Files
OmniRoute/tests/unit/oauth-providers-config.test.ts
Diego Rodrigues de Sa e Souza f59f8daa94 Release v3.8.6 (#2804)
* fix(gemini): preserve structured tool calls for antigravity

* fix(gemini): parse prefixed textual tool calls

* fix(antigravity): preserve textual SSE tool calls

* fix(stream): normalize textual passthrough tool calls

* fix(stream): normalize split textual tool calls

* fix(stream): suppress malformed textual tool calls

* fix(stream): suppress compact malformed tool calls

* fix(stream): emit structured textual tool calls

* fix(stream): suppress unknown textual tool calls

* fix(stream): normalize responses textual tool calls

* chore: ignore .claude/settings.local.json (per-user Claude Code permissions)

* fix(opencode-go): route qwen3.x via claude messages + repair fixMissingToolResponses for Claude-shape upstreams (#2791)

Integrated into release/v3.8.6

* fix: resolve npm install warnings — remove dead deps, relax engine constraint (#2792)

Integrated into release/v3.8.6

* fix: register missing web-cookie validators (claude-web, gemini-web, copilot-web, t3-web) (#2793)

Integrated into release/v3.8.6

* fix: Error: Unable to inspect existing database #2771 (#2795)

Integrated into release/v3.8.6

* fix(oauth): repair Google loopback callback flow (#2796)

Integrated into release/v3.8.6

* feat(logs): add clean history button (#2799)

Integrated into release/v3.8.6

* [codex] home: restore settings-driven home layout and quota auto-refresh (#2800)

Integrated into release/v3.8.6

* fix(gemini): emit signaturelessToolCallMode:text for GEMINI format models (#2801)

Integrated into release/v3.8.6

* feat(modelSpecs): align opencode-go family with upstream provider limits (#2802)

Integrated into release/v3.8.6

* chore: apply unit test fixes, polyfills, and environment precedence fixes

* docs(agents): atualiza fluxos de release e triagem

Expande os workflows de release para incluir auditoria de segurança,
CHANGELOG completo por commits, quality gate obrigatório, homologação em
VPS local, publicação oficial, deploy em Akamai e validação de artefatos.

Reorganiza a triagem de features com arquivos permanentes por bucket,
suporte a itens em andamento, regra de reclaim após 15 dias e novo
tratamento para ideias viáveis catalogadas.

Corrige a orientação de revisão de discussões para usar a ordem
cronológica real dos comentários e respostas ao identificar a última
atividade.

* fix(lockout): classify Gemini Antigravity resource exhaustion as quota_exhausted

* fix(reasoning): gate replay by interleaved field

* docs(rule-16): permit human Co-authored-by, restrict only AI/bot trailers

Rule #16 previously banned all `Co-Authored-By` trailers absolutely.
That blocked the upstream-port workflows (`/port-upstream-features` and
`/port-upstream-issues`), which must credit human upstream PR authors
and issue reporters in OmniRoute commits.

Refine the rule to ban only AI/bot-attributed trailers (Claude, GPT,
Copilot, Bot; anthropic.com / openai.com / bot-owned noreply.github.com
emails) while allowing standard human `Co-authored-by: Name <email>`
attribution.

Sync the rule across the source CLAUDE.md, the E2E shakedown doc note,
and 41 i18n translations.

* fix(gitlawb): add specialty validators for connection test — bypass /models probe

GitLawB OpenGateway API (xiaomi-mimo compatible) does not expose a /models
endpoint, causing validateOpenAILikeProvider to 404 on the initial probe
and report 'Provider validation endpoint not supported'.

Add specialty validators for both gitlawb and gitlawb-gmi that follow the
same pattern as the existing xiaomi-mimo validator: skip GET /models,
validate directly via POST /chat/completions with a minimal test message.
Any 401/403 response means an invalid key; all other responses mean auth
is OK.

Fixes test-connection returning 404 for GitLawB providers.

* test(gitlawb): add 12 unit tests for gitlawb and gitlawb-gmi specialty validators

Covers success, auth failure (401/403), non-auth acceptance (400/422/429),
network errors, and custom baseUrl overrides for both providers.

* feat(gitlawb): serve models from static registry without API-unavailable warning

GitLawB's OpenGateway API does not expose a /models endpoint per
provider-path. Previously the models route fell through to the generic
fallback which returned static catalog models with the misleading
'API unavailable — using local catalog' warning.

Now gitlawb and gitlawb-gmi are handled as static model providers
(same pattern as reka and qwen OAuth) — models are served from the
provider registry without any warning, since all registered models
are functional via POST /chat/completions.

* refactor(gitlawb): extract shared opengateway validator factory, fix docs path in test

- Extract gitlawb/gitlawb-gmi validators into buildOpengatewayValidator factory
- Fix dockerignore-docs-coverage test: update stale docs/AUTO-COMBO.md -> docs/routing/AUTO-COMBO.md

* fix(reasoning): guard interleaved capability lookup

* feat(gitlawb): dynamic model fetch with gmi-cloud fallback

Hybrid approach:
- gitlawb (xiaomi-mimo): dynamic /models endpoint → 356 models
- gitlawb-gmi (gmi-cloud): 404 fallback → local catalog gracefully
Mimics Gitlawb/openclaude's model-routing pattern

* i18n(pt-BR): complete missing translations and sync with en.json

* feat(build): nix multi-OS package manager install (#2806)

Integrated into release/v3.8.6

* fix(i18n): translate 144 new __MISSING__ pt-BR strings (#2816)

Integrated into release/v3.8.6

* chore(docs): set coverage gate to 40/40/40/40 in CLAUDE.md

Aligns the documented coverage gate with the v3.8.6 release decision
(lowered from 75/75/75/70). Matches the threshold already set in
package.json by the large feature PRs (planos 11-22).

* fix(cli): respect PORT env var in serve command (#2845)

Integrated into release/v3.8.6.

* fix(deepseek-web): return 400 when client sends tools[] - chat.deepseek.com has no tool support (#2854)

Integrated into release/v3.8.6.

* fix(qoder): reject invalid/expired PATs returning Cosy 500 error (#2860)

Integrated into release/v3.8.6.

* fix(cli): register openclaw in tool-detector (#2833) (#2850)

Integrated into release/v3.8.6.

* fix(api): include noAuth providers in /v1/models catalog (#2798) (#2814)

Integrated into release/v3.8.6.

* fix(combo): resolve custom provider targets via combo name (#2778) (#2812)

Integrated into release/v3.8.6.

* fix(translator): strip safety_identifier in openai-responses cleanup (#2770) (#2809)

Integrated into release/v3.8.6.

* fix(quota): honor explicit per-connection preflight opt-out (#2831) (#2844)

Integrated into release/v3.8.6.

* fix(usage): un-invert GitHub Copilot Free/limited quota — limited_user_quotas is remaining (#2876) (#2881)

Integrated into release/v3.8.6.

* fix(nous-research): correct baseUrl to include /chat/completions (#2826) (#2835)

Integrated into release/v3.8.6.

* fix(opencode): qwen3.x max/plus models lack vision support (#2822) (#2836)

Integrated into release/v3.8.6.

* fix(translator): pass-through tool_search built-in tool type (#2766) (#2811)

Integrated into release/v3.8.6.

* fix(github): route claude-opus-4.6 via chat completions (#2821)

Integrated into release/v3.8.6.

