zara-knowledge: preserve typed provider configuration before Brave dispatch #98

Closed
opened 2026-09-08 02:02:58 +00:00 by nsaspy · 0 comments
Owner

Problem

KnowledgeConfig.load() still coerces provider configuration before the hardened Brave adapter sees it: str() rewrites provider/key/file descriptors, float() accepts boolean timeouts, and int() truncates fractional response/result bounds. That can turn None into a literal credential string or mutate resource policy instead of failing closed.

Slice

  • deterministic RED coverage for malformed provider/API-key/API-key-file descriptor types;
  • reject boolean/non-numeric/non-finite timeout values;
  • require actual non-boolean integer response/result bounds;
  • preserve environment-supplied Brave key strings and secure credential-file behavior;
  • preserve existing provider and numeric bounds;
  • exact-head source/install compatibility, registry/plugin tests, and generated Nix package gates before merge.

Dependency-ready zara-knowledge correctness/security slice. No external todo work.

## Problem `KnowledgeConfig.load()` still coerces provider configuration before the hardened Brave adapter sees it: `str()` rewrites provider/key/file descriptors, `float()` accepts boolean timeouts, and `int()` truncates fractional response/result bounds. That can turn `None` into a literal credential string or mutate resource policy instead of failing closed. ## Slice - deterministic RED coverage for malformed provider/API-key/API-key-file descriptor types; - reject boolean/non-numeric/non-finite timeout values; - require actual non-boolean integer response/result bounds; - preserve environment-supplied Brave key strings and secure credential-file behavior; - preserve existing provider and numeric bounds; - exact-head source/install compatibility, registry/plugin tests, and generated Nix package gates before merge. Dependency-ready `zara-knowledge` correctness/security slice. No external todo work.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
nsaspy/zara-plugins#98
No description provided.