Files
OmniRoute/tests/unit/provider-validation-hardening.test.ts
Diego Rodrigues de Sa e Souza 68d5a0ab27 Release v3.8.10 (#3140)
* chore(release): open v3.8.10 development cycle

Bump 3.8.9 → 3.8.10 across package.json, lockfile, electron, open-sse, and
docs/reference/openapi.yaml; add the [3.8.10] CHANGELOG section (root + 41 i18n
mirrors) as the integration target for the cycle. Entries land here as work
merges into release/v3.8.10; finalized by the release flow.

* fix(providers): resolve web provider alias collisions

Assign unique aliases to HuggingChat, Kimi Web, and Qwen Web so they no longer shadow primary providers or trigger startup warnings.

Add a unit test to enforce provider alias uniqueness and prevent future collisions. Also expand local ignore and VS Code exclude rules for agent, build, and worktree artifacts.

* fix(responses): normalize image_url parts across input paths (#3150)

Normalize image_url parts across all Responses input paths. Integrated into release/v3.8.10.

* fix(api-manager): preserve API key expiration local time (#3146)

Preserve API key expiration local time + clear button. Integrated into release/v3.8.10.

* Strip previous_response_id for stateless Responses upstreams (#3143)

Strip previous_response_id for stateless Responses upstreams (auto/strip/preserve). Integrated into release/v3.8.10.

* fix(opencode-plugin): map thinking cap to interleaved in model+combo (#3138)

Map caps.thinking to ModelV2.capabilities.interleaved for opencode-plugin. Integrated into release/v3.8.10.

* fix(providers): use synced models as fallback for all providers (#3148)

Use synced models as authoritative local catalog for all providers (+regression test). Integrated into release/v3.8.10.

* fix(qoder): bifurcate validation by token type — PAT→Cosy, regular API key→dashscope (#3149)

Bifurcate Qoder validation by token type (PAT→Cosy, regular→dashscope) +regression test. Integrated into release/v3.8.10.

* fix(antigravity): dynamic model resolution via MITM alias table (#3144)

Dynamic antigravity MITM model resolution in the executor (+bug fix +regression test; DB import dropped from client-reachable config). Integrated into release/v3.8.10.

* Feature/batch allow big (#3128)

Podman deployment options + larger upload body-size limits (+CONTAINER_HOST docs). Integrated into release/v3.8.10.

* fix(fireworks): preserve fully-qualified router/model IDs (#3133) (#3160)

Fireworks router IDs (accounts/fireworks/routers/...) were double-prefixed
with accounts/fireworks/models/ → upstream 404. Add optional
acceptedModelIdPrefixes to the registry entry and skip the prepend when the
model already starts with an accepted prefix.

Co-authored-by: KooshaPari <KooshaPari@users.noreply.github.com>

* fix(llama-cpp): route to configured local baseUrl instead of OpenAI (#3136) (#3161)

llama-cpp was missing from the local-provider group in buildUrl(), so it
fell through to the OpenAI baseUrl and returned an OpenAI 401. Add the
case to resolve the connection's providerSpecificData.baseUrl.

Co-authored-by: tjengbudi <tjengbudi@users.noreply.github.com>

* fix(t3-chat-web): parse cookies + convexSessionId from stored credential (#3007) (#3162)

The executor read credentials.cookies/convexSessionId, but the pipeline
only stores the pasted string under apiKey → t3.chat always 400'd. Parse
both values from apiKey (fallback accessToken), mirroring validation.ts.

Co-authored-by: minhtran162 <minhtran162@users.noreply.github.com>

* fix(minimax): stop capping MiniMax-M3 / M2.7 max_tokens at 8192 (#3141) (#3163)

MiniMax-M3 had no MODEL_SPECS entry and capitalized MiniMax-M2.7 missed
its lowercase spec (case-sensitive lookup) → both fell to the 8192 default
cap. Add the M3 spec (512K output), alias the capitalized ids, and make
getModelSpec lookups case-insensitive.