* docs(oauth): add Windsurf login fix design (Phase 1 hotfix + Phase 2 Firebase OAuth)

Two-phase plan to fix the broken Windsurf OAuth flow:
- Phase 1: drop the dead app.devin.ai/editor/signin PKCE path, promote
  import-token from windsurf.com/show-auth-token as the primary path
- Phase 2: port Firebase OAuth + RegisterUser flow from
  fendoushaonian/WindSurf-gRPC-API for full browser-based automation

Spec only - no code changes yet.

* docs(plan): Phase 1 windsurf login hotfix implementation plan

10 tasks covering:
- TDD assertions for flowType + 410 Gone responses
- Provider switch to import_token
- Route handler retiring authorize/start-callback-server/poll-callback
- OAuthModal UI override
- i18n sync
- Verification + PR steps

* fix(cli): replace cli-table3 with hand-rolled formatter (#2752) (#2813)

Integrated into release/v3.8.6.

* fix(skills): skip interception for unregistered client-native tools (#2815) (#2817)

Integrated into release/v3.8.6.

* feat(sse): add RTK filters for kubectl, docker-build, composer, gh (#2824)

Integrated into release/v3.8.6.

* fix(geminiHelper): support rec.image content shape + warn on dropped remote URLs (refs #2807) (#2855)

Integrated into release/v3.8.6.

* fix(cli): allow nullable/optional apiKey in cliMitmStartSchema (#2857)

Integrated into release/v3.8.6.

* fix(combo): preserve system messages during context handoff summary generation (#2865)

Integrated into release/v3.8.6.

* fix: wire CLIProxyAPI fallback settings into chatCore routing engine (#2866)

Integrated into release/v3.8.6.

* fix(usage): add opencode quota fetcher (#2852) (#2867)

Integrated into release/v3.8.6.

* feat(claude): default xhigh support for newer Opus models (#2874)

Integrated into release/v3.8.6.

* fix(cli): restore omniroute logs command stream (#2756) (#2810)

Integrated into release/v3.8.6.

* fix(combo): normalize upstream Headers for Node 24 undici interop (#2751) (#2823)

Integrated into release/v3.8.6.

* Rename proxy log Public IP to Client IP (#2880)

Integrated into release/v3.8.6.

* fix(claude): preserve max effort for supported models (#2875)

Integrated into release/v3.8.6.

* fix(oauth): switch windsurf provider to import_token flow

The PKCE auth URL targeting app.devin.ai/editor/signin returns 404
post-rebrand. Until Phase 2 ports Firebase OAuth + RegisterUser, the
only supported path is import-token via windsurf.com/show-auth-token.

- windsurf.ts: drop buildAuthUrl, set flowType=import_token
- generateAuthData returns supported:false + helpful error for windsurf/devin-cli
- tests: assert flowType + disabled stub

* fix(oauth): return 410 Gone for retired windsurf/devin-cli PKCE actions

start-callback-server, authorize, and poll-callback (GET + POST) now
return 410 Gone with a pointer to /import-token. The 410 short-circuit
runs before auth so the response is honest about the action being
permanently gone, not gated. Codex PKCE flow unchanged.

Tests: 5 new assertions cover GET + POST 410 paths and a Codex
regression check.

* refactor(oauth): annotate retired PKCE fields in WINDSURF_CONFIG

No behaviour change - comment-only update documenting that authorizeUrl,
codeChallengeMethod, callbackPort, callbackPath, apiServerUrl, and
exchangePath are no longer consumed. Active fields (inferenceUrl,
showAuthTokenUrl, firebaseApiKey, ideName) called out separately.

* fix(cli,docs): use requireCliToolsAuth in logs route + document OPENCODE quota env

Post-merge contract fixes for v3.8.6:
- src/app/api/cli-tools/logs/route.ts (#2810) now uses the shared
  requireCliToolsAuth guard (param renamed req->request) to satisfy the
  cli-tools-auth-hardening contract test.
- Document OMNIROUTE_OPENCODE_QUOTA_URL (#2867) in docs/reference/ENVIRONMENT.md
  to satisfy the env/docs sync contract.

* fix(dashboard): force import-token panel for windsurf/devin-cli

Phase 1 hotfix: hide the 'Browser Login' tab and start in Paste API Key
mode. Removes windsurf/devin-cli from PKCE_CALLBACK_SERVER_PROVIDERS so
no callback server is started for them. Codex still uses the PKCE flow.

The 'Get token' link continues to point at windsurf.com/show-auth-token
via the existing supportsTokenPaste form copy.

* fix(oauth): windsurf import-token mapTokens signature mismatch

The route at `src/app/api/oauth/[provider]/[action]/route.ts` invokes
`providerData.mapTokens({ accessToken: token })` (object), matching the
cursor/kiro signature. The windsurf provider was declared with
`mapTokens(token: string)` instead, so the entire object was stored as
`accessToken`. When the connection record reached the SQLite layer it
crashed with:

  SQLite3 can only bind numbers, strings, bigints, buffers, and null

Fix by aligning windsurf's `mapTokens` signature with the route caller
and the cursor/kiro convention. Also dedupe a copy-pasted second
`if (action === "import-token")` block in the route handler — the
second block was unreachable but identical to the first.

Adds two regression tests asserting that
`provider.mapTokens({ accessToken })` returns a string `accessToken` for
both windsurf and devin-cli, so a future signature drift trips the gate
instead of the SQLite bind error in production.

* feat(compression): expand pt-BR pack with troglodita rules (15 → 49) (#2818)

Integrated into release/v3.8.6

* fix(sse): repair RTK engine defaults so dedup and direct calls work (#2825)

Integrated into release/v3.8.6

* fix(mcp): redirect console.log/warn to stderr in --mcp stdio mode (#2840)

Integrated into release/v3.8.6

* fix(gemini-cli): prefer real project IDs over default-project (#2841)

Integrated into release/v3.8.6

* fix(opencode-go): add provider limits quota fetcher (#2861)

Integrated into release/v3.8.6

* Audit & add web cookie providers: fix 4 missing registry entries + DuckDuckGo (#2862)

Integrated into release/v3.8.6

* fix(antigravity): harden signatureless tool history (#2878)

Integrated into release/v3.8.6

* fix: provider model sync pruning and dynamic antigravity MITM proxy mappings (#2886)

Integrated into release/v3.8.6

* feat(usage): per-API-key token limits scoped to model/provider/global (#2888)

Integrated into release/v3.8.6

* fix(audio): build multipart body manually to preserve Content-Type (#2842)

Integrated into release/v3.8.6

* refactor: remove agent skill documentation files and streamline maintenance workflows

* test(stabilization): resolve unit test failures in blackbox-web, schema-coercion, translator-helper-branches, usage-service-hardening, and audio-transcription

* fix(security): mitigate Socket.dev supply-chain findings + secrets opt-in + minimal build profile (#2863) (#2871)

Two real security gaps closed and four cosmetic Socket.dev fingerprints removed.
See docs/security/SOCKET_DEV_FINDINGS.md for the per-finding maintainer
attestation.

Real bugs fixed:
- cloudSync: HMAC verification of `X-Cloud-Sig` + opt-in
  `OMNIROUTE_CLOUD_SYNC_SECRETS=true` before overwriting `accessToken` /
  `refreshToken` / `providerSpecificData` from a remote response. Closes the
  silent-credential-swap surface (a misconfigured or hostile CLOUD_URL could
  previously replace local tokens unverified).
- Zed import: split into 2-step `/discover` + `/import` flow. `/import` now
  requires `confirmedAccounts: [{ service, account, fingerprint }]` and
  re-reads the keychain server-side to filter by fingerprint, so a tampered
  discover response cannot trick the endpoint into saving an unrelated token.

