Files
OmniRoute/tests/unit/oauth-providers-config.test.ts
Diego Rodrigues de Sa e Souza 19d91d82e2 Release v3.8.34 (#4614)
* chore(release): open v3.8.34 development cycle

* chore(quality): release-green pre-flight validator + nightly signal (C+D) (#4622)

C — scripts/quality/validate-release-green.mjs (npm run check:release-green):
reproduces the release-equivalent validation (typecheck, eslint, db-rules,
public-creds, full unit, vitest, ratchets, optional --with-build package-artifact)
against the current working tree and classifies each red as HARD (real defect,
exit 1) vs DRIFT (ratchet — reported, never affects exit / never blocks). Pure
helpers exported + orchestration behind a direct-run guard; unit-tested.

D — .github/workflows/nightly-release-green.yml: runs C on the active release
branch nightly (and on workflow_dispatch) and opens/updates a single tracking
issue on HARD failures. Never a required check, never touches a contributor PR.

Closes the gap where the full gate (ci.yml) only ran on the release PR, so reds
accrued silently on release/** and surfaced in 40-min layers at release time.
Non-blocking by construction; drift is the maintainer's to rebaseline at release.

Co-authored-by: Diego Rodrigues de Sa e Souza <diego.souza@cdwasolutions.com.br>

* fix(providers): show revealed connection API keys (#4583)

Integrated into release/v3.8.34

* fix(resilience): respect upstream retry hint toggle (#4585)

Integrated into release/v3.8.34

* feat(settings): expose stream recovery feature flags (#4586)

Integrated into release/v3.8.34

* fix(logs): make active request stale sweep configurable (#4599)

Integrated into release/v3.8.34

* fix(plugin): auto-prefix providerId with 'opencode-' for OC 1.17.8+ native gate (#4527)

Integrated into release/v3.8.34 (supersedes #4445)

* fix(models): treat unknown output caps as unset (#4584)

Integrated into release/v3.8.34

* fix(executors): strip temperature for GitHub Copilot gpt-5.4 family (#4564)

Integrated into release/v3.8.34 (rebuilt onto tip)

* fix(oauth): update Qwen OAuth URLs from chat.qwen.ai to qwen.ai (#4561)

Integrated into release/v3.8.34 (rebuilt onto tip)

* fix(api/settings): prevent cached /api/settings responses (port from 9router#951) (#4566)

Integrated into release/v3.8.34 (rebuilt onto tip)

* feat(audio): MiniMax T2A v2 TTS dispatch in audioSpeech (port #1043) (#4553)

Integrated into release/v3.8.34 (rebuilt onto tip)

* fix(dashboard): surface manual config CTA when Open Claw CLI auto-detect fails (#4562)

Integrated into release/v3.8.34 (rebuilt onto tip)

* feat(providers): optional model ID for custom API-key validation (#4555)

Integrated into release/v3.8.34 (rebuilt onto tip)

* fix(cli): align data dir and env loading with runtime (#4607)

Integrated into release/v3.8.34 (rebuilt onto tip)

* fix(quota): expose Bailian quota windows (#4610)

Integrated into release/v3.8.34 (rebuilt onto tip)

* fix: retain provider cooldowns for configured max window (#4588)

Integrated into release/v3.8.34 (rebuilt — bundled commits stripped)

* fix: reject invalid provider cooldown bounds (#4589)

Integrated into release/v3.8.34 (rebuilt — bundled commits stripped)

* fix: preserve production combo metrics on shadow eviction (#4590)

Integrated into release/v3.8.34 (rebuilt — bundled commits stripped)

* fix(stream): estimate input tokens when upstream reports prompt_tokens=0 (#4615)

Integrated into release/v3.8.34 (rebuilt onto tip)

* fix(catalog): shorten no-thinking gateway prefix to no-think/ (#4525)

Integrated into release/v3.8.34 (rebuilt — kept only the prefix rename, dropped stale-base reverts)

* fix(relay): apply IP rate limit to bifrost sidecar (#4593)

Integrated into release/v3.8.34 (rebuilt onto tip; merge before #4612)

* fix(bifrost): finalize SSE relay usage after stream (#4612)

Integrated into release/v3.8.34 (rebuilt + reconciled with #4593)

* feat(compression): per-request `x-omniroute-compression` header (Phase 3) (#4645)

* docs(compression): Phase 3 per-request header design spec

Approved brainstorming output for the x-omniroute-compression header:
header-first precedence, name-first combo matching (Decision A), explicit
value bypasses auto-trigger (Decision B), DerivedPlan.source, and the
X-OmniRoute-Compression response header.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs(compression): Phase 3 per-request header implementation plan

4-task TDD plan (resolver header-first + source, parser, chatCore wiring +
response header, docs/file-size) with full code and exact commands.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* feat(compression): header-first resolver + plan source (Phase 3 core)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* feat(compression): resolveCompressionHeader parser (Phase 3)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* feat(compression): wire x-omniroute-compression header + response header (Phase 3)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* refactor(compression): extract plan-resolution leaf (planResolution.ts) under size cap (Phase 3)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs(compression): document x-omniroute-compression header (Phase 3)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(compression): harden named-combo map + trim engine: header id (Phase 3 review)

Addresses gemini-code-assist review on #4645:
- Extract buildNamedComboLookup (pure) so a blank/whitespace/null combo name
  contributes only its id key (no '' key, no throw that disables all combos).
- Trim the engine:<id> header value so 'engine: rtk' resolves.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Diego Rodrigues de Sa e Souza <diego.souza@cdwasolutions.com.br>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>

* fix: exclude exhausted connections from auto scoring (#4592)

Integrated into release/v3.8.34 (rebuilt + opt-in gate fix)

* fix(dashboard): memoize compatible provider groups (#4613)

Integrated into release/v3.8.34 (rebuilt + test added)

* fix(dashboard): isolate quota widget refresh clock (#4611)

Integrated into release/v3.8.34 (rebuilt + jsdom test)

