mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-05 23:02:10 +03:00
* chore(release): open v3.8.39 development cycle * docs(changelog): backfill 5 v3.8.38 bullets merged after release finalize These PRs squash-merged into release/v3.8.38 between the CHANGELOG finalize (ff57be32f) and the merge-to-main (ae6e2342d), so they shipped in the v3.8.38 tag but had no bullet: - feat(compression): Ionizer engine (lossy JSON-array sampling + CCR) (#5148) - fix(sse): preserve non-stream reasoning fields (#5155, @rdself) - fix(i18n): add missing English UI labels (#5153, @rdself) - test(combo): gated live smoke (#5151) + release-expectations refresh (#5150, @KooshaPari) (#5129 exact-host Anthropic baseUrl is already covered by the #5130 bullet — same CodeQL #674.) Synced 41 i18n CHANGELOG mirrors. * feat(compression): TOON best-of-N candidate encoder + encoder A/B table (#5163) Integrated into release/v3.8.39. TOON best-of-N candidate encoder (GCF default, fail-open). 17/17 unit tests pass on merge result; CI reds were base-stale + Quality Ratchet DRIFT. * fix(zenmux): normalize vendor-prefixed GLM system roles (#5158) Integrated into release/v3.8.39. ZenMux vendor-prefixed GLM system-role normalization; 12/12 role-normalizer tests pass on merge result. CI reds base-stale. * [codex] fix xAI OAuth test and reasoning effort (#5157) Integrated into release/v3.8.39. xAI reasoning-effort normalization (max/xhigh→high) + OAuth test config; 46/46 xai-translator tests pass on merge result. CI reds base-stale. * docs(i18n): add Traditional Chinese (zh-TW) README and update zh-CN to latest (#5162) Integrated into release/v3.8.39. Traditional Chinese (zh-TW) README + zh-CN refresh; docs-only. * test(security): guard PII redaction stays opt-in (default off) + Hard Rule #20 (#5159) Integrated into release/v3.8.39. PII opt-in regression guard + Hard Rule #20; rebased to strip base-drift (+81/-1). 5/5 guard tests pass; flip-proof verified. * test(combo): deterministic context-relay universal-handoff coverage (closes phase-2 TODO) (#5168) Integrated into release/v3.8.39. Deterministic context-relay universal-handoff coverage (3 tests); 3/3 pass on merge result. * docs(i18n): full sync zh-TW and zh-CN README with canonical English v3.8.39 (#5171) Integrated into release/v3.8.39. Full zh-TW docs tree + zh-CN sync with canonical English v3.8.39; docs-only. * fix(serve): honour HOSTNAME from .env instead of hardcoding 0.0.0.0 (#5134) (#5170) Integrated into release/v3.8.39. HOSTNAME env override in serve (#5134) + regression test (4/4, TDD flip-proof verified). * fix(sse): resolve nameless deepseek-web tool blocks via parameter-schema match (#5154) (#5173) Integrated into release/v3.8.39. Schema-based nameless deepseek-web tool-block resolution (#5154); 6/6 tests pass on merge result (incl. ambiguous/no-match negatives + named-tag no-regression). * fix(sse): normalize array user content for Command Code to avoid upstream 400 (#5166) (#5174) Integrated into release/v3.8.39. Normalize array user content for Command Code (#5166, user-array/400 symptom); 4/4 tests pass on merge result. * fix(sse): defer </think> close so it never leaks before tool_calls (#5123) (#5175) Integrated into release/v3.8.39. Defer </think> close so it never leaks before tool_calls (#5123); 4/4 tests pass (incl. #4633 no-regression). CHANGELOG synced to keep all 3 v3.8.39 fixes. * fix(dashboard): use amber for home update-step warning icon (#5176) Integrated into release/v3.8.39. Amber for home update-step warning icon; 1/1 UI test. * fix(api): LAN/Tailscale dashboard — host-aware CSP + GET-exempt version route + combo field errors (#5083) (#5177) Integrated into release/v3.8.39. Host-aware CSP (ReDoS/injection-safe host validation) + GET-exempt /api/system/version (POST/spawn stays LOCAL_ONLY, exact-match safe-methods-only) + COMBO_002 firstField. 