diff --git a/tests/integration/agent-bridge-bypass-flow.test.ts b/tests/integration/agent-bridge-bypass-flow.test.ts new file mode 100644 index 0000000000..9abe58e3b5 --- /dev/null +++ b/tests/integration/agent-bridge-bypass-flow.test.ts @@ -0,0 +1,160 @@ +/** + * Integration tests: AgentBridge bypass patterns flow + * + * Covers: + * - POST /api/tools/agent-bridge/bypass → stores user patterns + * - GET /api/tools/agent-bridge/bypass → shows default + user patterns + * - DELETE /api/tools/agent-bridge/bypass?pattern=X → removes a pattern + */ +import test from "node:test"; +import assert from "node:assert/strict"; +import fs from "node:fs"; +import os from "node:os"; +import path from "node:path"; + +const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-ab-bypass-")); +process.env.DATA_DIR = TEST_DATA_DIR; +process.env.DISABLE_SQLITE_AUTO_BACKUP = "true"; + +const core = await import("../../src/lib/db/core.ts"); +const { seedDefaultBypassPatterns } = await import("../../src/lib/db/agentBridgeBypass.ts"); +const bypassRoute = await import("../../src/app/api/tools/agent-bridge/bypass/route.ts"); + +const DEFAULT_PATTERNS = [".bank.", ".gov.", "okta.com", "auth0.com"]; + +function resetDb() { + core.resetDbInstance(); + fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true }); + fs.mkdirSync(TEST_DATA_DIR, { recursive: true }); +} + +test.beforeEach(() => { + resetDb(); + seedDefaultBypassPatterns(DEFAULT_PATTERNS); +}); + +test.after(() => { + try { fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true }); } catch { /* noop */ } +}); + +// ── POST patterns ────────────────────────────────────────────────────────── + +test("POST /bypass: stores user patterns", async () => { + const res = await bypassRoute.POST( + new Request("http://localhost/api/tools/agent-bridge/bypass", { + method: "POST", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ patterns: ["*.mycompany.com", "internal.corp"] }), + }) + ); + assert.equal(res.status, 200); + const body = await res.json() as { ok: boolean; patterns: Array<{ pattern: string; source: string }> }; + assert.equal(body.ok, true); + assert.ok(Array.isArray(body.patterns)); + const userPatterns = body.patterns.filter((p) => p.source === "user"); + assert.equal(userPatterns.length, 2); +}); + +test("POST /bypass: invalid body returns 400", async () => { + const res = await bypassRoute.POST( + new Request("http://localhost/", { + method: "POST", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ patterns: "not-an-array" }), + }) + ); + assert.equal(res.status, 400); + const body = await res.json() as Record; + const errMsg = (body.error as Record)?.message as string; + assert.ok(!errMsg.includes("at /"), "stack trace leaked in 400 error"); +}); + +// ── GET patterns ─────────────────────────────────────────────────────────── + +test("GET /bypass: shows default + user patterns", async () => { + // Add user patterns first + await bypassRoute.POST( + new Request("http://localhost/", { + method: "POST", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ patterns: ["*.mycompany.com"] }), + }) + ); + + const res = await bypassRoute.GET(); + assert.equal(res.status, 200); + const body = await res.json() as { patterns: Array<{ pattern: string; source: string }> }; + assert.ok(Array.isArray(body.patterns)); + + const sources = new Set(body.patterns.map((p) => p.source)); + assert.ok(sources.has("default"), "No default patterns in response"); + assert.ok(sources.has("user"), "No user patterns in response"); + + const defaultPatterns = body.patterns.filter((p) => p.source === "default"); + assert.ok(defaultPatterns.length >= DEFAULT_PATTERNS.length); +}); + +test("GET /bypass: error response does not leak stack trace", async () => { + const res = await bypassRoute.GET(); + const text = await res.text(); + assert.ok(!text.includes("at /"), "stack trace leaked in GET /bypass response"); +}); + +// ── DELETE pattern ───────────────────────────────────────────────────────── + +test("DELETE /bypass?pattern=X: removes a user pattern", async () => { + // Add two patterns + await bypassRoute.POST( + new