* fix(dashboard): gate topology side effects behind widget visibility (#4606)

Integrated into release/v3.8.34 (rebuilt + jsdom test)

* fix(dashboard): keep play_arrow spinning on provider Test All buttons (#4563)

Integrated into release/v3.8.34 (rebuilt onto tip; UI-cosmetic per owner)

* fix(db): schedule retention cleanup + fix cleanup table/column names (extracted from #4428) (#4691)

Integrated into release/v3.8.34 (cleanup core extracted from #4428, credit @oyi77)

* fix(telemetry): back off live-WS event forwarding when the sidecar is unreachable (#4604) (#4687)

Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>

* fix(api): serve GET /v1/models/{model} as JSON, not the HTML dashboard (#4674) (#4677)

Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>

* feat(opencode): add go deepseek reasoning variants (#4647)

Integrated into release/v3.8.34

* fix(executors): robust deepseek-web tool-call parsing and agentic context retention (#4644)

Integrated into release/v3.8.34

* fix(cli): authenticate `omniroute logs` and honor active context (#4638)

Integrated into release/v3.8.34 (authored by Rahul Sharma, AI co-author trailer stripped per project policy)

* fix(proxy): apply pipelining:0 + connections cap to the direct dispatcher (#4580) (#4684)

Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>

* fix(executors): Firecrawl web_fetch 500 with include_metadata=true (#4692)

Integrated into release/v3.8.34

* fix(routing): include all noAuth models in auto-combos + add reka-flash + best-free template (#4621)

Integrated into release/v3.8.34 (dead getFirstRegistryModelId dropped, rebuilt onto tip)

* fix(dashboard): gate home topology live-WS networking (#4596) (#4618)

Integrated into release/v3.8.34 (adapted onto #4606's extracted topology section: default-hidden flip + enabled gate on useLiveDashboard)

* fix(cli): align `omniroute` env loading with the runtime data dir (#4597) (#4619)

Integrated into release/v3.8.34 (data-dir.mjs refactor reconciled with #4607; loadEnvFile aligned to getDefaultDataDir)

* chore(quality): reconcile file-size baseline for #4644 (deepseek-web.ts 1117->1125) (#4695)

file-size reconcile for #4644

* Support quota scraping for OpenCode Go and Ollama Cloud (#4642)

Integrated into release/v3.8.34 (Ollama Cloud + OpenCode Go dashboard quota scraping; rebuilt onto tip, gates green: typecheck/public-creds/file-size/lint/docs-sync + 31 tests)

* feat(executors): land M365 Copilot pure framing + connection helpers (#4042) (#4696)

Land M365 pure modules ahead of draft #4400

* deps: bump production + development groups; migrate js-yaml to v5 ESM (#4697)

Incorporates Dependabot #4667 + #4668 + js-yaml v5 ESM migration into release/v3.8.34

* fix: noAuth provider validation + kimi executor routing (#4699)

Integrated into release/v3.8.34 (noAuth in NOAUTH_PROVIDERS dynamic check + remove misrouted kimi web alias; 9 tests)

* refactor(imageGeneration): extract 8 provider families to co-located files (#4609)

Integrated into release/v3.8.34 (extraction completed: added missing imports/exports per module, main imports handlers locally; 145 image-gen tests pass, typecheck/cycles/file-size green)

* chore(release): v3.8.34 — finalize changelog, rebaseline drift, fix release-green reds

- Finalize CHANGELOG [3.8.34] (43 bullets, full contributor attribution) + seed i18n mirrors
- Rebaseline inherited cycle drift surfaced by release-green pre-flight: eslint warnings
  3900->3907, cognitive-complexity 797->801 (release-finalize touches no prod code; all
  drift is from this cycle's contributor merges)
- fix(providers): keep reka-flash-3 as the Reka provider default. #4621 inserted reka-flash
  at the head of the model list, silently changing the default from reka-flash-3 (the
  free-tier model) to reka-flash; reorder so reka-flash-3 stays default, reka-flash retained.
- test: align provider-models-config / provider-models-route / web-cookie-providers-new with
  #4621 (reka-flash now in the Reka catalog) and #4699 (the `kimi` API-key provider correctly
  falls through to DefaultExecutor instead of KimiWebExecutor)
- chore(quality): allowlist the COMPRESSION_GUIDE doc name in check-fabricated-docs
  (false-positive env-var match; docs/compression/COMPRESSION_GUIDE.md exists)

* fix(release-green): resolve release-PR full-CI reds for v3.8.34

Surfaced only on the release PR (these gates don't run on PR->release fast-gates):

- fix(quota): complete HTML-comment sanitization in opencodeOllamaUsage SSR reset-time
  parsing — strip any <!--...--> generically instead of the two literal React hydration
  markers, so no partial "<!--" can survive (CodeQL js/incomplete-multi-character-
  sanitization, HIGH, introduced by #4642). Regression test added.
- test(codex): correct the Codex-fingerprint body key order assertion to match the
  canonical bodyFieldOrder (prompt_cache_key precedes include); #4584 flipped the two
  and integration tests don't run on fast-gates so it never executed until the release PR.
- chore(quality): rebaseline inherited cycle drift surfaced by full CI —
  zizmorFindings 152->155 (+3 unpinned-uses in nightly-release-green.yml from #4622,
  same @vN convention as ci.yml) and openapiCoverage.pct 38.4->37.8 (-0.6, contributor
  routes added faster than openapi docs). Release-finalize touches no prod routes.

* fix(release-green): complete CodeQL sanitization + rebaseline complexity drift

- fix(quota): handle unterminated HTML comments in opencodeOllamaUsage SSR reset-time
  parsing — the `(?:-->|$)` arm consumes a trailing "<!--" with no closing "-->", so no
  partial "<!--" can survive (CodeQL js/incomplete-multi-character-sanitization persisted
  with the plain <!--...--> form because an unclosed comment could still leave "<!--").
- chore(quality): rebaseline cyclomatic complexity 1915->1916 (+1) — inherited v3.8.34
  cycle drift (contributor feature branches); check:complexity does not run on PR->release
  fast-gates so it surfaced only on the release PR. Release-finalize adds 0 complexity
  (measured 1916 with/without the regex tweak). dead-code/cognitive/type-coverage/
  compression-budget/codeql ratchets all pass.