Cosmetic Socket.dev mitigations:
- runElevatedPowerShell writes the elevated payload to a per-call temp `.ps1`
  file (mode 0o600) and references it via `-File`. Removes the textbook
  `-EncodedCommand <base64utf16le>` pattern flagged as malware by Socket's AI
  classifier.
- Maintainer attestation `SECURITY-AUDITOR-NOTE:` blocks added at every
  flagged call site pointing to `docs/security/SOCKET_DEV_FINDINGS.md`.

Build-time hardening:
- `OMNIROUTE_BUILD_PROFILE=minimal` (`npm run build:secure`) physically
  removes the four sensitive modules from the standalone bundle via webpack
  `NormalModuleReplacementPlugin`. Stubs throw `FeatureDisabledError` at
  runtime. Intended for the `omniroute-secure` artifact.

Tests:
- 24 new unit tests in `tests/unit/security/` covering the wrapper builder,
  HMAC verification (4 cases), credential fingerprint determinism (5 cases),
  confirmedAccounts validation + fingerprint filtering (6 cases), and the
  minimal-build stubs (5 cases).

Docs:
- New `docs/security/SOCKET_DEV_FINDINGS.md` — per-finding attestation.
- New `socket.yml` — Socket.dev v2 config pointing at the attestation.
- Updated `SECURITY.md` — supply-chain scanner section.
- Updated `.env.example` — three new env vars documented.

Backwards compatibility:
- Cloud sync token overwrite is OFF by default. Users who relied on
  it must set `OMNIROUTE_CLOUD_SYNC_SECRETS=true`. Breaking change documented
  in CHANGELOG.
- Zed import 2-step is the new default; legacy 1-step preserved behind
  `OMNIROUTE_ZED_IMPORT_LEGACY_ONE_STEP=true` and will be removed in v3.9.

Closes #2863

* fix(security): redact public Firebase Web key from windsurf spec; doc SHA-256 cache-key rationale (#2894)

Two security-scanning findings on release/v3.8.6:

- Secret-scanning alert 7 (google_api_key): the windsurf login-fix design spec
  embedded the literal public Firebase Web API key on two lines. Firebase Web
  API keys are non-sensitive by design (they identify the project; access is
  gated by Firebase Security Rules + key restrictions), but the literal trips
  secret scanning. Redacted to a placeholder; the embedded default still goes
  through resolvePublicCred per rule #11.

- Code-scanning alert 261 (js/insufficient-password-hash): tokenCacheKey() uses
  SHA-256 to derive an in-memory cache key from the session token, not for
  password-at-rest storage. Added a comment documenting why CWE-916 KDFs do not
  apply (false positive).

* fix(ci): resolve release/v3.8.6 gate failures (docs-sync, any-budget, pack-artifact) (#2895)

* fix(ci): resolve release/v3.8.6 gate failures (docs-sync, any-budget, pack-artifact)

Three CI gates failed on release/v3.8.6 (run 26630300877):

- docs-sync: CHANGELOG had a spurious "## [3.8.6-patch]" section above
  "## [3.8.6]", so the latest release no longer matched package.json (3.8.6)
  and the 41 i18n CHANGELOG mirrors were flagged as missing that section.
  Fold the lone #2752 entry into [3.8.6] and drop the patch heading.
- any-budget:t11: open-sse/handlers/chatCore.ts regressed to 1 explicit `any`
  (budget 0). Type the persist callback arg as Record<string, unknown>, which
  matches runWithOnPersist's RefreshPersistFn contract exactly.
- pack-artifact: open-sse/utils/setupPolyfill.ts ships via package.json "files"
  (bin/omniroute.mjs imports it at startup) but was missing from the pack
  policy allowlist. Allow it and add a regression test.

* fix(security): redact public Firebase Web key from windsurf spec

Redact the literal public Firebase Web API key (secret-scanning #7) to a
placeholder, mirroring the redaction on release/v3.8.6 (PR #2894) and the
windsurf fix branch. Non-sensitive public Web key; trips secret scanning.

* feat(combo): Zero-Latency Combos (Hedging, Proactive Compression, Predictive TTFT) (#2868)

* feat(combo): implement zero-latency combo optimizations (hedging, proactive compression, predictive TTFT)

* fix(combo): fix predictive TTFT skip logic and unhandled promise rejections

---------

Co-authored-by: Automation <automation@omniroute>

* feat: implement automated skill workflows and update system configuration and validation schemas

* test: eliminate dynamic cast warnings in cloud-sync unit test

* test: isolate services-branch-hardening database directory to avoid concurrency issues

* feat(providers): add 7 new web-cookie providers + research catalog + discovery tool

New providers:
- huggingchat: free LLM chat via huggingface.co/chat (no subscription)
- phind: free dev-focused AI chat via phind.com/api/agent
- poe-web: multi-model chat via poe.com GraphQL (p-b cookie)
- venice-web: privacy-focused AI chat via venice.ai (session cookie)
- v0-vercel-web: Vercel v0 code gen via v0.dev (session cookie)
- kimi-web: Moonshot Kimi chat via kimi.moonshot.cn (session cookie)
- doubao-web: ByteDance Doubao chat via doubao.com (session cookie)

Additional:
- Research catalog: docs/research/UNLIMITED_LLM_ACCESS.md
- Discovery tool design + stub: src/lib/discovery/ + migration 073
- Unit tests: 33 tests for all 7 providers
- Shared helpers consolidated in error.ts (slop cleanup)
- All registered in WEB_COOKIE_PROVIDERS + providerRegistry + webSessionCredentials

Closes #2885

* fix(typecheck): resolve typecheck errors in combo spec and compression modules

* feat(api,oauth): add `agy` (Antigravity CLI) standalone provider with CLI token import (#2899)

Add a standalone OAuth provider `agy` (Antigravity CLI) next to gemini-cli/antigravity.
It reuses the antigravity inference backend (identical Google client_id +
daily-cloudcode-pa.googleapis.com endpoint, executor and token-refresh) but ships its own
model catalog — including the Claude models the backend exposes (claude-opus-4-6-thinking,
claude-sonnet-4-6) — its own account pool, and four ways to connect:

- token-file import (paste/upload the agy oauth token JSON)
- auto-detect a local CLI login (~/.gemini/antigravity-cli/antigravity-oauth-token)
- browser OAuth (via the shared OAuthModal Google loopback flow)
- bulk / ZIP import

New routes: POST /api/providers/agy-auth/{import,import-bulk,zip-extract,apply-local}.
Catalog pinned from the live :fetchAvailableModels endpoint. Docs (openapi.yaml,
ENVIRONMENT.md, .env.example, CHANGELOG) updated; new unit tests for registration,
the token parser, and route auth-hardening.

* fix(security): redact public Firebase Web key from windsurf spec (#2896)

Redact the literal public Firebase Web API key (secret-scanning #7) to a
placeholder. Firebase Web API keys are non-sensitive by design but the literal
trips GitHub secret scanning. Mirrors the redaction landed on release/v3.8.6
(PR #2894). Embedded default still flows through resolvePublicCred (rule #11).

* Pr 2871 (#2897)

* fix(security): mitigate Socket.dev supply-chain findings + secrets opt-in + minimal build profile (#2863)

Two real security gaps closed and four cosmetic Socket.dev fingerprints removed.
See docs/security/SOCKET_DEV_FINDINGS.md for the per-finding maintainer
attestation.

