+21

![opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>](/assets/img/avatar_default.png)



![opencode-agent[bot] <opencode-agent[bot]@users.noreply.github.com>](/assets/img/avatar_default.png)



James Long
Brendan Allan
Kit Langton
opencode-agent[bot] <opencode-agent[bot]@users.noreply.github.com>
Affan Ali
affanali2k3
Frank
opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>
𝓛𝓲𝓽𝓽𝓵𝓮 𝓕𝓻𝓪𝓷𝓴
Aiden Cline
Jay V
Dax Raad
Aarav Sareen
OpeOginni
Luke Parker
Ben Guthrie
Dax
Filip
Max Anderson
Brendan Allan
Jack
Shoubhit Dash
Dustin Deus
starptech
Aiden Cline
usrnk1
Jay
runvip
opencode
Julian Coy
Vladimir Glafirov
8c94e9005f
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com> Co-authored-by: Kit Langton <kit.langton@gmail.com> Co-authored-by: opencode-agent[bot] <opencode-agent[bot]@users.noreply.github.com> Co-authored-by: Affan Ali <93028901+affanali2k3@users.noreply.github.com> Co-authored-by: affanali2k3 <affanalikhanxx@gmail.com> Co-authored-by: Frank <frank@anoma.ly> Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com> Co-authored-by: 𝓛𝓲𝓽𝓽𝓵𝓮 𝓕𝓻𝓪𝓷𝓴 <little-frank@opencord.local> Co-authored-by: Aiden Cline <63023139+rekram1-node@users.noreply.github.com> Co-authored-by: Jay V <air@live.ca> Co-authored-by: Dax Raad <d@ironbay.co> Co-authored-by: Aarav Sareen <96787824+arvsrn@users.noreply.github.com> Co-authored-by: OpeOginni <107570612+OpeOginni@users.noreply.github.com> Co-authored-by: Luke Parker <10430890+Hona@users.noreply.github.com> Co-authored-by: Ben Guthrie <benjee.012@gmail.com> Co-authored-by: Dax <mail@thdxr.com> Co-authored-by: Filip <34747899+neriousy@users.noreply.github.com> Co-authored-by: Max Anderson <max.a.anderson95@gmail.com> Co-authored-by: Brendan Allan <git@brendonovich.dev> Co-authored-by: Jack <jack@anoma.ly> Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com> Co-authored-by: Dustin Deus <deusdustin@gmail.com> Co-authored-by: starptech <starptech@starptechs-MBP.fritz.box> Co-authored-by: Aiden Cline <aidenpcline@gmail.com> Co-authored-by: usrnk1 <7547651+usrnk1@users.noreply.github.com> Co-authored-by: Jay <53023+jayair@users.noreply.github.com> Co-authored-by: runvip <164729189+runvip@users.noreply.github.com> Co-authored-by: opencode <opencode@sst.dev> Co-authored-by: Julian Coy <julian@ex-machina.co> Co-authored-by: Vladimir Glafirov <vglafirov@gitlab.com>
86 lines
2.6 KiB
TypeScript
86 lines
2.6 KiB
TypeScript
import { describe, expect } from "bun:test"
|
|
import { Effect, Layer } from "effect"
|
|
import { AppNodeBuilder } from "@opencode-ai/core/effect/app-node-builder"
|
|
import { Location } from "@opencode-ai/core/location"
|
|
import { Policy } from "@opencode-ai/core/policy"
|
|
import { AbsolutePath } from "@opencode-ai/core/schema"
|
|
import { location } from "./fixture/location"
|
|
import { testEffect } from "./lib/effect"
|
|
|
|
const it = testEffect(
|
|
AppNodeBuilder.build(Policy.node, [
|
|
[
|
|
Location.node,
|
|
Layer.succeed(Location.Service, Location.Service.of(location({ directory: AbsolutePath.make("test") }))),
|
|
],
|
|
]),
|
|
)
|
|
|
|
describe("Policy", () => {
|
|
it.effect("returns the caller's fallback when no statement matches", () =>
|
|
Effect.gen(function* () {
|
|
const policy = yield* Policy.Service
|
|
|
|
expect(yield* policy.evaluate("provider.use", "anthropic", "allow")).toBe("allow")
|
|
expect(yield* policy.evaluate("provider.use", "anthropic", "deny")).toBe("deny")
|
|
}),
|
|
)
|
|
|
|
it.effect("evaluates wildcard provider rules in written order", () =>
|
|
Effect.gen(function* () {
|
|
const policy = yield* Policy.Service
|
|
yield* policy.load([
|
|
new Policy.Info({
|
|
effect: "deny",
|
|
action: "provider.*",
|
|
resource: "*",
|
|
}),
|
|
new Policy.Info({
|
|
effect: "allow",
|
|
action: "provider.use",
|
|
resource: "anthropic",
|
|
}),
|
|
])
|
|
|
|
expect(yield* policy.evaluate("provider.use", "anthropic", "allow")).toBe("allow")
|
|
expect(yield* policy.evaluate("provider.use", "openai", "allow")).toBe("deny")
|
|
}),
|
|
)
|
|
|
|
it.effect("matches action and resource independently", () =>
|
|
Effect.gen(function* () {
|
|
const policy = yield* Policy.Service
|
|
yield* policy.load([
|
|
new Policy.Info({
|
|
effect: "deny",
|
|
action: "provider.*",
|
|
resource: "company-*",
|
|
}),
|
|
])
|
|
|
|
expect(yield* policy.evaluate("provider.use", "company-stable", "allow")).toBe("deny")
|
|
expect(yield* policy.evaluate("plugin.load", "company-stable", "allow")).toBe("allow")
|
|
}),
|
|
)
|
|
|
|
it.effect("uses the last matching loaded statement", () =>
|
|
Effect.gen(function* () {
|
|
const policy = yield* Policy.Service
|
|
yield* policy.load([
|
|
new Policy.Info({
|
|
effect: "allow",
|
|
action: "provider.use",
|
|
resource: "openai",
|
|
}),
|
|
new Policy.Info({
|
|
effect: "deny",
|
|
action: "provider.use",
|
|
resource: "openai",
|
|
}),
|
|
])
|
|
|
|
expect(yield* policy.evaluate("provider.use", "openai", "allow")).toBe("deny")
|
|
}),
|
|
)
|
|
})
|