---------

Co-authored-by: Diego Rodrigues de Sa e Souza <diego.souza@cdwasolutions.com.br>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: KooshaPari <42529354+KooshaPari@users.noreply.github.com>
Co-authored-by: Abhishek Divekar <adivekar@utexas.edu>
Co-authored-by: Rahul sharma <sharmaR0810@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
Co-authored-by: Ronald Estacion <DevEstacion@users.noreply.github.com>
Co-authored-by: Igor <60442260+BugsBag@users.noreply.github.com>
Co-authored-by: Oonishi <275808243+ponkcore@users.noreply.github.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Jan Leon <Jan.gaschler@gmail.com>
2026-06-23 03:08:29 -03:00

867 lines
30 KiB
TypeScript

import test from "node:test";
import assert from "node:assert/strict";
// Gemini, Antigravity and Windsurf public defaults come from
// open-sse/utils/publicCreds.ts — no env override needed in this suite.
const originalEnv = { ...process.env };
Object.assign(process.env, {
CLAUDE_OAUTH_CLIENT_ID: "9d1c250a-e61b-44d9-88ed-5944d1962f5e",
CODEX_OAUTH_CLIENT_ID: "app_EMoamEEZ73f0CkXaXp7hrann",
GITLAB_DUO_OAUTH_CLIENT_ID: "gitlab-duo-client-id",
QWEN_OAUTH_CLIENT_ID: "f0304373b74a44d2b584a3fb70ca9e56",
KIMI_CODING_OAUTH_CLIENT_ID: "17e5f671-d194-4dfb-9706-5516cb48c098",
KIMI_CODING_DEVICE_ID: "test-kimi-device-id",
GITHUB_OAUTH_CLIENT_ID: "Iv1.b507a08c87ecfe98",
});
const providersModule = await import("../../src/lib/oauth/providers/index.ts");
const oauthModule = await import("../../src/lib/oauth/constants/oauth.ts");
const registryModule = await import("../../open-sse/config/providerRegistry.ts");
const antigravityHeadersModule = await import("../../open-sse/services/antigravityHeaders.ts");
const oauthHelpersModule = await import("../../src/lib/oauth/providers.ts");
const PROVIDERS = providersModule.default;
const { resolveBrowserOAuthRedirectUri } = oauthHelpersModule;
const {
ANTIGRAVITY_CONFIG,
AGY_CONFIG,
CLAUDE_CONFIG,
CLINE_CONFIG,
CODEX_CONFIG,
CURSOR_CONFIG,
GEMINI_CONFIG,
GITHUB_CONFIG,
GITLAB_DUO_CONFIG,
KILOCODE_CONFIG,
KIMI_CODING_CONFIG,
KIRO_CONFIG,
OAUTH_TIMEOUT,
PROVIDERS: OAUTH_PROVIDER_IDS,
QODER_CONFIG,
QWEN_CONFIG,
TRAE_CONFIG,
WINDSURF_CONFIG,
} = oauthModule;
const { REGISTRY } = registryModule;
const { getAntigravityLoadCodeAssistMetadata } = antigravityHeadersModule;
const originalFetch = globalThis.fetch;
const EXPECTED_PROVIDER_KEYS = [
"claude",
"codex",
"gemini-cli",
"antigravity",
"agy",
"qoder",
"qwen",
"kimi-coding",
"github",
"gitlab-duo",
"kiro",
"amazon-q",
"cursor",
"trae",
"kilocode",
"cline",
"windsurf",
"devin-cli",
];
const EXPECTED_CONFIG_BY_PROVIDER = {
claude: CLAUDE_CONFIG,
codex: CODEX_CONFIG,
"gemini-cli": GEMINI_CONFIG,
antigravity: ANTIGRAVITY_CONFIG,
agy: AGY_CONFIG,
qoder: QODER_CONFIG,
qwen: QWEN_CONFIG,
"kimi-coding": KIMI_CODING_CONFIG,
github: GITHUB_CONFIG,
"gitlab-duo": GITLAB_DUO_CONFIG,
kiro: KIRO_CONFIG,
"amazon-q": KIRO_CONFIG,
cursor: CURSOR_CONFIG,
kilocode: KILOCODE_CONFIG,
cline: CLINE_CONFIG,
windsurf: WINDSURF_CONFIG,
"devin-cli": WINDSURF_CONFIG,
trae: TRAE_CONFIG,
};
const REQUIRED_FIELDS_BY_PROVIDER = {
claude: ["authorizeUrl", "tokenUrl", "redirectUri", "scopes", "clientId"],
codex: ["authorizeUrl", "tokenUrl", "scope", "clientId"],
"gemini-cli": ["authorizeUrl", "tokenUrl", "userInfoUrl", "scopes", "clientId"],
antigravity: ["authorizeUrl", "tokenUrl", "userInfoUrl", "scopes", "clientId"],
agy: ["authorizeUrl", "tokenUrl", "userInfoUrl", "scopes", "clientId"],
qoder: ["extraParams"],
qwen: ["deviceCodeUrl", "tokenUrl", "scope", "clientId"],
"kimi-coding": ["deviceCodeUrl", "tokenUrl", "clientId"],
github: ["deviceCodeUrl", "tokenUrl", "userInfoUrl", "copilotTokenUrl", "clientId"],
"gitlab-duo": [
"baseUrl",
"authorizeUrl",
"tokenUrl",
"userInfoUrl",
"directAccessUrl",
"scope",
"codeChallengeMethod",
"clientId",
],
kiro: [
"registerClientUrl",
"deviceAuthUrl",
"tokenUrl",
"socialAuthEndpoint",
"socialLoginUrl",
"socialTokenUrl",
"socialRefreshUrl",
"authMethods",
],
"amazon-q": [
"registerClientUrl",
"deviceAuthUrl",
"tokenUrl",
"socialAuthEndpoint",
"socialLoginUrl",
"socialTokenUrl",
"socialRefreshUrl",
"authMethods",
],
cursor: ["apiEndpoint", "api3Endpoint", "agentEndpoint", "agentNonPrivacyEndpoint", "dbKeys"],
kilocode: ["apiBaseUrl", "initiateUrl", "pollUrlBase"],
cline: ["appBaseUrl", "apiBaseUrl", "authorizeUrl", "tokenExchangeUrl", "refreshUrl"],
windsurf: ["authorizeUrl", "apiServerUrl", "exchangePath", "inferenceUrl"],
"devin-cli": ["authorizeUrl", "apiServerUrl", "exchangePath", "inferenceUrl"],
trae: ["apiEndpoint", "chatEndpoint", "webUrl"],
};
function getByPath(object, path) {
return path.split(".").reduce((value, segment) => value?.[segment], object);
}
function collectHttpsUrls(value, path = "config") {
const results = [];
if (typeof value === "string") {
if (/^https?:\/\//.test(value)) {
