Files
OmniRoute/tests/unit/route-edge-coverage.test.ts
Diego Rodrigues de Sa e Souza 9e45baae58 chore(release): v3.6.6 — Stabilization (#1241)
* fix(streaming): #1211 greedy strip omniModel tags to prevent literal \n\n artifacts

- Changed regex quantifier from ? to * in combo.ts, comboAgentMiddleware.ts,
  and contextHandoff.ts to greedily strip all JSON-escaped newline sequences
  surrounding <omniModel> tags in SSE streaming chunks
- Added \r to the character class for cross-platform robustness
- Fixed Playwright strict-mode violation in combo-unification.spec.ts
- Bumped OpenAPI version and CHANGELOG to 3.6.6

* fix: 3 bugs found during issue triage (#1175, #1187/#1218, #1202)

- fix(gemini): strip VS Code JSON Schema extensions from tool schemas (#1175)
  Add enumDescriptions, markdownDescription, markdownEnumDescriptions,
  enumItemLabels and tags to UNSUPPORTED_SCHEMA_CONSTRAINTS so the Gemini
  sanitizer removes them before forwarding. GitHub Copilot injects these
  non-standard fields into tool definitions, causing Gemini to reject with
  'Unknown name enumDescriptions at functionDeclarations[n].parameters'.

- fix(health-check): unwrap proxy config object before passing to getAccessToken (#1187 #1218)
  resolveProxyForConnection() returns { proxy, level, levelId } but the health
  check loop was passing the full wrapper to getAccessToken(), which expects the
  inner config object (.host, .port etc). The proxy dispatcher validated .host
  on the wrapper (undefined) and threw 'Context proxy host is required', silently
  marking every connection as unhealthy every sweep. Fix mirrors the pattern
  already used in chatHelpers.ts: proxyResult?.proxy || null.

- fix(ui): debounce models.dev sync interval slider to save only on release (#1202)
  The slider's onChange fired updateInterval() on every drag tick, sending a
  PATCH per pixel of movement. Rapid API responses overwrote UI state mid-drag.
  Introduce draftIntervalHours for smooth visual feedback; the PATCH fires
  on onMouseUp / onBlur once the user releases the control.

* fix(providers): update Xiaomi MiMo token-plan endpoints (#1238)

Integrated into release/v3.6.6

* fix(cc-compatible): trim beta flags and preserve cache passthrough (#1230)

Integrated into release/v3.6.6

* feat(memory+skills): full-featured memory & skills systems with tests (#1228)

Integrated into release/v3.6.6

* fix: forward client x-initiator header to GitHub Copilot upstream (#1227)

Integrated into release/v3.6.6

* feat(bailian-quota): add Alibaba Coding Plan quota monitoring (#1235)

* fix: resolve v3.6.6 backlog bugs (#1206, #1211, #1220, #1231)

- fix(core): #1206 inject startup guard against app/ and src/app/ conflict
- fix(health): #1220 add HEALTHCHECK_STAGGER_MS to prevent token refresh bursting
- fix(proxy): #1231 prioritize HTTP 429 over quota body heuristics
- fix(sse): #1211 strip leading double-newlines in responses API stream

* fix(tests): resolve memory migration and skills route pagination bugs from PR overlaps

* docs: Update CHANGELOG.md with v3.6.6 features (#1182, #1165, #1177)

* chore(release): bump version to 3.6.6

Update package versions for the electron app and open-sse package.
Sync llm.txt metadata and feature headings with the 3.6.6 release.

* feat(core): harden outbound provider calls and add cooldown retries

Add guarded outbound fetch helpers with private/local URL blocking,
controlled retries, timeout normalization, and route-level status
propagation for provider validation and model discovery.

Introduce cooldown-aware chat retries with configurable
requestRetry and maxRetryIntervalSec settings, model-scoped cooldown
responses, and improved rate-limit learning from headers and error
bodies so short upstream lockouts can recover automatically.

Also align Antigravity and Codex header handling, require API keys
for Pollinations, validate web runtime env at startup, restore
sanitized Gemini tool names in translated responses, and inject a
synthetic Claude text block when upstream SSE completes empty.

* feat(models): add glmt preset and hybrid token counting

Introduce GLM Thinking as a first-class provider preset with shared GLM
model metadata, pricing, usage sync, dashboard support, and provider
request defaults for higher token budgets and longer timeouts.

Use provider-side /messages/count_tokens when a Claude-compatible
upstream supports it, while preserving estimated fallback behavior for
missing models, missing credentials, and upstream failures.

Also add startup seeding for default model aliases and normalize common
cross-proxy model dialects so canonical slashful model ids do not get
misrouted during resolution.

* feat(api): add sync tokens and v1 websocket bridge

Add dedicated sync token storage, issuance, revocation, and bundle
download routes backed by stable config bundle versioning and ETag
support.

Expose the v1 websocket handshake route and custom Next server bridge so
OpenAI-compatible websocket traffic can be upgraded and proxied through
the dashboard and API bridge.

Expand compliance auditing with structured metadata, pagination, request
context, auth and provider credential events, and SSRF-blocked
validation logging.

* docs: Update all documentation for v3.6.6

- CHANGELOG: Add WebSocket bridge, GLM Thinking preset, safe outbound
  fetch/SSRF guard, cooldown-aware retries, compliance audit v2, model
  alias seeding, and all Internal Improvements for the 3 new commits
- README: Expand v3.6.x highlights table with 10 new features; add
  SafeOutboundFetch, CooldownAwareRetry, SSRF guard, TPS metric, sync
  tokens, WebSocket bridge to Resilience/Observability/Deployment tables
- ARCHITECTURE: Bump date; add new modules to executive summary, API
  routes, SSE core services, Auth/Security section; add SSRF/Outbound
  guard failure mode (section 6); expand module mapping
- ENVIRONMENT: Add OMNIROUTE_CRYPT_KEY/OMNIROUTE_API_KEY_BASE64 legacy
  aliases, OUTBOUND_SSRF_GUARD_ENABLED, CODEX_CLIENT_VERSION, and
  REQUEST_RETRY/MAX_RETRY_INTERVAL_SEC cooldown retry settings
- FEATURES: Add 6 new feature sections — V1 WebSocket Bridge, Sync
  Tokens & Config Bundle, GLM Thinking Preset, Safe Outbound Fetch &
  SSRF Guard, Cooldown-Aware Retries, Compliance Audit v2

