Files
memind/capabilities.test.mjs
T
john 229805a070 Improve WeChat MP replies and ship MindSpace/H5 production updates.
Add WeChat service account routing with sync acks, connectivity tests, and context isolation; document deploy runbooks; and bundle related MindSpace, voice, Plaza, and server gateway changes for production rollout.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-19 23:06:43 +08:00

174 lines
7.0 KiB
JavaScript

import test from 'node:test';
import assert from 'node:assert/strict';
import {
buildAgentExtensionPolicy,
buildPageEditAgentPolicy,
CAPABILITY_CATALOG,
clampUserCapabilities,
DEFAULT_USER_CAPABILITIES,
normalizeCapabilityPatch,
sandboxDeveloperTools,
sandboxMcpTools,
} from './capabilities.mjs';
import { applyPoliciesToCapabilities } from './policies.mjs';
test('default user policy blocks dangerous capabilities', () => {
assert.equal(DEFAULT_USER_CAPABILITIES.shell, false);
assert.equal(DEFAULT_USER_CAPABILITIES.filesystem, false);
assert.equal(DEFAULT_USER_CAPABILITIES.extension_admin, false);
assert.equal(DEFAULT_USER_CAPABILITIES.static_publish, false);
assert.equal(DEFAULT_USER_CAPABILITIES.code_browse, false);
assert.equal(DEFAULT_USER_CAPABILITIES.memory_store, true);
assert.equal(DEFAULT_USER_CAPABILITIES.skills, true);
assert.equal(DEFAULT_USER_CAPABILITIES.chat_recall, true);
});
test('buildAgentExtensionPolicy returns null overrides and auto mode for unrestricted users', () => {
const policy = buildAgentExtensionPolicy({}, { unrestricted: true });
assert.equal(policy.extensionOverrides, null);
assert.equal(policy.gooseMode, 'auto');
});
test('static_publish enables sandbox developer tools without shell by default', () => {
const caps = { ...DEFAULT_USER_CAPABILITIES, static_publish: true };
assert.deepEqual(sandboxDeveloperTools(caps), ['write', 'edit', 'read_image']);
const policy = buildAgentExtensionPolicy(caps);
const developer = policy.extensionOverrides.find((ext) => ext.name === 'developer');
assert.deepEqual(developer?.available_tools, ['write', 'edit', 'read_image']);
assert.equal(developer?.available_tools.includes('shell'), false);
assert.equal(developer?.available_tools.includes('tree'), false);
const summon = policy.extensionOverrides.find((ext) => ext.name === 'summon');
assert.deepEqual(summon?.available_tools, ['load_skill']);
assert.ok(policy.extensionOverrides.some((ext) => ext.name === 'projectmemory'));
assert.equal(policy.enableContextMemory, true);
});
test('static_publish with shell survives network deny and includes tree', () => {
const caps = applyPoliciesToCapabilities(
{ ...DEFAULT_USER_CAPABILITIES, static_publish: true, shell: true },
{ network_egress: 'deny' },
);
assert.equal(caps.shell, true);
const policy = buildAgentExtensionPolicy(caps, {
policies: { network_egress: 'deny', goose_mode: 'chat' },
});
const developer = policy.extensionOverrides.find((ext) => ext.name === 'developer');
assert.deepEqual(developer?.available_tools, ['write', 'edit', 'shell', 'tree', 'read_image']);
});
test('buildAgentExtensionPolicy filters developer tools', () => {
const policy = buildAgentExtensionPolicy({
...DEFAULT_USER_CAPABILITIES,
shell: true,
filesystem: false,
code_browse: true,
});
const developer = policy.extensionOverrides.find((ext) => ext.name === 'developer');
assert.ok(developer);
assert.deepEqual(developer.available_tools, ['shell', 'tree', 'read_image']);
assert.equal(
policy.extensionOverrides.some((ext) => ext.name === 'extensionmanager'),
false,
);
});
test('normalizeCapabilityPatch ignores unknown keys', () => {
assert.deepEqual(normalizeCapabilityPatch({ shell: true, unknown: true }), { shell: true });