Real bugs fixed:
- cloudSync: HMAC verification of `X-Cloud-Sig` + opt-in
  `OMNIROUTE_CLOUD_SYNC_SECRETS=true` before overwriting `accessToken` /
  `refreshToken` / `providerSpecificData` from a remote response. Closes the
  silent-credential-swap surface (a misconfigured or hostile CLOUD_URL could
  previously replace local tokens unverified).
- Zed import: split into 2-step `/discover` + `/import` flow. `/import` now
  requires `confirmedAccounts: [{ service, account, fingerprint }]` and
  re-reads the keychain server-side to filter by fingerprint, so a tampered
  discover response cannot trick the endpoint into saving an unrelated token.

Cosmetic Socket.dev mitigations:
- runElevatedPowerShell writes the elevated payload to a per-call temp `.ps1`
  file (mode 0o600) and references it via `-File`. Removes the textbook
  `-EncodedCommand <base64utf16le>` pattern flagged as malware by Socket's AI
  classifier.
- Maintainer attestation `SECURITY-AUDITOR-NOTE:` blocks added at every
  flagged call site pointing to `docs/security/SOCKET_DEV_FINDINGS.md`.

Build-time hardening:
- `OMNIROUTE_BUILD_PROFILE=minimal` (`npm run build:secure`) physically
  removes the four sensitive modules from the standalone bundle via webpack
  `NormalModuleReplacementPlugin`. Stubs throw `FeatureDisabledError` at
  runtime. Intended for the `omniroute-secure` artifact.

Tests:
- 24 new unit tests in `tests/unit/security/` covering the wrapper builder,
  HMAC verification (4 cases), credential fingerprint determinism (5 cases),
  confirmedAccounts validation + fingerprint filtering (6 cases), and the
  minimal-build stubs (5 cases).

Docs:
- New `docs/security/SOCKET_DEV_FINDINGS.md` — per-finding attestation.
- New `socket.yml` — Socket.dev v2 config pointing at the attestation.
- Updated `SECURITY.md` — supply-chain scanner section.
- Updated `.env.example` — three new env vars documented.

Backwards compatibility:
- Cloud sync token overwrite is OFF by default. Users who relied on
  it must set `OMNIROUTE_CLOUD_SYNC_SECRETS=true`. Breaking change documented
  in CHANGELOG.
- Zed import 2-step is the new default; legacy 1-step preserved behind
  `OMNIROUTE_ZED_IMPORT_LEGACY_ONE_STEP=true` and will be removed in v3.9.

Closes #2863

* feat: implement automated skill workflows and update system configuration and validation schemas

* test: eliminate dynamic cast warnings in cloud-sync unit test

* test: isolate services-branch-hardening database directory to avoid concurrency issues

* chore(docs): refresh generated docs collection index

Update the generated Fumadocs browser collection mapping to keep
documentation imports in sync with the current docs structure.

* docs: update generated browser docs collection manifest

Refresh the generated Fumadocs browser collection mapping so the docs site can resolve the current documentation files correctly.

---------

Co-authored-by: OpenClaw <openclaw@kuzhomesrv.local>
Co-authored-by: Dmitry Kuznetsov <139351986+dmitry@users.noreply.local>
Co-authored-by: KuzyaBot <kuzya@local>
Co-authored-by: JeferssonLemes <jeferssondev@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Markus Hartung <mail@hartmark.se>
Co-authored-by: akarray <akarray@users.noreply.github.com>
Co-authored-by: Apostol Apostolov <theapoapostolov@gmail.com>
Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Dmitry Kuznetsov <dmitry@kuznetsov.me>
Co-authored-by: Nikolay Alafuzov <alafuzov_nn@rusklimat.ru>
Co-authored-by: oyi77 <oyi77@users.noreply.github.com>
Co-authored-by: Ronaldo Davi <alltomatos@users.noreply.github.com>
Co-authored-by: levonk <277861+levonk@users.noreply.github.com>
Co-authored-by: Lenine Júnior <lenine@engrene.com.br>
Co-authored-by: Annas Alghoffar <aag.annas@gmail.com>
Co-authored-by: Tushar Agarwal <76201310+Tushar49@users.noreply.github.com>
Co-authored-by: GreatLiu <eurasiaxz@qq.com>
Co-authored-by: yuna amelia <230527278+yunaamelia@users.noreply.github.com>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
Co-authored-by: Container <78986709+disonjer@users.noreply.github.com>
Co-authored-by: nickwizard <35692452+nickwizard@users.noreply.github.com>
Co-authored-by: Rajvardhan Patil <rajvardhanpatil7890@gmail.com>
Co-authored-by: Raxxoor <manker_lol@hotmail.com>
Co-authored-by: Muhammad Mugni Hadi <mugnimaestra3@gmail.com>
Co-authored-by: mi <123757457+soyelmismo@users.noreply.github.com>
Co-authored-by: Automation <automation@omniroute>
2026-05-29 12:44:29 -03:00

