mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-02 05:12:11 +03:00
* chore(release): open v3.8.22 development cycle * refactor(dashboard): extract ProviderDetailPageClient — #3501 Phase 0 (#3633) #3501 Phase 0: extract ProviderDetailPageClient + smoke test. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * refactor(dashboard): extract auth-import modals — #3501 Phase 1a (#3634) #3501 Phase 1a: extract 3 auth-import modal clusters. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * fix(db): reclassify localDb unexported modules as intentionally-internal (#3499) (#3635) Closes #3499 — reclassify localDb unexported modules as intentionally-internal (audit + honest gate framing). * refactor(db): move call_logs aggregations into callLogStats db module (#3500) (#3636) #3500 slice 1: call_logs aggregations → src/lib/db/callLogStats.ts (Rule #5). Byte-identical queries; TDD 6/6. * refactor(dashboard): extract EditCompatibleNodeModal — #3501 Phase 1b (#3638) #3501 Phase 1b: extract EditCompatibleNodeModal (cycle-safe via leaf constants module). Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * refactor(db): move community_servers SQL into gamification db module (#3500 slice 3) (#3639) #3500 slice 3: community_servers SQL → gamification db module. * refactor(db): move usage_history SQL into usageAnalytics module (#3500 slice 2) (#3644) #3500 slice 2: usage_history/daily_usage_summary SQL → usageAnalytics db module. * refactor(db): move skills UPDATE + db-backups SQL into db modules (#3500 slice 5) (#3647) #3500 slice 5: skills UPDATE (allowlist) + db-backups SQL → db modules. * refactor(db): move usage_logs/semantic_cache/proxy_logs SQL into db modules (#3500 slice 4) (#3648) #3500 slice 4: usage_logs/semantic_cache/proxy_logs SQL → db modules. All internal routes done (2 external by-design remain). * chore(db-gate): reclassify external-DB reads, fully close #3500 (#3649) Closes #3500: reclassify external-DB reads; all internal raw-SQL migrated to db/ modules. * refactor(dashboard): extract pure helpers to providerPageHelpers — #3501 Phase 2 (#3653) #3501 Phase 2: extract pure helpers to providerPageHelpers (leaf, cycle-safe). Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * refactor(dashboard): extract remaining shared helpers to providerPageHelpers — #3501 Phase 2b (#3658) #3501 Phase 2b: extract remaining shared helpers to providerPageHelpers (leaf, cycle-safe). Heavy modals unblocked. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * fix(reasoning): replay reasoning_content on plain DeepSeek turns (#1682) (#3632) Integrated into release/v3.8.22 * fix(kiro): route enterprise IAM Identity Center accounts to their regional endpoint (#3631) Integrated into release/v3.8.22 * refactor: small code cleanup (#3523) Integrated into release/v3.8.22 * fix(combo): skip same-provider targets on 408/500/502/503/504/524 errors (#3637) Integrated into release/v3.8.22 — circuit-breaker guard added in review (#1731v2) * feat(providers): add MiMoCode free-tier provider with bootstrap JWT auth (#3659) Integrated into release/v3.8.22 — page.tsx conflict resolved + NoAuthAccountCard re-applied to ProviderDetailPageClient in review. MiMoCode endpoint validated live. * Log Responses WebSocket calls in history (#3616) Integrated into release/v3.8.22 — Codex Responses WebSocket call history logging. * Add Claude Code routing preference for unprefixed Claude models (#3540) Integrated into release/v3.8.22 — page.tsx conflict resolved (re-applied toggle to ProviderDetailPageClient) + disable-test updated for catalog drift in review. * docs(changelog): credit #3632/#3631/#3637/#3659/#3540/#3616/#3523 (v3.8.22 targeted review round) * fix(mimocode): add required authHeader:"none" to registry entry (#3659 follow-up) The mimocode RegistryEntry omitted the required authHeader field, which broke typecheck:core (TS2741). Match the no-auth convention (authType:"none" + authHeader:"none") used by veoaifree-web and other free providers. Follow-up to #3659 (@pizzav-xyz). * fix(responses): detect stream readiness for tool-call-only and object-less chunks (#3612) (#3661) Closes #3612 * fix(mitm): remove duplicated 'Command failed:' error prefix (#3641) (#3662) Closes #3641 * fix(cli): honor HERMES_HOME for Hermes Agent config path (#3628) (#3663) Closes #3628 * fix(api): fetch live OpenCode model catalog for no-auth model picker (#3611) (#3664) Closes #3611 * fix(api): flag provider topology error state by current status, not stale history (#3619) (#3666) Closes #3619 * fix(electron): launch peer-stamping server-ws.mjs entrypoint to avoid 403 LOCAL_ONLY (#3386) (#3665) Closes #3386 * fix(dashboard): restore home topology live in-flight pulse (#3507) (#3667) Closes #3507 * fix(oauth): name Kiro/AWS auto-imported accounts and dedupe by profileArn (#3615) (#3671) Closes #3615 * fix(resilience): clear stale transient connection cooldowns on startup (#3625) (#3672) Closes #3625 * fix(i18n): use logical CSS direction utilities for sidebar and key overlays (RTL #3541) (#3670) Closes #3541 * fix(dashboard): honor auto-hide and switch to visible filter on passthrough Test-all (#3610) (#3669) Closes #3610 * refactor(dashboard): extract AddApiKeyModal + EditConnectionModal — #3501 Phase 1c (#3674) #3501 Phase 1c: extract AddApiKeyModal, EditConnectionModal, WebSessionCredentialGuide into components/; god-component 10,166->8,092 LOC. Reconciles the v3.8.22 file-size drift for this file. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * docs(changelog): reconcile v3.8.22 — credit #3621/#3622 + MiMoCode follow-up roll-up * refactor(dashboard): extract ConnectionRow + ModelCompatPopover + SiliconFlowEndpointModal — #3501 Phase 1d (#3676) #3501 Phase 1d: god-component 8,092->6,838 LOC. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * feat(obsidian): add WebDAV config route + encrypt creds at rest (#3485 part 1) (#3677) Part 1 of #3485. Adds /api/settings/obsidian/webdav (GET/POST/DELETE) wiring the ready obsidianSync lib, encrypts webdav password + obsidian token at rest, removes the duplicate UI block, drops the KNOWN_MISSING entry. WebDAV file server is part 2. * feat(obsidian): add /api/v1/webdav file server for Obsidian vault sync (#3485 part 2) (#3678) Part 2 of #3485. WebDAV server (PROPFIND/GET/PUT/DELETE/MKCOL/MOVE/OPTIONS) handled in the custom server layer (standalone-server-ws.mjs) since the App Router cannot export WebDAV methods. Basic-Auth (constant-time), path-traversal hardened, password decrypt ported from encryption.ts (parity-tested), DATA_DIR resolution parity-tested against dataPaths.ts. End-to-end Obsidian-over-Tailscale validation is a live VPS step (Rule #18). * fix(combo): stop premature context compaction — real auto-combo windows + per-target compression limit (#3680) Integrated into release/v3.8.22 * feat(dashboard): deactivate/activate accounts from the quota overview (#3675) Integrated into release/v3.8.22 * fix(dashboard): close review gaps in bulk provider connection actions (#3271 follow-up) (#3673) Integrated into release/v3.8.22 — page.tsx conflict (god-component split #3501) resolved by re-applying the bulk-action deltas to ProviderDetailPageClient.tsx * refactor(dashboard): extract useModelCompatState hook + model sections — #3501 Phase 1e (#3683) #3501 Phase 1e: extract useModelCompatState hook (unblocks the model sections) + ModelRow/PassthroughModelsSection/PassthroughModelRow/CustomModelsSection/CompatibleModelsSection. god-component 6,838->4,921 LOC. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * refactor(dashboard): extract useProviderConnections/Settings/Models hooks — #3501 Phase 1f (#3684) #3501 Phase 1f: god-component 4,948->4,062 LOC. Connection state+handlers, settings, and model metadata moved into hooks/. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * chore(release): v3.8.22 CHANGELOG + env-doc sync - Set release date in CHANGELOG [3.8.22] to 2026-06-11 - Add HERMES_HOME to .env.example (from #3628/#3663) - Add HERMES_HOME + OMNIROUTE_PREFER_CLAUDE_CODE_FOR_UNPREFIXED_CLAUDE_MODELS to ENVIRONMENT.md (#3628/#3540) * docs(changelog): credit #3673 + #3675 — leninejunior bulk-actions + quota-toggle --------- Co-authored-by: oyi77 <oyi77@users.noreply.github.com> Co-authored-by: Abhishek Divekar <adivekar@utexas.edu> Co-authored-by: NOXX - Commiter <artur1992123@mail.ru> Co-authored-by: Nicolas Lorin <androw95220@gmail.com> Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com> Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: kkkayye <98376609+kkkayye@users.noreply.github.com> Co-authored-by: Witroch4 <witalo_rocha@hotmail.com> Co-authored-by: Lenine Júnior <lenine@engrene.com.br>
302 lines
12 KiB
TypeScript
302 lines
12 KiB
TypeScript
/**
|
|
* TDD tests for /api/settings/obsidian/webdav route (PR1 of #3485).
|
|
*
|
|
* Covers:
|
|
* - GET: no config → disabled shape with null creds
|
|
* - POST: valid temp dir → enabled, returns { username, password }
|
|
* - POST: non-existent path → 400 with no stack trace leaked
|
|
* - DELETE: after enable → disabled, creds cleared
|
|
* - Unauthenticated → 401
|
|
* - Encryption round-trip: set password → raw DB value is NOT plaintext → get returns plaintext
|
|
*/
|
|
|
|
import test from "node:test";
|
|
import assert from "node:assert/strict";
|
|
import fs from "node:fs";
|
|
import os from "node:os";
|
|
import path from "node:path";
|
|
import type { NextRequest } from "next/server";
|
|
import { makeManagementSessionRequest } from "../helpers/managementSession.ts";
|
|
|
|
const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omni-obsidian-webdav-route-"));
|
|
const ORIGINAL_DATA_DIR = process.env.DATA_DIR;
|
|
const ORIGINAL_INITIAL_PASSWORD = process.env.INITIAL_PASSWORD;
|
|
const ORIGINAL_JWT_SECRET = process.env.JWT_SECRET;
|
|
const ORIGINAL_STORAGE_ENCRYPTION_KEY = process.env.STORAGE_ENCRYPTION_KEY;
|
|
|
|
// Set DATA_DIR before any module imports so the DB picks up the temp dir.
|
|
process.env.DATA_DIR = TEST_DATA_DIR;
|
|
|
|
const core = await import("../../src/lib/db/core.ts");
|
|
// Import settings to control auth requirements
|
|
const settingsDb = await import("../../src/lib/db/settings.ts");
|
|
// Import the route under test
|
|
const route = await import("../../src/app/api/settings/obsidian/webdav/route.ts");
|
|
// Import DB module to inspect raw stored values
|
|
const obsidianDb = await import("../../src/lib/db/obsidian.ts");
|
|
|
|
async function resetStorage() {
|
|