});
test('clampUserCapabilities blocks extension_admin even when stored as true', () => {
const clamped = clampUserCapabilities({
...DEFAULT_USER_CAPABILITIES,
extension_admin: true,
shell: true,
});
assert.equal(clamped.extension_admin, false);
assert.equal(clamped.shell, true);
});
test('catalog keys are unique', () => {
const keys = CAPABILITY_CATALOG.map((item) => item.key);
assert.equal(keys.length, new Set(keys).size);
});
test('buildPageEditAgentPolicy narrows tools to shell when available', () => {
const base = buildAgentExtensionPolicy({
...DEFAULT_USER_CAPABILITIES,
shell: true,
filesystem: true,
skills: true,
});
const narrowed = buildPageEditAgentPolicy(base);
assert.equal(narrowed.enableContextMemory, false);
assert.equal(narrowed.gooseMode, 'auto');
assert.deepEqual(narrowed.extensionOverrides, [
{
type: 'platform',
name: 'developer',
description: '',
display_name: 'developer',
bundled: true,
available_tools: ['shell'],
},
]);
});
test('buildPageEditAgentPolicy without shell keeps empty developer tools', () => {
const base = buildAgentExtensionPolicy(DEFAULT_USER_CAPABILITIES);
const narrowed = buildPageEditAgentPolicy(base);
assert.deepEqual(narrowed.extensionOverrides, []);
});
test('buildPageEditAgentPolicy grants shell for static_publish sandbox users with shell capability', () => {
const base = {
...buildAgentExtensionPolicy(
{ ...DEFAULT_USER_CAPABILITIES, static_publish: true, shell: true },
{
sandboxMcp: {
serverPath: '/tmp/mindspace-sandbox-mcp.mjs',
sandboxRoot: '/tmp/sandbox',
},
},
),
capabilities: { ...DEFAULT_USER_CAPABILITIES, static_publish: true, shell: true },
};
const narrowed = buildPageEditAgentPolicy(base);
assert.deepEqual(narrowed.extensionOverrides?.[0]?.available_tools, ['shell']);
});
test('sandboxMcpTools returns correct tool list based on capabilities', () => {
const base = { ...DEFAULT_USER_CAPABILITIES, static_publish: true };
assert.deepEqual(sandboxMcpTools(base), ['read_file', 'write_file', 'edit_file', 'create_dir']);
const withBrowse = { ...base, code_browse: true };
assert.ok(sandboxMcpTools(withBrowse).includes('list_dir'));
const withShell = { ...base, shell: true };
assert.ok(sandboxMcpTools(withShell).includes('list_dir'));
});
test('static_publish with sandboxMcp uses stdio sandbox-fs extension instead of developer', () => {
const caps = { ...DEFAULT_USER_CAPABILITIES, static_publish: true };
const sandboxMcp = { serverPath: '/opt/h5/mindspace-sandbox-mcp.mjs', sandboxRoot: '/opt/h5/MindSpace/abc123' };
const policy = buildAgentExtensionPolicy(caps, { sandboxMcp });
const sandboxExt = policy.extensionOverrides.find((ext) => ext.name === 'sandbox-fs');
assert.ok(sandboxExt, 'sandbox-fs extension should be present');
assert.equal(sandboxExt.type, 'stdio');
assert.equal(sandboxExt.envs.SANDBOX_ROOT, '/opt/h5/MindSpace/abc123');
assert.equal(sandboxExt.args[1], '/opt/h5/MindSpace/abc123'); // also passed as argv[2]
assert.ok(sandboxExt.available_tools.includes('write_file'));
assert.ok(sandboxExt.available_tools.includes('read_file'));
// built-in developer extension should only remain for read_image (image_read: true by default)
const developer = policy.extensionOverrides.find((ext) => ext.name === 'developer');
assert.ok(developer, 'developer should remain for read_image');
assert.deepEqual(developer.available_tools, ['read_image']);
// no full developer write/edit/shell in extensions
const allTools = policy.extensionOverrides.flatMap((e) => e.available_tools ?? []);
assert.ok(!allTools.includes('write'), 'built-in write should not be exposed');
assert.ok(!allTools.includes('shell'), 'shell should not be exposed');
});