833 lines
29 KiB
TypeScript

import test from "node:test";
import assert from "node:assert/strict";
// Gemini, Antigravity and Windsurf public defaults come from
// open-sse/utils/publicCreds.ts — no env override needed in this suite.
const originalEnv = { ...process.env };
Object.assign(process.env, {
CLAUDE_OAUTH_CLIENT_ID: "9d1c250a-e61b-44d9-88ed-5944d1962f5e",
CODEX_OAUTH_CLIENT_ID: "app_EMoamEEZ73f0CkXaXp7hrann",
GITLAB_DUO_OAUTH_CLIENT_ID: "gitlab-duo-client-id",
QWEN_OAUTH_CLIENT_ID: "f0304373b74a44d2b584a3fb70ca9e56",
KIMI_CODING_OAUTH_CLIENT_ID: "17e5f671-d194-4dfb-9706-5516cb48c098",
KIMI_CODING_DEVICE_ID: "test-kimi-device-id",
GITHUB_OAUTH_CLIENT_ID: "Iv1.b507a08c87ecfe98",
});
const providersModule = await import("../../src/lib/oauth/providers/index.ts");
const oauthModule = await import("../../src/lib/oauth/constants/oauth.ts");
const registryModule = await import("../../open-sse/config/providerRegistry.ts");
const antigravityHeadersModule = await import("../../open-sse/services/antigravityHeaders.ts");
const oauthHelpersModule = await import("../../src/lib/oauth/providers.ts");
const PROVIDERS = providersModule.default;
const { resolveBrowserOAuthRedirectUri } = oauthHelpersModule;
const {
ANTIGRAVITY_CONFIG,
AGY_CONFIG,
CLAUDE_CONFIG,
CLINE_CONFIG,
CODEX_CONFIG,
CURSOR_CONFIG,
GEMINI_CONFIG,
GITHUB_CONFIG,
GITLAB_DUO_CONFIG,
KILOCODE_CONFIG,
KIMI_CODING_CONFIG,
KIRO_CONFIG,
OAUTH_TIMEOUT,
PROVIDERS: OAUTH_PROVIDER_IDS,
QODER_CONFIG,
QWEN_CONFIG,
TRAE_CONFIG,
WINDSURF_CONFIG,
} = oauthModule;
const { REGISTRY } = registryModule;
const { getAntigravityLoadCodeAssistMetadata } = antigravityHeadersModule;
const originalFetch = globalThis.fetch;
const EXPECTED_PROVIDER_KEYS = [
"claude",
"codex",
"gemini-cli",
"antigravity",
"agy",
"qoder",
"qwen",
"kimi-coding",
"github",
"gitlab-duo",
"kiro",
"amazon-q",
"cursor",
"trae",
"kilocode",
"cline",
"windsurf",
"devin-cli",
];
const EXPECTED_CONFIG_BY_PROVIDER = {
claude: CLAUDE_CONFIG,
codex: CODEX_CONFIG,
"gemini-cli": GEMINI_CONFIG,
antigravity: ANTIGRAVITY_CONFIG,
agy: AGY_CONFIG,
qoder: QODER_CONFIG,
qwen: QWEN_CONFIG,
"kimi-coding": KIMI_CODING_CONFIG,
github: GITHUB_CONFIG,
"gitlab-duo": GITLAB_DUO_CONFIG,
kiro: KIRO_CONFIG,
"amazon-q": KIRO_CONFIG,
cursor: CURSOR_CONFIG,
kilocode: KILOCODE_CONFIG,
cline: CLINE_CONFIG,
windsurf: WINDSURF_CONFIG,
"devin-cli": WINDSURF_CONFIG,
trae: TRAE_CONFIG,
};
const REQUIRED_FIELDS_BY_PROVIDER = {
claude: ["authorizeUrl", "tokenUrl", "redirectUri", "scopes", "clientId"],
codex: ["authorizeUrl", "tokenUrl", "scope", "clientId"],
"gemini-cli": ["authorizeUrl", "tokenUrl", "userInfoUrl", "scopes", "clientId"],
antigravity: ["authorizeUrl", "tokenUrl", "userInfoUrl", "scopes", "clientId"],
agy: ["authorizeUrl", "tokenUrl", "userInfoUrl", "scopes", "clientId"],
qoder: ["extraParams"],
qwen: ["deviceCodeUrl", "tokenUrl", "scope", "clientId"],
"kimi-coding": ["deviceCodeUrl", "tokenUrl", "clientId"],
github: ["deviceCodeUrl", "tokenUrl", "userInfoUrl", "copilotTokenUrl", "clientId"],
"gitlab-duo": [
"baseUrl",
"authorizeUrl",
"tokenUrl",
"userInfoUrl",
"directAccessUrl",
"scope",
"codeChallengeMethod",
"clientId",
],
kiro: [
"registerClientUrl",
"deviceAuthUrl",
"tokenUrl",
"socialAuthEndpoint",
"socialLoginUrl",
"socialTokenUrl",
"socialRefreshUrl",
"authMethods",
],
"amazon-q": [
"registerClientUrl",
"deviceAuthUrl",
"tokenUrl",
"socialAuthEndpoint",
"socialLoginUrl",
"socialTokenUrl",
"socialRefreshUrl",
"authMethods",
],
cursor: ["apiEndpoint", "api3Endpoint", "agentEndpoint", "agentNonPrivacyEndpoint", "dbKeys"],
kilocode: ["apiBaseUrl", "initiateUrl", "pollUrlBase"],
cline: ["appBaseUrl", "apiBaseUrl", "authorizeUrl", "tokenExchangeUrl", "refreshUrl"],
windsurf: ["authorizeUrl", "apiServerUrl", "exchangePath", "inferenceUrl"],
"devin-cli": ["authorizeUrl", "apiServerUrl", "exchangePath", "inferenceUrl"],
trae: ["apiEndpoint", "chatEndpoint", "webUrl"],
};
function getByPath(object, path) {
return path.split(".").reduce((value, segment) => value?.[segment], object);
}
function collectHttpsUrls(value, path = "config") {
const results = [];
if (typeof value === "string") {
if (/^https?:\/\//.test(value)) {
results.push({ path, value });
}
return results;
}
if (!value || typeof value !== "object" || Array.isArray(value)) {
return results;
}
for (const [key, nestedValue] of Object.entries(value)) {
results.push(...collectHttpsUrls(nestedValue, `${path}.${key}`));
}
return results;
}
function jsonResponse(body, status = 200) {
return new Response(JSON.stringify(body), {
status,
headers: { "Content-Type": "application/json" },
});
}
function textResponse(body, status = 200) {
return new Response(body, {
status,
headers: { "Content-Type": "text/plain" },
});
}
function createJwt(payload) {
const encode = (value) =>
Buffer.from(JSON.stringify(value)).toString("base64url").replace(/=/g, "");
return `${encode({ alg: "none", typ: "JWT" })}.${encode(payload)}.signature`;
}
function useFetchSequence(sequence) {
let index = 0;
globalThis.fetch = async (...args) => {
const next = sequence[index++];
if (!next) {
throw new Error(`Unexpected fetch call #${index}`);
}
return typeof next === "function" ? next(...args) : next;
};
}
test.afterEach(() => {
globalThis.fetch = originalFetch;
});
test.after(() => {
globalThis.fetch = originalFetch;
for (const key of Object.keys(process.env)) {
if (!(key in originalEnv)) {
delete process.env[key];
}
}
Object.assign(process.env, originalEnv);
});
test("OAuth provider registry exposes every expected provider exactly once", () => {
assert.deepEqual(Object.keys(PROVIDERS), EXPECTED_PROVIDER_KEYS);
assert.equal(new Set(Object.keys(PROVIDERS)).size, EXPECTED_PROVIDER_KEYS.length);
});
test("OAuth constants include all provider ids and use a sane timeout", () => {
const constantIds = Object.values(OAUTH_PROVIDER_IDS);
const registryIds = Object.keys(PROVIDERS);
assert.ok(Number.isInteger(OAUTH_TIMEOUT));
assert.ok(OAUTH_TIMEOUT > 0);
assert.equal(new Set(constantIds).size, constantIds.length);
for (const providerId of registryIds) {
assert.ok(
constantIds.includes(providerId),
`Expected oauth constants to include provider id ${providerId}`
);
}
});
test("every registered OAuth provider has a valid config object, flow type and token mapper", () => {
const allowedFlowTypes = new Set([
"authorization_code",
"authorization_code_pkce",
"device_code",
"import_token",
]);
for (const [providerId, provider] of Object.entries(PROVIDERS)) {
assert.equal(provider.config, EXPECTED_CONFIG_BY_PROVIDER[providerId]);
assert.ok(allowedFlowTypes.has(provider.flowType), `${providerId} has unsupported flowType`);
