2026-06-02 17:53:47 +01:00
|
|
|
"""Regression: agent_input_token_budget must be settable from chat (not flagged secret)."""
|
|
|
|
|
import asyncio
|
|
|
|
|
import json
|
|
|
|
|
|
|
|
|
|
import src.settings as settings_mod
|
refactor(tools): migrate config/integration admin tools to the registry (#4742)
Part of #3629 (the `admin_tools.py` bullet). Moves the config/integration admin
tools off the legacy elif dispatch chain in tool_implementations.py onto the
agent_tools registry:
manage_endpoints, manage_mcp, manage_webhooks, manage_tokens, manage_settings
The do_* implementations (and manage_mcp's command-allowlist / RCE guard:
_validate_mcp_command, _mcp_allowed_commands, and the _MCP_* constants) move
verbatim into the new src/agent_tools/admin_tools.py. They register through a
single ADMIN_TOOL_HANDLERS map that TOOL_HANDLERS.update()s, and the five elif
branches plus their imports are dropped from tool_execution.py, so these tools
now flow through _direct_fallback like the other migrated clusters. The names
are re-exported from src.agent_tools for back-compat.
Dedup:
- _parse_tool_args was duplicated in tool_implementations.py and
document_tools.py. It now lives once in src.tool_utils (which imports nothing
from the project beyond src.constants, so this introduces no cycle) and both
call sites import it from there. The orphaned `import json` in document_tools
is removed with it.
- The five tools share one _owner_adapter(fn) factory that threads ctx["owner"]
into the owner-taking do_* signature, instead of five near-identical wrappers.
Tests: new tests/test_admin_tools_registry.py pins the registration, the
re-export back-compat, the owner-threading adapter, and the single-source
_parse_tool_args (across admin_tools and document_tools). Existing MCP /
settings / webhook suites are repointed at the new module.
2026-06-24 09:29:10 +02:00
|
|
|
from src.agent_tools.admin_tools import do_manage_settings
|
2026-06-02 17:53:47 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_set_token_budget_is_not_refused_as_secret(monkeypatch):
|
|
|
|
|
store = {}
|
|
|
|
|
monkeypatch.setattr(settings_mod, "load_settings", lambda: dict(store))
|
|
|
|
|
monkeypatch.setattr(settings_mod, "save_settings", lambda s: store.update(s))
|
|
|
|
|
|
|
|
|
|
result = asyncio.run(do_manage_settings(json.dumps({
|
|
|
|
|
"action": "set", "key": "agent_input_token_budget", "value": 8000,
|
|
|
|
|
})))
|
|
|
|
|
|
|
|
|
|
# The "token" substring used to flag this int setting as a credential and
|
|
|
|
|
# refuse to set it (even though there's a deliberate "token budget" alias).
|
|
|
|
|
assert "credential" not in result.get("response", "").lower(), result
|
|
|
|
|
assert result.get("exit_code") == 0, result
|
|
|
|
|
assert store.get("agent_input_token_budget") == 8000
|