mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-09-13 18:32:12 +03:00
Rebased onto the current release/v3.8.51 tip as part of a combined provider-retirement/provenance merge batch (Designer Web, Felo Web, Runtime, GPL-derived removal, Qwen Web already landed). Large conflict set (this is the biggest PR in the batch — the common ChatGPT Web provider touches chat, images, count-tokens, session leases, and combos). Conflicts resolved: - `open-sse/config/providers/registry/chatgpt-web/*`, `open-sse/executors/chatgpt-web*`, `open-sse/handlers/imageGeneration/providers/chatgptWeb.ts`, and their tests: kept deleted, matching the PR's stated scope. - `open-sse/config/providers/registry/minimax/web/index.ts`, `open-sse/handlers/imageGeneration/providers/geminiWeb.ts`, `open-sse/executors/gemini-web.ts`'s stale image-mode branch: base-drift collisions against already-merged sibling retirements (#11691, #11708) — kept deleted / dropped the dead code, since this PR's own branch forked before those merged. - `src/shared/constants/reservedProviderPrefixes.ts`, `open-sse/executors/index.ts`, `executorProxy.ts`, `virtualFactory.ts`, `autoStrategy.ts`, `src/lib/db/providers.ts`, `src/sse/handlers/chat.ts`: combined the Designer + Runtime (Felo/Qwen) + common-ChatGPT-Web retirement guard calls at each shared chokepoint — compute-once-then-OR pattern, consistent with prior combinations in this batch. - `src/sse/services/model.ts` / `src/sse/handlers/chatHelpers.ts`: adopted this PR's new `getModelInfoOrRetirementResponse()` central wrapper (a real improvement over ad-hoc try/catch), and extended it to also catch the Designer + Runtime retirement errors it didn't originally cover, so the consolidation doesn't regress the other two mechanisms. - `src/app/api/v1/images/edits/route.ts`: this PR moved the retirement check earlier (before `enforceApiKeyPolicy`) but left the old later call+catch block in place from base drift — removed the now-redundant duplicate `resolveImageRouteModel()` call and merged the Designer catch into the earlier one. - `open-sse/config/imageRegistry.ts`, `tests/snapshots/executors/executor-map.json` (`keyCount` recomputed to 133), `tests/snapshots/provider/translate-path.json`: same "both sides inserted a different retired provider at the same slot" pattern — resolved by dropping both. - `tests/unit/chatcore-executor-proxy.test.ts`, `provider-node-reserved-prefix.test.ts`, `combo-auto-candidate-expansion.test.ts`, `messages-count-tokens-route.test.ts`, `virtual-auto-combo.test.ts`: split into independent per-mechanism test blocks (established pattern); `virtual-auto-combo.test.ts`'s old "includes cookie web-session providers" positive-inclusion test (which used chatgpt-web as its example) was retired along with the provider and replaced by this PR's negative-exclusion test for the same slot. - `docs/architecture/ARCHITECTURE.md`, `CODEBASE_DOCUMENTATION.md` (+ 4 i18n mirrors), `README.md`, `FREE-TIERS-GUIDE.md`, `docs/diagrams/free-tier-budget.svg`, `docs/screenshots/free-tier-budget-card.svg`, `docs/reference/PROVIDER_REFERENCE.md`: recomputed every stale count from the real merged state — 104 executors (`countFiles` gate logic), 351 providers (regenerated via `gen:provider-reference`), 152/351 `hasFree` entries, 445/438/7 free-tier catalog rows, 13 ToS-avoid providers, budget-card regenerated via its real generator script. One doc conflict (`oauth/` module list) needed picking HEAD's side specifically — theirs still listed the already-removed `raycast` module instead of the real `openference`. - `config/quality/test-masking-allowlist.json`: additive merge of the PR's 17 `_deletedWithReplacement` entries alongside the batch's existing ones (one real duplicate-key mistake in my first pass, caught and fixed via a `object_pairs_hook` duplicate-key check before finalizing). Also fixed two real, unrelated-to-my-merge issues surfaced by the focused suite: - `tests/unit/resolve-web-provider-host.test.ts`: the PR's own test had a typo — it asserted `perplexity-web`'s resolved host as `"perplexity.ai"`, but the provider's registered `website` is `"https://www.perplexity.ai"` and the resolver returns the URL's `host` verbatim (no www-stripping), so the correct value is `"www.perplexity.ai"` (consistent with the same test's own `url` assertion). - `tests/unit/hard-session-lease-bypass-inventory.test.ts`: this golden call-site inventory was already stale on the pristine post-#11713 tip (confirmed via a throwaway probe worktree) — `src/lib/db/providers.ts`'s 3 connection-fallback sites and a third `src/app/api/providers/route.ts` site were never added to the golden list by the earlier-merged #11698/#11720 PRs. Updated it to the real current inventory (dated inline comments explain each delta and which PR introduced it), plus this PR's own legitimate deltas (image-edits duplicate-call removal, `ChatGptWebExecutor.execute()` site removed). Focused suite green (433/433 across executor-proxy, reserved-prefix, hard-session-lease-bypass-inventory, resolve-web-provider-host, retirement/runtime-block/source-retirement/management-retirement/image-handler-retirement, migration-168, combo-auto-candidate-expansion, virtual-auto-combo, executor-map-golden and siblings), plus `typecheck:core`, `check-file-size`, and `check-changelog-integrity` clean. Thanks for the thorough provenance-hold retirement work — appreciated.
235 lines
8.4 KiB
TypeScript
235 lines
8.4 KiB
TypeScript
/**
|
|
* Bulk Web-Session Import — Unit Tests (PR6 of issue #3368)
|
|
*
|
|
* Run: node --import tsx/esm --test tests/unit/bulk-web-session-import.test.ts
|
|
*/
|
|
|
|
import { describe, it } from "node:test";
|
|
import assert from "node:assert/strict";
|
|
import { bulkWebSessionImportSchema } from "../../src/shared/validation/schemas.ts";
|
|
import {
|
|
requiresWebSessionCredential,
|
|
getWebSessionCredentialRequirement,
|
|
canUpdateProviderApiKey,
|
|
hasUsableWebSessionCredential,
|
|
resolveWebSessionImportApiKey,
|
|
} from "../../src/shared/providers/webSessionCredentials.ts";
|
|
|
|
describe("bulkWebSessionImportSchema", () => {
|
|
it("accepts valid input with single entry", () => {
|
|
const result = bulkWebSessionImportSchema.safeParse({
|
|
provider: "perplexity-web",
|
|
entries: [{ name: "Account 1", credential: "__Secure-next-auth.session-token=abc123" }],
|
|
});
|
|
assert.equal(result.success, true);
|
|
});
|
|
|
|
it("accepts valid input with multiple entries", () => {
|
|
const result = bulkWebSessionImportSchema.safeParse({
|
|
provider: "grok-web",
|
|
entries: [
|
|
{ name: "Account 1", credential: "sso=abc; sso-rw=def" },
|
|
{ name: "Account 2", credential: "sso=ghi; sso-rw=jkl" },
|
|
{ name: "Account 3", credential: "sso=mno; sso-rw=pqr" },
|
|
],
|
|
priority: 5,
|
|
});
|
|
assert.equal(result.success, true);
|
|
});
|
|
|
|
it("accepts optional globalPriority as null", () => {
|
|
const result = bulkWebSessionImportSchema.safeParse({
|
|
provider: "claude-web",
|
|
entries: [{ name: "A1", credential: "sessionKey=xyz" }],
|
|
globalPriority: null,
|
|
});
|
|
assert.equal(result.success, true);