44/44 tests + route-guard membership gate green. CHANGELOG synced to keep all 4 v3.8.39 fixes. * fix(api): replace #5083 global middleware CSP with declarative ws: scheme (#5083) Follow-up to PR #5177 (merged): that version implemented the LAN-CSP fix (Bug 1) with a new global `src/middleware.ts` + `src/server/csp.ts`, which contradicts the project's documented architecture — 'No global Next.js middleware — interception is route-specific' (CLAUDE.md / AGENTS.md) — and was merged unverified (middleware vs next.config header precedence was never confirmed in a real build). This replaces that approach with the minimal, declarative equivalent: • next.config.mjs: connect-src now permits the bare `ws:` scheme (symmetric with the bare `wss:` already allowed) so the dashboard can reach its own Live WS server from a LAN/Tailscale host. No middleware. • Removes src/middleware.ts, src/server/csp.ts, and tests/unit/csp-host-aware.test.ts. • Adds tests/unit/csp-lan-ws-5083.test.ts (incl. a guard asserting src/middleware.ts does NOT exist, so the global-middleware approach cannot silently return). Bugs 2 (GET-exempt /api/system/version) and 3 (COMBO_002 field surfacing) from #5177 are unaffected and remain in place. Co-authored-by: KooshaPari <KooshaPari@users.noreply.github.com> * test(combo): end-to-end quota-share DRR routing-decision coverage (matrix parity) (#5179) Integrated into release/v3.8.39. Quota-share DRR routing-decision coverage (matrix parity); 2/2 pass on merge result. * feat(agent-bridge): graceful cert-install fallback with manual guide for containers (#4546) (#5178) Integrated into release/v3.8.39. Agent-bridge graceful cert-install fallback + manual guide (#4546); 6/6 tests pass on merge result. * fix(antigravity): family-scoped quota lockout (gemini/claude buckets) (#5180) Integrated into release/v3.8.39 — family-scoped antigravity quota lockout. Rebased from v3.8.37 + validated (vitest 5/5, typecheck clean, full combo-matrix green, model-lockout 99/0). Same-model cross-account retry (chat.ts) deferred pending live antigravity VPS validation. * fix(cli): force NODE_ENV to match dev/start run mode in custom Next server (#5189) Integrated into release/v3.8.39. Force NODE_ENV to match dev/start run mode in custom Next server; 2/2 source-scan+ordering tests pass on merge result. * feat(compression): CCR ranged/grep/stats retrieval (ReDoS-safe, backward-compat) (#5187) Integrated into release/v3.8.39. CCR ranged/grep/stats retrieval (safe-regex ReDoS guard + length/match caps); 17/17 tests pass on merge result. * docs(combo): sync all combo/routing-strategy docs to current state + document test coverage (#5185) Integrated into release/v3.8.39. Combo/routing-strategy docs sync; docs-only. * fix(mcp): return 404 (not 400) for unknown Streamable HTTP session id (#5169) (#5191) * fix(api): respect blocked Auto (Zero-Config) provider in /v1/models catalog (#5192) (#5194) * test(combo): deterministic context-relay codex quota-handoff coverage (closes last gap) (#5195) * test(ci): wire antigravity-quota-family under test:vitest (fix test-discovery orphan) (#5196) * fix(oauth): antigravity login no longer hangs — fire-and-forget onboarding + bounded post-exchange (#5193) Antigravity OAuth hang fix (no-PKCE/no-openid + bounded post-exchange + exchange-500 fix). Includes #5200 (Koosha) revert + owner rebaseline to keep documented comments. Integrated into release/v3.8.39. * feat(oauth): remote Antigravity login via local helper + paste-credentials (#5203) Remote Antigravity login: local helper (omniroute login antigravity) + paste-credentials. Integrated into release/v3.8.39. * fix(translator): accept Claude Messages shape in non-stream malformed-200 guard (#5156) Integrated into release/v3.8.39 * fix(cli): default dev bundler to Turbopack (16.2.x panic no longer reproduces) (#5206) Integrated into release/v3.8.39 * fix(cli): auto-calibrate server V8 heap from physical RAM (#5172) (#5213) The server was spawned with a fixed --max-old-space-size=512 (omniroute serve) or no heap flag at all (Electron), so RAM-rich boxes still OOM-crashed under load (Ineffective mark-compacts near heap limit ~500MB) with many providers/ accounts and large