Files
openclaw/extensions/tavily/src/config.test.ts
VACInc 092bd16b79 fix: resolve Tavily SecretRefs in agent tools (#97827)
* fix(tools): preserve resolved search credentials

Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>

Co-authored-by: Karol Zalewski <karol.zalewski@4zal.net>

* test(agents): isolate Tool Search runtime config coverage

* test(agents): isolate Tool Search runtime config coverage

* test(agents): isolate Tool Search runtime config coverage

* test(agents): isolate Tool Search runtime config coverage

* fix(tools): restore reviewed search credential delta

* docs(changelog): defer release-owned entry

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Karol Zalewski <karol.zalewski@4zal.net>
2026-07-15 03:56:12 -07:00

116 lines
2.6 KiB
TypeScript

import type { OpenClawConfig } from "openclaw/plugin-sdk/config-contracts";
import { afterEach, describe, expect, it, vi } from "vitest";
import { resolveTavilyApiKey } from "./config.js";
function configWithApiKey(apiKey: unknown, extra?: Partial<OpenClawConfig>): OpenClawConfig {
return {
...extra,
plugins: {
entries: {
tavily: {
config: {
webSearch: {
apiKey,
},
},
},
},
},
} as OpenClawConfig;
}
describe("resolveTavilyApiKey", () => {
afterEach(() => {
vi.unstubAllEnvs();
});
it("falls back to process.env.TAVILY_API_KEY for a matching unresolved env SecretRef", () => {
vi.stubEnv("TAVILY_API_KEY", "dummy");
expect(
resolveTavilyApiKey(
configWithApiKey({
source: "env",
provider: "default",
id: "TAVILY_API_KEY",
}),
),
).toBe("dummy");
});
it("allows a configured env provider when its allowlist includes TAVILY_API_KEY", () => {
vi.stubEnv("TAVILY_API_KEY", "dummy");
expect(
resolveTavilyApiKey(
configWithApiKey(
{
source: "env",
provider: "managed-env",
id: "TAVILY_API_KEY",
},
{
secrets: {
providers: {
"managed-env": {
source: "env",
allowlist: ["TAVILY_API_KEY"],
},
},
},
} as Partial<OpenClawConfig>,
),
),
).toBe("dummy");
});
it.each([
{
name: "file SecretRef",
apiKey: {
source: "file",
provider: "default",
id: "/etc/secrets/tavily",
},
},
{
name: "exec SecretRef",
apiKey: {
source: "exec",
provider: "default",
id: "TAVILY_API_KEY",
},
},
{
name: "different env id",
apiKey: {
source: "env",
provider: "default",
id: "OTHER_API_KEY",
},
},
{
name: "env provider with a blocking allowlist",
apiKey: {
source: "env",
provider: "managed-env",
id: "TAVILY_API_KEY",
},
extra: {
secrets: {
providers: {
"managed-env": {
source: "env",
allowlist: [],
},
},
},
} as Partial<OpenClawConfig>,
},
])("does not fall back to process.env.TAVILY_API_KEY for $name", ({ apiKey, extra }) => {
vi.stubEnv("TAVILY_API_KEY", "dummy");
expect(resolveTavilyApiKey(configWithApiKey(apiKey, extra))).toBeUndefined();
});
});