Files
OmniRoute/tests/unit/guardrails-api-3496.test.ts
Diego Rodrigues de Sa e Souza c315a2394c Release v3.8.21 (#3593)
* chore(release): open v3.8.21 development cycle

* fix: pass through valid max_tokens-truncated responses instead of fake 502 (#3572) (#3595)

* fix: /v1/completions returns legacy text-completion format, not chat (#3571) (#3596)

* fix: z.ai/GLM coding plan no longer shows Monthly 0% when no monthly cap (#3580) (#3597)

* docs: mark DISCOVERY_TOOL_DESIGN endpoints as Phase-2 not-yet-implemented (#3498) (#3599)

* fix(agent-bridge): add validate-only upstream-ca/test route (#3488) (#3600)

* fix(gamification): add level/badges/badges-earned profile routes (#3484)

* security(oauth): migrate 5 public client_ids to resolvePublicCred (#3493)

* fix(mcp): ship MCP server source closure in npm files + coverage gate (#3578)

* fix: add reasoning token buffer for combo routing (fixes #3587) (#3588)

Integrated into release/v3.8.21

* Refactor: Extract chatCore phases into modular files (#3598)

Integrated into release/v3.8.21 — chatCore phase modularization. Adjusted: re-derive idempotencyKey for the save path after the check moved into the module (co-authored). Thanks @oyi77!

* docs(changelog): credit #3598 (chatCore modularization) + #3588 (combo reasoning buffer)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): implement GET /api/guardrails + POST /api/guardrails/test, drop shadow/guardrails doc-fiction (#3496) (#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.

* fix(gemini): isolate textual reasoning wrappers (#3605)

Split-out PR C from #3584. Isolates textual reasoning wrappers (<think>/<thinking>/<thought>/<internal_thought>, including malformed/open tags) into reasoning_content across both the non-streaming sanitizer and the Gemini streaming translator, with split-chunk buffering. Additive to the existing textual tool-call pipeline; does not touch the #3569 native functionResponse path. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(antigravity): normalize Gemini 3.5 Flash tier IDs (#3603)

Split-out PR A from #3584. Normalizes the Antigravity/agy Gemini 3.5 Flash tier IDs to clean public names (gemini-3.5-flash-low/medium/high), maps them to the live upstream IDs at the executor boundary, and removes Antigravity from the global model resolver so the executor owns wire normalization. Maintainer follow-up: kept gemini-3.5-flash-preview as a hidden backward-compat alias routing to the High tier (so saved combos/configs keep working). Live-validated the tier set via the agy CLI catalog. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(agent-bridge): surface real MITM startup-failure cause, not always port 443 (#3606) (#3608)

Integrated into release/v3.8.21 (#3606)

* fix(oauth): surface real Kiro import-token failure cause, not a bare 500 (#3589) (#3609)

Integrated into release/v3.8.21 (#3589)

* docs(opencode-provider): soft-deprecate in favor of @omniroute/opencode-plugin (#3419) (#3613)

Integrated into release/v3.8.21 (#3419)

* fix(usage): normalize Antigravity and agy provider quotas (#3604)

Split-out PR B from #3584. Normalizes Antigravity/agy provider quotas: prefers retrieveUserQuota for live consumption, falls back to fetchAvailableModels and local usage_history, sanitizes cached Provider Limits so retired upstream IDs are not re-exposed, and schedules a deduplicated post-usage refresh. Maintainer follow-up: decoupled the post-usage refresh via a lightweight usageEvents bus (usageHistory no longer dynamic-imports providerLimits) so it does not pull the executors/translator graph into the typecheck-core surface — typecheck:core stays at 0. Integrated into release/v3.8.21. Thanks @dhaern!

* feat(cli): add autostart on/off/toggle shorthand for headless serve mode (#3331) (#3614)

Integrated into release/v3.8.21 (#3331)

* docs(changelog): credit #3603 (Flash tier IDs) + #3604 (provider quotas) + #3605 (reasoning wrappers)

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>

* fix(review): resolve findings from /review-reviews battery (v3.8.21 hardening) (#3618)

Pre-release hardening from the /review-reviews battery — 15 findings resolved (L1-L13,L15) + L14 live-verified WONTFIX, convergence re-review clean. lint/typecheck:core/test:vitest(146)/build green; zero new test:unit failures vs baseline 797de433f.

