Files
OmniRoute/tests/unit/plugins-permissions.test.ts
Paijo 9e7f3cad10 feat(plugins): plugin hook wiring + comprehensive test suite + welcome-banner example (#3045)
Follow-up to the plugins framework (#3041): wires the plugin hooks end-to-end and adds full test coverage.

- Wires `onRequest` / `onResponse` / `onError` hooks into the chat pipeline (`chatCore` now imports from the unified `hooks` registry).
- Loads active plugins on server startup (`pluginManager.loadAll()` in `server-init`) so they survive restarts.
- Ships a `welcome-banner` example plugin (`examples/plugins/`) + test fixture.
- Adds a comprehensive plugin test suite (manifest, db, config, hooks, manager lifecycle, loader IPC, permissions, scanner, welcome-banner e2e).

Integration fixes applied during review:
- `manager.install` now removes an orphaned `destDir` (DB row gone but files left on disk) before the atomic rename, guarded by path containment — it previously failed with `ENOTEMPTY` (a regression surfaced by the new lifecycle test).
- `plugins-db` / `plugins-manager-lifecycle` tests now initialize the DB via the real migration `076` (`getDbInstance`) rather than relying on ambient state, so a missing/renumbered migration fails loudly instead of being masked.

348/348 plugin tests pass; typecheck / cycles clean.

Co-authored-by: oyi77 <14921983+oyi77@users.noreply.github.com>
2026-06-01 16:20:11 -03:00

64 lines
2.0 KiB
TypeScript

import { describe, it } from "node:test";
import assert from "node:assert/strict";
import {
PermissionSchema,
safeValidateManifest,
} from "../../src/lib/plugins/manifest.ts";
describe("Plugin permission enforcement", () => {
describe("PermissionSchema", () => {
it("accepts valid permission values", () => {
const valid = ["network", "file-read", "file-write", "env", "exec"];
for (const perm of valid) {
const result = PermissionSchema.safeParse(perm);
assert.ok(result.success, `should accept "${perm}"`);
}
});
it("rejects invalid permission values", () => {
const invalid = ["admin", "root", "shell", "database", ""];
for (const perm of invalid) {
const result = PermissionSchema.safeParse(perm);
assert.ok(!result.success, `should reject "${perm}"`);
}
});
it("rejects non-string permission values", () => {
const invalid = [123, true, null, undefined, {}];
for (const perm of invalid) {
const result = PermissionSchema.safeParse(perm);
assert.ok(!result.success, `should reject ${JSON.stringify(perm)}`);
}
});
});
describe("Manifest permission validation", () => {
it("accepts manifest with valid permissions", () => {
const result = safeValidateManifest({
name: "test-plugin",
version: "1.0.0",
requires: { permissions: ["network", "env"] },
});
assert.ok(result.success, "should accept valid permissions");
});
it("accepts manifest with empty permissions", () => {
const result = safeValidateManifest({
name: "test-plugin",
version: "1.0.0",
requires: { permissions: [] },
});
assert.ok(result.success, "should accept empty permissions");
});
it("accepts manifest without requires field", () => {
const result = safeValidateManifest({
name: "test-plugin",
version: "1.0.0",
});
assert.ok(result.success, "should accept manifest without requires");
});
});
});