mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-23 07:32:20 +03:00
fix(security): add test coverage for Tier 1 local-only route guard process-spawning endpoints (#11189)
Validated on the combined batch board (gates + typecheck clean) and this branch: security-route-guard-tiers green. Regression coverage for the Hard Rule #15/#17 contract — Tier 1 process-spawning prefixes (/api/services/, /api/mcp/, /api/cli-tools/runtime/) must stay LOCAL_ONLY before any auth check. Conflict with the tip was only stale provider-count docs. Thank you @rqzbeh!
This commit is contained in:
@@ -853,11 +853,6 @@
|
||||
"count": 1
|
||||
}
|
||||
},
|
||||
"src/app/api/usage/call-logs/route.ts": {
|
||||
"no-restricted-imports": {
|
||||
"count": 1
|
||||
}
|
||||
},
|
||||
"src/app/api/usage/quota/route.ts": {
|
||||
"no-restricted-imports": {
|
||||
"count": 1
|
||||
@@ -953,11 +948,6 @@
|
||||
"count": 1
|
||||
}
|
||||
},
|
||||
"src/app/api/v1/rerank/route.ts": {
|
||||
"no-restricted-imports": {
|
||||
"count": 1
|
||||
}
|
||||
},
|
||||
"src/app/api/v1/vscode/[token]/models/route.ts": {
|
||||
"no-restricted-syntax": {
|
||||
"count": 1
|
||||
@@ -3259,4 +3249,4 @@
|
||||
"count": 5
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
10
tests/unit/security-route-guard-tiers.test.ts
Normal file
10
tests/unit/security-route-guard-tiers.test.ts
Normal file
@@ -0,0 +1,10 @@
|
||||
import assert from "node:assert/strict";
|
||||
import { test } from "node:test";
|
||||
import { isLocalOnlyPath } from "../../src/server/authz/routeGuard.ts";
|
||||
|
||||
test("isLocalOnlyPath correctly classifies process-spawning endpoints under Tier 1 LOCAL_ONLY", () => {
|
||||
assert.equal(isLocalOnlyPath("/api/services/dario/start"), true);
|
||||
assert.equal(isLocalOnlyPath("/api/mcp/stream"), true);
|
||||
assert.equal(isLocalOnlyPath("/api/cli-tools/runtime/status"), true);
|
||||
assert.equal(isLocalOnlyPath("/api/v1/chat/completions"), false);
|
||||
});
|
||||
Reference in New Issue
Block a user