Files
OmniRoute/tests/unit/auth-anonymous-fallback-toggle.test.ts
Diego Rodrigues de Sa e Souza 3d4f3e4960 test(infra): retry recursive temp-dir removal instead of failing a shard on ENOTEMPTY (#11966) (#11968)
* test(infra): retry recursive temp-dir removal instead of failing a shard on ENOTEMPTY (#11966)

Two shards on release/v3.8.51 went red in one day with the same signature —
"ENOTEMPTY, Directory not empty: /tmp/omniroute-<test>-XXXXXX" — from
combo-same-provider-cascade (Unit Tests fast-path 4/4, on a PR that touches only
.github/) and auth-policy-embeddings-webfetch-7785 (the 20k-test TIA step). Both pass
alone and on re-run: the cleanup races something still writing into the directory
(SQLite WAL/-shm checkpoint, a worker, the backup) and under a loaded hosted runner
the window opens. 1154 test files do their own cleanup with
fs.rmSync(dir, { recursive: true, force: true }); 57 already asked for retries.

One-shot codemod (scripts/ad-hoc/codemod-rm-maxretries.mjs, kept for the record):
every rm / rmSync / rmdirSync option object with `recursive: true` and no
`maxRetries` gains `maxRetries: 5, retryDelay: 100` — Node itself then retries
ENOTEMPTY/EBUSY/EPERM for up to ~0.5 s before giving up. 2243 call sites in 1292
files under tests/, the shared tests/_setup/isolateDataDir.ts exit hook included.
Only the option object changes: no call site, assertion or import is touched.

Validation: prettier and ESLint (with the frozen suppressions) clean on all 1292
files; a random 20-file sample runs green (quota-redis-store hangs identically on
the untouched tree — it needs a Redis on localhost, an environment matter). The
four unit shards on this PR are the full run.

* fix(quality): let check-forgotten-sibling-tests read a 1,000-file diff

The gate shells out to `git diff` through execFileSync with Node's default 1 MB
maxBuffer; the 1,292-file codemod in this PR is the first diff large enough to
overflow it, and the gate died with `spawnSync git ENOBUFS` before comparing
anything. 64 MB is far above any real PR and costs nothing when unused.
2026-08-29 01:17:40 -03:00