* fix: use api64 for proxy test (#1255)

Integrated into release/v3.6.6 — IPv6 proxy test fix

* fix(page): update custom models section to include all providers #1200 (#1256)

Integrated into release/v3.6.6 — Gemini custom model picker fix

* fix: provide default client_id fallbacks to prevent broken OAuth requests (#1246)

Integrated into release/v3.6.6 — OAuth client_id default fallbacks

* fix: translate max_tokens/max_completion_tokens → max_output_tokens in Chat→Responses translator (#1245)

Integrated into release/v3.6.6 — max_tokens → max_output_tokens Responses API translation + unit tests

* feat(oauth): support cursor-agent CLI as Cursor credential source (#1258)

Integrated into release/v3.6.6 — cursor-agent CLI credential source support

* fix(cc-compatible): restore upstream SSE and correct stream/combo timeout behavior (#1257)

Integrated into release/v3.6.6 — CC-compatible upstream SSE restore + stream timeout fix + README table repair

* fix(cli-tools): resolve API key resolution and model mapping bugs in CLI tools (#1263)

Integrated into release/v3.6.6

* feat(cli-tools): add Qwen Code CLI integration (#1266)

Integrated into release/v3.6.6

* fix(i18n): add missing zh-CN translations and fix logger imports (#1269)

Integrated into release/v3.6.6

* fix(i18n): add Chinese i18n support to dashboard components (#1274)

Integrated into release/v3.6.6

* feat: update Pollinations to require API key, remove free tier flag (#1177)

* feat: friendly error messages for crypto/encryption failures (#1165)

* feat: add TPS (tokens per second) metric column to request logs (#1182)

* feat: merge custom/imported models into filter list for all providers (#1191)

* feat(fallback): Fix provider-profile-driven lockouts (#1267)

This integrates rdself's unify-provider-profile-locks PR manually to handle structural conflicts.

* fix(claude): proper Anthropic SDK integration (#1271)

* fix(healthcheck): use correct proxy wrapper format for getAccessToken (#1272)

* chore(release): v3.6.6 — skills registry stability fix + final integration

* fix(auth): harden bootstrap auth and memory dashboard behavior

Restrict unauthenticated writes to /api/settings/require-login to
the initial bootstrap window while keeping read-only checks public.
This prevents post-setup config changes without blocking first-run
login setup, and the onboarding flow now logs in immediately after
setting the password.

Restore memory API filtering and pagination behavior by supporting q
searches, honoring offset-based requests, and avoiding unrelated
fallback results when FTS misses. Update dashboard stats fallback to
use the response totals consistently.

Package the MCP server with explicit file entries and add regression
tests for bootstrap auth and memory route behavior

* fix(codex): remove max_output_tokens from body for compatibility

* chore(release): v3.6.6 — include PR 1274 fixes in changelog

* chore: exclude additional build artifacts and internal directories from npm package distribution

* fix: update Gemini OAuth test to match registry defaults + codex UI improvements

* fix: restore .mjs refs for scripts/ in test imports after ts migration

* fix: restore next.config.mjs ref in dev-origins test

* fix: implement db migration safety checks and codex config format

* fix: disable mass-migration abort during unit tests based on auto-backup flag

* fix: update script regex in auto-update tests to use .mjs

* feat: Add Perplexity Web (Session) provider (#1289)

Integrated into release/v3.6.6

* fix(cli): resolve codex routing config parsing, standardize select model button positioning, and clarify oauth documentation

* docs(changelog): record recent cli, provider, and test updates

Document the latest fixes for Codex routing configuration parsing and
Lobehub provider icon fallback behavior.

Add the note that the remaining JavaScript test files were migrated to
TypeScript ES modules to reflect the completed test stack transition.

* chore(release): merge #1286 minor improvements manually to avoid testing conflict

* chore(test): rename perplexity-web.test.mjs to .ts to maintain 100% TS codebase

* chore(docs): update CHANGELOG.md for perplexity-web provider

* fix(security): resolve CodeQL incomplete URL substring sanitization via URL parsing in test mocks

* fix: integrate compressContext() into chatCore.ts request pipeline

Proactively compress oversized contexts before sending to upstream providers,
preventing context_length_exceeded errors. Compression triggers at 85% of
model's context limit using the existing 3-layer compressContext() function.

- Import compressContext, estimateTokens, getTokenLimit from contextManager
- Add compression check after translation, before executor dispatch
- Estimate tokens and compare against 85% threshold of model's context limit
- Apply 3-layer compression (trim tools, compress thinking, purify history)
- Log compression events with before/after token counts and layers applied
- Audit compression events for observability
- Add unit tests verifying integration behavior

Closes #1290

* fix(tests): align reasoning expectations with GLM thinking structure

* fix: prevent orphaned tool_result messages in purifyHistory()

When purifyHistory() drops oldest messages to fit context window, it can
split tool_use/tool_result pairs — keeping the tool_result but dropping
the tool_use that initiated it. This causes upstream providers to reject
the request with format errors.

Add fixToolPairs() that runs after each purification pass to remove:
- OpenAI format: orphaned role='tool' messages without matching tool_calls ID
- Claude format: orphaned tool_result content blocks without matching tool_use ID

Closes #1291

* fix(tests): supply tool_use in mock so it is not dropped

* chore: convert remaining test to TypeScript

* fix(tests): restore compatibility with compressContext threshold test after tsx migration

* docs: finalize v3.6.6 release documentation

* fix(core): finalize provider removal, type issues, and codex API key config

* fix(dashboard): render Web/Cookie, Search, Audio provider sections and fix TypeScript errors

* fix: increase MCP web_search timeout to 60s (#1278)

* fix: route combo testing properly for embedding models (#1260)

* fix: accumulate excluded accounts in combo fallback loop (#1233)

* fix: strip leading whitespace and newlines from first streaming chunk (#1211)

* docs: clarify VPS and Docker settings for OAuth credentials (#1204)

* fix: return real retry-after for pipeline gates (#1301)

Integrated into release/v3.6.6 — returns real Retry-After values from pipeline gates

* feat: streaming semantic cache, Cursor auto-version detection, and call-log enhancements (#1296)

