mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-09-20 05:42:19 +03:00
* security(deps): pin and verify tls-client native artifacts * docs(changelog): link tls-client provenance PR * security(runtime): harden TLS and public error boundaries * security(runtime): resolve CodeQL error-boundary findings * security(lmarena): close public stream error boundary * fix(lmarena): normalize public error statuses * chore(quality): rebaseline chatCore.ts for the surviving log-boundary hardening open-sse/handlers/chatCore.ts 6219 -> 6287. This is the one part of #11742 that survived the rebase: sanitizeErrorMessage on the plugin onError hook, on the semaphore-timeout path and on failureMessage before it reaches console.log and the call log, sanitizeUpstreamDetails on the malformed-response log, and getSafeErrorMetadata + try/catch where hostile (Proxy) metadata could throw. That is the LOG boundary, which is broader than Hard Rule #12 (responses). The rest of the PR was dropped as already landed on the tip.
104 lines
3.5 KiB
TypeScript
104 lines
3.5 KiB
TypeScript
import test from "node:test";
|
|
import assert from "node:assert/strict";
|
|
|
|
const { createStreamFailureFinalizers } =
|
|
await import("../../open-sse/utils/streamFailureFinalization.ts");
|
|
const { formatTranslatedStreamError } = await import("../../open-sse/utils/streamErrorFormat.ts");
|
|
|
|
test("createStreamFailureFinalizers: 499 client disconnect body is client_disconnected", () => {
|
|
let captured: { status: number; responseBody: unknown; errorCode?: string | null } | null = null;
|
|
|
|
const { onPipelineStreamError } = createStreamFailureFinalizers({
|
|
isFailureCompletionRecorded: () => false,
|
|
onStreamComplete: (payload) => {
|
|
captured = {
|
|
status: payload.status,
|
|
responseBody: payload.responseBody,
|
|
errorCode: payload.errorCode,
|
|
};
|
|
},
|
|
persistFailureUsage: () => {},
|
|
});
|
|
|
|
onPipelineStreamError({
|
|
message: "Client disconnected: request_signal_aborted",
|
|
statusCode: 499,
|
|
});
|
|
|
|
assert.ok(captured, "onStreamComplete must fire");
|
|
assert.equal(captured.status, 499);
|
|
assert.equal(captured.errorCode, "client_disconnected");
|
|
|
|
const body = captured.responseBody as {
|
|
error: { type?: string; code?: string; message: string };
|
|
};
|
|
assert.equal(body.error.type, "client_disconnected");
|
|
assert.equal(body.error.code, "client_disconnected");
|
|
});
|
|
|
|
test("createStreamFailureFinalizers: caller classification survives into response body", () => {
|
|
let captured: unknown = null;
|
|
|
|
const { handleStreamFailure } = createStreamFailureFinalizers({
|
|
isFailureCompletionRecorded: () => false,
|
|
onStreamComplete: (payload) => {
|
|
captured = payload.responseBody;
|
|
},
|
|
persistFailureUsage: () => {},
|
|
});
|
|
|
|
const handled = handleStreamFailure({
|
|
status: 502,
|
|
message: "Upstream stream error",
|
|
code: "stream_pipeline_error",
|
|
type: "stream_error",
|
|
});
|
|
|
|
assert.equal(handled, true, "the callback contract reports that the stream failure was handled");
|
|
const body = captured as { error: { type?: string; code?: string } };
|
|
assert.equal(body.error.type, "stream_error");
|
|
assert.equal(body.error.code, "stream_pipeline_error");
|
|
});
|
|
|
|
test("formatTranslatedStreamError projects unsafe upstream classification fields", () => {
|
|
const unsafeCode = "bad access_token=TOP_SECRET /home/alice/code.ts";
|
|
const unsafeType = "bad_type\n at /home/alice/type.ts:1:2";
|
|
const text = formatTranslatedStreamError({
|
|
error: {
|
|
status: 502,
|
|
message: "Upstream failed",
|
|
code: unsafeCode,
|
|
type: unsafeType,
|
|
},
|
|
});
|
|
const dataLine = text.split("\n").find((line) => line.startsWith("data: {"));
|
|
assert.ok(dataLine, "OpenAI SSE must contain a JSON data line");
|
|
const payload = JSON.parse(dataLine.slice(6)) as {
|
|
error: { code?: string; type?: string };
|
|
};
|
|
|
|
assert.equal(payload.error.code, "bad_gateway");
|
|
assert.equal(payload.error.type, "server_error");
|
|
assert.ok(!text.includes("TOP_SECRET"));
|
|
assert.ok(!text.includes("/home/alice"));
|
|
});
|
|
|
|
test("formatTranslatedStreamError preserves safe rate-limit classification", () => {
|
|
const text = formatTranslatedStreamError({
|
|
error: {
|
|
status: 429,
|
|
message: "Weekly quota reached",
|
|
code: "usage_limit_reached",
|
|
type: "rate_limit_error",
|
|
},
|
|
});
|
|
const dataLine = text.split("\n").find((line) => line.startsWith("data: {"));
|
|
assert.ok(dataLine, "OpenAI SSE must contain a JSON data line");
|
|
const payload = JSON.parse(dataLine.slice(6)) as {
|
|
error: { code?: string; type?: string };
|
|
};
|
|
|
|
assert.equal(payload.error.code, "usage_limit_reached");
|
|
assert.equal(payload.error.type, "rate_limit_error");
|
|
});
|