Files
OmniRoute/tests/fixtures/adapta-web-stream-error-boundary.fixture.ts
Diego Rodrigues de Sa e Souza a721fc7295 fix(adapta): redact streamed upstream errors (#12438)
Validado em lote numa worktree combinada com os 14 PRs desta campanha de error-boundary sobre o tip de `release/v3.8.51`: `typecheck:core` limpo e **120/120** nos 23 arquivos de teste que os PRs trazem.

Um ponto que só apareceu no tree combinado: **#12465 e #12466 criam o mesmo arquivo novo** `open-sse/utils/streamReadiness.ts` (que não existe no tip) com desenhos divergentes de cancelamento — `cancelled` + `releaseLock` imediato num, `readInFlight`/`cancelRequested` com `cancelReader` fire-and-forget no outro. Adotei a versão do #12466, que difere e defere o release do lock para quando a leitura em voo termina, e validei a escolha rodando as suítes dos **dois** PRs contra ela: 21/21 no readiness compartilhado e 22/22 incluindo o boundary do Perplexity.
2026-09-03 20:57:02 -03:00

70 lines
2.5 KiB
TypeScript

import assert from "node:assert/strict";
import test from "node:test";
assert.ok(process.env.DATA_DIR, "the subprocess fixture requires an isolated DATA_DIR");
assert.ok(
process.env.OMNIROUTE_PLUGINS_DIR,
"the subprocess fixture requires an isolated OMNIROUTE_PLUGINS_DIR"
);
assert.equal(process.env.HOME, undefined, "the subprocess must not inherit HOME");
assert.equal(process.env.CODEX_HOME, undefined, "the subprocess must not inherit CODEX_HOME");
const { AdaptaWebExecutor } = await import("../../open-sse/executors/adapta-web.ts");
const originalFetch = globalThis.fetch;
test.afterEach(() => {
globalThis.fetch = originalFetch;
});
test("terminates an upstream error event without exposing its text in the public SSE", async () => {
const hostileError =
"SQLSTATE 42P01 at /srv/omniroute/private.ts:91 — Authorization: Bearer secret-token";
const requestedUrls: string[] = [];
const logMessages: string[] = [];
globalThis.fetch = (async (input: RequestInfo | URL) => {
const url = String(input);
requestedUrls.push(url);
if (url.endsWith("/v1/client")) {
return Response.json({
response: { sessions: [{ id: "session-stream-error", status: "active" }] },
});
}
if (url.includes("/tokens")) {
return Response.json({ jwt: "eyJ.test-session.jwt" });
}
return new Response(`data: ${JSON.stringify({ type: "error", errorText: hostileError })}\n\n`, {
status: 200,
headers: { "Content-Type": "text/event-stream" },
});
}) as typeof fetch;
const executor = new AdaptaWebExecutor();
const result = await executor.execute({
model: "adapta-one",
body: { messages: [{ role: "user", content: "hello" }] },
stream: true,
credentials: { apiKey: "__client=unique-stream-error-cookie" },
signal: null,
log: {
info: (_tag, message) => logMessages.push(message),
warn: (_tag, message) => logMessages.push(message),
},
});
assert.equal(result.response.status, 200);
assert.equal(result.response.headers.get("content-type"), "text/event-stream");
const publicSse = await result.response.text();
assert.equal(requestedUrls.length, 3);
assert.match(publicSse, /"content":"\\n\\n\[Erro: Adapta upstream error\]"/);
assert.match(publicSse, /"finish_reason":"stop"/);
assert.match(publicSse, /data: \[DONE\]/);
assert.doesNotMatch(publicSse, /SQLSTATE|\/srv\/omniroute|secret-token/);
assert.doesNotMatch(logMessages.join("\n"), /SQLSTATE|\/srv\/omniroute|secret-token/);
});