core.resetDbInstance();
|
|
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true });
|
|
fs.mkdirSync(TEST_DATA_DIR, { recursive: true });
|
|
}
|
|
|
|
function makeRequest(url: string, options?: RequestInit): NextRequest {
|
|
return new Request(url, options) as unknown as NextRequest;
|
|
}
|
|
|
|
test.beforeEach(async () => {
|
|
delete process.env.INITIAL_PASSWORD;
|
|
delete process.env.STORAGE_ENCRYPTION_KEY;
|
|
await resetStorage();
|
|
});
|
|
|
|
test.after(() => {
|
|
core.resetDbInstance();
|
|
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true });
|
|
|
|
if (ORIGINAL_DATA_DIR === undefined) {
|
|
delete process.env.DATA_DIR;
|
|
} else {
|
|
process.env.DATA_DIR = ORIGINAL_DATA_DIR;
|
|
}
|
|
if (ORIGINAL_INITIAL_PASSWORD === undefined) {
|
|
delete process.env.INITIAL_PASSWORD;
|
|
} else {
|
|
process.env.INITIAL_PASSWORD = ORIGINAL_INITIAL_PASSWORD;
|
|
}
|
|
if (ORIGINAL_JWT_SECRET === undefined) {
|
|
delete process.env.JWT_SECRET;
|
|
} else {
|
|
process.env.JWT_SECRET = ORIGINAL_JWT_SECRET;
|
|
}
|
|
if (ORIGINAL_STORAGE_ENCRYPTION_KEY === undefined) {
|
|
delete process.env.STORAGE_ENCRYPTION_KEY;
|
|
} else {
|
|
process.env.STORAGE_ENCRYPTION_KEY = ORIGINAL_STORAGE_ENCRYPTION_KEY;
|
|
}
|
|
});
|
|
|
|
// ── Auth is disabled by default (requireLogin not set) so requests succeed ──
|
|
|
|
test("GET with no config → webdavEnabled:false, all creds null", async () => {
|
|
const req = makeRequest("http://localhost/api/settings/obsidian/webdav");
|
|
const res = await route.GET(req);
|
|
|
|
assert.equal(res.status, 200);
|
|
const body = (await res.json()) as Record<string, unknown>;
|
|
assert.equal(body.webdavEnabled, false);
|
|
assert.equal(body.webdavUsername, null);
|
|
assert.equal(body.webdavPassword, null);
|
|
assert.equal(body.vaultPath, null);
|
|
});
|
|
|
|
test("POST with a valid temp dir → returns { username, password }, GET shows enabled", async () => {
|
|
const vaultDir = fs.mkdtempSync(path.join(os.tmpdir(), "omni-vault-"));
|
|
try {
|
|
const req = makeRequest("http://localhost/api/settings/obsidian/webdav", {
|
|
method: "POST",
|
|
headers: { "content-type": "application/json" },
|
|
body: JSON.stringify({ vaultPath: vaultDir }),
|
|
});
|
|
const res = await route.POST(req);
|
|
|
|
assert.equal(res.status, 200);
|
|
const body = (await res.json()) as Record<string, unknown>;
|
|
assert.ok(typeof body.username === "string" && (body.username as string).length > 0, "username non-empty");
|
|
assert.ok(typeof body.password === "string" && (body.password as string).length > 0, "password non-empty");
|
|
assert.ok(typeof body.vaultPath === "string", "vaultPath returned");
|
|
|
|
// GET should now reflect enabled state
|
|
const getReq = makeRequest("http://localhost/api/settings/obsidian/webdav");
|
|
const getRes = await route.GET(getReq);
|
|
assert.equal(getRes.status, 200);
|
|
const getBody = (await getRes.json()) as Record<string, unknown>;
|
|
assert.equal(getBody.webdavEnabled, true);
|
|
assert.ok(typeof getBody.webdavUsername === "string" && (getBody.webdavUsername as string).length > 0);
|
|
assert.ok(typeof getBody.webdavPassword === "string" && (getBody.webdavPassword as string).length > 0);
|
|
} finally {
|
|
fs.rmSync(vaultDir, { recursive: true, force: true });
|
|
}
|
|
});
|
|
|
|
test("POST with a non-existent path → 400, body does NOT contain a stack trace", async () => {
|
|
const nonExistentPath = path.join(os.tmpdir(), "omni-nonexistent-vault-" + Date.now());