* chore(release): v3.8.21 CHANGELOG + i18n + env-doc sync

---------

Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Raxxoor <manker_lol@hotmail.com>
2026-06-11 04:01:24 -03:00

127 lines
5.1 KiB
TypeScript

import test from "node:test";
import assert from "node:assert/strict";
import fs from "node:fs";
import os from "node:os";
import path from "node:path";
import { makeManagementSessionRequest } from "../helpers/managementSession.ts";
// #3496 — docs/reference/API_REFERENCE.md documented a `/api/guardrails*` and
// `/api/shadow*` surface that did not exist (doc-fiction, frozen in the
// check-docs-symbols allowlist). The guardrail pipeline itself is real
// (src/lib/guardrails), so the fix implements the two routes that map to real
// behavior — GET /api/guardrails (list) and POST /api/guardrails/test (dry-run
// the pre-call hooks) — removes the fictional enable/disable/logs + shadow rows
// from the docs, and drops them from KNOWN_STALE_DOC_REFS.
const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-guardrails-3496-"));
process.env.DATA_DIR = TEST_DATA_DIR;
if (!process.env.JWT_SECRET) process.env.JWT_SECRET = "test-guardrails-3496-jwt-secret";
if (!process.env.API_KEY_SECRET) process.env.API_KEY_SECRET = "test-guardrails-3496-apikey-secret";
const listRoute = await import("../../src/app/api/guardrails/route.ts");
const testRoute = await import("../../src/app/api/guardrails/test/route.ts");
const core = await import("../../src/lib/db/core.ts");
test.after(() => {
try {
core.getDbInstance().close();
} catch {
/* ignore */
}
try {
core.resetDbInstance();
} catch {
/* ignore */
}
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true });
});
test("#3496 GET /api/guardrails lists the registered guardrails with status", async () => {
const req = await makeManagementSessionRequest("http://localhost/api/guardrails");
const res = await listRoute.GET(req);
assert.equal(res.status, 200);
const body = await res.json();
assert.ok(Array.isArray(body.guardrails), "expected guardrails[] in the body");
const names = body.guardrails.map((g) => g.name);
for (const expected of ["vision-bridge", "pii-masker", "prompt-injection"]) {
assert.ok(names.includes(expected), `expected ${expected} in [${names.join(", ")}]`);
}
for (const g of body.guardrails) {
assert.equal(typeof g.name, "string");
assert.equal(typeof g.enabled, "boolean");
assert.equal(typeof g.priority, "number");
}
});
test("#3496 POST /api/guardrails/test runs the pre-call pipeline over a sample input", async () => {
const req = await makeManagementSessionRequest("http://localhost/api/guardrails/test", {
method: "POST",
body: { input: { messages: [{ role: "user", content: "hello world" }] } },
});
const res = await testRoute.POST(req);
assert.equal(res.status, 200);
const body = await res.json();
assert.equal(typeof body.blocked, "boolean");
assert.ok(Array.isArray(body.results), "expected a per-guardrail results[]");
const evaluated = body.results.map((r) => r.guardrail);
assert.ok(
evaluated.includes("pii-masker"),
`expected pii-masker to be evaluated, got [${evaluated.join(", ")}]`
);
});
test("#3496 POST /api/guardrails/test honors disabledGuardrails", async () => {
const req = await makeManagementSessionRequest("http://localhost/api/guardrails/test", {
method: "POST",
body: { input: "hello", disabledGuardrails: ["pii-masker"] },
});
const res = await testRoute.POST(req);
assert.equal(res.status, 200);
const body = await res.json();
const pii = body.results.find((r) => r.guardrail === "pii-masker");
assert.ok(pii, "pii-masker should still appear in results");
assert.equal(pii.skipped, true, "pii-masker should be skipped when disabled");
});
test("#3496 POST /api/guardrails/test rejects a body without input (400)", async () => {
const req = await makeManagementSessionRequest("http://localhost/api/guardrails/test", {
method: "POST",
body: {},
});
const res = await testRoute.POST(req);
assert.equal(res.status, 400);
});
// Regression guard for the quality gate: the docs no longer reference any
// non-existent guardrails/shadow route, and the allowlist no longer freezes them.
test("#3496 check-docs-symbols no longer freezes guardrails/shadow + API_REFERENCE is clean", async () => {
const { KNOWN_STALE_DOC_REFS, collectRouteFiles, extractDocApiPaths, findStaleDocApiRefs } =
await import("../../scripts/check/check-docs-symbols.mjs");
// (1) allowlist no longer freezes any guardrails/shadow path
for (const frozen of [...KNOWN_STALE_DOC_REFS]) {
assert.ok(
!frozen.startsWith("/api/guardrails") && !frozen.startsWith("/api/shadow"),
`allowlist should not still freeze ${frozen}`
);
}
// (2) API_REFERENCE.md no longer references a non-existent guardrails/shadow route
const routeFiles = collectRouteFiles();
const apiRefRel = "docs/reference/API_REFERENCE.md";
const src = fs.readFileSync(path.join(process.cwd(), apiRefRel), "utf8");
const docPathsByFile = [{ file: apiRefRel, paths: extractDocApiPaths(src) }];
const misses = findStaleDocApiRefs(docPathsByFile, routeFiles, KNOWN_STALE_DOC_REFS);
const ghosts = misses.filter(
(m) => m.includes("/api/guardrails") || m.includes("/api/shadow")
);
assert.deepEqual(ghosts, [], `stale guardrails/shadow refs remain: ${ghosts.join("; ")}`);
});