Request("http://localhost/", { + method: "POST", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ patterns: ["*.mycompany.com", "internal.corp"] }), + }) + ); + + // Delete one + const deleteRes = await bypassRoute.DELETE( + new Request("http://localhost/api/tools/agent-bridge/bypass?pattern=internal.corp", { + method: "DELETE", + }) + ); + assert.equal(deleteRes.status, 200); + const deleteBody = await deleteRes.json() as { ok: boolean; patterns: Array<{ pattern: string; source: string }> }; + assert.equal(deleteBody.ok, true); + + // Verify it's gone + const remaining = deleteBody.patterns.filter( + (p) => p.source === "user" && p.pattern === "internal.corp" + ); + assert.equal(remaining.length, 0, "Deleted pattern still present"); + + // Other pattern still present + const kept = deleteBody.patterns.filter( + (p) => p.source === "user" && p.pattern === "*.mycompany.com" + ); + assert.equal(kept.length, 1, "Remaining user pattern is missing"); +}); + +test("DELETE /bypass: missing pattern param returns 400", async () => { + const res = await bypassRoute.DELETE( + new Request("http://localhost/api/tools/agent-bridge/bypass", { + method: "DELETE", + }) + ); + assert.equal(res.status, 400); + const body = await res.json() as Record; + const errMsg = (body.error as Record)?.message as string; + assert.ok(!errMsg.includes("at /"), "stack trace leaked in DELETE 400"); +}); + +test("DELETE /bypass?pattern=X: no-op when pattern not in user list", async () => { + const res = await bypassRoute.DELETE( + new Request( + "http://localhost/api/tools/agent-bridge/bypass?pattern=not-in-list.com", + { method: "DELETE" } + ) + ); + assert.equal(res.status, 200); + const body = await res.json() as { ok: boolean }; + assert.equal(body.ok, true); +}); diff --git a/tests/integration/agent-bridge-cert-flow.test.ts b/tests/integration/agent-bridge-cert-flow.test.ts new file mode 100644 index 0000000000..ee26b9fade --- /dev/null +++ b/tests/integration/agent-bridge-cert-flow.test.ts @@ -0,0 +1,158 @@ +/** + * Integration tests: AgentBridge cert flow + * + * Covers: + * - GET /api/tools/agent-bridge/cert — status (exists + trusted) + * - POST /api/tools/agent-bridge/cert — trust (mocked OS call) + * - GET /api/tools/agent-bridge/cert/download — content-type PEM + * - POST /api/tools/agent-bridge/cert/regenerate — generates cert + */ +import test from "node:test"; +import assert from "node:assert/strict"; +import fs from "node:fs"; +import os from "node:os"; +import path from "node:path"; + +const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-ab-cert-")); +process.env.DATA_DIR = TEST_DATA_DIR; +process.env.DISABLE_SQLITE_AUTO_BACKUP = "true"; + +const certRoute = await import("../../src/app/api/tools/agent-bridge/cert/route.ts"); +const downloadRoute = await import("../../src/app/api/tools/agent-bridge/cert/download/route.ts"); +const regenerateRoute = await import("../../src/app/api/tools/agent-bridge/cert/regenerate/route.ts"); + +function certDir() { + return path.join(TEST_DATA_DIR, "mitm"); +} + +function certFilePath() { + return path.join(certDir(), "server.crt"); +} + +function resetCertDir() { + fs.rmSync(certDir(), { recursive: true, force: true }); + fs.mkdirSync(certDir(), { recursive: true }); +} + +test.beforeEach(() => { + resetCertDir(); +}); + +test.after(() => { + try { fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true }); } catch { /* noop */ } +}); + +// ── GET /cert ───────────────────────────────────────────────────────────── + +test("GET /cert: returns exists:false when no cert file", async () => { + const res = await certRoute.GET(); + assert.equal(res.status, 200); + const body = await res.json() as Record; + assert.equal(body.exists, false); + assert.equal(body.trusted, false); + assert.equal(body.path, null); +}); + +test("GET /cert: returns exists:true when cert file present", async () => { + const fakeCert = "-----BEGIN CERTIFICATE-----\nfake\n-----END CERTIFICATE-----\n"; + fs.writeFileSync(certFilePath(), fakeCert); + + const res = await certRoute.GET(); + assert.equal(res.status, 200); + const body = await res.json() as