|
|
const req = makeRequest("http://localhost/api/settings/obsidian/webdav", {
|
|
method: "POST",
|
|
headers: { "content-type": "application/json" },
|
|
body: JSON.stringify({ vaultPath: nonExistentPath }),
|
|
});
|
|
const res = await route.POST(req);
|
|
|
|
assert.equal(res.status, 400);
|
|
const body = (await res.json()) as Record<string, unknown>;
|
|
const errorMsg = (body.error as Record<string, unknown> | undefined)?.message as string | undefined;
|
|
// Must not leak stack trace
|
|
assert.ok(
|
|
!errorMsg || !errorMsg.includes("at /"),
|
|
`Error message should not contain a stack trace, got: ${errorMsg}`
|
|
);
|
|
});
|
|
|
|
test("POST with invalid body (missing vaultPath) → 400", async () => {
|
|
const req = makeRequest("http://localhost/api/settings/obsidian/webdav", {
|
|
method: "POST",
|
|
headers: { "content-type": "application/json" },
|
|
body: JSON.stringify({}),
|
|
});
|
|
const res = await route.POST(req);
|
|
assert.equal(res.status, 400);
|
|
});
|
|
|
|
test("DELETE after enable → webdavEnabled:false, creds cleared in GET", async () => {
|
|
const vaultDir = fs.mkdtempSync(path.join(os.tmpdir(), "omni-vault2-"));
|
|
try {
|
|
// Enable first
|
|
const enableReq = makeRequest("http://localhost/api/settings/obsidian/webdav", {
|
|
method: "POST",
|
|
headers: { "content-type": "application/json" },
|
|
body: JSON.stringify({ vaultPath: vaultDir }),
|
|
});
|
|
const enableRes = await route.POST(enableReq);
|
|
assert.equal(enableRes.status, 200);
|
|
|
|
// Delete
|
|
const deleteReq = makeRequest("http://localhost/api/settings/obsidian/webdav", {
|
|
method: "DELETE",
|
|
});
|
|
const deleteRes = await route.DELETE(deleteReq);
|
|
assert.equal(deleteRes.status, 200);
|
|
const deleteBody = (await deleteRes.json()) as Record<string, unknown>;
|
|
assert.equal(deleteBody.success, true);
|
|
|
|
// GET should now show disabled
|
|
const getReq = makeRequest("http://localhost/api/settings/obsidian/webdav");
|
|
const getRes = await route.GET(getReq);
|
|
const getBody = (await getRes.json()) as Record<string, unknown>;
|
|
assert.equal(getBody.webdavEnabled, false);
|
|
assert.equal(getBody.webdavUsername, null);
|
|
assert.equal(getBody.webdavPassword, null);
|
|
} finally {
|
|
fs.rmSync(vaultDir, { recursive: true, force: true });
|
|
}
|
|
});
|
|
|
|
test("GET when disabled does not leak password even if stale data exists", async () => {
|
|
const vaultDir = fs.mkdtempSync(path.join(os.tmpdir(), "omni-vault3-"));
|
|
try {
|
|
// Enable, then disable
|
|
const enableReq = makeRequest("http://localhost/api/settings/obsidian/webdav", {
|
|
method: "POST",
|
|
headers: { "content-type": "application/json" },
|
|
body: JSON.stringify({ vaultPath: vaultDir }),
|
|
});
|
|
await route.POST(enableReq);
|
|
const deleteReq = makeRequest("http://localhost/api/settings/obsidian/webdav", {
|
|
method: "DELETE",
|
|
});
|
|
await route.DELETE(deleteReq);
|
|
|
|
// GET now: password must be null (not a stale value)
|
|
const getReq = makeRequest("http://localhost/api/settings/obsidian/webdav");
|
|
const getRes = await route.GET(getReq);
|
|
const getBody = (await getRes.json()) as Record<string, unknown>;
|
|
assert.equal(getBody.webdavEnabled, false);
|
|
assert.equal(getBody.webdavPassword, null);
|
|
} finally {
|
|
fs.rmSync(vaultDir, { recursive: true, force: true });
|
|
}
|
|
});
|
|
|
|
// ── Auth guard tests ──
|
|
|
|
test("Unauthenticated GET → 401 when auth is required", async () => {
|