results.push({ path, value });
}
return results;
}
if (!value || typeof value !== "object" || Array.isArray(value)) {
return results;
}
for (const [key, nestedValue] of Object.entries(value)) {
results.push(...collectHttpsUrls(nestedValue, `${path}.${key}`));
}
return results;
}
function jsonResponse(body, status = 200) {
return new Response(JSON.stringify(body), {
status,
headers: { "Content-Type": "application/json" },
});
}
function textResponse(body, status = 200) {
return new Response(body, {
status,
headers: { "Content-Type": "text/plain" },
});
}
function createJwt(payload) {
const encode = (value) =>
Buffer.from(JSON.stringify(value)).toString("base64url").replace(/=/g, "");
return `${encode({ alg: "none", typ: "JWT" })}.${encode(payload)}.signature`;
}
function useFetchSequence(sequence) {
let index = 0;
globalThis.fetch = async (...args) => {
const next = sequence[index++];
if (!next) {
throw new Error(`Unexpected fetch call #${index}`);
}
return typeof next === "function" ? next(...args) : next;
};
}
test.afterEach(() => {
globalThis.fetch = originalFetch;
});
test.after(() => {
globalThis.fetch = originalFetch;
for (const key of Object.keys(process.env)) {
if (!(key in originalEnv)) {
delete process.env[key];
}
}
Object.assign(process.env, originalEnv);
});
test("OAuth provider registry exposes every expected provider exactly once", () => {
assert.deepEqual(Object.keys(PROVIDERS), EXPECTED_PROVIDER_KEYS);
assert.equal(new Set(Object.keys(PROVIDERS)).size, EXPECTED_PROVIDER_KEYS.length);
});
test("OAuth constants include all provider ids and use a sane timeout", () => {
const constantIds = Object.values(OAUTH_PROVIDER_IDS);
const registryIds = Object.keys(PROVIDERS);
assert.ok(Number.isInteger(OAUTH_TIMEOUT));
assert.ok(OAUTH_TIMEOUT > 0);
assert.equal(new Set(constantIds).size, constantIds.length);
for (const providerId of registryIds) {
assert.ok(
constantIds.includes(providerId),
`Expected oauth constants to include provider id ${providerId}`
);
}
});
test("every registered OAuth provider has a valid config object, flow type and token mapper", () => {
const allowedFlowTypes = new Set([
"authorization_code",
"authorization_code_pkce",
"device_code",
"import_token",
]);
for (const [providerId, provider] of Object.entries(PROVIDERS)) {
assert.equal(provider.config, EXPECTED_CONFIG_BY_PROVIDER[providerId]);
assert.ok(allowedFlowTypes.has(provider.flowType), `${providerId} has unsupported flowType`);
assert.equal(typeof provider.mapTokens, "function", `${providerId} must expose mapTokens`);
const mapped = provider.mapTokens({});
assert.ok(
mapped && typeof mapped === "object",
`${providerId} mapTokens must return an object`
);
}
});
test("every required provider config field is present when the provider is enabled for that flow", () => {
for (const [providerId, fields] of Object.entries(REQUIRED_FIELDS_BY_PROVIDER)) {
const provider = PROVIDERS[providerId];
const config = provider.config;
for (const field of fields) {
const value = getByPath(config, field);
if (
providerId === "qoder" &&
!config.enabled &&
["authorizeUrl", "tokenUrl", "userInfoUrl", "clientId"].includes(field)
) {
continue;
}
assert.notEqual(value, undefined, `${providerId} missing config field ${field}`);
if (Array.isArray(value)) {
assert.ok(value.length > 0, `${providerId}.${field} must not be empty`);
} else if (typeof value === "string") {
assert.ok(value.length > 0, `${providerId}.${field} must not be empty`);
} else if (typeof value === "object") {
assert.ok(
value && Object.keys(value).length > 0,
`${providerId}.${field} must not be empty`
);
}
}
}
});
test("all provider endpoint URLs use HTTPS when a URL is configured", () => {
for (const [providerId, provider] of Object.entries(PROVIDERS)) {
const httpsUrls = collectHttpsUrls(provider.config);
for (const entry of httpsUrls) {
const parsed = new URL(entry.value);
assert.equal(parsed.protocol, "https:", `${providerId} ${entry.path} must use HTTPS`);
}
}
});
test("Qwen OAuth uses qwen.ai (not chat.qwen.ai) for device/token URLs — upstream PR #683 / decolua issue #572", () => {
// The legacy host `chat.qwen.ai` started returning errors; the correct authoritative
// host for Qwen's device-code OAuth endpoints is `qwen.ai`. Regression guard for the
// port of decolua/9router#683 (closes decolua issue #572).
const deviceUrl = new URL(QWEN_CONFIG.deviceCodeUrl);
const tokenUrl = new URL(QWEN_CONFIG.tokenUrl);
assert.equal(deviceUrl.hostname, "qwen.ai", "deviceCodeUrl must use qwen.ai");
assert.equal(tokenUrl.hostname, "qwen.ai", "tokenUrl must use qwen.ai");
assert.equal(deviceUrl.pathname, "/api/v1/oauth2/device/code");
assert.equal(tokenUrl.pathname, "/api/v1/oauth2/token");
});
test("browser-based providers expose buildAuthUrl and return provider-specific auth URLs", () => {
const redirectUri = "http://localhost:43121/callback";