Record; + assert.equal(body.exists, true); + // trusted may be false in test env (no system store) + assert.ok(typeof body.trusted === "boolean"); + assert.equal(body.path, certFilePath()); +}); + +test("GET /cert: error response does not leak stack trace", async () => { + const res = await certRoute.GET(); + const text = await res.text(); + assert.ok(!text.includes("at /"), "stack trace leaked in GET /cert response"); +}); + +// ── POST /cert (trust — mocked OS) ──────────────────────────────────────── + +test("POST /cert: returns 404 when no cert file", async () => { + const res = await certRoute.POST( + new Request("http://localhost/", { + method: "POST", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ sudoPassword: "" }), + }) + ); + assert.equal(res.status, 404); + const body = await res.json() as Record; + const errMsg = (body.error as Record)?.message as string; + assert.ok(!errMsg.includes("at /"), "stack trace leaked in 404 error message"); +}); + +test("POST /cert: installs trust when cert exists (OS call best-effort)", async () => { + // Write a minimal valid-looking PEM (checkCertInstalled reads it) + const fakePem = `-----BEGIN CERTIFICATE----- +MIIBpDCCAQ2gAwIBAgIUFakeMITMCertForTestingOnlyXX== +-----END CERTIFICATE----- +`; + fs.writeFileSync(certFilePath(), fakePem); + + const res = await certRoute.POST( + new Request("http://localhost/", { + method: "POST", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ sudoPassword: "" }), + }) + ); + + // In test env: installCert may throw because the PEM is fake; we accept + // either 200 (mocked) or 500 (real OS failure) — NOT a 500 with stack trace + const body = await res.json() as Record; + const errMsg = (body.error as Record)?.message as string | undefined; + if (errMsg) { + assert.ok(!errMsg.includes("at /"), "stack trace leaked in POST /cert error"); + } +}); + +// ── GET /cert/download ──────────────────────────────────────────────────── + +test("GET /cert/download: 404 when no cert file", async () => { + const res = await downloadRoute.GET(); + assert.equal(res.status, 404); + const body = await res.json() as Record; + const errMsg = (body.error as Record)?.message as string; + assert.ok(!errMsg.includes("at /"), "stack trace leaked in download 404"); +}); + +test("GET /cert/download: returns PEM content-type when cert exists", async () => { + const fakeCert = "-----BEGIN CERTIFICATE-----\nfake\n-----END CERTIFICATE-----\n"; + fs.writeFileSync(certFilePath(), fakeCert); + + const res = await downloadRoute.GET(); + assert.equal(res.status, 200); + const contentType = res.headers.get("content-type"); + assert.ok( + contentType?.includes("pem") || contentType?.includes("x-pem-file"), + `Unexpected Content-Type: ${contentType}` + ); + const text = await res.text(); + assert.ok(text.includes("BEGIN CERTIFICATE"), "PEM content missing"); +}); + +// ── POST /cert/regenerate ───────────────────────────────────────────────── + +test("POST /cert/regenerate: generates cert and returns paths", async () => { + // generateCert uses 'selfsigned' — in test env this should work + const res = await regenerateRoute.POST(); + + // Acceptable: 200 (cert generated) or 500 (selfsigned not available in test env) + // We just verify: no stack trace in response + const text = await res.text(); + assert.ok(!text.includes("at /"), "stack trace leaked in regenerate response"); + + if (res.status === 200) { + const body = JSON.parse(text) as Record; + assert.equal(body.ok, true); + assert.ok(typeof body.certPath === "string"); + assert.ok(typeof body.keyPath === "string"); + } +}); diff --git a/tests/integration/agent-bridge-mappings.test.ts b/tests/integration/agent-bridge-mappings.test.ts new file mode 100644 index 0000000000..0dec4bb1e4 --- /dev/null +++ b/tests/integration/agent-bridge-mappings.test.ts @@ -0,0 +1,192 @@ +/** + * Integration tests: AgentBridge model mappings round-trip + * + * Covers: + * - PUT /api/tools/agent-bridge/agents/[id]/mappings — replace mappings + * - GET /api/tools/agent-bridge/agents/[id]/mappings — read back + * - Zod 400 on invalid body + * - Error responses do not leak