fix(security): add test coverage for Tier 1 local-only route guard process-spawning endpoints (#11189)

Validated on the combined batch board (gates + typecheck clean) and this branch: security-route-guard-tiers green. Regression coverage for the Hard Rule #15/#17 contract — Tier 1 process-spawning prefixes (/api/services/, /api/mcp/, /api/cli-tools/runtime/) must stay LOCAL_ONLY before any auth check. Conflict with the tip was only stale provider-count docs. Thank you @rqzbeh!
This commit is contained in:
Rouzbeh†
2026-08-23 07:30:14 +03:30
committed by GitHub
parent 79c5bdf681
commit f131b64a6e
2 changed files with 11 additions and 11 deletions

View File

@@ -853,11 +853,6 @@
"count": 1
}
},
"src/app/api/usage/call-logs/route.ts": {
"no-restricted-imports": {
"count": 1
}
},
"src/app/api/usage/quota/route.ts": {
"no-restricted-imports": {
"count": 1
@@ -953,11 +948,6 @@
"count": 1
}
},
"src/app/api/v1/rerank/route.ts": {
"no-restricted-imports": {
"count": 1
}
},
"src/app/api/v1/vscode/[token]/models/route.ts": {
"no-restricted-syntax": {
"count": 1
@@ -3259,4 +3249,4 @@
"count": 5
}
}
}
}

View File

@@ -0,0 +1,10 @@
import assert from "node:assert/strict";
import { test } from "node:test";
import { isLocalOnlyPath } from "../../src/server/authz/routeGuard.ts";
test("isLocalOnlyPath correctly classifies process-spawning endpoints under Tier 1 LOCAL_ONLY", () => {
assert.equal(isLocalOnlyPath("/api/services/dario/start"), true);
assert.equal(isLocalOnlyPath("/api/mcp/stream"), true);
assert.equal(isLocalOnlyPath("/api/cli-tools/runtime/status"), true);
assert.equal(isLocalOnlyPath("/api/v1/chat/completions"), false);
});