const state = "state-123";
const codeChallenge = "challenge-456";
const claudeUrl = new URL(
PROVIDERS.claude.buildAuthUrl(CLAUDE_CONFIG, redirectUri, state, codeChallenge)
);
const codexUrl = new URL(
PROVIDERS.codex.buildAuthUrl(CODEX_CONFIG, redirectUri, state, codeChallenge)
);
const geminiUrl = new URL(
PROVIDERS["gemini-cli"].buildAuthUrl(GEMINI_CONFIG, redirectUri, state)
);
const antigravityUrl = new URL(
PROVIDERS.antigravity.buildAuthUrl(ANTIGRAVITY_CONFIG, redirectUri, state)
);
const clineUrl = new URL(PROVIDERS.cline.buildAuthUrl(CLINE_CONFIG, redirectUri));
assert.equal(claudeUrl.origin, "https://claude.ai");
assert.equal(claudeUrl.searchParams.get("client_id"), CLAUDE_CONFIG.clientId);
assert.equal(codexUrl.origin, "https://auth.openai.com");
assert.equal(codexUrl.searchParams.get("code_challenge"), codeChallenge);
assert.equal(geminiUrl.origin, "https://accounts.google.com");
assert.equal(geminiUrl.searchParams.get("redirect_uri"), redirectUri);
assert.equal(antigravityUrl.origin, "https://accounts.google.com");
assert.equal(clineUrl.origin, "https://api.cline.bot");
});
// Regression for #3861: GitLab Duo needs an operator-registered OAuth client_id.
// When it's missing, buildAuthUrl must return null (like Qoder) so the authorize route
// can surface a clear "configure it" message — it previously THREW, which the route
// swallowed into an opaque "Internal server error" 500 at the Add Connection step.
test("gitlab-duo buildAuthUrl returns null (not throw) when client_id is unconfigured (#3861)", () => {
const redirectUri = "http://localhost:20128/callback";
const unconfigured = PROVIDERS["gitlab-duo"].buildAuthUrl(
{ ...GITLAB_DUO_CONFIG, clientId: "" },
redirectUri,
"state-x",
"challenge-y"
);
assert.equal(unconfigured, null);
// Configured: returns a real authorize URL carrying the client_id + PKCE challenge.
const configured = new URL(
PROVIDERS["gitlab-duo"].buildAuthUrl(GITLAB_DUO_CONFIG, redirectUri, "state-x", "challenge-y")
);
assert.equal(configured.searchParams.get("client_id"), GITLAB_DUO_CONFIG.clientId);
assert.equal(configured.searchParams.get("code_challenge"), "challenge-y");
});
test("custom Google OAuth credentials switch Antigravity remote callbacks to NEXT_PUBLIC_BASE_URL", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"antigravity",
"http://localhost:20128/callback",
{
NEXT_PUBLIC_BASE_URL: "https://omniroute.example.com/",
ANTIGRAVITY_OAUTH_CLIENT_ID: "custom-antigravity.apps.googleusercontent.com",
ANTIGRAVITY_OAUTH_CLIENT_SECRET: "custom-antigravity-secret",
}
);
assert.equal(redirectUri, "https://omniroute.example.com/callback");
});
test("custom Google OAuth credentials switch Gemini remote callbacks to OMNIROUTE_PUBLIC_BASE_URL", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"gemini-cli",
"http://127.0.0.1:20128/callback",
{
OMNIROUTE_PUBLIC_BASE_URL: "https://omniroute.example.com",
GEMINI_CLI_OAUTH_CLIENT_ID: "custom-gemini.apps.googleusercontent.com",
GEMINI_CLI_OAUTH_CLIENT_SECRET: "custom-gemini-secret",
}
);
assert.equal(redirectUri, "https://omniroute.example.com/callback");
});
test("custom Google OAuth callbacks preserve the requested callback path and query", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"antigravity",
"http://127.0.0.1:20128/auth/callback?source=popup",
{
NEXT_PUBLIC_BASE_URL: "https://omniroute.example.com/base",
ANTIGRAVITY_OAUTH_CLIENT_ID: "custom-antigravity.apps.googleusercontent.com",
ANTIGRAVITY_OAUTH_CLIENT_SECRET: "custom-antigravity-secret",
}
);
assert.equal(redirectUri, "https://omniroute.example.com/base/auth/callback?source=popup");
});
test("custom Google OAuth credentials switch IPv6 loopback callbacks to public base URL", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"gemini-cli",
"http://[::1]:20128/callback",
{
OMNIROUTE_PUBLIC_BASE_URL: "https://omniroute.example.com",
GEMINI_OAUTH_CLIENT_ID: "custom-gemini.apps.googleusercontent.com",
GEMINI_OAUTH_CLIENT_SECRET: "custom-gemini-secret",
}
);
assert.equal(redirectUri, "https://omniroute.example.com/callback");
});
test("custom Google OAuth callbacks default root loopback paths to callback path", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"antigravity",
"http://127.0.0.1:20128",
{
NEXT_PUBLIC_BASE_URL: "https://omniroute.example.com",
ANTIGRAVITY_OAUTH_CLIENT_ID: "custom-antigravity.apps.googleusercontent.com",
ANTIGRAVITY_OAUTH_CLIENT_SECRET: "custom-antigravity-secret",
}
);
assert.equal(redirectUri, "https://omniroute.example.com/callback");
});
test("custom Google OAuth credentials ignore blank Gemini CLI values before checking Gemini fallback values", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"gemini-cli",
"http://127.0.0.1:20128/callback",
{
OMNIROUTE_PUBLIC_BASE_URL: "https://omniroute.example.com",
GEMINI_CLI_OAUTH_CLIENT_ID: " ",
GEMINI_CLI_OAUTH_CLIENT_SECRET: " ",