assert.equal(typeof provider.mapTokens, "function", `${providerId} must expose mapTokens`);
const mapped = provider.mapTokens({});
assert.ok(
mapped && typeof mapped === "object",
`${providerId} mapTokens must return an object`
);
}
});
test("every required provider config field is present when the provider is enabled for that flow", () => {
for (const [providerId, fields] of Object.entries(REQUIRED_FIELDS_BY_PROVIDER)) {
const provider = PROVIDERS[providerId];
const config = provider.config;
for (const field of fields) {
const value = getByPath(config, field);
if (
providerId === "qoder" &&
!config.enabled &&
["authorizeUrl", "tokenUrl", "userInfoUrl", "clientId"].includes(field)
) {
continue;
}
assert.notEqual(value, undefined, `${providerId} missing config field ${field}`);
if (Array.isArray(value)) {
assert.ok(value.length > 0, `${providerId}.${field} must not be empty`);
} else if (typeof value === "string") {
assert.ok(value.length > 0, `${providerId}.${field} must not be empty`);
} else if (typeof value === "object") {
assert.ok(
value && Object.keys(value).length > 0,
`${providerId}.${field} must not be empty`
);
}
}
}
});
test("all provider endpoint URLs use HTTPS when a URL is configured", () => {
for (const [providerId, provider] of Object.entries(PROVIDERS)) {
const httpsUrls = collectHttpsUrls(provider.config);
for (const entry of httpsUrls) {
const parsed = new URL(entry.value);
assert.equal(parsed.protocol, "https:", `${providerId} ${entry.path} must use HTTPS`);
}
}
});
test("browser-based providers expose buildAuthUrl and return provider-specific auth URLs", () => {
const redirectUri = "http://localhost:43121/callback";
const state = "state-123";
const codeChallenge = "challenge-456";
const claudeUrl = new URL(
PROVIDERS.claude.buildAuthUrl(CLAUDE_CONFIG, redirectUri, state, codeChallenge)
);
const codexUrl = new URL(
PROVIDERS.codex.buildAuthUrl(CODEX_CONFIG, redirectUri, state, codeChallenge)
);
const geminiUrl = new URL(
PROVIDERS["gemini-cli"].buildAuthUrl(GEMINI_CONFIG, redirectUri, state)
);
const antigravityUrl = new URL(
PROVIDERS.antigravity.buildAuthUrl(ANTIGRAVITY_CONFIG, redirectUri, state)
);
const clineUrl = new URL(PROVIDERS.cline.buildAuthUrl(CLINE_CONFIG, redirectUri));
assert.equal(claudeUrl.origin, "https://claude.ai");
assert.equal(claudeUrl.searchParams.get("client_id"), CLAUDE_CONFIG.clientId);
assert.equal(codexUrl.origin, "https://auth.openai.com");
assert.equal(codexUrl.searchParams.get("code_challenge"), codeChallenge);
assert.equal(geminiUrl.origin, "https://accounts.google.com");
assert.equal(geminiUrl.searchParams.get("redirect_uri"), redirectUri);
assert.equal(antigravityUrl.origin, "https://accounts.google.com");
assert.equal(clineUrl.origin, "https://api.cline.bot");
});
test("custom Google OAuth credentials switch Antigravity remote callbacks to NEXT_PUBLIC_BASE_URL", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"antigravity",
"http://localhost:20128/callback",
{
NEXT_PUBLIC_BASE_URL: "https://omniroute.example.com/",
ANTIGRAVITY_OAUTH_CLIENT_ID: "custom-antigravity.apps.googleusercontent.com",
ANTIGRAVITY_OAUTH_CLIENT_SECRET: "custom-antigravity-secret",
}
);
assert.equal(redirectUri, "https://omniroute.example.com/callback");
});
test("custom Google OAuth credentials switch Gemini remote callbacks to OMNIROUTE_PUBLIC_BASE_URL", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"gemini-cli",
"http://127.0.0.1:20128/callback",
{
OMNIROUTE_PUBLIC_BASE_URL: "https://omniroute.example.com",
GEMINI_CLI_OAUTH_CLIENT_ID: "custom-gemini.apps.googleusercontent.com",
GEMINI_CLI_OAUTH_CLIENT_SECRET: "custom-gemini-secret",
}
);
assert.equal(redirectUri, "https://omniroute.example.com/callback");
});
test("custom Google OAuth callbacks preserve the requested callback path and query", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"antigravity",
"http://127.0.0.1:20128/auth/callback?source=popup",
{
NEXT_PUBLIC_BASE_URL: "https://omniroute.example.com/base",
ANTIGRAVITY_OAUTH_CLIENT_ID: "custom-antigravity.apps.googleusercontent.com",
ANTIGRAVITY_OAUTH_CLIENT_SECRET: "custom-antigravity-secret",
}
);
assert.equal(redirectUri, "https://omniroute.example.com/base/auth/callback?source=popup");
});
test("custom Google OAuth credentials switch IPv6 loopback callbacks to public base URL", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"gemini-cli",
"http://[::1]:20128/callback",
{
OMNIROUTE_PUBLIC_BASE_URL: "https://omniroute.example.com",
GEMINI_OAUTH_CLIENT_ID: "custom-gemini.apps.googleusercontent.com",
GEMINI_OAUTH_CLIENT_SECRET: "custom-gemini-secret",
}
);
assert.equal(redirectUri, "https://omniroute.example.com/callback");
});
test("custom Google OAuth callbacks default root loopback paths to callback path", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"antigravity",
"http://127.0.0.1:20128",
{
NEXT_PUBLIC_BASE_URL: "https://omniroute.example.com",
ANTIGRAVITY_OAUTH_CLIENT_ID: "custom-antigravity.apps.googleusercontent.com",
ANTIGRAVITY_OAUTH_CLIENT_SECRET: "custom-antigravity-secret",
}
);
assert.equal(redirectUri, "https://omniroute.example.com/callback");
});
test("custom Google OAuth credentials ignore blank Gemini CLI values before checking Gemini fallback values", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"gemini-cli",
"http://127.0.0.1:20128/callback",
{
OMNIROUTE_PUBLIC_BASE_URL: "https://omniroute.example.com",
GEMINI_CLI_OAUTH_CLIENT_ID: " ",
GEMINI_CLI_OAUTH_CLIENT_SECRET: " ",
GEMINI_OAUTH_CLIENT_ID: "custom-gemini.apps.googleusercontent.com",
GEMINI_OAUTH_CLIENT_SECRET: "custom-gemini-secret",
}
);
assert.equal(redirectUri, "https://omniroute.example.com/callback");
});
test("Google OAuth callbacks stay on loopback when custom credentials are incomplete", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"antigravity",
"http://127.0.0.1:20128/callback",
{
NEXT_PUBLIC_BASE_URL: "https://omniroute.example.com",
ANTIGRAVITY_OAUTH_CLIENT_ID: "custom-antigravity.apps.googleusercontent.com",
}
);
assert.equal(redirectUri, "http://127.0.0.1:20128/callback");
});
test("Google OAuth callbacks stay on localhost when no custom credentials are configured", () => {
const redirectUri = resolveBrowserOAuthRedirectUri(
"antigravity",
"http://localhost:20128/callback",
{
NEXT_PUBLIC_BASE_URL: "https://omniroute.example.com",
}
);
assert.equal(redirectUri, "http://localhost:20128/callback");
});
test("device and import-token providers expose the flow-specific fields expected by their configs", () => {
const deviceProviders = ["qwen", "kimi-coding", "github", "kiro", "amazon-q", "kilocode"];
for (const providerId of deviceProviders) {
const provider = PROVIDERS[providerId];
