Moves the agent model out of env-only config into an admin-editable Settings
section, and enforces is_admin for the first time — it has been in the schema
since migration 0001, plumbed to the client, and checked nowhere.
Backend:
- Migration 0010: instance_settings, a single-row (CHECK id=1) table — pansy's
first instance-level state. Holds agent_model ('' = inherit env) and
agent_enabled (NULL = inherit env), version-guarded like every mutable row.
SECRETS STAY IN ENV: OLLAMA_CLOUD_API_KEY is never stored here.
- requireAdmin at the service seam (authoritative) plus a cheap middleware
early-403. Non-admin gets 403, not 404 — settings existence isn't masked.
- EffectiveAgent resolves DB-over-env (model, enabled); key always from env.
- The live Runner is hot-swapped, not built once. agentHolder holds it behind
an atomic.Pointer; the chat routes are now registered UNCONDITIONALLY and
nil-check agent.get(), so a settings change turns the assistant on/off/onto a
new model with no restart and no race against in-flight readers. /capabilities
reads the pointer, so it reports what's live, not what booted.
- internal/agentmodel is a new leaf package holding the one place that knows how
to turn a spec into a model. Both agent (to run) and service (to validate a
spec before storing it) import it; it can't live in agent, which imports
service. Settings PATCH validates the spec via Parse, so a typo is a 400 now
rather than a broken assistant on the next turn.
Frontend:
- /settings route (admin guard), a Settings page (model field, tri-state
enabled, live status), nav link shown only to admins.
- useCapabilities drops staleTime:Infinity — the assistant can now change under
a running page — and the settings save invalidates it.
Contract change: chat routes always exist, so "assistant off" is a runtime 503
+ capabilities:false, not a missing route. Updated the test that asserted the
old shape.
Verified live against the built binary: disable flips capabilities to false and
logs it; re-enable with a new model swaps it back; a bad spec is rejected 400;
the setting persists across a restart. Swap is race-clean under `go test -race`.
Docs: README (precedence + key-stays-in-env), DESIGN (decision + routes),
CLAUDE (don't re-add conditional route registration; key never in the DB).
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
118 lines
4.2 KiB
Go
118 lines
4.2 KiB
Go
package service
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"testing"
|
|
|
|
"gitea.stevedudenhoeffer.com/steve/pansy/internal/config"
|
|
"gitea.stevedudenhoeffer.com/steve/pansy/internal/domain"
|
|
)
|
|
|
|
// settingsTestService builds a service whose env config carries the given agent
|
|
// model/enabled/key, so EffectiveAgent's env fallback can be exercised.
|
|
func settingsTestService(t *testing.T, envModel string, envEnabled bool, key string) (*Service, int64) {
|
|
t.Helper()
|
|
cfg := openConfig()
|
|
cfg.Agent = config.AgentConfig{Model: envModel, Enabled: envEnabled, OllamaCloudAPIKey: key}
|
|
s := newTestService(t, cfg)
|
|
admin := seedUser(t, s, "[email protected]") // first user is admin
|
|
return s, admin
|
|
}
|
|
|
|
// TestRequireAdmin: the first user is admin; a second is not and gets
|
|
// ErrForbidden (not ErrNotFound — settings existence isn't masked).
|
|
func TestRequireAdmin(t *testing.T) {
|
|
s, admin := settingsTestService(t, "ollama-cloud/x", true, "k")
|
|
member := seedUser(t, s, "[email protected]")
|
|
|
|
if err := s.requireAdmin(context.Background(), admin); err != nil {
|
|
t.Errorf("admin rejected: %v", err)
|
|
}
|
|
if err := s.requireAdmin(context.Background(), member); !errors.Is(err, domain.ErrForbidden) {
|
|
t.Errorf("member requireAdmin = %v, want ErrForbidden", err)
|
|
}
|
|
}
|
|
|
|
// TestEffectiveAgentLayering: DB settings override env; the API key always comes
|
|
// from env; the "inherit" sentinels fall back.
|
|
func TestEffectiveAgentLayering(t *testing.T) {
|
|
ctx := context.Background()
|
|
s, admin := settingsTestService(t, "ollama-cloud/env-model", true, "envkey")
|
|
|
|
// Untouched: everything inherits env.