Co-authored-by: totaltube <totaltube@users.noreply.github.com>

* fix(github-copilot): discover model catalog live from api.githubcopilot.com (#3120, #3121) (#3164)

The github (Copilot) provider had a static hardcoded catalog with no
discovery source, so Import Models never refreshed (#3120) and advertised
non-entitled models that 400 on use (#3121). Add a live /models fetch with
fallback to the static list.

Co-authored-by: gabrielmoreira <gabrielmoreira@users.noreply.github.com>

* fix(combo): invalidate nested-combo cache on edits + log DATA_DIR (#3147) (#3165)

Editing a combo did not invalidate the 10s nested-combo expansion caches
(chat.ts getCombosCachedForChat + chatCore.ts getCombosCached; the exported
clearCombosCache was dead code), so a removed nested target/model could be
served as a phantom for up to 10s. Wire a shared monotonic combos-cache
version in readCache (bumped by invalidateDbCache("combos") on every combo
write); both cache layers treat a version mismatch as a miss.

Also log the resolved DATA_DIR/SQLITE_FILE absolute path at DB init so the
reporter's 'persists across restart + volume wipe' symptom (a multi-replica
Docker volume/DATA_DIR mismatch, not a routing bug) is diagnosable from logs.

Includes consolidated CHANGELOG entries for #3133/#3136/#3007/#3141/#3120/#3121.

Co-authored-by: ViFigueiredo <ViFigueiredo@users.noreply.github.com>

* fix(web-tools): parse bare JSON tool calls (#3157)

Parse bare JSON tool calls for deepseek-web (#2820) + fuzzy tool-name matching. Integrated into release/v3.8.10.

* fix(misc): minor fixes across reasoning cache, account fallback, binary manager (#3177)

Misc: ProviderProfile export, DeepSeek reasoning regex, binary guard. Integrated into release/v3.8.10.

* fix(kiro): minor OAuth social exchange tweaks (#3176)

Kiro social OAuth: optional targetProvider passthrough. Integrated into release/v3.8.10.

* deps: bump hono from 4.12.18 to 4.12.23 (#3179)

Bump hono to 4.12.23. Integrated into release/v3.8.10.

* fix(providerRegistry): update kilocode format and executor (#3166)

kilocode: openai format + default executor (matches kilo-gateway) + registry test. Integrated into release/v3.8.10.

* feat(metrics): cross-request TTFT and gap latency after tool calls (#3173)

Cross-request TTFT + gap-after-tool latency metrics (+test). Integrated into release/v3.8.10.

* feat(dashboard): provider stats API endpoint and dashboard page (#3175)

Provider stats dashboard + API (SQL moved to db module per Hard Rule #5, +test). Integrated into release/v3.8.10.

* fix(usage): sequential+spaced OAuth quota sync, reactive force-refresh, actionable 401 (#3156)

Sequential+spaced OAuth quota sync, reactive force-refresh on 401, actionable 401 in UI. Integrated into release/v3.8.10.

* fix(healthcheck): per-provider proactive-refresh skip list (rescue short-TTL OAuth) (#3159)

Per-provider proactive-refresh skip list (OMNIROUTE_HEALTHCHECK_SKIP_PROVIDERS) to rescue short-TTL OAuth. Integrated into release/v3.8.10.

* feat(quota): show OAuth token expiry on provider cards (small, blue, informative) (#3178)

Show OAuth token expiry on provider cards (small, blue, informative). Integrated into release/v3.8.10.

* fix(providers): empty refresh must not resurface just-cleared synced models (#3181)

Empty refresh must not resurface just-cleared synced models (fixes the release-blocking provider-models-route test). Integrated into release/v3.8.10.