Integrated into release/v3.6.6 — streaming semantic cache, Cursor auto-version detection, call-log cache_source tracking

* feat(api): support more OpenAI types (image, embeddings, audio-transcriptions, audio-speech) (#1297)

Integrated into release/v3.6.6 — adds embeddings, audio-transcriptions, audio-speech, and images-generations support for custom OpenAI-compatible providers, plus Pollinations image registry

* deps: bump hono from 4.12.12 to 4.12.14 (#1302)

Integrated into release/v3.6.6

* deps: bump hono from 4.12.12 to 4.12.14 (#1306)

Integrated into release/v3.6.6

* chore: stabilization fixes for v3.6.6 (#1298, #1254, #59, CI)

* fix(providers): match correct endpoint for Xiaomi MiMo, strip routing prefix for custom openai endpoints (#1303, #1261)

* feat(storage): add database backup cleanup controls

* chore(release): v3.6.6 — Final Stabilization Push

* Backport call log storage refactor to release/v3.6.6 (#1307)

Integrated into release/v3.6.6

* deps: update dompurify to 3.4.0 to resolve CVE-XYZ (#60)

* test: disable sqlite auto backup in CI to resolve E2E timeout (#24481475058)

* chore(docs): sync CHANGELOG for v3.6.6 with missing features and fixes

* chore(release): prep v3.6.6 infrastructure and type safety fixes

- Migrated legacy .mjs scripts to .ts (bin, prepublish, policies)
- Resolved pre-commit strict lint (t11 budget) errors in combo.ts
- Explicitly typed all TS bindings in pack-artifact policies
- Updated package.json commands to run Node via tsx/esm internally
- Hardened CI/CD with explicit node version 22.22.2 checks
- Completed stage validations for v3.6.6 final release

* chore: fix TS build errors and e2e timeouts in CI

- Migrate nodeRuntimeSupport to TS interfaces avoiding implicit any
- Increase visibility timeouts in skills-marketplace E2E test to 15s to bypass CI flakiness
- Complete migration of .mjs scripts to .ts ensuring type safety

* chore(release): sync package version 3.6.6 across workspaces

* test(e2e): universally increase UI component visibility timeouts from 5s to 15s to bypass CI starvation

* chore(build): inject baseUrl, paths, and types:node into MITM tsconfig within prepublish hook to fix missing types in CI check

---------

Co-authored-by: diegosouzapw <diegosouzapw@users.noreply.github.com>
Co-authored-by: Jack <5443152+hijak@users.noreply.github.com>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Samuel Cedric <ceds.sam@gmail.com>
Co-authored-by: Max Garmash <max@37bytes.com>
Co-authored-by: Markus Hartung <mail@hartmark.se>
Co-authored-by: Gi99lin <74502520+Gi99lin@users.noreply.github.com>
Co-authored-by: Payne <baboialex95@gmail.com>
Co-authored-by: Benson K B <bensonkbmca@gmail.com>
Co-authored-by: clousky2020 <33016567+clousky2020@users.noreply.github.com>
Co-authored-by: Ravi Tharuma <25951435+RaviTharuma@users.noreply.github.com>
Co-authored-by: oyi77 <oyi77@users.noreply.github.com>
Co-authored-by: Hdsje <vovan877@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: xiaoge1688 <moyekongling@gmail.com>
2026-04-16 05:26:17 -03:00

