Files
OmniRoute/tests/unit/route-guard-cursor-agent-availability.test.ts
Praveen K Palaniswamy 65e81158ab fix(ollama): route models by advertised capability (#11088)
Landed with the design call resolved per the owner's pick — **option 1**: the synced store is now endpoint-agnostic (persistDiscoveredModels and managedModelImport no longer drop non-chat models at write time), and chat selectability moved to read time (auto-pool expansion in autoStrategy applies filterChatSelectableModels; the models-route projection already had its chatOnly filter). Your discovery test now passes end-to-end (3/3): /api/show capabilities persist per connection and image/embedding requests route through the advertising host.

Reconciliation notes: conflicted areas merged onto the current tip (adobe discovery import, requestedModel preflight signature, resolvedProvider fast-path coexists with the synced-route override — explicit resolution wins); carried base-red drains (#10055 memoization, #11071 test variants) dropped as already-landed; the managed-model-import exclusion test was propagated to the new contract (image/video models persist; the read filter still hides them from chat pickers — pinned by a new assertion). Full battery: 205/206 focused (the one red is a confirmed periodic-timer timing flake on the loaded devbox — 20/20 isolated), autoCombo vitest 30/30, combo suites 46/46, gates + typecheck clean.

Thank you @yourspraveen — the capability probe + routing design was right; it just needed the store contract opened up. Fixes #11087.
2026-08-23 11:45:01 -03:00

50 lines
2.7 KiB
TypeScript

/**
* Security regression (Cursor renewal plan, Task 5): GET
* /api/providers/cursor/agent-availability is a credential-free check for the
* dashboard's install-nudge banner, but it still spawns `cursor-agent status
* --format json` (via checkCursorAgentAvailability()/
* getCachedCursorAgentAvailability()) — so it MUST be LOCAL_ONLY, same as
* every other spawn-capable route (Hard Rules #15 + #17).
*
* Unlike Task 4's refresh-cursor route, this one is a STATIC path (no dynamic
* `[id]` segment), so it's classified via the flat LOCAL_ONLY_API_PREFIXES
* list, not a regex in LOCAL_ONLY_API_PATTERNS. It was originally scoped
* under `/api/oauth/cursor/agent-availability` during planning, then
* relocated under `/api/providers/` because `/api/oauth/` is PUBLIC-classified
* (see classify.ts) and never reaches the LOCAL_ONLY gate at all — see
* docs/security/ROUTE_GUARD_TIERS.md. The classifyRoute assertion below pins
* that decision as a regression guard against ever moving this back.
*/
import test from "node:test";
import assert from "node:assert/strict";
import { isLocalOnlyPath } from "../../src/server/authz/routeGuard.ts";
import { classifyRoute } from "../../src/server/authz/classify.ts";
test("/api/providers/cursor/agent-availability is LOCAL_ONLY (spawns cursor-agent status)", () => {
assert.equal(isLocalOnlyPath("/api/providers/cursor/agent-availability"), true);
});
test("/api/providers/cursor/agent-availability with a trailing slash is LOCAL_ONLY", () => {
assert.equal(isLocalOnlyPath("/api/providers/cursor/agent-availability/"), true);
});
test("classifyRoute resolves this path to MANAGEMENT, never PUBLIC (regression guard against moving it under /api/oauth/)", () => {
const classification = classifyRoute("/api/providers/cursor/agent-availability", "GET");
assert.equal(classification.routeClass, "MANAGEMENT");
});
test("does not over-match unrelated /api/providers paths", () => {
// LOCAL_ONLY_API_PREFIXES entries are matched via plain startsWith (see
// isLocalOnlyPath) — like every other exact-path-style sibling entry in
// that array (e.g. /api/system/version, /api/oauth/cursor/auto-import,
// /api/acp/agents), this is a bare path with no trailing slash, so it is
// NOT segment-boundary-anchored the way the regex-based /login and
// /refresh-cursor entries in LOCAL_ONLY_API_PATTERNS are (see
// tests/unit/route-guard-cursor-refresh.test.ts). Only paths that don't
// share the prefix at all are meaningful negative cases here.
assert.equal(isLocalOnlyPath("/api/providers"), false);
assert.equal(isLocalOnlyPath("/api/providers/"), false);
assert.equal(isLocalOnlyPath("/api/providers/cursor"), false);
assert.equal(isLocalOnlyPath("/api/providers/abc123/refresh"), false);
});