- 1
use serde_json::json; - 2
use vak_agent::{ApprovalMode, auto_approve}; - 3
use vak_permission::{AskSource, Mode}; - 4
- 5
#[test] - 6
fn approve_safe_never_bypasses_explicit_rules_or_circuit_breaker() - 7
-> Result<(), Box<dyn std::error::Error>> { - 8
let cwd = tempfile::tempdir()?; - 9
let input = json!({"path": "file.txt"}); - 10
- 11
assert!(!auto_approve( - 12
ApprovalMode::ApproveSafe, - 13
AskSource::Rule, - 14
"write", - 15
&input, - 16
Mode::WorkspaceWrite, - 17
true, - 18
cwd.path(), - 19
)); - 20
assert!(!auto_approve( - 21
ApprovalMode::ApproveSafe, - 22
AskSource::CircuitBreaker, - 23
"read", - 24
&input, - 25
Mode::ReadOnly, - 26
true, - 27
cwd.path(), - 28
)); - 29
assert!(!auto_approve( - 30
ApprovalMode::AutoApprove, - 31
AskSource::CircuitBreaker, - 32
"read", - 33
&input, - 34
Mode::ReadOnly, - 35
true, - 36
cwd.path(), - 37
)); - 38
Ok(()) - 39
} - 40
- 41
#[test] - 42
fn approve_safe_rejects_paths_that_escape_the_workspace() -> Result<(), Box<dyn std::error::Error>> - 43
{ - 44
let cwd = tempfile::tempdir()?; - 45
let input = json!({"path": "../outside.txt"}); - 46
- 47
assert!(!auto_approve( - 48
ApprovalMode::ApproveSafe, - 49
AskSource::Scope, - 50
"write", - 51
&input, - 52
Mode::WorkspaceWrite, - 53
true, - 54
cwd.path(), - 55
)); - 56
Ok(()) - 57
} - 58
- 59
/// An approver that refuses without consulting anyone must say so. - 60
/// - 61
/// `AutoDeny` used to produce "denied by user: ..." on unattended - 62
/// surfaces. No user was asked — the gate was never put to a person — and - 63
/// the wording sent the model looking for a substitute tool and the - 64
/// operator looking for a decision nobody made. The refusal is the same; - 65
/// only the attribution is corrected. - 66
#[test] - 67
fn an_unanswerable_approver_does_not_blame_a_user() { - 68
assert!( - 69
!vak_agent::Approver::answerable(&vak_agent::AutoDeny), - 70
"AutoDeny consults no one and must not claim to be answerable" - 71
); - 72
assert!( - 73
vak_agent::Approver::answerable(&vak_agent::AutoApprove), - 74
"AutoApprove resolves gates, so it is answerable" - 75
); - 76
} - 77
Indexing the workspace…
Vakyartha documentation is discovering safe artifacts, anchors, and source references.