1087 lines
36 KiB
TypeScript

import test from "node:test";
import assert from "node:assert/strict";
import fs from "node:fs";
import os from "node:os";
import path from "node:path";
const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-route-edges-"));
process.env.DATA_DIR = TEST_DATA_DIR;
process.env.API_KEY_SECRET = "test-api-key-secret";
process.env.CLOUD_URL = "http://cloud.example";
const core = await import("../../src/lib/db/core.ts");
const apiKeysDb = await import("../../src/lib/db/apiKeys.ts");
const compliance = await import("../../src/lib/compliance/index.ts");
const providersDb = await import("../../src/lib/db/providers.ts");
const modelsDb = await import("../../src/lib/db/models.ts");
const localDb = await import("../../src/lib/localDb.ts");
const listKeysRoute = await import("../../src/app/api/keys/route.ts");
const settingsProxyRoute = await import("../../src/app/api/settings/proxy/route.ts");
const managementProxiesRoute = await import("../../src/app/api/v1/management/proxies/route.ts");
const embeddingsRoute = await import("../../src/app/api/v1/embeddings/route.ts");
const MACHINE_ID = "1234567890abcdef";
async function resetStorage() {
delete process.env.ALLOW_API_KEY_REVEAL;
delete process.env.INITIAL_PASSWORD;
delete process.env.REQUIRE_API_KEY;
delete process.env.ENABLE_SOCKS5_PROXY;
core.resetDbInstance();
apiKeysDb.resetApiKeyState();
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true });
fs.mkdirSync(TEST_DATA_DIR, { recursive: true });
}
async function enableManagementAuth() {
process.env.INITIAL_PASSWORD = "bootstrap-password";
await localDb.updateSettings({ requireLogin: true, password: "" });
}
async function createManagementKey() {
return apiKeysDb.createApiKey("management", MACHINE_ID);
}
function makeRequest(url, { method = "GET", token, body, headers } = {}) {
const requestHeaders = new Headers(headers);
if (token) {
requestHeaders.set("authorization", `Bearer ${token}`);
}
if (body !== undefined && !requestHeaders.has("content-type")) {
requestHeaders.set("content-type", "application/json");
}
return new Request(url, {
method,
headers: requestHeaders,
body: body === undefined ? undefined : JSON.stringify(body),
});
}
async function seedOpenAIConnection({
email = "embeddings@example.com",
provider = "openai",
rateLimitedUntil = null,
} = {}) {
return providersDb.createProviderConnection({
provider,
authType: "apikey",
email,
name: email,
apiKey: "sk-provider",
testStatus: "active",
lastError: null,
lastErrorType: "token_refresh_failed",
lastErrorSource: "oauth",
errorCode: "refresh_failed",
rateLimitedUntil,
backoffLevel: 2,
});
}
async function withPrepareFailure(match, message, fn) {
const db = core.getDbInstance();
const originalPrepare = db.prepare.bind(db);
db.prepare = (sql, ...args) => {
const sqlText = String(sql);
const matched = typeof match === "function" ? match(sqlText) : sqlText.includes(match);
if (matched) {
throw new Error(message);
}
return originalPrepare(sql, ...args);
};
try {
return await fn();
} finally {
db.prepare = originalPrepare;
}
}
async function withPrepareOverride(match, override, fn) {
const db = core.getDbInstance();
const originalPrepare = db.prepare.bind(db);
db.prepare = (sql, ...args) => {
const sqlText = String(sql);
const matched = typeof match === "function" ? match(sqlText) : sqlText.includes(match);
const statement = originalPrepare(sql, ...args);
if (!matched) {
return statement;
}
return override({ sqlText, statement, args });
};
try {
return await fn();
} finally {
db.prepare = originalPrepare;
}
}
test.beforeEach(async () => {
await resetStorage();
});
test.after(async () => {
await resetStorage();
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true });
});
test("api keys route covers auth, create, masking, pagination fallback and cloud sync", async () => {
await enableManagementAuth();
const unauthenticated = await listKeysRoute.GET(new Request("http://localhost/api/keys"));
const invalidToken = await listKeysRoute.GET(
new Request("http://localhost/api/keys", {
headers: { authorization: "Bearer sk-invalid" },
})
);
const managementKey = await createManagementKey();
const originalFetch = globalThis.fetch;
const fetchCalls = [];
globalThis.fetch = async (url, options = {}) => {
fetchCalls.push({ url: String(url), options });
return Response.json({ changes: { apiKeys: 1 } });
};
try {
await localDb.updateSettings({ cloudEnabled: true });
const created = await listKeysRoute.POST(
makeRequest("http://localhost/api/keys", {
method: "POST",
token: managementKey.key,
body: { name: "Key / Prod #1", noLog: true },
})
);
const createdBody = await created.json();
const stored = await apiKeysDb.getApiKeyById(createdBody.id);
await apiKeysDb.createApiKey("Alpha", MACHINE_ID);
await apiKeysDb.createApiKey("Beta", MACHINE_ID);
const paged = await listKeysRoute.GET(
makeRequest("http://localhost/api/keys?limit=0&offset=-25", {
token: managementKey.key,
})
);
const unauthenticatedBody = await unauthenticated.json();
const invalidTokenBody = await invalidToken.json();
const pagedBody = await paged.json();
assert.equal(unauthenticated.status, 401);
assert.equal(unauthenticatedBody.error.message, "Authentication required");
assert.equal(invalidToken.status, 403);
assert.equal(invalidTokenBody.error.message, "Invalid management token");
assert.equal(created.status, 201);
assert.equal(createdBody.name, "Key / Prod #1");
assert.equal(createdBody.noLog, true);
assert.match(createdBody.key, /^sk-/);
assert.equal(stored?.noLog, true);
assert.equal(compliance.isNoLog(createdBody.id), true);
assert.equal(paged.status, 200);
assert.equal(pagedBody.total, 4);
assert.equal(pagedBody.keys.length, 4);
assert.match(pagedBody.keys[0].key, /\*{4}/);
assert.equal(fetchCalls.length, 1);
assert.match(fetchCalls[0].url, /^http:\/\/cloud\.example\/sync\//);
} finally {
globalThis.fetch = originalFetch;
}
});
test("api keys route rejects invalid payloads and malformed JSON", async () => {
await enableManagementAuth();
const managementKey = await createManagementKey();
const missingName = await listKeysRoute.POST(
makeRequest("http://localhost/api/keys", {
method: "POST",
token: managementKey.key,
body: {},
})
);
const malformed = await listKeysRoute.POST(
new Request("http://localhost/api/keys", {
method: "POST",
headers: {
authorization: `Bearer ${managementKey.key}`,
"content-type": "application/json",
},
body: "{",
})
);
const malformedBody = await malformed.json();