|
process.env.INITIAL_PASSWORD = "bootstrap-password";
|
|
await settingsDb.updateSettings({ requireLogin: true, password: "" });
|
|
|
|
const req = makeRequest("http://localhost/api/settings/obsidian/webdav");
|
|
const res = await route.GET(req);
|
|
assert.equal(res.status, 401);
|
|
});
|
|
|
|
test("Unauthenticated POST → 401 when auth is required", async () => {
|
|
const vaultDir = fs.mkdtempSync(path.join(os.tmpdir(), "omni-vault4-"));
|
|
try {
|
|
process.env.INITIAL_PASSWORD = "bootstrap-password";
|
|
await settingsDb.updateSettings({ requireLogin: true, password: "" });
|
|
|
|
const req = makeRequest("http://localhost/api/settings/obsidian/webdav", {
|
|
method: "POST",
|
|
headers: { "content-type": "application/json" },
|
|
body: JSON.stringify({ vaultPath: vaultDir }),
|
|
});
|
|
const res = await route.POST(req);
|
|
assert.equal(res.status, 401);
|
|
} finally {
|
|
fs.rmSync(vaultDir, { recursive: true, force: true });
|
|
}
|
|
});
|
|
|
|
test("Unauthenticated DELETE → 401 when auth is required", async () => {
|
|
process.env.INITIAL_PASSWORD = "bootstrap-password";
|
|
await settingsDb.updateSettings({ requireLogin: true, password: "" });
|
|
|
|
const req = makeRequest("http://localhost/api/settings/obsidian/webdav", {
|
|
method: "DELETE",
|
|
});
|
|
const res = await route.DELETE(req);
|
|
assert.equal(res.status, 401);
|
|
});
|
|
|
|
// ── Encryption round-trip ──
|
|
|
|
test("encryption round-trip: setWebdavPassword stores encrypted, getWebdavPassword returns plaintext", async () => {
|
|
// Enable encryption
|
|
process.env.STORAGE_ENCRYPTION_KEY = "test-encryption-key-for-webdav-route-tests";
|
|
|
|
// Invalidate cached encryption keys so the new env var is picked up.
|
|
// The encryption module caches keys in module-level vars; we reset via db instance.
|
|
core.resetDbInstance();
|
|
|
|
const plaintext = "super-secret-webdav-password-12345";
|
|
obsidianDb.setWebdavPassword(plaintext);
|
|
|
|
// Inspect raw DB row — it must NOT be the plaintext
|
|
const db = core.getDbInstance();
|
|
type KVRow = { value: string };
|
|
const row = db
|
|
.prepare("SELECT value FROM key_value WHERE namespace = ? AND key = ?")
|
|
.get("obsidian", "webdav_password") as KVRow | undefined;
|
|
|
|
assert.ok(row !== undefined, "Row should exist");
|
|
// The stored JSON string — parse to get inner value
|
|
const storedInner = JSON.parse(row!.value) as string;
|
|
assert.notEqual(
|
|
storedInner,
|
|
plaintext,
|
|
"Raw DB value must NOT be plaintext when encryption is enabled"
|
|
);
|
|
assert.ok(
|
|
storedInner.startsWith("enc:v1:"),
|
|
`Raw DB value should start with enc:v1: prefix, got: ${storedInner.slice(0, 40)}`
|
|
);
|
|
|
|
// getWebdavPassword must round-trip back to plaintext
|
|
const retrieved = obsidianDb.getWebdavPassword();
|
|
assert.equal(retrieved, plaintext, "getWebdavPassword must return original plaintext");
|
|
|
|
// Clean up env for other tests
|
|
delete process.env.STORAGE_ENCRYPTION_KEY;
|
|
core.resetDbInstance();
|
|
});
|
|
|
|
test("encryption graceful fallback: plaintext stored without key reads back correctly", async () => {
|
|
// No encryption key set — store plaintext
|
|
const plaintext = "plaintext-webdav-password";
|
|
obsidianDb.setWebdavPassword(plaintext);
|
|
|
|
// Must read back the same value
|
|
const retrieved = obsidianDb.getWebdavPassword();
|
|
assert.equal(retrieved, plaintext, "Plaintext value must read back unchanged when no encryption key");
|
|
});
|