test: align Docker auth expectation with key policy

Co-authored-by: openhands <openhands@all-hands.dev>
This commit is contained in:
neubig
2026-08-30 01:44:17 +00:00
co-authored by openhands
parent 5747dc3e56
commit 88acaa8499
2 changed files with 7 additions and 6 deletions
+2 -4
View File
@@ -77,6 +77,7 @@ const MOCK_LLM_PYTHON = process.env.MOCK_LLM_PYTHON ?? "python3";
process.env.MOCK_LLM_BACKEND_URL = `http://localhost:${INGRESS_PORT}`;
process.env.MOCK_LLM_PORT = MOCK_LLM_PORT;
process.env.MOCK_LLM_PUBLIC_MODE_URL = `http://localhost:${PUBLIC_MODE_PORT}`;
process.env.MOCK_LLM_DOCKER_MODE = "true";
process.env.VITE_SESSION_API_KEY = sessionApiKey;
// MOCK_LLM_AGENT_URL — the URL the agent-server inside Docker uses to
@@ -150,10 +151,7 @@ export default defineConfig({
globalTimeout: process.env.CI ? ciGlobalTimeoutMs : 0, // 20 min hard cap in CI
reporter: [
["line"],
[
"json",
{ outputFile: "test-results-mock-llm-docker/results.json" },
],
["json", { outputFile: "test-results-mock-llm-docker/results.json" }],
[
"html",
{
@@ -99,13 +99,16 @@ test.describe("auth mode: fresh install with runtime-injected key", () => {
});
expect(settingsResp.ok()).toBe(true);
// Sanity check: the runtime key landed on the window global.
// Docker's externally reachable listener must not expose the key. The
// loopback-only npm launcher injects it for the local first-run path.
const injected = await page.evaluate(
() =>
(window as unknown as Record<string, unknown>)
.__AGENT_CANVAS_SESSION_API_KEY__,
);
expect(injected).toBe(SESSION_API_KEY);
expect(injected).toBe(
process.env.MOCK_LLM_DOCKER_MODE ? undefined : SESSION_API_KEY,
);
});
});