assert.equal(missingName.status, 400);
assert.equal(malformed.status, 500);
assert.equal(malformedBody.error, "Failed to create key");
});
test("settings proxy route covers full config, resolve, validation, delete and global fallback", async () => {
const providerConnection = await providersDb.createProviderConnection({
provider: "openai",
authType: "apikey",
name: "provider-conn",
apiKey: "sk-openai",
});
const invalidJson = await settingsProxyRoute.PUT(
new Request("http://localhost/api/settings/proxy", {
method: "PUT",
headers: { "content-type": "application/json" },
body: "{",
})
);
const invalidBody = await settingsProxyRoute.PUT(
makeRequest("http://localhost/api/settings/proxy", {
method: "PUT",
body: { level: "provider", proxy: "bad-shape" },
})
);
const validPut = await settingsProxyRoute.PUT(
makeRequest("http://localhost/api/settings/proxy", {
method: "PUT",
body: {
level: "provider",
id: "openai",
proxy: { type: "http", host: "provider.local", port: "8080" },
global: { type: "https", host: "global.local", port: "443" },
combos: {
primary: { type: "http", host: "combo.local", port: "9000" },
},
keys: {
key1: { type: "https", host: "key.local", port: "9443" },
},
},
})
);
const legacyPut = await settingsProxyRoute.PUT(
makeRequest("http://localhost/api/settings/proxy", {
method: "PUT",
body: {
global: { type: "https", host: "global.local", port: "443" },
combos: {
primary: { type: "http", host: "combo.local", port: "9000" },
},
keys: {
key1: { type: "https", host: "key.local", port: "9443" },
},
},
})
);
const providerGet = await settingsProxyRoute.GET(
new Request("http://localhost/api/settings/proxy?level=provider&id=openai")
);
const resolveGet = await settingsProxyRoute.GET(
new Request(`http://localhost/api/settings/proxy?resolve=${providerConnection.id}`)
);
const fullConfig = await settingsProxyRoute.GET(
new Request("http://localhost/api/settings/proxy")
);
const deleted = await settingsProxyRoute.DELETE(
new Request("http://localhost/api/settings/proxy?level=provider&id=openai", {
method: "DELETE",
})
);
const resolveAfterDelete = await settingsProxyRoute.GET(
new Request(`http://localhost/api/settings/proxy?resolve=${providerConnection.id}`)
);
const missingLevel = await settingsProxyRoute.DELETE(
new Request("http://localhost/api/settings/proxy", { method: "DELETE" })
);
const invalidJsonBody = await invalidJson.json();
const invalidBodyPayload = await invalidBody.json();
const validPutBody = await validPut.json();
const legacyPutBody = await legacyPut.json();
const providerGetBody = await providerGet.json();
const resolveBody = await resolveGet.json();
const fullConfigBody = await fullConfig.json();
const deletedBody = await deleted.json();
const resolveAfterDeleteBody = await resolveAfterDelete.json();
const missingLevelBody = await missingLevel.json();
assert.equal(invalidJson.status, 400);
assert.equal(invalidJsonBody.error.message, "Invalid JSON body");
assert.equal(invalidBody.status, 400);
assert.match(invalidBodyPayload.error.message, /invalid/i);
assert.equal(validPut.status, 200);
assert.equal(validPutBody.providers.openai.host, "provider.local");
assert.equal(legacyPut.status, 200);
assert.equal(legacyPutBody.global.host, "global.local");
assert.equal(providerGet.status, 200);
assert.equal(providerGetBody.proxy.host, "provider.local");
assert.equal(resolveGet.status, 200);
assert.equal(resolveBody.proxy.host, "provider.local");
assert.equal(fullConfig.status, 200);
assert.equal(fullConfigBody.global.host, "global.local");
assert.equal(deleted.status, 200);
assert.equal(Object.prototype.hasOwnProperty.call(deletedBody.providers, "openai"), false);
assert.equal(resolveAfterDelete.status, 200);
assert.equal(resolveAfterDeleteBody.level, "global");
assert.equal(resolveAfterDeleteBody.proxy.host, "global.local");
assert.equal(missingLevel.status, 400);
assert.equal(missingLevelBody.error.message, "level is required");
});
test("settings proxy route prefers proxy registry assignments and enforces socks5 feature gating", async () => {
const created = await localDb.createProxy({
name: "Global Proxy",
type: "http",
host: "registry.local",
port: 8080,
username: "alice",
password: "secret",
});
await localDb.assignProxyToScope("global", null, created.id);
const registryBacked = await settingsProxyRoute.GET(
new Request("http://localhost/api/settings/proxy?level=global")
);
const registryBackedBody = await registryBacked.json();
process.env.ENABLE_SOCKS5_PROXY = "false";
const disabledSocks = await settingsProxyRoute.PUT(
makeRequest("http://localhost/api/settings/proxy", {
method: "PUT",
body: {
level: "global",
proxy: { type: "socks5", host: "127.0.0.1", port: "1080" },
},
})
);
process.env.ENABLE_SOCKS5_PROXY = "true";
const enabledSocks = await settingsProxyRoute.PUT(
makeRequest("http://localhost/api/settings/proxy", {
method: "PUT",
body: {
level: "global",
proxy: { type: "SOCKS5", host: "127.0.0.1", port: "1080" },
},
})
);
const disabledSocksBody = await disabledSocks.json();
const enabledSocksBody = await enabledSocks.json();
assert.equal(registryBacked.status, 200);
assert.equal(registryBackedBody.proxy.host, "registry.local");
assert.equal(registryBackedBody.proxy.password, "secret");
assert.equal(disabledSocks.status, 400);
assert.match(disabledSocksBody.error.message, /SOCKS5 proxy is disabled/i);
assert.equal(enabledSocks.status, 200);
assert.equal(enabledSocksBody.global.type, "socks5");
});
test("settings proxy route covers default types, null maps, registry fallback, and server-error branches", async () => {
const defaultTypePut = await settingsProxyRoute.PUT(
makeRequest("http://localhost/api/settings/proxy", {
method: "PUT",
body: {
level: "global",
proxy: { host: "default-type.local", port: "8088" },
},
})
);
assert.equal(defaultTypePut.status, 200);
const defaultTypeBody = await defaultTypePut.json();
assert.equal(defaultTypeBody.global.type, "http");
const clearMapPut = await settingsProxyRoute.PUT(
makeRequest("http://localhost/api/settings/proxy", {
method: "PUT",
body: {
global: null,
providers: { openai: null },
},
})
);
assert.equal(clearMapPut.status, 200);
const clearMapBody = await clearMapPut.json();
assert.equal(clearMapBody.global, null);
assert.equal(Object.prototype.hasOwnProperty.call(clearMapBody.providers || {}, "openai"), false);
await settingsProxyRoute.PUT(
makeRequest("http://localhost/api/settings/proxy", {
method: "PUT",
body: {
level: "global",
proxy: { type: "https", host: "legacy-fallback.local", port: "9443" },
