Files
OmniRoute/tests/unit/security-route-guard-tiers.test.ts
Rouzbeh† f131b64a6e fix(security): add test coverage for Tier 1 local-only route guard process-spawning endpoints (#11189)
Validated on the combined batch board (gates + typecheck clean) and this branch: security-route-guard-tiers green. Regression coverage for the Hard Rule #15/#17 contract — Tier 1 process-spawning prefixes (/api/services/, /api/mcp/, /api/cli-tools/runtime/) must stay LOCAL_ONLY before any auth check. Conflict with the tip was only stale provider-count docs. Thank you @rqzbeh!
2026-08-23 01:00:14 -03:00

11 lines
522 B
TypeScript

import assert from "node:assert/strict";
import { test } from "node:test";
import { isLocalOnlyPath } from "../../src/server/authz/routeGuard.ts";
test("isLocalOnlyPath correctly classifies process-spawning endpoints under Tier 1 LOCAL_ONLY", () => {
assert.equal(isLocalOnlyPath("/api/services/dario/start"), true);
assert.equal(isLocalOnlyPath("/api/mcp/stream"), true);
assert.equal(isLocalOnlyPath("/api/cli-tools/runtime/status"), true);
assert.equal(isLocalOnlyPath("/api/v1/chat/completions"), false);
});