assert.equal(provider.flowType, "device_code");
assert.equal(typeof provider.requestDeviceCode, "function");
assert.equal(typeof provider.pollToken, "function");
}
assert.equal(PROVIDERS.cursor.flowType, "import_token");
assert.equal(CURSOR_CONFIG.dbKeys.accessToken, "cursorAuth/accessToken");
assert.equal(CURSOR_CONFIG.dbKeys.machineId, "storage.serviceMachineId");
assert.equal(PROVIDERS.trae.flowType, "import_token");
assert.equal(typeof TRAE_CONFIG.apiEndpoint, "string");
assert.ok(Array.isArray(KIRO_CONFIG.authMethods));
assert.ok(KIRO_CONFIG.authMethods.includes("builder-id"));
});
test("provider-specific config shapes remain valid for special cases", () => {
assert.ok(Array.isArray(CLAUDE_CONFIG.scopes) && CLAUDE_CONFIG.scopes.length > 0);
assert.ok(Array.isArray(GEMINI_CONFIG.scopes) && GEMINI_CONFIG.scopes.length > 0);
assert.ok(Array.isArray(ANTIGRAVITY_CONFIG.scopes) && ANTIGRAVITY_CONFIG.scopes.length > 0);
assert.equal(typeof CODEX_CONFIG.extraParams.originator, "string");
assert.equal(typeof QODER_CONFIG.extraParams.loginMethod, "string");
assert.ok(Array.isArray(KIRO_CONFIG.grantTypes) && KIRO_CONFIG.grantTypes.length > 0);
assert.equal(typeof KILOCODE_CONFIG.pollUrlBase, "string");
});
test("Gemini OAuth defaults resolve to a GOCSPX-style client secret shared by both endpoints", () => {
// No env override: GEMINI_CONFIG.clientSecret must come from the embedded
// public default in open-sse/utils/publicCreds.ts.
const expected = GEMINI_CONFIG.clientSecret;
assert.ok(expected.startsWith("G" + "OCSPX-"), "must be a GOCSPX-style secret");
assert.equal(REGISTRY.gemini.oauth.clientSecretDefault, expected);
assert.equal(REGISTRY["gemini-cli"].oauth.clientSecretDefault, expected);
});
test("Qoder remains a safe special case when browser OAuth is disabled", () => {
if (!QODER_CONFIG.enabled) {
assert.equal(
PROVIDERS.qoder.buildAuthUrl(QODER_CONFIG, "http://localhost/callback", "state"),
null
);
return;
}
const authUrl = PROVIDERS.qoder.buildAuthUrl(
QODER_CONFIG,
"http://localhost/callback",
"state-123"
);
assert.equal(typeof authUrl, "string");
assert.ok(authUrl.startsWith("https://"));
});
test("Codex parses id_token metadata and prefers a team workspace when the JWT only marks the personal plan", async () => {
const idToken = createJwt({
email: "dev@example.com",
"https://api.openai.com/auth": {
chatgpt_account_id: "personal-workspace",
chatgpt_plan_type: "free",
chatgpt_user_id: "user-123",
organizations: [
{
id: "team-workspace",
is_default: false,
role: "member",
title: "Platform Team",
},
],
},
});
const extra = await PROVIDERS.codex.postExchange({ id_token: idToken });
const mapped = PROVIDERS.codex.mapTokens(
{
access_token: "access-token",
refresh_token: "refresh-token",
id_token: idToken,
expires_in: 3600,
},
extra
);
assert.equal(extra.authInfo.chatgpt_account_id, "personal-workspace");
assert.equal(mapped.email, "dev@example.com");
assert.equal(mapped.providerSpecificData.workspaceId, "team-workspace");
assert.equal(mapped.providerSpecificData.workspacePlanType, "team");
});
test("Cline decodes embedded callback payloads without using the network", async () => {
const encodedCode = Buffer.from(
JSON.stringify({
accessToken: "cline-access",
refreshToken: "cline-refresh",
email: "cline@example.com",
firstName: "Cline",
lastName: "Bot",
expiresAt: "2030-01-01T00:00:00.000Z",
})
).toString("base64");
const tokens = await PROVIDERS.cline.exchangeToken(CLINE_CONFIG, encodedCode, "http://localhost");
const mapped = PROVIDERS.cline.mapTokens(tokens);
assert.equal(tokens.access_token, "cline-access");
assert.equal(mapped.accessToken, "cline-access");
assert.equal(mapped.email, "cline@example.com");
assert.equal(mapped.name, "Cline Bot");
});
test("Gemini and Antigravity run mocked browser OAuth exchanges and post-exchange enrichment", async () => {
const geminiConfig = { ...GEMINI_CONFIG, clientSecret: "gemini-secret" };
useFetchSequence([
jsonResponse({
access_token: "gemini-access",
refresh_token: "gemini-refresh",
expires_in: 3600,
}),
jsonResponse({ email: "gemini@example.com" }),
jsonResponse({ cloudaicompanionProject: { id: "gemini-project" } }),
jsonResponse({ access_token: "anti-access", refresh_token: "anti-refresh", expires_in: 7200 }),
jsonResponse({ email: "anti@example.com" }),
(_url, init: any = {}) => {
assert.equal(init.method, "POST");
assert.equal(init.headers.Authorization, "Bearer anti-access");
assert.match(init.headers["User-Agent"], /^vscode\/1\.X\.X \(Antigravity\//);
assert.equal(init.headers["X-Goog-Api-Client"], undefined);
assert.deepEqual(
JSON.parse(String(init.body)).metadata,
getAntigravityLoadCodeAssistMetadata()
);
assert.equal(JSON.parse(String(init.body)).cloudaicompanionProject, undefined);
return jsonResponse({
cloudaicompanionProject: { id: "anti-project" },
allowedTiers: [{ id: "tier-default", isDefault: true }],
});
},
(_url, init: any = {}) => {
assert.equal(init.method, "POST");
assert.equal(init.headers.Authorization, "Bearer anti-access");
assert.match(init.headers["User-Agent"], /^vscode\/1\.X\.X \(Antigravity\//);
assert.equal(init.headers["X-Goog-Api-Client"], undefined);
assert.deepEqual(
JSON.parse(String(init.body)).metadata,
getAntigravityLoadCodeAssistMetadata()
);
assert.equal(JSON.parse(String(init.body)).tier_id, "tier-default");
assert.equal(JSON.parse(String(init.body)).cloudaicompanionProject, undefined);
return jsonResponse({
done: true,
response: { cloudaicompanionProject: { id: "anti-project-final" } },
});
},
]);
const geminiTokens = await PROVIDERS["gemini-cli"].exchangeToken(
geminiConfig,
"code-1",
"http://localhost/callback"
);
const geminiExtra = await PROVIDERS["gemini-cli"].postExchange(geminiTokens);
const geminiMapped = PROVIDERS["gemini-cli"].mapTokens(geminiTokens, geminiExtra);
const antigravityTokens = await PROVIDERS.antigravity.exchangeToken(
ANTIGRAVITY_CONFIG,
"code-2",
"http://localhost/callback"
);
const antigravityExtra = await PROVIDERS.antigravity.postExchange(antigravityTokens);
const antigravityMapped = PROVIDERS.antigravity.mapTokens(antigravityTokens, antigravityExtra);
assert.equal(geminiMapped.email, "gemini@example.com");
assert.equal(geminiMapped.projectId, "gemini-project");
assert.equal(antigravityMapped.email, "anti@example.com");
assert.equal(antigravityMapped.projectId, "anti-project-final");
});
test("Qoder enabled mode exchanges tokens and loads profile metadata through mocked endpoints", async () => {
const originalQoderConfig = structuredClone(QODER_CONFIG);
const qoderConfig = Object.assign(QODER_CONFIG, {
enabled: true,
clientId: "qoder-client",
clientSecret: "qoder-secret",
authorizeUrl: "https://auth.qoder.dev/authorize",