},
})
);
const missingRegistryProxy = await localDb.createProxy({
name: "Missing Registry Proxy",
type: "http",
host: "missing-registry.local",
port: 8080,
});
await localDb.assignProxyToScope("global", null, missingRegistryProxy.id);
await withPrepareOverride(
"FROM proxy_registry WHERE id = ?",
({ statement }) => ({
...statement,
get() {
return undefined;
},
}),
async () => {
const response = await settingsProxyRoute.GET(
new Request("http://localhost/api/settings/proxy?level=global")
);
assert.equal(response.status, 200);
const body = await response.json();
assert.equal(body.level, "global");
assert.equal(body.proxy.host, "legacy-fallback.local");
}
);
await withPrepareFailure(
"SELECT key, value FROM key_value WHERE namespace = 'proxyConfig'",
"proxy config read failure",
async () => {
const response = await settingsProxyRoute.GET(
new Request("http://localhost/api/settings/proxy")
);
assert.equal(response.status, 500);
assert.match((await response.json()).error.message, /proxy config read failure/i);
}
);
await withPrepareFailure(
"INSERT OR REPLACE INTO key_value (namespace, key, value) VALUES ('proxyConfig', 'global', ?)",
"proxy config write failure",
async () => {
const response = await settingsProxyRoute.PUT(
makeRequest("http://localhost/api/settings/proxy", {
method: "PUT",
body: {
level: "global",
proxy: { host: "broken-write.local", port: "8080" },
},
})
);
assert.equal(response.status, 500);
const body = await response.json();
assert.equal(body.error.type, "server_error");
assert.match(body.error.message, /proxy config write failure/i);
}
);
await withPrepareFailure(
"INSERT OR REPLACE INTO key_value (namespace, key, value) VALUES ('proxyConfig', 'global', ?)",
"proxy config delete failure",
async () => {
const response = await settingsProxyRoute.DELETE(
new Request("http://localhost/api/settings/proxy?level=global", {
method: "DELETE",
})
);
assert.equal(response.status, 500);
assert.match((await response.json()).error.message, /proxy config delete failure/i);
}
);
});
test("management proxies route covers auth, pagination, lookup, where-used, patch and delete flows", async () => {
await enableManagementAuth();
const managementKey = await createManagementKey();
const unauthenticated = await managementProxiesRoute.GET(
new Request("http://localhost/api/v1/management/proxies")
);
const invalidToken = await managementProxiesRoute.GET(
new Request("http://localhost/api/v1/management/proxies", {
headers: { authorization: "Bearer sk-invalid" },
})
);
const createdResponse = await managementProxiesRoute.POST(
makeRequest("http://localhost/api/v1/management/proxies", {
method: "POST",
token: managementKey.key,
body: {
name: "Branch Proxy",
type: "http",
host: "branch.local",
port: 8080,
},
})
);
const created = await createdResponse.json();
await localDb.assignProxyToScope("provider", "openai", created.id);
const pagedList = await managementProxiesRoute.GET(
makeRequest("http://localhost/api/v1/management/proxies?limit=999&offset=-5", {
token: managementKey.key,
})
);
const byId = await managementProxiesRoute.GET(
makeRequest(`http://localhost/api/v1/management/proxies?id=${created.id}`, {
token: managementKey.key,
})
);
const whereUsed = await managementProxiesRoute.GET(
makeRequest(`http://localhost/api/v1/management/proxies?id=${created.id}&where_used=1`, {
token: managementKey.key,
})
);
const missingGet = await managementProxiesRoute.GET(
makeRequest("http://localhost/api/v1/management/proxies?id=missing", {
token: managementKey.key,
})
);
const invalidJsonPatch = await managementProxiesRoute.PATCH(
new Request("http://localhost/api/v1/management/proxies", {
method: "PATCH",
headers: {
authorization: `Bearer ${managementKey.key}`,
"content-type": "application/json",
},
body: "{",
})
);
const invalidPatch = await managementProxiesRoute.PATCH(
makeRequest("http://localhost/api/v1/management/proxies", {
method: "PATCH",
token: managementKey.key,
body: {},
})
);
const patched = await managementProxiesRoute.PATCH(
makeRequest("http://localhost/api/v1/management/proxies", {
method: "PATCH",
token: managementKey.key,
body: { id: created.id, host: "patched.local", notes: "updated" },
})
);
const missingDelete = await managementProxiesRoute.DELETE(
makeRequest("http://localhost/api/v1/management/proxies", {
method: "DELETE",
token: managementKey.key,
})
);
const conflictDelete = await managementProxiesRoute.DELETE(
makeRequest(`http://localhost/api/v1/management/proxies?id=${created.id}`, {
method: "DELETE",
token: managementKey.key,
})
);
const forcedDelete = await managementProxiesRoute.DELETE(
makeRequest(`http://localhost/api/v1/management/proxies?id=${created.id}&force=1`, {
method: "DELETE",
token: managementKey.key,
})
);
const unauthenticatedBody = await unauthenticated.json();
const invalidTokenBody = await invalidToken.json();
const pagedListBody = await pagedList.json();
const byIdBody = await byId.json();
const whereUsedBody = await whereUsed.json();
const missingGetBody = await missingGet.json();
const invalidJsonPatchBody = await invalidJsonPatch.json();
const invalidPatchBody = await invalidPatch.json();
const patchedBody = await patched.json();
const missingDeleteBody = await missingDelete.json();
const conflictDeleteBody = await conflictDelete.json();
const forcedDeleteBody = await forcedDelete.json();
assert.equal(unauthenticated.status, 401);
assert.equal(unauthenticatedBody.error.message, "Authentication required");
assert.equal(invalidToken.status, 403);
assert.equal(invalidTokenBody.error.message, "Invalid management token");
assert.equal(createdResponse.status, 201);
assert.equal(pagedList.status, 200);
assert.equal(pagedListBody.page.limit, 200);
assert.equal(pagedListBody.page.offset, 0);
assert.equal(byId.status, 200);
assert.equal(byIdBody.id, created.id);
assert.equal(whereUsed.status, 200);
assert.equal(whereUsedBody.count, 1);
assert.equal(missingGet.status, 404);
assert.equal(missingGetBody.error.message, "Proxy not found");
assert.equal(invalidJsonPatch.status, 400);
assert.equal(invalidJsonPatchBody.error.message, "Invalid JSON body");
assert.equal(invalidPatch.status, 400);
assert.equal(invalidPatchBody.error.message, "Invalid request");
assert.equal(patched.status, 200);
assert.equal(patchedBody.host, "patched.local");
assert.equal(missingDelete.status, 400);
assert.equal(missingDeleteBody.error.message, "id is required");
assert.equal(conflictDelete.status, 409);