GEMINI_OAUTH_CLIENT_ID: "custom-gemini.apps.googleusercontent.com",
GEMINI_OAUTH_CLIENT_SECRET: "custom-gemini-secret",
}
);
assert.equal(redirectUri, "https://omniroute.example.com/callback");
});
test("Google OAuth callbacks stay on loopback when custom credentials are incomplete", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"antigravity",
"http://127.0.0.1:20128/callback",
{
NEXT_PUBLIC_BASE_URL: "https://omniroute.example.com",
ANTIGRAVITY_OAUTH_CLIENT_ID: "custom-antigravity.apps.googleusercontent.com",
}
);
assert.equal(redirectUri, "http://127.0.0.1:20128/callback");
});
test("Google OAuth callbacks stay on localhost when no custom credentials are configured", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"antigravity",
"http://localhost:20128/callback",
{
NEXT_PUBLIC_BASE_URL: "https://omniroute.example.com",
}
);
assert.equal(redirectUri, "http://localhost:20128/callback");
});
test("device and import-token providers expose the flow-specific fields expected by their configs", () => {
const deviceProviders = ["qwen", "kimi-coding", "github", "kiro", "amazon-q", "kilocode"];
for (const providerId of deviceProviders) {
const provider = PROVIDERS[providerId];
assert.equal(provider.flowType, "device_code");
assert.equal(typeof provider.requestDeviceCode, "function");
assert.equal(typeof provider.pollToken, "function");
}
assert.equal(PROVIDERS.cursor.flowType, "import_token");
assert.equal(CURSOR_CONFIG.dbKeys.accessToken, "cursorAuth/accessToken");
assert.equal(CURSOR_CONFIG.dbKeys.machineId, "storage.serviceMachineId");
assert.equal(PROVIDERS.trae.flowType, "import_token");
assert.equal(typeof TRAE_CONFIG.apiEndpoint, "string");
assert.ok(Array.isArray(KIRO_CONFIG.authMethods));
assert.ok(KIRO_CONFIG.authMethods.includes("builder-id"));
});
test("provider-specific config shapes remain valid for special cases", () => {
assert.ok(Array.isArray(CLAUDE_CONFIG.scopes) && CLAUDE_CONFIG.scopes.length > 0);
assert.ok(Array.isArray(GEMINI_CONFIG.scopes) && GEMINI_CONFIG.scopes.length > 0);
assert.ok(Array.isArray(ANTIGRAVITY_CONFIG.scopes) && ANTIGRAVITY_CONFIG.scopes.length > 0);
assert.equal(typeof CODEX_CONFIG.extraParams.originator, "string");
assert.equal(typeof QODER_CONFIG.extraParams.loginMethod, "string");
assert.ok(Array.isArray(KIRO_CONFIG.grantTypes) && KIRO_CONFIG.grantTypes.length > 0);
assert.equal(typeof KILOCODE_CONFIG.pollUrlBase, "string");
});
test("Gemini OAuth defaults resolve to a GOCSPX-style client secret shared by both endpoints", () => {
// No env override: GEMINI_CONFIG.clientSecret must come from the embedded
// public default in open-sse/utils/publicCreds.ts.
const expected = GEMINI_CONFIG.clientSecret;
assert.ok(expected.startsWith("G" + "OCSPX-"), "must be a GOCSPX-style secret");
assert.equal(REGISTRY.gemini.oauth.clientSecretDefault, expected);
assert.equal(REGISTRY["gemini-cli"].oauth.clientSecretDefault, expected);
});
test("Qoder remains a safe special case when browser OAuth is disabled", () => {
if (!QODER_CONFIG.enabled) {
assert.equal(
PROVIDERS.qoder.buildAuthUrl(QODER_CONFIG, "http://localhost/callback", "state"),
null
);
return;
}
const authUrl = PROVIDERS.qoder.buildAuthUrl(
QODER_CONFIG,
"http://localhost/callback",
"state-123"
);
assert.equal(typeof authUrl, "string");
assert.ok(authUrl.startsWith("https://"));
});
test("Codex parses id_token metadata and prefers a team workspace when the JWT only marks the personal plan", async () => {
const idToken = createJwt({
email: "dev@example.com",
"https://api.openai.com/auth": {
chatgpt_account_id: "personal-workspace",
chatgpt_plan_type: "free",
chatgpt_user_id: "user-123",
organizations: [
{
id: "team-workspace",
is_default: false,
role: "member",
title: "Platform Team",
},
],
},
});
const extra = await PROVIDERS.codex.postExchange({ id_token: idToken });
const mapped = PROVIDERS.codex.mapTokens(
{
access_token: "access-token",
refresh_token: "refresh-token",
id_token: idToken,
expires_in: 3600,
},
extra
);
assert.equal(extra.authInfo.chatgpt_account_id, "personal-workspace");
assert.equal(mapped.email, "dev@example.com");
assert.equal(mapped.providerSpecificData.workspaceId, "team-workspace");
assert.equal(mapped.providerSpecificData.workspacePlanType, "team");
});
test("Cline decodes embedded callback payloads without using the network", async () => {
const encodedCode = Buffer.from(
JSON.stringify({
accessToken: "cline-access",
refreshToken: "cline-refresh",
email: "cline@example.com",
firstName: "Cline",
lastName: "Bot",
expiresAt: "2030-01-01T00:00:00.000Z",
})
).toString("base64");
const tokens = await PROVIDERS.cline.exchangeToken(CLINE_CONFIG, encodedCode, "http://localhost");
const mapped = PROVIDERS.cline.mapTokens(tokens);
assert.equal(tokens.access_token, "cline-access");
assert.equal(mapped.accessToken, "cline-access");