stack traces + */ +import test from "node:test"; +import assert from "node:assert/strict"; +import fs from "node:fs"; +import os from "node:os"; +import path from "node:path"; + +const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-ab-mappings-")); +process.env.DATA_DIR = TEST_DATA_DIR; +process.env.DISABLE_SQLITE_AUTO_BACKUP = "true"; + +const core = await import("../../src/lib/db/core.ts"); +const mappingsRoute = await import( + "../../src/app/api/tools/agent-bridge/agents/[id]/mappings/route.ts" +); + +function resetDb() { + core.resetDbInstance(); + fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true }); + fs.mkdirSync(TEST_DATA_DIR, { recursive: true }); +} + +test.beforeEach(() => { + resetDb(); +}); + +test.after(() => { + try { fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true }); } catch { /* noop */ } +}); + +// ── GET (empty) ──────────────────────────────────────────────────────────── + +test("GET /mappings: returns empty array for new agent", async () => { + const res = await mappingsRoute.GET( + new Request("http://localhost/"), + { params: { id: "copilot" } } + ); + assert.equal(res.status, 200); + const body = await res.json() as { mappings: unknown[] }; + assert.ok(Array.isArray(body.mappings)); + assert.equal(body.mappings.length, 0); +}); + +// ── PUT → GET round-trip ─────────────────────────────────────────────────── + +test("PUT → GET round-trip: stores and retrieves mappings", async () => { + const mappings = [ + { source: "gpt-4o", target: "claude-sonnet-4-5" }, + { source: "gpt-4o-mini", target: "claude-haiku-3" }, + ]; + + const putRes = await mappingsRoute.PUT( + new Request("http://localhost/", { + method: "PUT", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ mappings }), + }), + { params: { id: "copilot" } } + ); + assert.equal(putRes.status, 200); + const putBody = await putRes.json() as { ok: boolean; mappings: Array<{ agent_id: string; source_model: string; target_model: string }> }; + assert.equal(putBody.ok, true); + assert.equal(putBody.mappings.length, 2); + + // GET reads back the same data + const getRes = await mappingsRoute.GET( + new Request("http://localhost/"), + { params: { id: "copilot" } } + ); + assert.equal(getRes.status, 200); + const getBody = await getRes.json() as { mappings: Array<{ source_model: string; target_model: string }> }; + assert.equal(getBody.mappings.length, 2); + + const sources = getBody.mappings.map((m) => m.source_model).sort(); + assert.deepEqual(sources, ["gpt-4o", "gpt-4o-mini"]); + + const targets = getBody.mappings.map((m) => m.target_model).sort(); + assert.deepEqual(targets, ["claude-haiku-3", "claude-sonnet-4-5"]); +}); + +test("PUT: replaces all previous mappings", async () => { + // First PUT + await mappingsRoute.PUT( + new Request("http://localhost/", { + method: "PUT", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ mappings: [{ source: "old-model", target: "old-target" }] }), + }), + { params: { id: "cursor" } } + ); + + // Second PUT — replaces + const putRes = await mappingsRoute.PUT( + new Request("http://localhost/", { + method: "PUT", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ mappings: [{ source: "new-model", target: "new-target" }] }), + }), + { params: { id: "cursor" } } + ); + assert.equal(putRes.status, 200); + + const getRes = await mappingsRoute.GET( + new Request("http://localhost/"), + { params: { id: "cursor" } } + ); + const body = await getRes.json() as { mappings: Array<{ source_model: string }> }; + assert.equal(body.mappings.length, 1); + assert.equal(body.mappings[0].source_model, "new-model"); +}); + +test("PUT: empty mappings array clears all mappings", async () => { + // Add then clear + await mappingsRoute.PUT( + new Request("http://localhost/", { + method: "PUT", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ mappings: [{ source: "x", target: "y" }] }), + }), + { params: { id: "zed" } } + ); + const putRes = await mappingsRoute.PUT( + new Request("http://localhost/", { + method: "PUT", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ mappings: [] }), + }), + { params: { id: "zed" } } + ); + assert.equal(putRes.status, 200); + const body = await putRes.json() as { mappings: unknown[] }; + assert.equal(body.mappings.length, 0); +}); + +// ── Zod validation ───────────────────────────────────────────────────────── + +test("PUT: invalid body (missing mappings) returns 400", async () => { + const res = await mappingsRoute.PUT( + new Request("http://localhost/", { + method: "PUT", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ wrong_key: [] }), + }), + { params: { id: "antigravity" } } + ); + assert.equal(res.status, 400); + const body = await res.json() as Record; + const errMsg = (body.error as Record)?.message as string; + assert.ok(!errMsg.includes("at /"), "stack trace leaked in 400 error"); +}); + +test("PUT: invalid JSON returns 400", async () => { + const res = await mappingsRoute.PUT( + new Request("http://localhost/", { + method: "PUT", + headers: { "content-type": "application/json" }, + body: "not-json", + }), + { params: { id: "antigravity" } } + ); + assert.equal(res.status, 400); +}); + +test("PUT: error responses do not leak stack traces", async () => { + const res = await mappingsRoute.PUT( + new Request("http://localhost/", { + method: "PUT", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ mappings: "not-an-array" }), + }), + { params: { id: "codex" } } + ); + const text = await res.text(); + assert.ok(!text.includes("at /"), "stack trace leaked in PUT /mappings error"); +}); + +test("GET: error responses do not leak stack traces", async () => { + const res = await mappingsRoute.GET( + new Request("http://localhost/"), + { params: { id: "antigravity" } } + ); + const text = await res.text(); + assert.ok(!text.includes("at /"), "stack trace leaked in GET /mappings response"); +}); diff --git a/tests/integration/agent-bridge-routes.test.ts b/tests/integration/agent-bridge-routes.test.ts new file mode 100644 index 0000000000..4724043fc3 --- /dev/null +++ b/tests/integration/agent-bridge-routes.test.ts @@ -0,0 +1,290 @@ +/** + * Integration tests: AgentBridge REST routes — happy paths + LOCAL_ONLY + Zod 400 + * + * Covers: + * - GET /api/tools/agent-bridge/state + * - POST /api/tools/agent-bridge/server (invalid body → 400) + * - GET /api/tools/agent-bridge/agents + * - GET /api/tools/agent-bridge/agents/[id] + * - PATCH /api/tools/agent-bridge/agents/[id] (setup_completed) + * - GET /api/tools/agent-bridge/agents/[id]/detect + * - GET /api/tools/agent-bridge/upstream-ca + * - POST /api/tools/agent-bridge/upstream-ca (path validation) + * + * LOCAL_ONLY enforcement: request with non-loopback Host header → 403 + * (tested via routeGuard helper) + */ +import test from "node:test"; +import assert from "node:assert/strict"; +import fs from "node:fs"; +import os from "node:os"; +import path from "node:path"; + +const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-ab-routes-")); +process.env.DATA_DIR = TEST_DATA_DIR; +process.env.DISABLE_SQLITE_AUTO_BACKUP = "true"; + +// Import db core first to allow reset +const core = await import("../../src/lib/db/core.ts"); + +// Import routes under test +const stateRoute = await import( + "../../src/app/api/tools/agent-bridge/state/route.ts" +); +const serverRoute = await import( + "../../src/app/api/tools/agent-bridge/server/route.ts" +); +const agentsRoute = await import( + "../../src/app/api/tools/agent-bridge/agents/route.ts" +); +const agentIdRoute = await import( + "../../src/app/api/tools/agent-bridge/agents/[id]/route.ts" +); +const detectRoute = await import( + "../../src/app/api/tools/agent-bridge/agents/[id]/detect/route.ts" +); +const upstreamCaRoute = await import( + "../../src/app/api/tools/agent-bridge/upstream-ca/route.ts" +); +const routeGuard = await import("../../src/server/authz/routeGuard.ts"); + +function resetDb() { + core.resetDbInstance(); + fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true }); + fs.mkdirSync(TEST_DATA_DIR, { recursive: true }); +} + +test.beforeEach(() => { + resetDb(); +}); + +test.after(() => { + try { fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true }); } catch { /* noop */ } +}); + +// ── routeGuard