assert.match(conflictDeleteBody.error.message, /force=true/i);
assert.equal(forcedDelete.status, 200);
assert.equal(forcedDeleteBody.success, true);
});
test("embeddings route covers options, custom-model listing and defensive POST branches", async () => {
await modelsDb.addCustomModel(
"custom-embedder",
"text-embed-1",
"Custom Embedder",
"manual",
"responses",
["embeddings"]
);
const optionsResponse = await embeddingsRoute.OPTIONS();
const getResponse = await embeddingsRoute.GET();
const getBody = await getResponse.json();
const invalidJson = await embeddingsRoute.POST(
new Request("http://localhost/v1/embeddings", {
method: "POST",
headers: { "content-type": "application/json" },
body: "{",
})
);
const validationFailure = await embeddingsRoute.POST(
makeRequest("http://localhost/v1/embeddings", {
method: "POST",
body: {},
})
);
const invalidModel = await embeddingsRoute.POST(
makeRequest("http://localhost/v1/embeddings", {
method: "POST",
body: { model: "unknown/model", input: "hello" },
})
);
const optionsHeaders = Object.fromEntries(optionsResponse.headers.entries());
const invalidJsonBody = await invalidJson.json();
const validationFailureBody = await validationFailure.json();
const invalidModelBody = await invalidModel.json();
assert.equal(optionsHeaders["access-control-allow-origin"], "*");
assert.equal(getResponse.status, 200);
assert.equal(
getBody.data.some((model) => model.id === "custom-embedder/text-embed-1"),
true
);
assert.equal(invalidJson.status, 400);
assert.equal(invalidJsonBody.error.message, "Invalid JSON body");
assert.equal(validationFailure.status, 400);
assert.match(validationFailureBody.error.message, /invalid|required/i);
assert.equal(invalidModel.status, 400);
assert.match(
invalidModelBody.error.message,
/Invalid embedding model|Unknown embedding provider/
);
});
test("embeddings route enforces caller auth, missing credentials and provider rate limits", async () => {
process.env.REQUIRE_API_KEY = "true";
const missingKey = await embeddingsRoute.POST(
makeRequest("http://localhost/v1/embeddings", {
method: "POST",
body: { model: "openai/text-embedding-3-small", input: "hello" },
})
);
const invalidKey = await embeddingsRoute.POST(
new Request("http://localhost/v1/embeddings", {
method: "POST",
headers: {
"content-type": "application/json",
authorization: "Bearer sk-invalid",
},
body: JSON.stringify({ model: "openai/text-embedding-3-small", input: "hello" }),
})
);
const validApiKey = await apiKeysDb.createApiKey("caller", MACHINE_ID);
const missingCredentials = await embeddingsRoute.POST(
new Request("http://localhost/v1/embeddings", {
method: "POST",
headers: {
"content-type": "application/json",
authorization: `Bearer ${validApiKey.key}`,
},
body: JSON.stringify({ model: "openai/text-embedding-3-small", input: "hello" }),
})
);
await seedOpenAIConnection({
email: "rate-limited@example.com",
rateLimitedUntil: new Date(Date.now() + 60_000).toISOString(),
});
const allRateLimited = await embeddingsRoute.POST(
new Request("http://localhost/v1/embeddings", {
method: "POST",
headers: {
"content-type": "application/json",
authorization: `Bearer ${validApiKey.key}`,
},
body: JSON.stringify({ model: "openai/text-embedding-3-small", input: "hello" }),
})
);
const missingKeyBody = await missingKey.json();
const invalidKeyBody = await invalidKey.json();
const missingCredentialsBody = await missingCredentials.json();
const allRateLimitedBody = await allRateLimited.json();
assert.equal(missingKey.status, 401);
assert.equal(missingKeyBody.error.message, "Missing API key");
assert.equal(invalidKey.status, 401);
assert.equal(invalidKeyBody.error.message, "Invalid API key");
assert.equal(missingCredentials.status, 400);
assert.match(missingCredentialsBody.error.message, /No credentials for embedding provider/);
assert.equal(allRateLimited.status, 429);
assert.match(allRateLimitedBody.error.message, /All accounts rate limited/);
});
test("embeddings route tolerates custom-model and provider-node lookup failures", async () => {
await seedOpenAIConnection();
const originalFetch = globalThis.fetch;
globalThis.fetch = async () =>
Response.json({
data: [{ object: "embedding", index: 0, embedding: [0.1, 0.2] }],
usage: { prompt_tokens: 3, total_tokens: 3 },
});
try {
await withPrepareFailure(
"SELECT key, value FROM key_value WHERE namespace = 'customModels'",
"custom models unavailable",
async () => {
const response = await embeddingsRoute.GET();
const body = await response.json();
assert.equal(response.status, 200);
assert.ok(body.data.some((model) => model.id === "openai/text-embedding-3-small"));
}
);
await withPrepareFailure(
"SELECT * FROM provider_nodes",
"provider nodes unavailable",
async () => {
const response = await embeddingsRoute.POST(
makeRequest("http://localhost/v1/embeddings", {
method: "POST",
body: { model: "openai/text-embedding-3-small", input: "hello" },
})
);
const body = await response.json();
assert.equal(response.status, 200);
assert.equal(body.model, "openai/text-embedding-3-small");
}
);
} finally {
globalThis.fetch = originalFetch;
}
});
test("embeddings route supports local provider nodes without credentials and enforces model policy", async () => {
await providersDb.createProviderNode({
id: "local-embed-node",
type: "openai-compatible",
name: "Local Embed Node",
prefix: "localembed",
apiType: "chat",
baseUrl: "http://localhost:7788/v1",
});
const localFetchCalls = [];
const originalFetch = globalThis.fetch;
globalThis.fetch = async (url, init = {}) => {
localFetchCalls.push({
url: String(url),
headers: init.headers,
body: JSON.parse(String(init.body)),
});
return Response.json({
data: [{ object: "embedding", index: 0, embedding: [0.9, 0.1] }],
usage: { prompt_tokens: 2, total_tokens: 2 },
});
};
try {
const localResponse = await embeddingsRoute.POST(
makeRequest("http://localhost/v1/embeddings", {
method: "POST",
body: {
model: "localembed/demo-embed",
input: "hello",
user: "user-123",
},
})
);
const localBody = await localResponse.json();
assert.equal(localResponse.status, 200);
assert.equal(localBody.model, "localembed/demo-embed");
assert.equal(localFetchCalls.length, 1);
assert.equal(localFetchCalls[0].url, "http://localhost:7788/v1/embeddings");
assert.equal(localFetchCalls[0].headers.Authorization, undefined);
assert.equal(localFetchCalls[0].body.model, "demo-embed");
assert.equal(localFetchCalls[0].body.user, "user-123");
process.env.REQUIRE_API_KEY = "true";
