1+ import { createEmbeddedClient } from 'sim/embed'
12import { describe , expect , it } from 'vitest'
3+ import { runEngine } from '@/lib/mothership/agent-cli/engines'
24import { isReadOnlyCliRequest , readOnlyCliTransport } from '@/lib/mothership/agent-cli/read-only'
35
46describe ( 'benchmark reference workspace inspection' , ( ) => {
@@ -49,7 +51,7 @@ describe('benchmark reference workspace inspection', () => {
4951 }
5052 )
5153
52- it . each ( [ '/api/v2/secrets' , '/api/v2/secrets?cursor=next' , '/api/v2/secrets /name'] ) (
54+ it . each ( [ '/api/v2/secrets/name' ] ) (
5355 'refuses credential values from %s before contacting the source' ,
5456 async ( path ) => {
5557 let dispatched = false
@@ -62,6 +64,67 @@ describe('benchmark reference workspace inspection', () => {
6264 }
6365 )
6466
67+ it ( 'preserves secret metadata and pagination without returning even visible values' , async ( ) => {
68+ const metadata = {
69+ name : 'EXAMPLE_REFERENCE' ,
70+ scope : 'workspace' ,
71+ description : null ,
72+ unredacted : true ,
73+ role : 'admin' ,
74+ createdAt : '2026-01-01T00:00:00.000Z' ,
75+ updatedAt : '2026-01-01T00:00:00.000Z' ,
76+ }
77+ const transport = readOnlyCliTransport ( async ( ) =>
78+ Response . json ( {
79+ data : [ { ...metadata , value : 'private-fixture-value' } ] ,
80+ nextCursor : 'next-page' ,
81+ } )
82+ )
83+ const response = await transport ( 'https://sim.test/api/v2/secrets?cursor=first-page' )
84+ expect ( response . status ) . toBe ( 200 )
85+ expect ( await response . json ( ) ) . toEqual ( { data : [ metadata ] , nextCursor : 'next-page' } )
86+ } )
87+
88+ it ( 'lets the real grep engine search paginated secret names through benchmark transport' , async ( ) => {
89+ const transport = readOnlyCliTransport ( async ( input ) => {
90+ const last = new URL ( new Request ( input ) . url ) . searchParams . get ( 'cursor' ) === 'next-page'
91+ return Response . json ( {
92+ data : [
93+ {
94+ name : last ? 'EXAMPLE_SECOND' : 'EXAMPLE_FIRST' ,
95+ scope : 'workspace' ,
96+ description : null ,
97+ unredacted : true ,
98+ role : 'admin' ,
99+ value : 'private-fixture-value' ,
100+ createdAt : '2026-01-01T00:00:00.000Z' ,
101+ updatedAt : '2026-01-01T00:00:00.000Z' ,
102+ } ,
103+ ] ,
104+ nextCursor : last ? null : 'next-page' ,
105+ } )
106+ } )
107+ const result = await runEngine (
108+ 'grep' ,
109+ [ 'EXAMPLE_' ] ,
110+ {
111+ userId : 'user-1' ,
112+ workspaceId : 'workspace' ,
113+ client : createEmbeddedClient ( {
114+ endpoint : 'https://sim.test' ,
115+ apiKey : 'fixture' ,
116+ workspaceId : 'workspace' ,
117+ transport,
118+ } ) ,
119+ } ,
120+ { scope : 'secrets' }
121+ )
122+ expect ( result . exitCode ) . toBe ( 0 )
123+ expect ( result . stdout ) . toContain ( 'EXAMPLE_FIRST' )
124+ expect ( result . stdout ) . toContain ( 'EXAMPLE_SECOND' )
125+ expect ( result . stdout ) . not . toContain ( 'private-fixture-value' )
126+ } )
127+
65128 it ( 'retains paginated reads and table queries without allowing lookalike mutation paths' , async ( ) => {
66129 const transport = readOnlyCliTransport ( async ( ) => Response . json ( { data : 'authorized result' } ) )
67130 for ( const path of [ '/api/v2/workflows?cursor=next' , '/api/v2/tables/table' ] ) {
0 commit comments