From 7818cac342b15ad4ad382ef6f53a12b89b06a3da Mon Sep 17 00:00:00 2001 From: can1357 Date: Fri, 31 Jul 2026 19:00:39 +0200 Subject: [PATCH] test(ai): scope Bedrock auth bypass to stream calls --- .../ai/test/bedrock-inference-profile.test.ts | 18 ++---------------- packages/ai/test/bedrock-prompt-cache.test.ts | 18 ++---------------- packages/ai/test/bedrock-system-prompt.test.ts | 18 ++---------------- 3 files changed, 6 insertions(+), 48 deletions(-) diff --git a/packages/ai/test/bedrock-inference-profile.test.ts b/packages/ai/test/bedrock-inference-profile.test.ts index 49755fe71..88a1e76e5 100644 --- a/packages/ai/test/bedrock-inference-profile.test.ts +++ b/packages/ai/test/bedrock-inference-profile.test.ts @@ -1,25 +1,10 @@ -import { afterAll, beforeAll, describe, expect, test } from "bun:test"; +import { describe, expect, test } from "bun:test"; import { streamBedrock } from "@oh-my-pi/pi-ai/providers/amazon-bedrock"; import type { Context, FetchImpl, Model } from "@oh-my-pi/pi-ai/types"; import { buildModel } from "@oh-my-pi/pi-catalog/build"; import { Effort } from "@oh-my-pi/pi-catalog/effort"; import { withEnv } from "./helpers"; -// These suites capture the request payload from a fire-and-forget stream, so a -// credential lookup that rejects after the test ends surfaces as an unhandled -// error against whatever runs next. Skip Bedrock auth: the payload is built -// before signing and no request leaves the process. -const originalSkipAuth = process.env.AWS_BEDROCK_SKIP_AUTH; - -beforeAll(() => { - process.env.AWS_BEDROCK_SKIP_AUTH = "1"; -}); - -afterAll(() => { - if (originalSkipAuth === undefined) delete process.env.AWS_BEDROCK_SKIP_AUTH; - else process.env.AWS_BEDROCK_SKIP_AUTH = originalSkipAuth; -}); - const profileArn = "arn:aws:bedrock:us-east-2:1234567890:application-inference-profile/company-opus-48"; const profileModel: Model<"bedrock-converse-stream"> = buildModel({ id: profileArn, @@ -100,6 +85,7 @@ describe("Bedrock inference profile ARNs", () => { const { promise, resolve } = Promise.withResolvers(); void streamBedrock(profileModel, context, { + bearerToken: "test-token", signal: controller.signal, reasoning: Effort.High, maxTokens: 16, diff --git a/packages/ai/test/bedrock-prompt-cache.test.ts b/packages/ai/test/bedrock-prompt-cache.test.ts index 8b85e3798..e456b6c86 100644 --- a/packages/ai/test/bedrock-prompt-cache.test.ts +++ b/packages/ai/test/bedrock-prompt-cache.test.ts @@ -1,25 +1,10 @@ -import { afterAll, beforeAll, describe, expect, test } from "bun:test"; +import { describe, expect, test } from "bun:test"; import { streamBedrock } from "@oh-my-pi/pi-ai/providers/amazon-bedrock"; import type { Context, Model } from "@oh-my-pi/pi-ai/types"; import { buildModel } from "@oh-my-pi/pi-catalog/build"; import { getBundledModel } from "@oh-my-pi/pi-catalog/models"; import { withEnv } from "./helpers"; -// These suites capture the request payload from a fire-and-forget stream, so a -// credential lookup that rejects after the test ends surfaces as an unhandled -// error against whatever runs next. Skip Bedrock auth: the payload is built -// before signing and no request leaves the process. -const originalSkipAuth = process.env.AWS_BEDROCK_SKIP_AUTH; - -beforeAll(() => { - process.env.AWS_BEDROCK_SKIP_AUTH = "1"; -}); - -afterAll(() => { - if (originalSkipAuth === undefined) delete process.env.AWS_BEDROCK_SKIP_AUTH; - else process.env.AWS_BEDROCK_SKIP_AUTH = originalSkipAuth; -}); - interface CachePoint { cachePoint: { type: "default"; ttl?: "1h" }; } @@ -63,6 +48,7 @@ function capturePayload( ): Promise { const { promise, resolve } = Promise.withResolvers(); void streamBedrock(bedrockModel, context, { + bearerToken: "test-token", signal: abortedSignal(), cacheRetention, onPayload: payload => { diff --git a/packages/ai/test/bedrock-system-prompt.test.ts b/packages/ai/test/bedrock-system-prompt.test.ts index 0fd6b9c64..aaa79327f 100644 --- a/packages/ai/test/bedrock-system-prompt.test.ts +++ b/packages/ai/test/bedrock-system-prompt.test.ts @@ -1,23 +1,8 @@ -import { afterAll, beforeAll, describe, expect, test } from "bun:test"; +import { describe, expect, test } from "bun:test"; import { streamBedrock } from "@oh-my-pi/pi-ai/providers/amazon-bedrock"; import type { Context, Model } from "@oh-my-pi/pi-ai/types"; import { buildModel } from "@oh-my-pi/pi-catalog/build"; -// These suites capture the request payload from a fire-and-forget stream, so a -// credential lookup that rejects after the test ends surfaces as an unhandled -// error against whatever runs next. Skip Bedrock auth: the payload is built -// before signing and no request leaves the process. -const originalSkipAuth = process.env.AWS_BEDROCK_SKIP_AUTH; - -beforeAll(() => { - process.env.AWS_BEDROCK_SKIP_AUTH = "1"; -}); - -afterAll(() => { - if (originalSkipAuth === undefined) delete process.env.AWS_BEDROCK_SKIP_AUTH; - else process.env.AWS_BEDROCK_SKIP_AUTH = originalSkipAuth; -}); - interface Payload { system?: Array<{ text: string } | { cachePoint: unknown }>; } @@ -52,6 +37,7 @@ async function capturePayload(systemPrompt: Context["systemPrompt"]): Promise(); const stream = streamBedrock(model(), context, { + bearerToken: "test-token", signal: abortedSignal(), onPayload: payload => { resolve(payload as Payload);