* chore(release): v3.8.10 — 2026-06-04 (finalize CHANGELOG)

---------

Co-authored-by: Wilson <pedbookmed@gmail.com>
Co-authored-by: Xiangzhe <32761048+xz-dev@users.noreply.github.com>
Co-authored-by: Jan Leon <Jan.gaschler@gmail.com>
Co-authored-by: M.M <mr.maatoug@gmail.com>
Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Markus Hartung <mail@hartmark.se>
Co-authored-by: KooshaPari <KooshaPari@users.noreply.github.com>
Co-authored-by: tjengbudi <tjengbudi@users.noreply.github.com>
Co-authored-by: minhtran162 <minhtran162@users.noreply.github.com>
Co-authored-by: totaltube <totaltube@users.noreply.github.com>
Co-authored-by: gabrielmoreira <gabrielmoreira@users.noreply.github.com>
Co-authored-by: ViFigueiredo <ViFigueiredo@users.noreply.github.com>
Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Nicolas Lorin <androw95220@gmail.com>
2026-06-04 20:05:38 -03:00

231 lines
7.7 KiB
TypeScript

import test from "node:test";
import assert from "node:assert/strict";
const { validateProviderApiKey, validateClaudeCodeCompatibleProvider } =
await import("../../src/lib/providers/validation.ts");
const originalFetch = globalThis.fetch;
test.afterEach(() => {
globalThis.fetch = originalFetch;
});
test("openai-compatible validation covers chat 429 fallback after a failed /models probe", async () => {
const calls = [];
globalThis.fetch = async (url) => {
calls.push(String(url));
if (String(url).endsWith("/models")) {
return new Response(JSON.stringify({ error: "server error" }), { status: 500 });
}
return new Response(JSON.stringify({ error: "rate limited" }), { status: 429 });
};
const result = await validateProviderApiKey({
provider: "openai-compatible-chat-rate-limit",
apiKey: "sk-test",
providerSpecificData: {
baseUrl: "https://compat.example.com/v1",
validationModelId: "gpt-hardening",
},
});
assert.equal(result.valid, true);
assert.equal(result.method, "chat_completions");
assert.match(result.warning, /Rate limited/i);
assert.deepEqual(calls, [
"https://compat.example.com/v1/models",
"https://compat.example.com/v1/chat/completions",
]);
});
test("openai-compatible validation covers final ping fallback when chat probing fails", async () => {
const calls = [];
globalThis.fetch = async (url) => {
calls.push(String(url));
if (String(url).endsWith("/models")) {
return new Response(JSON.stringify({ error: "server error" }), { status: 500 });
}
if (String(url).endsWith("/chat/completions")) {
throw new Error("chat probe offline");
}
return new Response("gateway down", { status: 503 });
};
const result = await validateProviderApiKey({
provider: "openai-compatible-ping-503",
apiKey: "sk-test",
providerSpecificData: {
baseUrl: "https://compat.example.com/v1",
validationModelId: "gpt-hardening",
},
});
assert.equal(result.valid, false);
assert.equal(result.error, "Provider unavailable (503)");
assert.deepEqual(calls, [
"https://compat.example.com/v1/models",
"https://compat.example.com/v1/chat/completions",
"https://compat.example.com/v1",
]);
});
test("gemini validation distinguishes non-auth 400 responses from auth failures and server errors", async () => {
globalThis.fetch = async () =>
new Response(
JSON.stringify({
error: {
code: 400,
message: "Model parameter is malformed",
status: "INVALID_ARGUMENT",
details: [],
},
}),
{ status: 400 }
);
const invalidRequest = await validateProviderApiKey({
provider: "gemini",
apiKey: "gem-key",
});
assert.equal(invalidRequest.valid, false);
assert.equal(invalidRequest.error, "Validation failed: 400");
globalThis.fetch = async () =>
new Response(
JSON.stringify({
error: {
code: 503,
message: "Service unavailable",
status: "UNAVAILABLE",
},
}),
{ status: 503 }
);
const unavailable = await validateProviderApiKey({
provider: "gemini",
apiKey: "gem-key",
});
assert.equal(unavailable.valid, false);
assert.equal(unavailable.error, "Validation failed: 503");
});
test("Claude Code compatible validation surfaces bridge connection failures", async () => {
globalThis.fetch = async (url, init = {}) => {
if (init.method === "GET") {
throw new Error("models endpoint offline");
}