const restrictedKey = await apiKeysDb.createApiKey("embeddings-policy", MACHINE_ID);
await apiKeysDb.updateApiKeyPermissions(restrictedKey.id, {
allowedModels: ["openai/text-embedding-ada-002"],
});
const rejected = await embeddingsRoute.POST(
new Request("http://localhost/v1/embeddings", {
method: "POST",
headers: {
"content-type": "application/json",
authorization: `Bearer ${restrictedKey.key}`,
},
body: JSON.stringify({
model: "openai/text-embedding-3-small",
input: "hello",
}),
})
);
const rejectedBody = await rejected.json();
assert.equal(rejected.status, 403);
assert.match(rejectedBody.error.message, /not allowed/i);
} finally {
globalThis.fetch = originalFetch;
}
});
test("embeddings route returns normalized upstream failures", async () => {
await seedOpenAIConnection();
const originalFetch = globalThis.fetch;
globalThis.fetch = async () => new Response("upstream boom", { status: 502 });
try {
const response = await embeddingsRoute.POST(
makeRequest("http://localhost/v1/embeddings", {
method: "POST",
body: { model: "openai/text-embedding-3-small", input: "hello" },
})
);
const body = await response.json();
assert.equal(response.status, 502);
assert.equal(body.error.message, "upstream boom");
assert.equal(body.error.type, "upstream_error");
} finally {
globalThis.fetch = originalFetch;
}
});
test("embeddings route GET skips malformed, non-embedding, and duplicate custom model rows", async () => {
await modelsDb.addCustomModel(
"openai",
"text-embedding-3-small",
"Duplicate OpenAI Embed",
"manual",
"responses",
["embeddings"]
);
const db = core.getDbInstance();
db.prepare(
"INSERT OR REPLACE INTO key_value (namespace, key, value) VALUES ('customModels', ?, ?)"
).run("broken-embed-provider", JSON.stringify({ invalid: true }));
db.prepare(
"INSERT OR REPLACE INTO key_value (namespace, key, value) VALUES ('customModels', ?, ?)"
).run(
"mixed-embed-provider",
JSON.stringify([
{ name: "Missing Id", supportedEndpoints: ["embeddings"] },
{ id: "chat-only", supportedEndpoints: ["chat"] },
{ id: "edge-embed", supportedEndpoints: ["embeddings"] },
])
);
const response = await embeddingsRoute.GET();
const body = await response.json();
const ids = body.data.map((model) => model.id);
assert.equal(response.status, 200);
assert.equal(ids.filter((id) => id === "openai/text-embedding-3-small").length, 1);
assert.ok(ids.includes("mixed-embed-provider/edge-embed"));
assert.equal(ids.includes("mixed-embed-provider/chat-only"), false);
assert.equal(ids.includes("broken-embed-provider/edge-embed"), false);
});
test("embeddings route tolerates non-array provider nodes and remote fallback lookup errors", async () => {
await seedOpenAIConnection();
const originalFetch = globalThis.fetch;
globalThis.fetch = async () =>
Response.json({
data: [{ object: "embedding", index: 0, embedding: [0.3, 0.4] }],
usage: { prompt_tokens: 2, total_tokens: 2 },
});
try {
await withPrepareOverride(
"SELECT * FROM provider_nodes",
({ statement }) =>
new Proxy(statement, {
get(target, prop, receiver) {
if (prop === "all") {
return () => ({ broken: true });
}
return Reflect.get(target, prop, receiver);
},
}),
async () => {
const response = await embeddingsRoute.POST(
makeRequest("http://localhost/v1/embeddings", {
method: "POST",
body: { model: "openai/text-embedding-3-small", input: "hello" },
})
);
assert.equal(response.status, 200);
}
);
let providerNodeSelects = 0;
const remoteFallback = await withPrepareOverride(
"SELECT * FROM provider_nodes",
({ statement }) =>
new Proxy(statement, {
get(target, prop, receiver) {
if (prop === "all") {
return (...args) => {
providerNodeSelects++;
if (providerNodeSelects === 1) {
return [];
}
throw new Error("remote provider node lookup failed");
};
}
return Reflect.get(target, prop, receiver);
},
}),
async () =>
embeddingsRoute.POST(
makeRequest("http://localhost/v1/embeddings", {
method: "POST",
body: { model: "remote/demo-embed", input: "hello" },
})
)
);
const remoteFallbackBody = await remoteFallback.json();
assert.equal(remoteFallback.status, 400);
assert.match(remoteFallbackBody.error.message, /Unknown embedding provider|No matching/i);
} finally {
globalThis.fetch = originalFetch;
}
});
test("embeddings route handles responses provider nodes, invalid local nodes, and id-less remote fallback", async () => {
await providersDb.createProviderNode({
type: "openai-compatible",
name: "Local Responses Embed Node",
prefix: "localresponses",
apiType: "responses",
baseUrl: "http://localhost:7790/v1",
});
await providersDb.createProviderNode({
type: "openai-compatible",
name: "Invalid URL Node",
prefix: "badurl",
apiType: "chat",
baseUrl: "not a valid url",
});
await providersDb.createProviderNode({
type: "openai-compatible",
name: "Invalid Prefix Node",
prefix: "bad/prefix",
apiType: "chat",
baseUrl: "http://localhost:7791/v1",
});
await providersDb.createProviderConnection({
provider: "remoteprefix",
authType: "apikey",
name: "remoteprefix-key",
apiKey: "sk-remoteprefix",
});
const originalFetch = globalThis.fetch;
const fetchCalls = [];
globalThis.fetch = async (url, init = {}) => {
fetchCalls.push({
url: String(url),
headers: init.headers,
body: JSON.parse(String(init.body)),
});
return Response.json({
data: [{ object: "embedding", index: 0, embedding: [0.7, 0.8] }],
usage: { prompt_tokens: 4, total_tokens: 4 },
});
};
try {
const localResponse = await embeddingsRoute.POST(
makeRequest("http://localhost/v1/embeddings", {
method: "POST",
body: { model: "localresponses/demo-embed", input: "hello" },
})
);
assert.equal(localResponse.status, 200);
assert.equal(fetchCalls[0].url, "http://localhost:7790/v1/embeddings");
const remoteResponse = await withPrepareOverride(
"SELECT * FROM provider_nodes",
({ statement }) =>
new Proxy(statement, {
get(target, prop, receiver) {
if (prop === "all") {
return () => [
{
prefix: "remoteprefix",
apiType: "responses",
baseUrl: "https://remote.example.com/v1beta/openai",
},
];
}
return Reflect.get(target, prop, receiver);
},
}),
async () =>
embeddingsRoute.POST(
makeRequest("http://localhost/v1/embeddings", {
method: "POST",
body: { model: "remoteprefix/demo-embed", input: "hello" },
})
)
);
const remoteBody = await remoteResponse.json();
assert.equal(remoteResponse.status, 200);
assert.equal(fetchCalls[1].url, "https://remote.example.com/v1beta/openai/embeddings");
assert.equal(fetchCalls[1].headers.Authorization, "Bearer sk-remoteprefix");
assert.equal(remoteBody.model, "remoteprefix/demo-embed");
} finally {
globalThis.fetch = originalFetch;
}
});