feat(credentials): abstract credential seam (ctx.credentials)

References-not-values doctrine: settings carry env-shaped CredentialRefs,
providers own storage. Per-operation resolve, UI-safe describe, fail-loud
set/unset under read-only shadowing, credentials/updated commit event with
a live-service invariant.
This commit is contained in:
Yichen Jiang
2026-07-29 13:03:12 +08:00
parent ba37180946
commit 3a794495ad
12 changed files with 479 additions and 0 deletions

View File

@@ -0,0 +1,37 @@
import { describe, expect, it } from 'vitest'
import { Context } from 'cordis'
import InvariantService from '@deepseek-ai/dsh-invariants'
import { credentialRef } from '../src/index.ts'
import * as CredentialsInvariant from '../src/invariant.ts'
import { MemoryCredentials } from './memory.ts'
const REF = credentialRef('DEEPSEEK_API_KEY')
describe('credentials invariant companion', () => {
it('accepts a committed change emitted by a live service', async () => {
const ctx = new Context()
await ctx.plugin(InvariantService)
await ctx.plugin(CredentialsInvariant)
await ctx.plugin(MemoryCredentials)
await expect(ctx.credentials.set(REF, 'sk-live')).resolves.toBeUndefined()
})
it('fails an update event emitted without a live service', async () => {
const ctx = new Context()
await ctx.plugin(InvariantService)
await ctx.plugin(CredentialsInvariant)
expect(() => { ctx.emit('credentials/updated', REF) }).toThrow(/invariant violated by "@deepseek-ai\/dsh-credentials"/)
})
it('reserves the package name against duplicate registration', async () => {
const ctx = new Context()
await ctx.plugin(InvariantService)
await ctx.plugin(CredentialsInvariant)
expect(() => {
ctx.invariants.register('@deepseek-ai/dsh-credentials', () => {})
}).toThrow(/already registered/)
})
})