|
|
eff, err := s.EffectiveAgent(ctx)
|
|
if err != nil {
|
|
t.Fatalf("effective: %v", err)
|
|
}
|
|
if eff.Model != "ollama-cloud/env-model" || !eff.Enabled || eff.APIKey != "envkey" {
|
|
t.Errorf("inherited effective = %+v, want the env values", eff)
|
|
}
|
|
|
|
// Override the model only; enabled still inherits env (true).
|
|
cur, _ := s.GetInstanceSettings(ctx, admin)
|
|
if _, err := s.UpdateInstanceSettings(ctx, admin, InstanceSettingsPatch{
|
|
AgentModel: "ollama-cloud/glm-5.2:cloud", Version: cur.Version,
|
|
}); err != nil {
|
|
t.Fatalf("update model: %v", err)
|
|
}
|
|
eff, _ = s.EffectiveAgent(ctx)
|
|
if eff.Model != "ollama-cloud/glm-5.2:cloud" {
|
|
t.Errorf("model = %q, want the DB override", eff.Model)
|
|
}
|
|
if !eff.Enabled {
|
|
t.Error("enabled should still inherit env (true) when unset")
|
|
}
|
|
|
|
// Now override enabled to false explicitly.
|
|
cur, _ = s.GetInstanceSettings(ctx, admin)
|
|
no := false
|
|
if _, err := s.UpdateInstanceSettings(ctx, admin, InstanceSettingsPatch{
|
|
AgentModel: "ollama-cloud/glm-5.2:cloud", AgentEnabled: &no, Version: cur.Version,
|
|
}); err != nil {
|
|
t.Fatalf("update enabled: %v", err)
|
|
}
|
|
eff, _ = s.EffectiveAgent(ctx)
|
|
if eff.Enabled {
|
|
t.Error("enabled should be the explicit false override now")
|
|
}
|
|
if eff.Ready() {
|
|
t.Error("Ready() should be false when disabled")
|
|
}
|
|
}
|
|
|
|
// TestUpdateInstanceSettingsRejectsBadModel: a spec that won't resolve is
|
|
// ErrInvalidInput, before it is stored.
|
|
func TestUpdateInstanceSettingsRejectsBadModel(t *testing.T) {
|
|
ctx := context.Background()
|
|
s, admin := settingsTestService(t, "ollama-cloud/x", true, "k")
|
|
cur, _ := s.GetInstanceSettings(ctx, admin)
|
|
|
|
if _, err := s.UpdateInstanceSettings(ctx, admin, InstanceSettingsPatch{
|
|
AgentModel: "nonesuch/model", Version: cur.Version,
|
|
}); !errors.Is(err, domain.ErrInvalidInput) {
|
|
t.Errorf("bad model = %v, want ErrInvalidInput", err)
|
|
}
|
|
|
|
// The rejected write didn't touch the row.
|
|
after, _ := s.GetInstanceSettings(ctx, admin)
|
|
if after.Version != cur.Version || after.AgentModel != "" {
|
|
t.Errorf("a rejected update changed the row: %+v", after)
|
|
}
|
|
}
|
|
|
|
// TestInstanceSettingsAdminGate: the read/write operations are admin-gated at the
|
|
// service seam, not just in the handler.
|
|
func TestInstanceSettingsAdminGate(t *testing.T) {
|
|
ctx := context.Background()
|
|
s, _ := settingsTestService(t, "ollama-cloud/x", true, "k")
|
|
member := seedUser(t, s, "[email protected]")
|
|
|
|
if _, err := s.GetInstanceSettings(ctx, member); !errors.Is(err, domain.ErrForbidden) {
|
|
t.Errorf("member GetInstanceSettings = %v, want ErrForbidden", err)
|
|
}
|
|
if _, err := s.UpdateInstanceSettings(ctx, member, InstanceSettingsPatch{Version: 1}); !errors.Is(err, domain.ErrForbidden) {
|
|
t.Errorf("member UpdateInstanceSettings = %v, want ErrForbidden", err)
|
|
}
|
|
}
|