Files
cowork-local/tests/test_agent_security_cycle.py
f9f6bc01fd
CI / test (push) Canceled after 0s
Feature/delta team/epic r04 (#7)
## Summary

epic r04 - begin refactor

## Change Type

- [x] Cowork feature
- [ ] Bug fix
- [ ] Core AI contribution
- [ ] Test / hardening
- [ ] Performance
- [ ] Documentation

## Related Work

Cowork Task:

Core Repo: http://34.143.229.138/gitea-admin/fsg-ai-core-assets

Core AI Issue:

Core Task:

Related PR:

## Scope

What is intentionally included?

What is intentionally NOT included?

## Validation

- [ ] Unit tests
- [ ] Integration tests
- [ ] Manual verification
- [ ] Regression check

Commands / evidence:

## Security Impact

Permission / credential / network / customer data impact:

## Compatibility

- [ ] No breaking change
- [ ] Breaking change documented

## Reviewer Notes

Anything Cowork reviewers should pay attention to.

---------

Co-authored-by: Anh Tran Nguyen Minh <anhtnm1@fpt.com>
Co-authored-by: Huong Le Thi Thien <huongltt35@fpt.com>
Co-authored-by: Nam Pham Dinh Thanh <nampdt@fpt.com>
Co-authored-by: Vu Dam Tuan <vudt15@fpt.com>
Co-authored-by: Hiep Ha Van <hiephv3@fpt.com>
Co-authored-by: Lam Hoang Van <lamhv7@fpt.com>
Reviewed-on: #7
Co-authored-by: Duy Le Huu <duylh19@fpt.com>
2026-08-31 05:15:13 +00:00

76 lines
2.8 KiB
Python

"""Task 4b — agent_security <-> agent_security_alert circular dependency is gone.
Before this fix, ``agent_security_alert.py`` imported ``SecurityVerdict`` from
``agent_security.py`` at module level (for the ``notify_admin`` type
annotation), while ``agent_security.py`` deferred-imported
``agent_security_alert.notify_admin`` inside ``enforce_prompt``/
``enforce_command`` — an architectural cycle only avoided at runtime by
pushing that second import inside a function body.
``SecurityVerdict``/``SecurityBlocked`` now live in the dependency-free leaf
module ``agent_security_types.py``. ``agent_security_alert.py`` imports the
type from there instead of from ``agent_security.py``, which lets
``agent_security.py`` import ``agent_security_alert.notify_admin`` at module
top level with no cycle.
"""
from __future__ import annotations
from cowork_local.core import (
agent_security,
agent_security_alert,
agent_security_types,
)
def test_shared_types_live_in_the_leaf_module() -> None:
assert agent_security.SecurityVerdict is agent_security_types.SecurityVerdict
assert agent_security.SecurityBlocked is agent_security_types.SecurityBlocked
assert agent_security_alert.SecurityVerdict is agent_security_types.SecurityVerdict
def test_agent_security_alert_no_longer_imports_agent_security() -> None:
assert "agent_security" not in agent_security_alert.__dict__
def test_notify_admin_imported_at_module_top_level_in_agent_security() -> None:
assert agent_security.notify_admin is agent_security_alert.notify_admin
def test_enforce_command_still_blocks_and_alerts_like_before(monkeypatch) -> None:
class _FakeProvider:
def chat(self, messages, tools=None):
return {"content": '{"allowed": false, "reason": "destructive"}'}
class _Config:
data = {"agent_security": {"enabled": True, "validate_commands": True,
"command_ai_check": True}}
ms365 = {}
@property
def agent_security(self):
return self.data["agent_security"]
notify_calls = []
record_calls = []
monkeypatch.setattr(agent_security, "notify_admin",
lambda config, verdict, detail="": notify_calls.append((verdict, detail)))
from cowork_local.core import audit_log
monkeypatch.setattr(audit_log, "record",
lambda *a, **k: record_calls.append((a, k)))
emitted = []
raised = False
try:
agent_security.enforce_command(
_FakeProvider(), "run_command", {"command": "rm -rf /"}, _Config(),
emit=emitted.append,
)
except agent_security.SecurityBlocked as exc:
raised = True
assert exc.verdict.layer == "command"
assert raised is True
assert notify_calls
assert record_calls
assert emitted and emitted[0]["type"] == "notice"