assert.equal(mapped.email, "cline@example.com");
assert.equal(mapped.name, "Cline Bot");
});
test("Gemini and Antigravity run mocked browser OAuth exchanges and post-exchange enrichment", async () => {
const geminiConfig = { ...GEMINI_CONFIG, clientSecret: "gemini-secret" };
useFetchSequence([
jsonResponse({
access_token: "gemini-access",
refresh_token: "gemini-refresh",
expires_in: 3600,
}),
jsonResponse({ email: "gemini@example.com" }),
jsonResponse({ cloudaicompanionProject: { id: "gemini-project" } }),
jsonResponse({ access_token: "anti-access", refresh_token: "anti-refresh", expires_in: 7200 }),
jsonResponse({ email: "anti@example.com" }),
(_url, init: any = {}) => {
assert.equal(init.method, "POST");
assert.equal(init.headers.Authorization, "Bearer anti-access");
assert.match(init.headers["User-Agent"], /^vscode\/1\.X\.X \(Antigravity\//);
assert.equal(init.headers["X-Goog-Api-Client"], undefined);
assert.deepEqual(
JSON.parse(String(init.body)).metadata,
getAntigravityLoadCodeAssistMetadata()
);
assert.equal(JSON.parse(String(init.body)).cloudaicompanionProject, undefined);
return jsonResponse({
cloudaicompanionProject: { id: "anti-project" },
allowedTiers: [{ id: "tier-default", isDefault: true }],
});
},
(_url, init: any = {}) => {
assert.equal(init.method, "POST");
assert.equal(init.headers.Authorization, "Bearer anti-access");
assert.match(init.headers["User-Agent"], /^vscode\/1\.X\.X \(Antigravity\//);
assert.equal(init.headers["X-Goog-Api-Client"], undefined);
assert.deepEqual(
JSON.parse(String(init.body)).metadata,
getAntigravityLoadCodeAssistMetadata()
);
assert.equal(JSON.parse(String(init.body)).tier_id, "tier-default");
assert.equal(JSON.parse(String(init.body)).cloudaicompanionProject, undefined);
return jsonResponse({
done: true,
response: { cloudaicompanionProject: { id: "anti-project-final" } },
});
},
]);
const geminiTokens = await PROVIDERS["gemini-cli"].exchangeToken(
geminiConfig,
"code-1",
"http://localhost/callback"
);
const geminiExtra = await PROVIDERS["gemini-cli"].postExchange(geminiTokens);
const geminiMapped = PROVIDERS["gemini-cli"].mapTokens(geminiTokens, geminiExtra);
const antigravityTokens = await PROVIDERS.antigravity.exchangeToken(
ANTIGRAVITY_CONFIG,
"code-2",
"http://localhost/callback"
);
const antigravityExtra = await PROVIDERS.antigravity.postExchange(antigravityTokens);
const antigravityMapped = PROVIDERS.antigravity.mapTokens(antigravityTokens, antigravityExtra);
assert.equal(geminiMapped.email, "gemini@example.com");
assert.equal(geminiMapped.projectId, "gemini-project");
assert.equal(antigravityMapped.email, "anti@example.com");
assert.equal(antigravityMapped.projectId, "anti-project-final");
});
test("Qoder enabled mode exchanges tokens and loads profile metadata through mocked endpoints", async () => {
const originalQoderConfig = structuredClone(QODER_CONFIG);
const qoderConfig = Object.assign(QODER_CONFIG, {
enabled: true,
clientId: "qoder-client",
clientSecret: "qoder-secret",
authorizeUrl: "https://auth.qoder.dev/authorize",
tokenUrl: "https://auth.qoder.dev/token",
userInfoUrl: "https://auth.qoder.dev/user",
extraParams: {
loginMethod: "phone",
type: "phone",
},
});
try {
useFetchSequence([
jsonResponse({
access_token: "qoder-access",
refresh_token: "qoder-refresh",
expires_in: 1800,
}),
jsonResponse({
success: true,
data: {
apiKey: "qoder-api-key",
email: "qoder@example.com",
nickname: "Qoder User",
},
}),
]);
const authUrl = PROVIDERS.qoder.buildAuthUrl(
qoderConfig,
"http://localhost/callback",
"state-123"
);
const tokens = await PROVIDERS.qoder.exchangeToken(
qoderConfig,
"browser-code",
"http://localhost/callback"
);
const extra = await PROVIDERS.qoder.postExchange(tokens);
const mapped = PROVIDERS.qoder.mapTokens(tokens, extra);
assert.ok(authUrl.startsWith("https://auth.qoder.dev/authorize?"));
assert.equal(mapped.apiKey, "qoder-api-key");
assert.equal(mapped.email, "qoder@example.com");
assert.equal(mapped.displayName, "Qoder User");
} finally {
Object.assign(QODER_CONFIG, originalQoderConfig);
}
});
test("Qwen and Kimi Coding execute mocked device-code flows and token mapping", async () => {
const qwenIdToken = createJwt({
email: "qwen@example.com",
name: "Qwen User",
});
useFetchSequence([
jsonResponse({
device_code: "qwen-device",
user_code: "QWEN123",
verification_uri: "https://chat.qwen.ai/activate",
expires_in: 300,
interval: 5,
}),
jsonResponse({
access_token: createJwt({ sub: "qwen-subject" }),
refresh_token: "qwen-refresh",
expires_in: 3600,
id_token: qwenIdToken,
resource_url: "https://chat.qwen.ai/resource",
}),
(url, init) => {
const params = init.body;
assert.equal(String(url), KIMI_CODING_CONFIG.deviceCodeUrl);
assert.equal(params.get("client_id"), KIMI_CODING_CONFIG.clientId);
assert.equal(init.headers["X-Msh-Platform"], "kimi_cli");
assert.equal(init.headers["X-Msh-Device-Id"], "test-kimi-device-id");
