Files
OmniRoute/tests/unit/cli-tools-keys-route.test.ts
diegosouzapw dd67b25df1 fix(cli-tools): preserve opencode config and raw key copy (#1626)
- Use jsonc-parser to update only provider.omniroute in opencode.json,
  preserving MCP servers, comments, and other provider entries
- Add /api/cli-tools/keys endpoint returning raw keys for CLI tools UI
  (session-auth protected via requireCliToolsAuth)
- Fix OpenCode guide step 3 to use ICU-style {baseUrl} placeholder
  instead of broken {{baseUrl}} across all 40+ locales
- Restore valid OpenCode light/dark SVG logos (were broken HTML downloads)
- Add customCliTab translation key to en.json
- Add modelLabels support for human-readable model names in config
- Fix 9 additional locale files (bn, fa, gu, in, mr, sw, ta, te, ur)
  that were added after the original PR and still had double-braces

Co-authored-by: JasonLandbridge <JasonLandbridge@users.noreply.github.com>
2026-04-26 14:26:34 -03:00

79 lines
2.7 KiB
TypeScript

import test from "node:test";
import assert from "node:assert/strict";
import { SignJWT } from "jose";
const keysRoute = await import("../../src/app/api/keys/route.ts");
const cliToolsKeysRoute = await import("../../src/app/api/cli-tools/keys/route.ts");
const { createApiKey, deleteApiKey } = await import("../../src/lib/db/apiKeys.ts");
const originalJwtSecret = process.env.JWT_SECRET;
const originalApiKeySecret = process.env.API_KEY_SECRET;
async function createAuthCookie() {
process.env.JWT_SECRET = "test-cli-tools-keys-secret";
const secret = new TextEncoder().encode(process.env.JWT_SECRET);
const token = await new SignJWT({ sub: "test-user" })
.setProtectedHeader({ alg: "HS256" })
.setIssuedAt()
.setExpirationTime("1h")
.sign(secret);
return `auth_token=${token}`;
}
test.afterEach(() => {
if (originalJwtSecret === undefined) delete process.env.JWT_SECRET;
else process.env.JWT_SECRET = originalJwtSecret;
if (originalApiKeySecret === undefined) delete process.env.API_KEY_SECRET;
else process.env.API_KEY_SECRET = originalApiKeySecret;
});
test("CLI tools key list can return unmasked keys for authenticated internal consumers", async () => {
process.env.API_KEY_SECRET = "test-api-key-secret";
const created = await createApiKey("CLI Tools Test Key", "test-machine-cli-tools");
try {
const cookie = await createAuthCookie();
const request = new Request("http://localhost/api/cli-tools/keys", {
headers: {
cookie,
},
});
const response = await cliToolsKeysRoute.GET(request);
assert.equal(response.status, 200);
const payload = await response.json();
const key = payload.keys.find((entry) => entry.id === created.id);
assert.ok(key, "created key should be present");
assert.notEqual(key.key, created.key);
assert.match(key.key, /^.{8}\*\*\*\*.*$/);
assert.equal(key.rawKey, created.key);
} finally {
await deleteApiKey(created.id);
}
});
test("general keys route stays masked for non-CLI consumers", async () => {
process.env.API_KEY_SECRET = "test-api-key-secret";
const created = await createApiKey("Masked Key Test", "test-machine-masked");
try {
const cookie = await createAuthCookie();
const request = new Request("http://localhost/api/keys", {
headers: { cookie },
});
const response = await keysRoute.GET(request);
assert.equal(response.status, 200);
const payload = await response.json();
const key = payload.keys.find((entry) => entry.id === created.id);
assert.ok(key, "created key should be present");
assert.notEqual(key.key, created.key);
assert.match(key.key, /^.{8}\*\*\*\*.*$/);
} finally {
await deleteApiKey(created.id);
}
});