Files
OmniRoute/tests/unit/github-copilot-discovery-token.test.ts
Armin Anton” ∴ 10276821cd Integration: security tier + self-hosted operator blockers (rebased onto v3.8.51) (#10952)
Validated on the resolved merge against the current tip (527da656 + the post-#11281 rebaseline): the single conflict was a comment-only collision in providers/[id]/models/route.ts (kept the tip's #10828-ordering note). Focused suites 125/125 across all 13 touched test files (build-sqlite-stub, cc-compatible, copilot-claude-messages, copilot-gemini-route, executor-github, ghe-copilot, github-copilot-discovery-token, github-copilot-model-discovery, noauth-sibling-7620, provider-header-profiles, provider-models-config, request-log-payloads, upstream-error-passthrough), typecheck:core clean, file-size/changelog-integrity OK. Merged --admin over the inherited 2026-08-23 base-red cluster (#9985) — the reds are proven tip failures (CLI catalog cluster + @testing-library allowlist, being drained by #11280), not from this diff. Note: the rebase means several items the body listed (relay x-relay-path SSRF, /v1/search blocked-providers, #10736 rotation fence, #10903, #10865, #10899, #10916) already landed upstream and are NOT in this delta — the delta is: better-sqlite3 build guard + build heap/worker caps + telemetry-off (#10060 re-derived), credential-echo passthrough refusal + OCR/moderation redaction + call-log key redaction, Copilot CLI 1.0.81-6 wire identity + Claude→/v1/messages name-matched routing + discovery token fix, CC model_not_found 400, compat overrides for no-auth aliases (#7620-pinned). The Copilot wire-identity change is the one to watch in production. Thank you @arminanton — and the ported-author credits in the commit history (@rqzbeh, yidecode, the #10899/#10916 authors) are preserved. Your config-posture finding (REQUIRE_API_KEY default vs 0.0.0.0) is noted for a maintainer decision, as you scoped it.
2026-08-23 16:51:25 -03:00

78 lines
3.2 KiB
TypeScript

import { test } from "node:test";
import assert from "node:assert/strict";
import {
fetchGitHubCopilotModels,
GITHUB_COPILOT_MODELS_URL,
} from "../../open-sse/services/githubCopilotModels.ts";
// Regression guard for the Copilot catalog-discovery token fix.
//
// The full entitled Copilot model catalog (incl. grok-4.x and mai-code) is only
// unlocked when `copilot-integration-id: copilot-developer-cli` rides on a RAW
// GitHub Bearer token. The exchanged copilot_internal/v2/token bearer is minted
// without the developer-cli identity and unlocks only the narrower default set,
// silently dropping grok/mai. So discovery in
// src/app/api/providers/[id]/models/route.ts now prefers the raw accessToken over
// psd.copilotToken. These tests pin the two halves of the contract:
// (a) fetchGitHubCopilotModels sends whatever token it is given as
// `Authorization: Bearer *** on api.githubcopilot.com/models, and
// (b) a /responses-only entitled model (grok/mai shape) is preserved, not
// filtered out, when the live catalog returns it.
function jsonResponse(body: unknown): Response {
return new Response(JSON.stringify(body), {
status: 200,
headers: { "content-type": "application/json" },
});
}
test("fetchGitHubCopilotModels sends the given token as Authorization: Bearer", async () => {
let seenUrl = "";
let seenAuth: string | null = null;
let seenIntegrationId: string | null = null;
const result = await fetchGitHubCopilotModels({
token: "gho_raw_github_token",
fetchImpl: (async (url: string, init?: RequestInit) => {
seenUrl = String(url);
const headers = new Headers(init?.headers as HeadersInit);
seenAuth = headers.get("authorization");
seenIntegrationId = headers.get("copilot-integration-id");
return jsonResponse({
data: [
{ id: "gpt-5.6", capabilities: { type: "chat" } },
// grok/mai are /responses-only; they must survive discovery.
{ id: "grok-4.6", capabilities: { type: "chat" }, supported_endpoints: ["/responses"] },
{ id: "mai-code-1.1-flash", supported_endpoints: ["/responses"] },
],
});
}) as typeof fetch,
});
assert.equal(seenUrl, GITHUB_COPILOT_MODELS_URL);
// The raw token is presented verbatim — the unlock lever.
assert.equal(seenAuth, "Bearer gho_raw_github_token");
// The developer-cli integration id is what unlocks the full catalog.
assert.equal(seenIntegrationId, "copilot-developer-cli");
assert.equal(result.source, "api");
});
test("fetchGitHubCopilotModels keeps /responses-only entitled models (grok/mai)", async () => {
const result = await fetchGitHubCopilotModels({
token: "gho_raw_github_token",
fetchImpl: (async () =>
jsonResponse({
data: [
{ id: "grok-4.6", capabilities: { type: "chat" }, supported_endpoints: ["/responses"] },
{ id: "mai-code-1.1-flash", supported_endpoints: ["/responses"] },
],
})) as typeof fetch,
});
assert.equal(result.source, "api");
const ids = new Set(result.models.map((m) => m.id));
assert.ok(ids.has("grok-4.6"), "grok-4.6 must survive discovery");
assert.ok(ids.has("mai-code-1.1-flash"), "mai-code must survive discovery");
});