assert.ok(init.headers["X-Msh-Os-Version"]);
return jsonResponse({
device_code: "kimi-device",
user_code: "KIMI123",
verification_uri: "https://www.kimi.com/code/authorize_device",
verification_uri_complete: "https://www.kimi.com/code/authorize_device?user_code=KIMI123",
expires_in: 600,
interval: 4,
});
},
(url, init) => {
const params = init.body;
assert.equal(String(url), KIMI_CODING_CONFIG.tokenUrl);
assert.equal(params.get("client_id"), KIMI_CODING_CONFIG.clientId);
assert.equal(params.get("device_code"), "kimi-device");
assert.equal(params.get("grant_type"), "urn:ietf:params:oauth:grant-type:device_code");
assert.equal(init.headers["X-Msh-Platform"], "kimi_cli");
assert.equal(init.headers["X-Msh-Device-Id"], "test-kimi-device-id");
return jsonResponse({
access_token: "kimi-access",
refresh_token: "kimi-refresh",
expires_in: 7200,
token_type: "Bearer",
scope: "profile",
});
},
]);
const qwenDevice = await PROVIDERS.qwen.requestDeviceCode(QWEN_CONFIG, "challenge-123");
const qwenPoll = await PROVIDERS.qwen.pollToken(QWEN_CONFIG, qwenDevice.device_code, "verifier");
const qwenMapped = PROVIDERS.qwen.mapTokens(qwenPoll.data);
const kimiDevice = await PROVIDERS["kimi-coding"].requestDeviceCode(KIMI_CODING_CONFIG);
const kimiPoll = await PROVIDERS["kimi-coding"].pollToken(
KIMI_CODING_CONFIG,
kimiDevice.device_code
);
const kimiMapped = PROVIDERS["kimi-coding"].mapTokens(kimiPoll.data);
assert.equal(qwenMapped.email, "qwen@example.com");
assert.equal(qwenMapped.displayName, "Qwen User");
assert.equal(qwenMapped.providerSpecificData.resourceUrl, "https://chat.qwen.ai/resource");
assert.equal(kimiMapped.accessToken, "kimi-access");
assert.equal(kimiMapped.tokenType, "Bearer");
assert.equal(
kimiDevice.verification_uri_complete,
"https://www.kimi.com/code/authorize_device?user_code=KIMI123"
);
});
test("GitHub executes mocked device-code and profile enrichment flows", async () => {
useFetchSequence([
jsonResponse({
device_code: "github-device",
user_code: "GH123",
verification_uri: "https://github.com/login/device",
expires_in: 900,
interval: 5,
}),
jsonResponse({
access_token: "github-access",
refresh_token: "github-refresh",
expires_in: 3600,
}),
jsonResponse({ token: "copilot-token", expires_at: "2030-01-01T00:00:00.000Z" }),
jsonResponse({
id: 42,
login: "octocat",
name: "Octo Cat",
email: "octo@example.com",
}),
]);
const device = await PROVIDERS.github.requestDeviceCode(GITHUB_CONFIG);
const poll = await PROVIDERS.github.pollToken(GITHUB_CONFIG, device.device_code);
const extra = await PROVIDERS.github.postExchange(poll.data);
const mapped = PROVIDERS.github.mapTokens(poll.data, extra);
assert.equal(poll.ok, true);
assert.equal(mapped.providerSpecificData.copilotToken, "copilot-token");
assert.equal(mapped.providerSpecificData.githubLogin, "octocat");
assert.equal(mapped.providerSpecificData.githubEmail, "octo@example.com");
});
test("Kiro and KiloCode execute mocked device-code flows across their custom endpoints", async () => {
useFetchSequence([
jsonResponse({ clientId: "kiro-client", clientSecret: "kiro-secret" }),
jsonResponse({
deviceCode: "kiro-device",
userCode: "KIRO123",
verificationUri: "https://device.kiro.dev/verify",
verificationUriComplete: "https://device.kiro.dev/verify?code=KIRO123",
expiresIn: 600,
interval: 5,
}),
jsonResponse({
accessToken: "kiro-access",
refreshToken: "kiro-refresh",
expiresIn: 3600,
}),
jsonResponse({
code: "kilo-code",
verificationUrl: "https://api.kilo.ai/device-auth/kilo-code",
expiresIn: 300,
}),
jsonResponse({ status: "approved", token: "kilo-access", userEmail: "kilo@example.com" }),
textResponse("", 202),
textResponse("", 403),
textResponse("", 410),
]);
const kiroDevice = await PROVIDERS.kiro.requestDeviceCode(KIRO_CONFIG);
const kiroPoll = await PROVIDERS.kiro.pollToken(
KIRO_CONFIG,
kiroDevice.device_code,
undefined,
kiroDevice
);
const kiroMapped = PROVIDERS.kiro.mapTokens(kiroPoll.data);
const kiloDevice = await PROVIDERS.kilocode.requestDeviceCode(KILOCODE_CONFIG);
const kiloApproved = await PROVIDERS.kilocode.pollToken(KILOCODE_CONFIG, kiloDevice.device_code);
const kiloPending = await PROVIDERS.kilocode.pollToken(KILOCODE_CONFIG, kiloDevice.device_code);
const kiloDenied = await PROVIDERS.kilocode.pollToken(KILOCODE_CONFIG, kiloDevice.device_code);
const kiloExpired = await PROVIDERS.kilocode.pollToken(KILOCODE_CONFIG, kiloDevice.device_code);
const kiloMapped = PROVIDERS.kilocode.mapTokens(kiloApproved.data);
assert.equal(kiroMapped.accessToken, "kiro-access");
assert.equal(kiroMapped.providerSpecificData.clientId, "kiro-client");
assert.equal(kiloApproved.ok, true);
assert.equal(kiloPending.data.error, "authorization_pending");
assert.equal(kiloDenied.data.error, "access_denied");
assert.equal(kiloExpired.data.error, "expired_token");
assert.equal(kiloMapped.email, "kilo@example.com");
});