tls_settings():
agent = SimpleNamespace(
api_mode="chat_completions",
provider="custom",
model="shared-model",
api_key="old",
base_url="https://a.example/v1",
_client_kwargs={
"api_key": "old",
"base_url": "https://a.example/v1",
"ssl_verify": False,
"ssl_ca_cert": "/a.pem",
},
_apply_client_headers_for_base_url=MagicMock(),
_replace_primary_openai_client=MagicMock(),
)
entry = SimpleNamespace(
runtime_api_key="new",
access_token="",
runtime_base_url="https://b.example/v1",
base_url="https://b.example/v1",
)
config = {
"custom_providers": [
{
"name": "b",
"base_url": "https://b.example/v1",
"ssl_verify": True,
}
]
}
with patch("hermes_cli.config.load_config_readonly", return_value=config):
AIAgent._swap_credential(agent, entry)
assert agent._client_kwargs["ssl_verify"] is True
assert "ssl_ca_cert" not in agent._client_kwargs
agent._replace_primary_openai_client.assert_called_once_with(
reason="credential_rotation"
)
def test_credential_rotation_does_not_carry_global_headers_across_routes():
agent = SimpleNamespace(
api_mode="chat_completions",
provider="custom",
model="shared-model",
api_key="old",
base_url="https://a.example/v1",
_client_kwargs={
"api_key": "old",
"base_url": "https://a.example/v1",
"default_headers": {"Authorization": "old-secret"},
},
_replace_primary_openai_client=MagicMock(),
)
agent._apply_client_headers_for_base_url = MethodType(
AIAgent._apply_client_headers_for_base_url,
agent,
)
agent._apply_user_default_headers = MethodType(
AIAgent._apply_user_default_headers,
agent,
)
entry = SimpleNamespace(
runtime_api_key="new",
access_token="",
runtime_base_url="https://b.example/v1",
base_url="https://b.example/v1",
)
config = {
"model": {
"default_headers": {"Authorization": "global-secret"},
},
"custom_providers": [
{
"name": "b",
"base_url": "https://b.example/v1",
"extra_headers": {"X-Route": "b"},
}
],
}
with (
patch("hermes_cli.config.load_config_readonly", return_value=config),
patch(
"hermes_cli.config.get_compatible_custom_providers",
return_value=config["custom_providers"],
),
):
AIAgent._swap_credential(agent, entry)
headers = agent._client_kwargs["default_headers"]
assert "Authorization" not in headers
assert headers["X-Route"] == "b"