classification ────────────────────────────────────────────── + +test("routeGuard: /api/tools/agent-bridge/ is LOCAL_ONLY", () => { + assert.equal(routeGuard.isLocalOnlyPath("/api/tools/agent-bridge/"), true); + assert.equal(routeGuard.isLocalOnlyPath("/api/tools/agent-bridge/state"), true); + assert.equal(routeGuard.isLocalOnlyPath("/api/tools/agent-bridge/agents"), true); +}); + +test("routeGuard: /api/tools/agent-bridge/ is SPAWN_CAPABLE", () => { + const { SPAWN_CAPABLE_PREFIXES } = routeGuard; + const found = (SPAWN_CAPABLE_PREFIXES as ReadonlyArray).some( + (p) => p === "/api/tools/agent-bridge/" + ); + assert.equal(found, true, "Expected /api/tools/agent-bridge/ in SPAWN_CAPABLE_PREFIXES"); +}); + +// ── GET /state ───────────────────────────────────────────────────────────── + +test("GET /state: returns server + agents shape", async () => { + const res = await stateRoute.GET(); + assert.equal(res.status, 200); + const body = await res.json() as Record; + assert.ok("server" in body, "body.server missing"); + assert.ok("agents" in body, "body.agents missing"); + assert.ok(Array.isArray(body.agents), "agents should be array"); +}); + +test("GET /state: error responses do not leak stack traces", async () => { + // Routine GET — should always succeed in test env; just verify if it errors it's clean + const res = await stateRoute.GET(); + const text = await res.text(); + assert.ok(!text.includes("at /"), "stack trace leaked in GET /state response"); +}); + +// ── POST /server (Zod validation) ───────────────────────────────────────── + +test("POST /server: invalid body returns 400", async () => { + const res = await serverRoute.POST( + new Request("http://localhost/api/tools/agent-bridge/server", { + method: "POST", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ action: "invalid-action" }), + }) + ); + assert.equal(res.status, 400); + const body = await res.json() as Record; + assert.ok("error" in body); + const errMsg = (body.error as Record)?.message as string; + assert.ok(typeof errMsg === "string"); + assert.ok(!errMsg.includes("at /"), "stack trace leaked in 400 error message"); +}); + +test("POST /server: missing body returns 400", async () => { + const res = await serverRoute.POST( + new Request("http://localhost/api/tools/agent-bridge/server", { + method: "POST", + headers: { "content-type": "application/json" }, + body: "not-json", + }) + ); + assert.equal(res.status, 400); +}); + +// ── GET /agents ──────────────────────────────────────────────────────────── + +test("GET /agents: returns agents array with expected shape", async () => { + const res = await agentsRoute.GET(); + assert.equal(res.status, 200); + const body = await res.json() as { agents: unknown[] }; + assert.ok(Array.isArray(body.agents)); + assert.ok(body.agents.length >= 9, `Expected ≥9 agents, got ${body.agents.length}`); + const first = body.agents[0] as Record; + assert.ok("id" in first); + assert.ok("name" in first); + assert.ok("hosts" in first); + assert.ok("viability" in first); + assert.ok("state" in first); +}); + +// ── GET /agents/[id] ─────────────────────────────────────────────────────── + +test("GET /agents/[id]: returns 404 for unknown id", async () => { + const res = await agentIdRoute.GET( + new Request("http://localhost/"), + { params: { id: "nonexistent-agent" } } + ); + assert.equal(res.status, 404); + const body = await res.json() as Record; + const errMsg = (body.error as Record)?.message as string; + assert.ok(!errMsg.includes("at /"), "stack trace leaked in 404 message"); +}); + +test("GET /agents/[id]: returns agent detail for 'copilot'", async () => { + const res = await agentIdRoute.GET( + new Request("http://localhost/"), + { params: { id: "copilot" } } + ); + // resolveTarget searches by hostname, not agent id directly; 'copilot' may return 404 + // if resolveTarget doesn't match by id. In current implementation resolveTarget checks hosts. + // Acceptable: either 200 with agent or 404 — but NOT a 500. + assert.ok(res.status === 200 || res.status === 404, `Unexpected status: ${res.status}`); + if (res.status === 200) { + const body = await