|
|
});
|
|
|
|
it("rejects empty entries array", () => {
|
|
const result = bulkWebSessionImportSchema.safeParse({
|
|
provider: "perplexity-web",
|
|
entries: [],
|
|
});
|
|
assert.equal(result.success, false);
|
|
});
|
|
|
|
it("rejects more than 50 entries", () => {
|
|
const entries = Array.from({ length: 51 }, (_, i) => ({
|
|
name: `Account ${i}`,
|
|
credential: "cookie=value",
|
|
}));
|
|
const result = bulkWebSessionImportSchema.safeParse({
|
|
provider: "perplexity-web",
|
|
entries,
|
|
});
|
|
assert.equal(result.success, false);
|
|
});
|
|
|
|
it("rejects entry with empty credential", () => {
|
|
const result = bulkWebSessionImportSchema.safeParse({
|
|
provider: "perplexity-web",
|
|
entries: [{ name: "Account 1", credential: "" }],
|
|
});
|
|
assert.equal(result.success, false);
|
|
});
|
|
|
|
it("rejects entry with empty name", () => {
|
|
const result = bulkWebSessionImportSchema.safeParse({
|
|
provider: "perplexity-web",
|
|
entries: [{ name: "", credential: "cookie=value" }],
|
|
});
|
|
assert.equal(result.success, false);
|
|
});
|
|
|
|
it("rejects missing provider", () => {
|
|
const result = bulkWebSessionImportSchema.safeParse({
|
|
entries: [{ name: "A1", credential: "cookie=value" }],
|
|
});
|
|
assert.equal(result.success, false);
|
|
});
|
|
|
|
it("rejects priority out of range", () => {
|
|
const result = bulkWebSessionImportSchema.safeParse({
|
|
provider: "perplexity-web",
|
|
entries: [{ name: "A1", credential: "cookie=value" }],
|
|
priority: 0,
|
|
});
|
|
assert.equal(result.success, false);
|
|
|
|
const result2 = bulkWebSessionImportSchema.safeParse({
|
|
provider: "perplexity-web",
|
|
entries: [{ name: "A1", credential: "cookie=value" }],
|
|
priority: 101,
|
|
});
|
|
assert.equal(result2.success, false);
|
|
});
|
|
|
|
it("accepts exactly 50 entries (boundary)", () => {
|
|
const entries = Array.from({ length: 50 }, (_, i) => ({
|
|
name: `Account ${i}`,
|
|
credential: "cookie=value",
|
|
}));
|
|
const result = bulkWebSessionImportSchema.safeParse({
|
|
provider: "perplexity-web",
|
|
entries,
|
|
});
|
|
assert.equal(result.success, true);
|
|
});
|
|
});
|
|
|
|
describe("web-session credential helpers", () => {
|
|
it("requiresWebSessionCredential returns true for web-cookie providers", () => {
|
|
assert.equal(requiresWebSessionCredential("perplexity-web"), true);
|
|
assert.equal(requiresWebSessionCredential("grok-web"), true);
|
|
assert.equal(requiresWebSessionCredential("claude-web"), true);
|
|
assert.equal(requiresWebSessionCredential("deepseek-web"), true);
|
|
});
|
|
|
|
it("requiresWebSessionCredential returns false for non-web providers", () => {
|
|
assert.equal(requiresWebSessionCredential("openai"), false);
|
|
assert.equal(requiresWebSessionCredential("anthropic"), false);
|
|
assert.equal(requiresWebSessionCredential("nonexistent"), false);
|
|
});
|
|
|
|
it("getWebSessionCredentialRequirement returns correct kind for cookie providers", () => {
|
|
const req = getWebSessionCredentialRequirement("perplexity-web");
|
|
assert.ok(req);
|
|
assert.equal(req.kind, "cookie");
|
|
});
|
|
|
|
it("getWebSessionCredentialRequirement returns correct kind for token providers", () => {
|
|
const req = getWebSessionCredentialRequirement("deepseek-web");
|
|
assert.ok(req);
|
|
assert.equal(req.kind, "token");
|
|
});
|
|
|
|
it("hasUsableWebSessionCredential validates cookie data correctly", () => {
|
|
assert.equal(
|
|
hasUsableWebSessionCredential("perplexity-web", {
|
|
cookie: "__Secure-next-auth.session-token=abc",
|
|