tokenUrl: "https://auth.qoder.dev/token",
userInfoUrl: "https://auth.qoder.dev/user",
extraParams: {
loginMethod: "phone",
type: "phone",
},
});
try {
useFetchSequence([
jsonResponse({
access_token: "qoder-access",
refresh_token: "qoder-refresh",
expires_in: 1800,
}),
jsonResponse({
success: true,
data: {
apiKey: "qoder-api-key",
email: "qoder@example.com",
nickname: "Qoder User",
},
}),
]);
const authUrl = PROVIDERS.qoder.buildAuthUrl(
qoderConfig,
"http://localhost/callback",
"state-123"
);
const tokens = await PROVIDERS.qoder.exchangeToken(
qoderConfig,
"browser-code",
"http://localhost/callback"
);
const extra = await PROVIDERS.qoder.postExchange(tokens);
const mapped = PROVIDERS.qoder.mapTokens(tokens, extra);
assert.ok(authUrl.startsWith("https://auth.qoder.dev/authorize?"));
assert.equal(mapped.apiKey, "qoder-api-key");
assert.equal(mapped.email, "qoder@example.com");
assert.equal(mapped.displayName, "Qoder User");
} finally {
Object.assign(QODER_CONFIG, originalQoderConfig);
}
});
test("Qwen and Kimi Coding execute mocked device-code flows and token mapping", async () => {
const qwenIdToken = createJwt({
email: "qwen@example.com",
name: "Qwen User",
});
useFetchSequence([
jsonResponse({
device_code: "qwen-device",
user_code: "QWEN123",
verification_uri: "https://chat.qwen.ai/activate",
expires_in: 300,
interval: 5,
}),
jsonResponse({
access_token: createJwt({ sub: "qwen-subject" }),
refresh_token: "qwen-refresh",
expires_in: 3600,
id_token: qwenIdToken,
resource_url: "https://chat.qwen.ai/resource",
}),
(url, init) => {
const params = init.body;
assert.equal(String(url), KIMI_CODING_CONFIG.deviceCodeUrl);
assert.equal(params.get("client_id"), KIMI_CODING_CONFIG.clientId);
assert.equal(init.headers["X-Msh-Platform"], "kimi_cli");
assert.equal(init.headers["X-Msh-Device-Id"], "test-kimi-device-id");
assert.ok(init.headers["X-Msh-Os-Version"]);
return jsonResponse({
device_code: "kimi-device",
user_code: "KIMI123",
verification_uri: "https://www.kimi.com/code/authorize_device",
verification_uri_complete: "https://www.kimi.com/code/authorize_device?user_code=KIMI123",
expires_in: 600,
interval: 4,
});
},
(url, init) => {
const params = init.body;
assert.equal(String(url), KIMI_CODING_CONFIG.tokenUrl);
assert.equal(params.get("client_id"), KIMI_CODING_CONFIG.clientId);
assert.equal(params.get("device_code"), "kimi-device");
assert.equal(params.get("grant_type"), "urn:ietf:params:oauth:grant-type:device_code");
assert.equal(init.headers["X-Msh-Platform"], "kimi_cli");
assert.equal(init.headers["X-Msh-Device-Id"], "test-kimi-device-id");
return jsonResponse({
access_token: "kimi-access",
refresh_token: "kimi-refresh",
expires_in: 7200,
token_type: "Bearer",
scope: "profile",
});
},
]);
const qwenDevice = await PROVIDERS.qwen.requestDeviceCode(QWEN_CONFIG, "challenge-123");
const qwenPoll = await PROVIDERS.qwen.pollToken(QWEN_CONFIG, qwenDevice.device_code, "verifier");
const qwenMapped = PROVIDERS.qwen.mapTokens(qwenPoll.data);
const kimiDevice = await PROVIDERS["kimi-coding"].requestDeviceCode(KIMI_CODING_CONFIG);
const kimiPoll = await PROVIDERS["kimi-coding"].pollToken(
KIMI_CODING_CONFIG,
kimiDevice.device_code
);
const kimiMapped = PROVIDERS["kimi-coding"].mapTokens(kimiPoll.data);
assert.equal(qwenMapped.email, "qwen@example.com");
assert.equal(qwenMapped.displayName, "Qwen User");
assert.equal(qwenMapped.providerSpecificData.resourceUrl, "https://chat.qwen.ai/resource");
assert.equal(kimiMapped.accessToken, "kimi-access");
assert.equal(kimiMapped.tokenType, "Bearer");
assert.equal(
kimiDevice.verification_uri_complete,
"https://www.kimi.com/code/authorize_device?user_code=KIMI123"
);
});
test("GitHub executes mocked device-code and profile enrichment flows", async () => {
useFetchSequence([
jsonResponse({
device_code: "github-device",
user_code: "GH123",
verification_uri: "https://github.com/login/device",
expires_in: 900,
interval: 5,
}),
jsonResponse({
access_token: "github-access",
refresh_token: "github-refresh",
expires_in: 3600,
}),
jsonResponse({ token: "copilot-token", expires_at: "2030-01-01T00:00:00.000Z" }),
jsonResponse({
id: 42,
login: "octocat",
name: "Octo Cat",
email: "octo@example.com",
}),
]);
const device = await PROVIDERS.github.requestDeviceCode(GITHUB_CONFIG);
const poll = await PROVIDERS.github.pollToken(GITHUB_CONFIG, device.device_code);
const extra = await PROVIDERS.github.postExchange(poll.data);
const mapped = PROVIDERS.github.mapTokens(poll.data, extra);
assert.equal(poll.ok, true);
assert.equal(mapped.providerSpecificData.copilotToken, "copilot-token");
assert.equal(mapped.providerSpecificData.githubLogin, "octocat");
assert.equal(mapped.providerSpecificData.githubEmail, "octo@example.com");
});
test("Kiro and KiloCode execute mocked device-code flows across their custom endpoints", async () => {
useFetchSequence([
jsonResponse({ clientId: "kiro-client", clientSecret: "kiro-secret" }),
jsonResponse({
deviceCode: "kiro-device",
userCode: "KIRO123",
verificationUri: "https://device.kiro.dev/verify",
verificationUriComplete: "https://device.kiro.dev/verify?code=KIRO123",
expiresIn: 600,
interval: 5,
}),
jsonResponse({
accessToken: "kiro-access",
refreshToken: "kiro-refresh",
expiresIn: 3600,
}),
jsonResponse({
code: "kilo-code",
verificationUrl: "https://api.kilo.ai/device-auth/kilo-code",
expiresIn: 300,
}),
jsonResponse({ status: "approved", token: "kilo-access", userEmail: "kilo@example.com" }),
textResponse("", 202),
textResponse("", 403),
textResponse("", 410),
]);
const kiroDevice = await PROVIDERS.kiro.requestDeviceCode(KIRO_CONFIG);
const kiroPoll = await PROVIDERS.kiro.pollToken(
KIRO_CONFIG,
kiroDevice.device_code,
undefined,
kiroDevice
);
const kiroMapped = PROVIDERS.kiro.mapTokens(kiroPoll.data);
const kiloDevice = await PROVIDERS.kilocode.requestDeviceCode(KILOCODE_CONFIG);
const kiloApproved = await PROVIDERS.kilocode.pollToken(KILOCODE_CONFIG, kiloDevice.device_code);
const kiloPending = await PROVIDERS.kilocode.pollToken(KILOCODE_CONFIG, kiloDevice.device_code);
const kiloDenied = await PROVIDERS.kilocode.pollToken(KILOCODE_CONFIG, kiloDevice.device_code);
const kiloExpired = await PROVIDERS.kilocode.pollToken(KILOCODE_CONFIG, kiloDevice.device_code);
const kiloMapped = PROVIDERS.kilocode.mapTokens(kiloApproved.data);
assert.equal(kiroMapped.accessToken, "kiro-access");
assert.equal(kiroMapped.providerSpecificData.clientId, "kiro-client");
assert.equal(kiloApproved.ok, true);
assert.equal(kiloPending.data.error, "authorization_pending");
assert.equal(kiloDenied.data.error, "access_denied");
assert.equal(kiloExpired.data.error, "expired_token");
assert.equal(kiloMapped.email, "kilo@example.com");
});