PoietesCMD

Documentation

Tests and verification

Two kinds of checks exist, and they prove different things.

Automated tests

pnpm test

Runs the server test suite with Vitest against a real PostgreSQL 17 server started for the run (no Docker needed). Each test file gets its own database. What the files cover:

FileCovers
lifecycle.test.tsA task end to end, the plan gate, invalid and unpermitted tool calls, pause at a safe boundary, cancel (queued, running, in-flight request), limits and resuming past them, provider failures, discarded turns
recovery.test.tsSix pollers never claiming the same task; crash after a completed step; crash during a read-only, an idempotent and an external operation; review by retry and by skip; fencing of a worker that lost its lease; shutdown hand-back
approvals.test.tsApproval bound to exact arguments, denial, a changed operation needing a new approval, tampered arguments refused, several approvals in one turn, allowed domains, content that tries to grant itself a tool
memory.test.tsPersistence across a restart, retrieval order and scope, a preference reaching the model and being recorded, deletion and scrubbing, audit references, proposals
scheduler.test.tsCron compilation and time zones, persistence, a due run, two schedulers ticking at once, overlap, missed runs under both policies, pause and edit
tools.test.tsWorkspace path escapes including links, file tools, the CSV parser and statistics, artifact names, address classification, DNS rebinding at connect time, redirects, size and request limits
security.test.tsRedaction in data, logs, events, transcripts and artifacts; encryption of stored keys; password hashing; operation hashes
providers.test.tsBoth adapters through the official SDKs against local stand-ins: request shapes, replay of saved turns, error mapping, abort
api.test.tsSetup token, sessions, CSRF and origin checks, throttling, provider connections never showing connected after a failure, tasks and approvals over HTTP, authenticated artifact access, uploads, event stream replay

In these tests the model is a deterministic double: either a scripted list of turns inside the test, or a local HTTP server that imitates a provider's wire format. They prove the runner, the queue, the tools, the permissions and the adapters' handling of requests and responses. They do not prove anything about a real model.

End-to-end run

pnpm e2e:local

Builds the server, then starts PostgreSQL 17, the API process, a worker process and the rule-based model double, and drives them over HTTP like the console does:

  • A. File summary: upload a text file, run a task, read its events, download the summary.
  • B. CSV report: upload a CSV, check the statistics computed by the tool, check the report quotes them.
  • C. Memory reuse: save a preference, run a task, check the entry was supplied, recorded and used; delete it.
  • D. Restart recovery: kill the worker process after a completed step, start a new one, check the step was not repeated.
  • E. Scheduled run: create a schedule, keep no client connected, check the scheduler starts the task.
  • F. Approval gate: check a protected write does not proceed until its exact arguments are approved, and that an approved fetch of a cloud-metadata address is still refused.

It also checks cancellation of an in-flight request, the connection test, stored-key encryption, and that no credential appears in any process log.

Console checks

The console was exercised in headless Chrome against pnpm dev and the model double, with the scripts in scripts/flows/: first-run setup with a wrong and a right token, connecting the double through Settings and seeing it become Connected only after the test request, uploading files and a refused upload, workflows A, B, C, E and F from the console pages, the command palette and keyboard focus, the navigation drawer and dialogs at 390 px, and the landing page with reduced motion. Each script is a sequence of clicks and assertions run with pnpm shot; they are a record of what was checked, not part of pnpm test, and they expect a fresh database in the order listed in that folder's README.

Real provider check

OPENAI_API_KEY=... pnpm smoke:provider openai <model-id>
ANTHROPIC_API_KEY=... pnpm smoke:provider anthropic <model-id>
PCMD_LOCAL_BASE_URL=http://localhost:11434/v1 pnpm smoke:provider local <model-id>

One text request and one tool-calling request to a real provider, through the adapters the worker uses. This is the only check that involves a real model. It needs a key and costs a few tokens.

Results for this version

Recorded on the machine this version was built on (Windows 11, Node 24.16, PostgreSQL 17.10 from embedded-postgres).

CheckResult
pnpm typecheckPassed: packages/shared, apps/server (source and tests), apps/web
pnpm testPassed: 117 tests in 9 files, 11 s, against PostgreSQL 17.10
pnpm e2e:localPassed: 54/54 checks (workflows A–F, cancellation, connection test, key encryption, log redaction)
pnpm buildPassed: server bundle (tsup) and console (Next.js 15.5, 30 static pages)
pnpm smoke:provider anthropic claude-sonnet-5-5Passed on 2026-09-30 with the owner's key: text request answered "ready" (1.8 s), tool-calling probe called connection_probe (1.2 s), model list returned 13 models. OpenAI and local endpoints: not run, no key or server available
Real task on Anthropic (claude-sonnet-5-5)Completed on 2026-09-30 through the console: read a text file, ran analyze_csv, wrote briefing.md; 5 model turns, 23 s, 32,044 tokens as reported by the provider
Production at poietescmd.xyz (console on Vercel, backend on the VPS)First-run setup, the Anthropic connection test for both models, two uploads and a real task (claude-sonnet-5-5, 5 turns, 20 s, 30,473 tokens, briefing.md written) completed through the public console on 2026-09-30
docker compose up (server image, deploy/ layout)Run on 2026-09-30 on an Ubuntu 26.04 VPS: the server image built from the Dockerfile, postgres, api, worker and caddy came up healthy on the first attempt; the API is served at https://api.poietescmd.xyz. The bundled web service and the console image have not been built there (the console runs on Vercel)
NextKnown limitations