mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-09-18 04:42:30 +03:00
Landed with the design call resolved per the owner's pick — **option 1**: the synced store is now endpoint-agnostic (persistDiscoveredModels and managedModelImport no longer drop non-chat models at write time), and chat selectability moved to read time (auto-pool expansion in autoStrategy applies filterChatSelectableModels; the models-route projection already had its chatOnly filter). Your discovery test now passes end-to-end (3/3): /api/show capabilities persist per connection and image/embedding requests route through the advertising host. Reconciliation notes: conflicted areas merged onto the current tip (adobe discovery import, requestedModel preflight signature, resolvedProvider fast-path coexists with the synced-route override — explicit resolution wins); carried base-red drains (#10055 memoization, #11071 test variants) dropped as already-landed; the managed-model-import exclusion test was propagated to the new contract (image/video models persist; the read filter still hides them from chat pickers — pinned by a new assertion). Full battery: 205/206 focused (the one red is a confirmed periodic-timer timing flake on the loaded devbox — 20/20 isolated), autoCombo vitest 30/30, combo suites 46/46, gates + typecheck clean. Thank you @yourspraveen — the capability probe + routing design was right; it just needed the store contract opened up. Fixes #11087.
91 lines
3.6 KiB
TypeScript
91 lines
3.6 KiB
TypeScript
// #7859: adding a token to "Gemini Web (Free)" always failed the connection test with
|
|
// "Redirect blocked for GET https://gemini.google.com/app (302)". Root cause:
|
|
// validateGeminiWebProvider() probes https://gemini.google.com/app via validationRead(),
|
|
// which uses the `validationRead` safeOutboundFetch preset (allowRedirect: false). Gemini
|
|
// Web responds with a 302 to a public host (e.g. accounts.google.com) for EVERY session —
|
|
// valid or not — so safeOutboundFetch always throws SafeOutboundFetchError with code
|
|
// REDIRECT_BLOCKED *before* the "200/302 = valid" status check the function's own comment
|
|
// describes ever runs. The throw fell through to the generic catch → toValidationErrorResult(),
|
|
// which always returned `valid: false`, making the provider permanently unusable.
|
|
//
|
|
// Fix: catch REDIRECT_BLOCKED explicitly and treat a redirect to a PUBLIC host as success
|
|
// (the session probe reached Gemini and got redirected onward — that is what a valid
|
|
// session looks like). A redirect to a PRIVATE/internal host must still be rejected — that
|
|
// would be a genuine SSRF signal, not a valid Gemini session.
|
|
import test from "node:test";
|
|
import assert from "node:assert/strict";
|
|
|
|
const { validateGeminiWebProvider } =
|
|
await import("../../src/lib/providers/validation/webProvidersB.ts");
|
|
|
|
const originalFetch = globalThis.fetch;
|
|
|
|
test.afterEach(() => {
|
|
globalThis.fetch = originalFetch;
|
|
});
|
|
|
|
// #9407 refined this contract: a redirect to accounts.google.com/ServiceLogin is
|
|
// specifically an EXPIRED session (valid:false with re-paste guidance), while other
|
|
// public accounts.google.com paths remain valid-with-warning. The original #7859
|
|
// regression (public redirect must not fall through to the generic catch → invalid)
|
|
// is still covered — by the non-ServiceLogin variant below.
|
|
test("gemini-web validator: 302 redirect to ServiceLogin → expired session (#9407)", async () => {
|
|
globalThis.fetch = async (url) => {
|
|
const target = String(url);
|
|
if (target.includes("gemini.google.com/app")) {
|
|
return new Response(null, {
|
|
status: 302,
|
|
headers: { location: "https://accounts.google.com/ServiceLogin" },
|
|
});
|
|
}
|
|
throw new Error(`unexpected fetch: ${target}`);
|
|
};
|
|
|
|
const result = await validateGeminiWebProvider({
|
|
apiKey: "__Secure-1PSID=eyJvalidsession",
|
|
});
|
|
|
|
assert.equal(result.valid, false);
|
|
assert.match(result.error || "", /Session expired/i);
|
|
});
|
|
|
|
test("gemini-web validator: 302 redirect to a PUBLIC host → valid (regression #7859)", async () => {
|
|
globalThis.fetch = async (url) => {
|
|
const target = String(url);
|
|
if (target.includes("gemini.google.com/app")) {
|
|
return new Response(null, {
|
|
status: 302,
|
|
headers: { location: "https://accounts.google.com/signin/continue" },
|
|
});
|
|
}
|
|
throw new Error(`unexpected fetch: ${target}`);
|
|
};
|
|
|
|
const result = await validateGeminiWebProvider({
|
|
apiKey: "__Secure-1PSID=eyJvalidsession",
|
|
});
|
|
|
|
assert.equal(result.valid, true);
|
|
assert.equal(result.error, null);
|
|
});
|
|
|
|
test("gemini-web validator: 302 redirect to a PRIVATE host stays invalid (no SSRF)", async () => {
|
|
globalThis.fetch = async (url) => {
|
|
const target = String(url);
|
|
if (target.includes("gemini.google.com/app")) {
|
|
return new Response(null, {
|
|
status: 302,
|
|
headers: { location: "http://169.254.169.254/latest/meta-data/" },
|
|
});
|
|
}
|
|
throw new Error(`unexpected fetch: ${target}`);
|
|
};
|
|
|
|
const result = await validateGeminiWebProvider({
|
|
apiKey: "__Secure-1PSID=eyJvalidsession",
|
|
});
|
|
|
|
assert.equal(result.valid, false);
|
|
assert.equal((result as { securityBlocked?: boolean }).securityBlocked, true);
|
|
});
|