Files
OmniRoute/tests/unit/noauth-provider-validation.test.ts
Diego Rodrigues de Sa e Souza b6975537c1 fix(providers): remove the chipotle/pepper provider (#13131) (#13913)
* fix(providers): remove the chipotle/pepper provider (#13131)

amelia.chipotle.com (the reverse-engineered Amelia chat-widget backend
chipotle/pepper-1 talked to) now returns 404 on every route, including
root, from its Azure Application Gateway — confirmed live 2026-09-15.
This regressed from a WS handshake timeout (#4037, June 2026) to a
fully decommissioned host, so the upstream protocol cannot be fixed.
Owner decided to retire the provider entirely (Option B), following
the phind/kluster quiet-removal precedent: no REMOVED_PROVIDERS.md
entry (reserved for operator takedowns), just a one-line note under
FREE_TIERS.md "Removed / no free tier".

Removed every surface: executor, registry entry, executors/index.ts
and providers/index.ts wiring, noauth provider catalog entry,
ProviderIcon generic-fallback set, the autoCombo exclusion-list
comment, the chipotle_error code from the sanitizer allowlist,
PROVIDER_REFERENCE.md (regenerated), and every doc/test reference.

Regression test: tests/unit/issue-13131-chipotle-provider-removed.test.ts
asserts the provider is fully gone from the executor registry, the
provider REGISTRY and the noauth catalog, and that the executor module
no longer resolves — not a live-network repro (flaky/third-party).

Several existing tests used "chipotle" only as a generic noAuth-provider
example (proxy scoping, error classification, onboarding, fallback
text) with no chipotle-specific behavior under test; those were
re-pointed at another still-existing noAuth provider
(cloudflare-playground / duckduckgo-web) rather than weakened.

* test(providers): document the agnes-cn/chipotle count coincidence (#13131)

provider-node-reserved-prefix.test.ts's REGISTRY id+alias walk was
already red on the base tip (414 vs. expected 412) from agnes-cn
(#13399, +id/+alias). Removing chipotle's REGISTRY id/alias in this
PR nets it back to 412, making the test pass again without a numeric
edit — record why in a comment so it doesn't read as an untracked
coincidence later.
2026-09-17 13:22:09 -03:00

46 lines
1.6 KiB
TypeScript

/**
* Tests for noAuth provider validation:
* - Bug 1: a noAuth provider missing from providerAllowsOptionalApiKey
* - `kimi` API key provider stays on the dedicated Moonshot executor
*/
import test from "node:test";
import assert from "node:assert/strict";
import {
NOAUTH_PROVIDERS,
providerAllowsOptionalApiKey,
supportsNoAuthProviderProxy,
} from "../../src/shared/constants/providers.ts";
import { hasSpecializedExecutor } from "../../open-sse/executors/index.ts";
// Bug 1: all noAuth providers should allow optional API key
for (const provider of ["cloudflare-playground", "opencode", "duckduckgo-web", "veoaifree-web"]) {
test(`${provider} allows optional API key (noAuth provider)`, () => {
assert.equal(providerAllowsOptionalApiKey(provider), true);
});
}
// `kimi` is the hidden legacy id for Moonshot API compatibility, not Kimi Web.
test("kimi API key provider uses the specialized Moonshot executor", () => {
assert.equal(hasSpecializedExecutor("kimi"), true);
});
// no regression: kimi-web and kimi-coding still have their executors
test("kimi-web still has specialized executor", () => {
assert.equal(hasSpecializedExecutor("kimi-web"), true);
});
test("kimi-coding-apikey still has specialized executor", () => {
assert.equal(hasSpecializedExecutor("kimi-coding-apikey"), true);
});
test("provider proxy controls use a centralized no-auth capability allowlist", () => {
assert.equal(supportsNoAuthProviderProxy("opencode"), true);
for (const providerId of Object.keys(NOAUTH_PROVIDERS)) {
if (providerId !== "opencode") {
assert.equal(supportsNoAuthProviderProxy(providerId), false, providerId);
}
}
});