|
1 | 1 | import { describe, it, expect } from "@effect/vitest"; |
2 | 2 | import { Effect } from "effect"; |
| 3 | +import { TestClock } from "effect/testing"; |
3 | 4 |
|
4 | 5 | import { ProviderKey, ToolAddress, createExecutor } from "@executor-js/sdk"; |
5 | 6 | import { makeInMemoryBlobStore, pluginBlobStore } from "@executor-js/sdk/core"; |
6 | 7 | import { makeTestConfig } from "@executor-js/sdk/testing"; |
7 | 8 |
|
8 | | -import { makeOnePasswordStore, onepasswordPlugin, resolveConfiguredRef } from "./plugin"; |
| 9 | +import { |
| 10 | + makeCachedRefResolver, |
| 11 | + makeOnePasswordStore, |
| 12 | + onepasswordPlugin, |
| 13 | + resolveConfiguredRef, |
| 14 | +} from "./plugin"; |
9 | 15 | import type { OnePasswordService } from "./service"; |
10 | 16 | import { OnePasswordError } from "./errors"; |
11 | 17 | import { OnePasswordAccount, OnePasswordConfig, DesktopAppAuth } from "./types"; |
@@ -524,3 +530,121 @@ describe("resolveConfiguredRef", () => { |
524 | 530 | }), |
525 | 531 | ); |
526 | 532 | }); |
| 533 | + |
| 534 | +// --------------------------------------------------------------------------- |
| 535 | +// Cached ref resolution — the executor resolves a connection's credential on |
| 536 | +// every tool call, so successful resolutions are served from memory for a |
| 537 | +// short TTL instead of paying a 1Password round trip per call. |
| 538 | +// --------------------------------------------------------------------------- |
| 539 | + |
| 540 | +describe("makeCachedRefResolver", () => { |
| 541 | + const countingBackend = () => { |
| 542 | + let resolves = 0; |
| 543 | + const serviceFor = (account: OnePasswordAccount) => |
| 544 | + Effect.succeed<OnePasswordService>({ |
| 545 | + resolveSecret: (uri) => |
| 546 | + Effect.sync(() => { |
| 547 | + resolves += 1; |
| 548 | + return `secret:${account.id}:${uri}`; |
| 549 | + }), |
| 550 | + listVaults: () => Effect.succeed([]), |
| 551 | + listItems: () => Effect.succeed([]), |
| 552 | + }); |
| 553 | + return { serviceFor, resolveCount: () => resolves }; |
| 554 | + }; |
| 555 | + |
| 556 | + it.effect("serves a repeated resolution from memory within the TTL", () => |
| 557 | + Effect.gen(function* () { |
| 558 | + const backend = countingBackend(); |
| 559 | + const resolve = makeCachedRefResolver(backend.serviceFor, 60_000); |
| 560 | + |
| 561 | + const first = yield* resolve(oneAccountConfig, "op://vault-123/item-1/credential"); |
| 562 | + const second = yield* resolve(oneAccountConfig, "op://vault-123/item-1/credential"); |
| 563 | + |
| 564 | + expect(first).toEqual({ |
| 565 | + kind: "resolved", |
| 566 | + value: "secret:acct-default:op://vault-123/item-1/credential", |
| 567 | + }); |
| 568 | + expect(second).toEqual(first); |
| 569 | + expect(backend.resolveCount()).toBe(1); |
| 570 | + }), |
| 571 | + ); |
| 572 | + |
| 573 | + it.effect("asks the backend again once the TTL has passed", () => |
| 574 | + Effect.gen(function* () { |
| 575 | + const backend = countingBackend(); |
| 576 | + const resolve = makeCachedRefResolver(backend.serviceFor, 60_000); |
| 577 | + |
| 578 | + yield* resolve(oneAccountConfig, "op://vault-123/item-1/credential"); |
| 579 | + yield* TestClock.adjust("61 seconds"); |
| 580 | + yield* resolve(oneAccountConfig, "op://vault-123/item-1/credential"); |
| 581 | + |
| 582 | + expect(backend.resolveCount()).toBe(2); |
| 583 | + }), |
| 584 | + ); |
| 585 | + |
| 586 | + it.effect("never retains a not-found outcome", () => |
| 587 | + Effect.gen(function* () { |
| 588 | + // A bare ref against empty vault listings resolves to not-found; the |
| 589 | + // item may be created a moment later, so the miss must not stick. |
| 590 | + const backend = countingBackend(); |
| 591 | + let listings = 0; |
| 592 | + const serviceFor = (account: OnePasswordAccount) => |
| 593 | + backend.serviceFor(account).pipe( |
| 594 | + Effect.map((service) => ({ |
| 595 | + ...service, |
| 596 | + listItems: () => |
| 597 | + Effect.sync(() => { |
| 598 | + listings += 1; |
| 599 | + return []; |
| 600 | + }), |
| 601 | + })), |
| 602 | + ); |
| 603 | + const resolve = makeCachedRefResolver(serviceFor, 60_000); |
| 604 | + |
| 605 | + const first = yield* resolve(oneAccountConfig, "missing-item"); |
| 606 | + const second = yield* resolve(oneAccountConfig, "missing-item"); |
| 607 | + |
| 608 | + expect(first).toEqual({ kind: "not-found" }); |
| 609 | + expect(second).toEqual({ kind: "not-found" }); |
| 610 | + // Two vaults in the config, listed once per resolution. |
| 611 | + expect(listings).toBe(4); |
| 612 | + }), |
| 613 | + ); |
| 614 | + |
| 615 | + it.effect("drops every cached secret the moment the config changes", () => |
| 616 | + Effect.gen(function* () { |
| 617 | + const backend = countingBackend(); |
| 618 | + const resolve = makeCachedRefResolver(backend.serviceFor, 60_000); |
| 619 | + |
| 620 | + yield* resolve(oneAccountConfig, "op://vault-123/item-1/credential"); |
| 621 | + // Same ref, edited config (one vault removed): a removed account or |
| 622 | + // vault must not keep serving secrets it used to grant. |
| 623 | + const edited = OnePasswordConfig.make({ |
| 624 | + accounts: [ |
| 625 | + OnePasswordAccount.make({ |
| 626 | + id: "acct-default", |
| 627 | + name: "1Password", |
| 628 | + auth: desktopAuth, |
| 629 | + vaults: [{ id: "vault-123", name: "Personal" }], |
| 630 | + }), |
| 631 | + ], |
| 632 | + }); |
| 633 | + yield* resolve(edited, "op://vault-123/item-1/credential"); |
| 634 | + |
| 635 | + expect(backend.resolveCount()).toBe(2); |
| 636 | + }), |
| 637 | + ); |
| 638 | + |
| 639 | + it.effect("with a zero TTL every sequential resolution reaches the backend", () => |
| 640 | + Effect.gen(function* () { |
| 641 | + const backend = countingBackend(); |
| 642 | + const resolve = makeCachedRefResolver(backend.serviceFor, 0); |
| 643 | + |
| 644 | + yield* resolve(oneAccountConfig, "op://vault-123/item-1/credential"); |
| 645 | + yield* resolve(oneAccountConfig, "op://vault-123/item-1/credential"); |
| 646 | + |
| 647 | + expect(backend.resolveCount()).toBe(2); |
| 648 | + }), |
| 649 | + ); |
| 650 | +}); |
0 commit comments