mirror of
https://github.com/bytedance/deer-flow.git
synced 2026-07-28 17:06:05 +00:00
* feat: add lark cli integration * fix: polish lark integration actions * feat: support lark incremental permissions * fix: detect lark authorization completion * fix: harden lark integration install * feat: expand lark auth scopes and reuse host auth in sandbox Default lark auth to least-privilege (recommend=false, base sign-in only) and expose the full set of lark-cli --domain business domains as native --domain grants instead of a 4-domain read-only mapping. Resolve the skill pack from the latest larksuite/cli GitHub release at install time with content-hash integrity, and surface version/runtime drift in status. Share the per-user lark-cli config/data profile between the Gateway Settings auth flow and agent conversations by mounting the integration dirs into the AIO sandbox and injecting the matching env for lark-cli commands, with an allowlisted extra_mounts path in the provisioner/K8s backend and traversal guards on integration paths. * style: fix lint issues from ruff and prettier Sort imports in the provisioner PVC test and re-wrap two long i18n description strings to satisfy backend ruff and frontend prettier CI. * fix(lark): address managed integration review feedback * fix(frontend): stabilize integrations settings e2e * test(sandbox): isolate remote backend legacy visibility check * test: fix backend unit failures after merge * Harden Lark integration review fixes * Format Lark integration E2E test * fix(lark): harden sandbox credential exposure and status disclosure Address willem_bd's security review on PR #3971: - Mount the per-user lark-cli config dir (long-lived appSecret) read-only into the AIO sandbox; only the refreshable-token data dir stays writable. - Redact host filesystem paths (install_path, cli.path) from GET /lark/status and the config/auth complete responses for non-admin callers, fail-closed on any auth error. - Document the npm postinstall trade-off (--ignore-scripts is not viable because @larksuite/cli fetches its platform binary in postinstall). - Document the sandbox credential trust boundary in AGENTS.md and README, pointing at the sidecar-broker follow-up (#4338). --------- Co-authored-by: Willem Jiang <willem.jiang@gmail.com>
58 lines
1.5 KiB
TypeScript
58 lines
1.5 KiB
TypeScript
import { afterEach, expect, test } from "@rstest/core";
|
|
|
|
import {
|
|
getSettingsDialogSnapshot,
|
|
openSettingsDialog,
|
|
setSettingsDialogOpen,
|
|
subscribeSettingsDialog,
|
|
} from "@/components/workspace/settings/settings-dialog-store";
|
|
|
|
afterEach(() => {
|
|
// Reset shared module state between tests.
|
|
setSettingsDialogOpen(false);
|
|
});
|
|
|
|
test("starts closed on the default section", () => {
|
|
expect(getSettingsDialogSnapshot()).toEqual({
|
|
open: false,
|
|
section: "appearance",
|
|
});
|
|
});
|
|
|
|
test("openSettingsDialog opens on the requested section", () => {
|
|
openSettingsDialog("integrations");
|
|
expect(getSettingsDialogSnapshot()).toEqual({
|
|
open: true,
|
|
section: "integrations",
|
|
});
|
|
});
|
|
|
|
test("setSettingsDialogOpen(false) keeps the last section", () => {
|
|
openSettingsDialog("channels");
|
|
setSettingsDialogOpen(false);
|
|
expect(getSettingsDialogSnapshot()).toEqual({
|
|
open: false,
|
|
section: "channels",
|
|
});
|
|
});
|
|
|
|
test("notifies subscribers only on real state changes", () => {
|
|
let notifications = 0;
|
|
const unsubscribe = subscribeSettingsDialog(() => {
|
|
notifications += 1;
|
|
});
|
|
|
|
openSettingsDialog("integrations");
|
|
// Opening again on the same section is a no-op and must not re-notify.
|
|
openSettingsDialog("integrations");
|
|
expect(notifications).toBe(1);
|
|
|
|
openSettingsDialog("memory");
|
|
expect(notifications).toBe(2);
|
|
|
|
unsubscribe();
|
|
openSettingsDialog("about");
|
|
// No further notifications after unsubscribe.
|
|
expect(notifications).toBe(2);
|
|
});
|