Moves the agent model out of env-only config into an admin-editable Settings
section, and enforces is_admin for the first time — it has been in the schema
since migration 0001, plumbed to the client, and checked nowhere.
Backend:
- Migration 0010: instance_settings, a single-row (CHECK id=1) table — pansy's
first instance-level state. Holds agent_model ('' = inherit env) and
agent_enabled (NULL = inherit env), version-guarded like every mutable row.
SECRETS STAY IN ENV: OLLAMA_CLOUD_API_KEY is never stored here.
- requireAdmin at the service seam (authoritative) plus a cheap middleware
early-403. Non-admin gets 403, not 404 — settings existence isn't masked.
- EffectiveAgent resolves DB-over-env (model, enabled); key always from env.
- The live Runner is hot-swapped, not built once. agentHolder holds it behind
an atomic.Pointer; the chat routes are now registered UNCONDITIONALLY and
nil-check agent.get(), so a settings change turns the assistant on/off/onto a
new model with no restart and no race against in-flight readers. /capabilities
reads the pointer, so it reports what's live, not what booted.
- internal/agentmodel is a new leaf package holding the one place that knows how
to turn a spec into a model. Both agent (to run) and service (to validate a
spec before storing it) import it; it can't live in agent, which imports
service. Settings PATCH validates the spec via Parse, so a typo is a 400 now
rather than a broken assistant on the next turn.
Frontend:
- /settings route (admin guard), a Settings page (model field, tri-state
enabled, live status), nav link shown only to admins.
- useCapabilities drops staleTime:Infinity — the assistant can now change under
a running page — and the settings save invalidates it.
Contract change: chat routes always exist, so "assistant off" is a runtime 503
+ capabilities:false, not a missing route. Updated the test that asserted the
old shape.
Verified live against the built binary: disable flips capabilities to false and
logs it; re-enable with a new model swaps it back; a bad spec is rejected 400;
the setting persists across a restart. Swap is race-clean under `go test -race`.
Docs: README (precedence + key-stays-in-env), DESIGN (decision + routes),
CLAUDE (don't re-add conditional route registration; key never in the DB).
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
50 lines
2.0 KiB
Go
50 lines
2.0 KiB
Go
package api
|
|
|
|
import (
|
|
"net/http"
|
|
"strconv"
|
|
"testing"
|
|
)
|
|
|
|
// TestAgentDisabledWithoutAKey — an instance with no API key must start, serve
|
|
// the app, and not offer the assistant.
|
|
//
|
|
// The contract CHANGED with #79: the chat route is now always registered (so a
|
|
// settings change can turn the assistant on without a restart), so "off" is a
|
|
// runtime 503 rather than a missing route. capabilities reports agent:false, and
|
|
// the frontend keys the chat tab off that — so a user never reaches the 503.
|
|
func TestAgentDisabledWithoutAKey(t *testing.T) {
|
|
r := authEngine(t, localCfg()) // localCfg has no agent configuration
|
|
cookie := registerAndCookie(t, r, "[email protected]")
|
|
gid := createGardenAPI(t, r, cookie, "G")
|
|
|
|
// Chat is refused, plainly, because there is no Runner to run.
|
|
w := doJSON(t, r, http.MethodPost, "/api/v1/agent/chat",
|
|
map[string]any{"gardenId": gid, "message": "plant garlic"}, cookie)
|
|
if w.Code != http.StatusServiceUnavailable {
|
|
t.Errorf("chat without a key: status %d, want 503", w.Code)
|
|
}
|
|
|
|
// Capabilities advertises the assistant as unavailable, which is what the UI
|
|
// actually consults.
|
|
w = doJSON(t, r, http.MethodGet, "/api/v1/capabilities", nil, cookie)
|
|
if w.Code != http.StatusOK {
|
|
t.Fatalf("capabilities: status %d", w.Code)
|
|
}
|
|
if agent, _ := decodeMap(t, w.Body.Bytes())["agent"].(bool); agent {
|
|
t.Error("capabilities reported agent:true with no key")
|
|
}
|
|
|
|
// History is just stored data behind the ordinary garden-role check, so it
|
|
// reads fine (empty) whether or not a Runner exists — it isn't gated on one.
|
|
path := "/api/v1/gardens/" + strconv.FormatInt(gid, 10) + "/agent/history"
|
|
if w := doJSON(t, r, http.MethodGet, path, nil, cookie); w.Code != http.StatusOK {
|
|
t.Errorf("history without a key: status %d, want 200 (it's data, not the model)", w.Code)
|
|
}
|
|
|
|
// And the rest of the app is entirely unaffected.
|
|
if w := doJSON(t, r, http.MethodGet, fullPath(gid), nil, cookie); w.Code != http.StatusOK {
|
|
t.Errorf("editor load: status %d, want 200 — an unconfigured agent must not break the app", w.Code)
|
|
}
|
|
}
|