res.json() as Record; + assert.ok("detection" in body); + } +}); + +// ── PATCH /agents/[id] ──────────────────────────────────────────────────── + +test("PATCH /agents/[id]: invalid body returns 400", async () => { + const res = await agentIdRoute.PATCH( + new Request("http://localhost/", { + method: "PATCH", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ setup_completed: "not-a-boolean" }), + }), + { params: { id: "antigravity" } } + ); + assert.equal(res.status, 400); + const body = await res.json() as Record; + const errMsg = (body.error as Record)?.message as string; + assert.ok(!errMsg.includes("at /"), "stack trace in 400 error"); +}); + +test("PATCH /agents/[id]: valid body persists setup_completed", async () => { + const res = await agentIdRoute.PATCH( + new Request("http://localhost/", { + method: "PATCH", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ setup_completed: true }), + }), + { params: { id: "antigravity" } } + ); + assert.equal(res.status, 200); + const body = await res.json() as Record; + assert.equal((body as Record).ok, true); +}); + +// ── GET /agents/[id]/detect ──────────────────────────────────────────────── + +test("GET /detect: returns installed:false for unknown id", async () => { + const res = await detectRoute.GET( + new Request("http://localhost/"), + { params: { id: "unknown-agent-xyz" } } + ); + assert.equal(res.status, 404); +}); + +test("GET /detect: returns detection result for valid id", async () => { + const res = await detectRoute.GET( + new Request("http://localhost/"), + { params: { id: "copilot" } } + ); + assert.equal(res.status, 200); + const body = await res.json() as Record; + assert.ok("installed" in body); + assert.ok(typeof body.installed === "boolean"); +}); + +test("GET /detect: error response does not leak stack trace", async () => { + const res = await detectRoute.GET( + new Request("http://localhost/"), + { params: { id: "unknown-id-test" } } + ); + const text = await res.text(); + assert.ok(!text.includes("at /"), "stack trace leaked in detect response"); +}); + +// ── GET + POST /upstream-ca ──────────────────────────────────────────────── + +test("GET /upstream-ca: returns null when not configured", async () => { + delete process.env.AGENTBRIDGE_UPSTREAM_CA_CERT; + const res = await upstreamCaRoute.GET(); + assert.equal(res.status, 200); + const body = await res.json() as { path: string | null }; + // path is either null or whatever AGENTBRIDGE_UPSTREAM_CA_CERT is set to + assert.ok(body.path === null || typeof body.path === "string"); +}); + +test("POST /upstream-ca: non-existent file returns 400", async () => { + const res = await upstreamCaRoute.POST( + new Request("http://localhost/", { + method: "POST", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ path: "/nonexistent/path/ca.pem" }), + }) + ); + assert.equal(res.status, 400); + const body = await res.json() as Record; + const errMsg = (body.error as Record)?.message as string; + assert.ok(!errMsg.includes("at /"), "stack trace leaked in 400 body"); +}); + +test("POST /upstream-ca: valid file persists path", async () => { + // Create a temp PEM file + const tmpFile = path.join(TEST_DATA_DIR, "test-ca.pem"); + fs.writeFileSync(tmpFile, "-----BEGIN CERTIFICATE-----\nfake\n-----END CERTIFICATE-----\n"); + + const res = await upstreamCaRoute.POST( + new Request("http://localhost/", { + method: "POST", + headers: { "content-type": "application/json" }, + body: JSON.stringify({ path: tmpFile }), + }) + ); + assert.equal(res.status, 200); + const body = await res.json() as Record; + assert.equal(body.ok, true); + assert.equal(body.path, tmpFile); + + // Verify GET returns the stored path + const getRes = await upstreamCaRoute.GET(); + const getBody = await getRes.json() as { path: string | null }; + assert.equal(getBody.path, tmpFile); +}); + +test("POST /upstream-ca: invalid JSON returns 400", async () => { + const res = await upstreamCaRoute.POST( + new Request("http://localhost/", { + method: "POST", + headers: { "content-type": "application/json" }, + body: "not-json", + }) + ); + assert.equal(res.status, 400); +});