182 lines
7.3 KiB
TypeScript

/**
* Per-provider opt-out for the synthetic anonymous (no-auth) credential
* fallback (`noAuthFallbackDisabledProviders`).
*
* API-key gateway providers whose static definition declares
* `anonymousFallback: true` (opencode-go, opencode-zen, pollinations, …) get a
* synthetic "noauth" connection whenever all real configured connections are
* terminal (expired/banned/credits_exhausted) or all unavailable. Upstream
* endpoints now reject anonymous requests with 401 Missing API key, so operators
* need a per-provider toggle to disable that fallback while keeping the provider
* enabled and real keyed connections working.
*
* The gate applies ONLY to `anonymousFallback: true` API-key providers. True
* no-auth providers (NOAUTH_PROVIDERS / WEB_COOKIE_PROVIDERS entries with
* `noAuth: true`, e.g. opencode, mimocode) are NOT affected — for them the
* synthetic credential is the only credential path and `blockedProviders` is
* the disable mechanism.
*/
import test from "node:test";
import assert from "node:assert/strict";
import fs from "node:fs";
import os from "node:os";
import path from "node:path";
const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-anon-fallback-toggle-"));
process.env.DATA_DIR = TEST_DATA_DIR;
const core = await import("../../src/lib/db/core.ts");
const { getProviderCredentials } = await import("../../src/sse/services/auth.ts");
const { createProviderConnection, updateProviderConnection, deleteProviderConnectionsByProvider } =
await import("../../src/lib/db/providers.ts");
const { updateSettings } = await import("../../src/lib/db/settings.ts");
test.after(() => {
core.resetDbInstance();
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true, maxRetries: 5, retryDelay: 100 });
});
/** Set the opt-out list; pass null to remove the key entirely (absent setting). */
async function setNoAuthFallbackDisabledProviders(providers: string[] | null): Promise<void> {
if (providers === null) {
const db = core.getDbInstance();
db.prepare(
"DELETE FROM key_value WHERE namespace = 'settings' AND key = 'noAuthFallbackDisabledProviders'"
).run();
return;
}
await updateSettings({ noAuthFallbackDisabledProviders: providers });
}
function assertSyntheticNoAuth(creds: unknown, providerId: string): void {
assert.ok(creds, `${providerId} must resolve to synthetic no-auth credentials`);
assert.equal(
(creds as { connectionId?: string }).connectionId,
"noauth",
`${providerId} should return the synthetic "noauth" connection`
);
assert.equal((creds as { apiKey?: unknown }).apiKey, null, "anonymous access carries no api key");
}
test("a. backward compat default: no setting → terminal opencode-go falls back to noauth", async () => {
await setNoAuthFallbackDisabledProviders(null);
await deleteProviderConnectionsByProvider("opencode-go");
await createProviderConnection({
provider: "opencode-go",
authType: "apikey",
name: "expired-key-default",
apiKey: "sk-expired-default",
isActive: false,
testStatus: "expired",
});
const creds = await getProviderCredentials("opencode-go");
assertSyntheticNoAuth(creds, "opencode-go");
});
test("b. disabled + all terminal → allExpired result, never noauth", async () => {
await setNoAuthFallbackDisabledProviders(["opencode-go"]);
await deleteProviderConnectionsByProvider("opencode-go");
await createProviderConnection({
provider: "opencode-go",
authType: "apikey",
name: "expired-key-disabled",
apiKey: "sk-expired-disabled",
isActive: false,
testStatus: "expired",
});
const result = (await getProviderCredentials("opencode-go")) as Record<string, unknown> | null;
assert.ok(result, "must return a structured result (allExpired), not null");
assert.equal(result.allExpired, true, "terminal connections should surface as allExpired");
assert.notEqual(
result.connectionId,
"noauth",
"disabled provider must never receive synthetic no-auth credentials"
);
});
test("c. disabled + zero connections → null, never noauth", async () => {
await setNoAuthFallbackDisabledProviders(["opencode-go", "opencode-zen"]);
await deleteProviderConnectionsByProvider("opencode-zen");
const result = await getProviderCredentials("opencode-zen");
assert.equal(result, null, "disabled provider with no connections must not fall back to noauth");
});
test("d. disabled + healthy real connection → real credentials still selected", async () => {
await setNoAuthFallbackDisabledProviders(["opencode-go"]);
await deleteProviderConnectionsByProvider("opencode-go");
const created = await createProviderConnection({
provider: "opencode-go",
authType: "apikey",
name: "healthy-key",
apiKey: "sk-opencode-go-live",
isActive: true,
testStatus: "active",
});
const result = (await getProviderCredentials("opencode-go")) as Record<string, unknown> | null;
assert.ok(result, "healthy keyed connection must still resolve to credentials");
assert.equal(result.connectionId, created.id, "must select the real DB connection");
assert.equal(result.apiKey, "sk-opencode-go-live", "real api key must be returned");
assert.notEqual(result.connectionId, "noauth");
});
test("e. recovery: rate-limited → allRateLimited; quota recovered → real connection again", async () => {
await setNoAuthFallbackDisabledProviders(["opencode-go"]);
await deleteProviderConnectionsByProvider("opencode-go");
const created = await createProviderConnection({
provider: "opencode-go",
authType: "apikey",
name: "recovering-key",
apiKey: "sk-opencode-go-recover",
isActive: true,
testStatus: "active",
rateLimitedUntil: new Date(Date.now() + 60 * 60 * 1000).toISOString(),
});
const exhausted = (await getProviderCredentials("opencode-go")) as Record<string, unknown> | null;
assert.ok(exhausted, "rate-limited connection must produce a structured result");
assert.equal(
exhausted.allRateLimited,
true,
"while rate limited the provider should surface allRateLimited, not noauth"
);
assert.notEqual(exhausted.connectionId, "noauth");
await updateProviderConnection(created.id as string, { rateLimitedUntil: null });
const recovered = (await getProviderCredentials("opencode-go")) as Record<string, unknown> | null;
assert.ok(recovered, "recovered connection must resolve to credentials again");
assert.equal(
recovered.connectionId,
created.id,
"once quota recovers the real connection must be selected again"
);
assert.equal(recovered.apiKey, "sk-opencode-go-recover");
});
test("f. true no-auth provider unaffected: opencode still returns synthetic noauth", async () => {
await setNoAuthFallbackDisabledProviders(["opencode", "opencode-go", "opencode-zen"]);
const creds = await getProviderCredentials("opencode");
assertSyntheticNoAuth(creds, "opencode");
});
test("g. re-enable: removing provider from the list restores the fallback", async () => {
await setNoAuthFallbackDisabledProviders(["opencode-zen"]);
await deleteProviderConnectionsByProvider("opencode-go");
await createProviderConnection({
provider: "opencode-go",
authType: "apikey",
name: "expired-key-reenabled",
apiKey: "sk-expired-reenabled",
isActive: false,
testStatus: "expired",
});
const creds = await getProviderCredentials("opencode-go");
assertSyntheticNoAuth(creds, "opencode-go");
});