File tree Expand file tree Collapse file tree
apps/sim/lib/copilot/tools/handlers Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -328,6 +328,35 @@ describe('vfs handlers oversize policy', () => {
328328 expect ( result ) . toEqual ( { success : false , error } )
329329 } )
330330
331+ it ( 'does not expose dynamic file read errors when provenance cannot be verified' , async ( ) => {
332+ const vfs = makeVfs ( )
333+ const error = 'Document compiler not configured (MOTHERSHIP_E2B_DOC_TEMPLATE_ID is unset)'
334+ vfs . readFileContentWithProvenance . mockResolvedValue ( {
335+ value : {
336+ content : JSON . stringify ( { ok : false , error } ) ,
337+ totalLines : 1 ,
338+ error,
339+ } ,
340+ file : { fileId : 'file-1' , key : 'workspace/key-1' , context : 'workspace' } ,
341+ } )
342+ getOrMaterializeVFS . mockResolvedValue ( vfs )
343+ importWorkspaceFileSecretProvenanceForModelView . mockResolvedValueOnce ( false )
344+
345+ const result = await executeVfsRead ( { path : 'files/reports/brief.pdf/render' } , GREP_CTX )
346+
347+ expect ( result ) . toEqual ( {
348+ success : false ,
349+ error :
350+ 'This file result cannot be shared safely because its secret provenance is unavailable.' ,
351+ } )
352+ expect ( importWorkspaceFileSecretProvenanceForModelView ) . toHaveBeenCalledWith (
353+ expect . objectContaining ( {
354+ identity : { fileId : 'file-1' , key : 'workspace/key-1' , context : 'workspace' } ,
355+ view : 'derived' ,
356+ } )
357+ )
358+ } )
359+
331360 it ( 'marks a windowed read as a derived provenance view' , async ( ) => {
332361 const vfs = makeVfs ( )
333362 vfs . readFileContentWithProvenance . mockResolvedValue ( {
Original file line number Diff line number Diff line change @@ -405,9 +405,6 @@ export async function executeVfsRead(
405405 : null
406406 const fileContent = fileEnvelope ?. value
407407 if ( fileContent ) {
408- if ( fileContent . error !== undefined ) {
409- return { success : false , error : fileContent . error }
410- }
411408 const isAttachment = hasModelAttachment ( fileContent )
412409 if (
413410 ! isAttachment &&
@@ -445,6 +442,9 @@ export async function executeVfsRead(
445442 'This file result cannot be shared safely because its secret provenance is unavailable.' ,
446443 }
447444 }
445+ if ( fileContent . error !== undefined ) {
446+ return { success : false , error : fileContent . error }
447+ }
448448 logger . debug ( 'vfs_read resolved workspace file' , {
449449 path,
450450 totalLines : fileContent . totalLines ,
You can’t perform that action at this time.
0 commit comments