Files
OmniRoute/tests/unit/adobe-firefly-security.test.ts
Praveen K Palaniswamy 65e81158ab fix(ollama): route models by advertised capability (#11088)
Landed with the design call resolved per the owner's pick — **option 1**: the synced store is now endpoint-agnostic (persistDiscoveredModels and managedModelImport no longer drop non-chat models at write time), and chat selectability moved to read time (auto-pool expansion in autoStrategy applies filterChatSelectableModels; the models-route projection already had its chatOnly filter). Your discovery test now passes end-to-end (3/3): /api/show capabilities persist per connection and image/embedding requests route through the advertising host.

Reconciliation notes: conflicted areas merged onto the current tip (adobe discovery import, requestedModel preflight signature, resolvedProvider fast-path coexists with the synced-route override — explicit resolution wins); carried base-red drains (#10055 memoization, #11071 test variants) dropped as already-landed; the managed-model-import exclusion test was propagated to the new contract (image/video models persist; the read filter still hides them from chat pickers — pinned by a new assertion). Full battery: 205/206 focused (the one red is a confirmed periodic-timer timing flake on the loaded devbox — 20/20 isolated), autoCombo vitest 30/30, combo suites 46/46, gates + typecheck clean.

Thank you @yourspraveen — the capability probe + routing design was right; it just needed the store contract opened up. Fixes #11087.
2026-08-23 11:45:01 -03:00

51 lines
2.1 KiB
TypeScript

import assert from "node:assert/strict";
import test from "node:test";
import {
decodeAdobeJwtPayload,
extractAdobeCookieHeader,
extractAdobeCredentialToken,
} from "../../open-sse/services/adobeFireflyClient.ts";
import {
isAdobeFireflyApiUrl,
isAdobeLoginCookieDomain,
} from "../../open-sse/services/adobeFireflySecurity.ts";
function adobeJwt(payload: Record<string, unknown>): string {
const header = Buffer.from(JSON.stringify({ alg: "none", typ: "JWT" })).toString("base64url");
const body = Buffer.from(JSON.stringify(payload)).toString("base64url");
return `${header}.${body}.signature`;
}
test("Adobe JWT extraction accepts bounded tokens and strips them from cookie blobs", () => {
const token = adobeJwt({ user_id: "account-1", exp: 4_102_444_800 });
assert.equal(extractAdobeCredentialToken(`Authorization: Bearer ${token}`), token);
assert.deepEqual(decodeAdobeJwtPayload(token), {
user_id: "account-1",
exp: 4_102_444_800,
});
assert.equal(
extractAdobeCookieHeader(`session=live; ${token}; locale=en`),
"session=live; locale=en"
);
});
test("Adobe JWT parsing rejects adversarial unbounded segments", () => {
const oversized = `eyJ${"a".repeat(5_000)}.${"b".repeat(5_000)}.${"c".repeat(5_000)}`;
assert.equal(decodeAdobeJwtPayload(oversized), null);
});
test("Adobe CDP capture only trusts exact Adobe DNS suffixes", () => {
assert.equal(isAdobeFireflyApiUrl("https://firefly-3p.ff.adobe.io/v1/jobs"), true);
assert.equal(isAdobeFireflyApiUrl("https://edge.firefly-3p.ff.adobe.io/v1/jobs"), true);
assert.equal(isAdobeFireflyApiUrl("https://firefly-3p.ff.adobe.io.attacker.test/v1"), false);
assert.equal(isAdobeFireflyApiUrl("https://attacker.test/firefly-3p.ff.adobe.io"), false);
assert.equal(isAdobeFireflyApiUrl("not a URL"), false);
assert.equal(isAdobeLoginCookieDomain("adobelogin.com"), true);
assert.equal(isAdobeLoginCookieDomain(".auth.adobelogin.com"), true);
assert.equal(isAdobeLoginCookieDomain("evil-adobelogin.com"), false);
assert.equal(isAdobeLoginCookieDomain("adobelogin.com.attacker.test"), false);
});