}),
|
|
true
|
|
);
|
|
assert.equal(hasUsableWebSessionCredential("perplexity-web", { cookie: "" }), false);
|
|
assert.equal(hasUsableWebSessionCredential("perplexity-web", {}), false);
|
|
});
|
|
|
|
it("hasUsableWebSessionCredential validates token data correctly", () => {
|
|
assert.equal(hasUsableWebSessionCredential("deepseek-web", { token: "my-token" }), true);
|
|
assert.equal(hasUsableWebSessionCredential("deepseek-web", { token: " " }), false);
|
|
});
|
|
});
|
|
|
|
describe("canUpdateProviderApiKey", () => {
|
|
it("preserves normal API-key credential updates", () => {
|
|
assert.equal(canUpdateProviderApiKey("apikey", "openai"), true);
|
|
});
|
|
|
|
it("allows token-kind web sessions stored with cookie authType", () => {
|
|
assert.equal(canUpdateProviderApiKey("cookie", "deepseek-web"), true);
|
|
assert.equal(canUpdateProviderApiKey("cookie", "zai-web"), true);
|
|
});
|
|
|
|
it("does not allow cookie-kind web sessions to update apiKey", () => {
|
|
assert.equal(canUpdateProviderApiKey("cookie", "perplexity-web"), false);
|
|
assert.equal(canUpdateProviderApiKey("cookie", "claude-web"), false);
|
|
});
|
|
|
|
it("does not broaden non-cookie auth types", () => {
|
|
assert.equal(canUpdateProviderApiKey("oauth", "deepseek-web"), false);
|
|
assert.equal(canUpdateProviderApiKey(null, "deepseek-web"), false);
|
|
});
|
|
});
|
|
|
|
describe("resolveWebSessionImportApiKey (token-kind imports must populate apiKey)", () => {
|
|
// Regression: the bulk web-session import stored token-kind credentials
|
|
// (deepseek-web, copilot-web, t3-chat-web, …) only in providerSpecificData and
|
|
// left apiKey null. Both the connection validator (validateDeepSeekWebProvider)
|
|
// and the executor (extractUserToken → credentials.apiKey) read the token from
|
|
// apiKey, so imported token-kind connections were never recognized. Token-kind
|
|
// must resolve the credential into apiKey; cookie-kind keeps apiKey null (those
|
|
// executors read providerSpecificData.cookie).
|
|
it("returns the credential for a token-kind provider (deepseek-web)", () => {
|
|
const req = getWebSessionCredentialRequirement("deepseek-web");
|
|
assert.equal(
|
|
resolveWebSessionImportApiKey(req, "j9CVFGvd8Y/deadbeeftoken"),
|
|
"j9CVFGvd8Y/deadbeeftoken"
|
|
);
|
|
});
|
|
|
|
it("preserves a JSON-wrapped userToken verbatim (extractUserToken unwraps it later)", () => {
|
|
const req = getWebSessionCredentialRequirement("deepseek-web");
|
|
const blob = '{"value":"abc123","__version":"0"}';
|
|
assert.equal(resolveWebSessionImportApiKey(req, blob), blob);
|
|
});
|
|
|
|
it("returns null for cookie-kind providers (they read providerSpecificData.cookie)", () => {
|
|
assert.equal(
|
|
resolveWebSessionImportApiKey(
|
|
getWebSessionCredentialRequirement("claude-web"),
|
|
"sessionKey=abc"
|
|
),
|
|
null
|
|
);
|
|
assert.equal(
|
|
resolveWebSessionImportApiKey(
|
|
getWebSessionCredentialRequirement("perplexity-web"),
|
|
"__Secure-next-auth.session-token=abc"
|
|
),
|
|
null
|
|
);
|
|
});
|
|
|
|
it("returns null for a whitespace-only or missing credential", () => {
|
|
const req = getWebSessionCredentialRequirement("deepseek-web");
|
|
assert.equal(resolveWebSessionImportApiKey(req, " "), null);
|
|
assert.equal(resolveWebSessionImportApiKey(null, "anything"), null);
|
|
});
|
|
|
|
it("trims surrounding whitespace from the stored token", () => {
|
|
const req = getWebSessionCredentialRequirement("copilot-web");
|
|
assert.equal(resolveWebSessionImportApiKey(req, " tok-123 "), "tok-123");
|
|
});
|
|
});
|