Files
OmniRoute/tests/unit/migration-149-api-key-combo-access.test.ts
Xiangzhe b082d0735b fix(api-manager): allow empty combo restrictions (#10066)
* fix(api-manager): allow empty combo restrictions

Represent unrestricted Combo access explicitly as combo/* so an empty Allowed Combos list can deny every Combo without affecting direct model routes. Preserve existing keys through migration 149 and cover Dashboard, policy, routing-target, and migration behavior.

* docs: sync migration count to 149 after api-key combo-access migration

Merging release/v3.8.50 forward landed 149_api_key_combo_access.sql,
bumping the real migration count from 148 to 149. Updates README.md,
AGENTS.md, llm.txt (root + all 42 i18n mirrors, exact-copy requirement)
so the strict docs-counts-sync gate matches the live count again.

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>

---------

Co-authored-by: adevwithpurpose <adevwithpurpose@users.noreply.github.com>
Co-authored-by: xz-dev <xz-dev@users.noreply.github.com>
Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
2026-08-17 07:00:05 -03:00

47 lines
1.6 KiB
TypeScript

import test from "node:test";
import assert from "node:assert/strict";
import fs from "node:fs";
import path from "node:path";
import { fileURLToPath } from "node:url";
import DatabaseSync from "better-sqlite3";
const repoRoot = path.resolve(path.dirname(fileURLToPath(import.meta.url)), "../..");
const migrationPath = path.join(repoRoot, "src/lib/db/migrations/149_api_key_combo_access.sql");
test("combo-access migration preserves legacy allow-all rows and named allowlists", () => {
const sql = fs.readFileSync(migrationPath, "utf8");
const db = new DatabaseSync(":memory:");
db.exec(`
CREATE TABLE api_keys (
id TEXT PRIMARY KEY,
allowed_combos TEXT
);
INSERT INTO api_keys (id, allowed_combos) VALUES
('legacy-null', NULL),
('legacy-empty', '[]'),
('legacy-blank', ''),
('legacy-malformed', 'not-json'),
('named', '["fast-chat"]'),
('all', '["combo/*"]');
`);
db.exec(sql);
db.exec(sql);
const rows = db.prepare("SELECT id, allowed_combos FROM api_keys ORDER BY id").all() as Array<{
id: string;
allowed_combos: string;
}>;
const combosById = new Map(
rows.map((row) => [row.id, JSON.parse(row.allowed_combos) as string[]])
);
assert.deepEqual(combosById.get("legacy-null"), ["combo/*"]);
assert.deepEqual(combosById.get("legacy-empty"), ["combo/*"]);
assert.deepEqual(combosById.get("legacy-blank"), ["combo/*"]);
assert.deepEqual(combosById.get("legacy-malformed"), ["combo/*"]);
assert.deepEqual(combosById.get("named"), ["fast-chat"]);
assert.deepEqual(combosById.get("all"), ["combo/*"]);
});