throw new Error(`bridge failed for ${url}`);
};
const result = await validateClaudeCodeCompatibleProvider({
apiKey: "sk-cc",
providerSpecificData: {
baseUrl: "https://cc-compat.example.com/v1/messages",
},
});
assert.equal(result.valid, false);
assert.match(result.error, /bridge failed/i);
});
// Regression for the non-string-input crash class surfaced by #2463
// ("e.startsWith is not a function" during a connection test). A non-string
// apiKey / modelsUrl must never throw a TypeError mid-validation — it should
// return a clean { valid: boolean } result.
test("#2463 snowflake validation does not throw on non-string apiKey", async () => {
globalThis.fetch = async () => new Response(JSON.stringify({ data: [] }), { status: 200 });
const result = await validateProviderApiKey({
provider: "snowflake",
apiKey: 12345 as any, // simulates a corrupted / mis-typed credential
providerSpecificData: { baseUrl: "https://acct.snowflakecomputing.com" },
});
assert.equal(typeof result.valid, "boolean");
});
test("#2463 gemini validation does not throw on non-string apiKey", async () => {
globalThis.fetch = async () => new Response(JSON.stringify({ data: [] }), { status: 200 });
const result = await validateProviderApiKey({
provider: "gemini",
apiKey: null as any,
providerSpecificData: {},
});
assert.equal(typeof result.valid, "boolean");
});
test("#2463 openai-compatible validation does not throw on non-string modelsUrl", async () => {
globalThis.fetch = async () => new Response(JSON.stringify({ data: [] }), { status: 200 });
const result = await validateProviderApiKey({
provider: "openai-compatible-nonstring-modelsurl",
apiKey: "sk-test",
providerSpecificData: { baseUrl: "https://compat.example.com/v1", modelsUrl: 999 as any },
});
assert.equal(typeof result.valid, "boolean");
});
// Regression for #2545: the default Gemini (AI Studio) base URL ends in /v1beta/models,
// so the validator must not append a second /models (which produced /models/models → 404).
test("#2545 gemini validation does not produce /models/models", async () => {
const calls: string[] = [];
globalThis.fetch = async (url: any) => {
calls.push(String(url));
return new Response(JSON.stringify({ models: [] }), { status: 200 });
};
const result = await validateProviderApiKey({
provider: "gemini",
apiKey: "AIzaTestKey",
providerSpecificData: {},
});
assert.equal(typeof result.valid, "boolean");
assert.ok(calls.length > 0, "validator must make a request");
assert.ok(
!calls.some((u) => u.includes("/models/models")),
`outbound URL must not contain /models/models — got ${calls.join(", ")}`
);
assert.ok(
calls.some((u) => /\/v1beta\/models(\?|$)/.test(u)),
`outbound URL must hit a single /models segment — got ${calls.join(", ")}`
);
});
test("qoder regular API key validates against dashscope, not the Cosy PAT endpoint (#3149)", async () => {
const calls: string[] = [];
globalThis.fetch = async (url: any, init: any) => {
calls.push(String(url));
const auth = new Headers(init?.headers as HeadersInit | undefined).get("authorization");
assert.equal(auth, "Bearer sk-qoder-regular", "dashscope probe must forward the API key");
return new Response(JSON.stringify({ data: [] }), { status: 200 });
};
const result = await validateProviderApiKey({
provider: "qoder",
apiKey: "sk-qoder-regular",
providerSpecificData: {},
});
assert.equal(result.valid, true);
assert.ok(
calls.some((u) => u.includes("dashscope.aliyuncs.com/compatible-mode/v1/models")),
`regular qoder key must validate against dashscope — got ${calls.join(", ")}`
);
assert.ok(
!calls.some((u) => u.includes("api1.qoder.sh")),
"regular (non-PAT) key must not hit the Cosy PAT endpoint"
);
});
test("qoder regular API key surfaces an auth error when dashscope rejects it (#3149)", async () => {
globalThis.fetch = async () =>
new Response(JSON.stringify({ error: { message: "invalid api key" } }), { status: 401 });
const result = await validateProviderApiKey({
provider: "qoder",
apiKey: "sk-qoder-bad",
providerSpecificData: {},
});
assert.equal(result.valid, false);
assert.match(result.error, /Qoder|Dashscope|API key/i);
});