model catalogs. New calibrateHeapFallbackMb(os.totalmem()) defaults the heap to ~35% of RAM clamped [512,4096], wired into serve.mjs and electron/main.js. Explicit OMNIROUTE_MEMORY_MB still wins (#2939 unchanged). Also addresses #5160 (same OOM root); #5152 (docker) benefits via the same knob. Closes #5172 * fix(proxy): coalesce fast-fail health probes (#5208) Integrated into release/v3.8.39 * fix(proxy): close dispatchers when clearing cache (#5202) Integrated into release/v3.8.39 * fix(cli): raise dev server Node heap limit to 8GB to prevent OOM (#5198) Integrated into release/v3.8.39 * fix(auth): allow synthetic no-auth fallback for mimocode (#5205) Integrated into release/v3.8.39 * fix(oauth): preserve Antigravity refresh_token on empty/omitted upstream response (#3850) (#5214) Google's OAuth refresh tokens are non-rotating: the refresh response usually omits refresh_token and occasionally returns it as an empty string. The Antigravity executor used `typeof tokens.refresh_token === "string" ? ... ` which accepts "" (typeof "" === "string") and overwrote the stored token with empty, nulling it on first refresh. Now treats non-string OR empty as absent and preserves credentials.refreshToken, matching refreshGoogleToken semantics. Closes #3850 * fix(responses): normalize non-array input (#5204) Integrated into release/v3.8.39 * fix(stream): normalize safety finish reasons via shared helper (#5197) Integrated into release/v3.8.39 * fix(request-logger): never render negative '(-100%)' compression badge (#5201) Integrated into release/v3.8.39 * fix(combo): reject empty responses api output (#5207) Integrated into release/v3.8.39 — combo failover now rejects empty Responses API output (validateQuality). Baseline rebaseline dropped (main-measured drift; maintainer rebaselines at release). * fix(pwa): prefer cached navigation before offline page (#5209) Integrated into release/v3.8.39 — PWA service worker prefers cached navigation before offline page (#5165). * chore(release): v3.8.39 — 2026-06-28 * chore(release): rebaseline openapi+i18n coverage ratchet drift for v3.8.39 --------- Co-authored-by: Arthur Bodera <abodera@gmail.com> Co-authored-by: Nguyen Minh <lop123thcs@gmail.com> Co-authored-by: lunkerchen <labanchen@gmail.com> Co-authored-by: Ankit <177378174+anki1kr@users.noreply.github.com> Co-authored-by: KooshaPari <KooshaPari@users.noreply.github.com> Co-authored-by: Ardem2025 <ardemb22@gmail.com> Co-authored-by: backryun <bakryun0718@proton.me> Co-authored-by: Anton <39598727+NomenAK@users.noreply.github.com> Co-authored-by: KooshaPari <42529354+KooshaPari@users.noreply.github.com> Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
350 lines
13 KiB
TypeScript
350 lines
13 KiB
TypeScript
import test from "node:test";
|
|
import assert from "node:assert/strict";
|
|
import { readFileSync } from "node:fs";
|
|
import { resolve, dirname } from "node:path";
|
|
import { fileURLToPath } from "node:url";
|
|
|
|
const __dirname = dirname(fileURLToPath(import.meta.url));
|
|
const srcPath = resolve(__dirname, "../../open-sse/mcp-server/httpTransport.ts");
|
|
const src = readFileSync(srcPath, "utf-8");
|
|
|
|
const mod = await import("../../open-sse/mcp-server/httpTransport.ts");
|
|
|
|
// ── Module exports ───────────────────────────────────────────────────────────
|
|
|
|
test("module exports handleMcpStreamableHTTP", () => {
|
|
assert.equal(typeof mod.handleMcpStreamableHTTP, "function");
|
|
});
|
|
|
|
test("module exports handleMcpSSE", () => {
|
|
assert.equal(typeof mod.handleMcpSSE, "function");
|
|
});
|
|
|
|
test("module exports getMcpHttpStatus", () => {
|
|
assert.equal(typeof mod.getMcpHttpStatus, "function");
|
|
});
|
|
|
|
test("module exports shutdownMcpHttp", () => {
|
|
assert.equal(typeof mod.shutdownMcpHttp, "function");
|
|
});
|
|
|
|
test("module exports isMcpHttpTransportReady", () => {
|
|
assert.equal(typeof mod.isMcpHttpTransportReady, "function");
|
|
});
|
|
|
|
test("module exports isMcpHttpActive", () => {
|
|
assert.equal(typeof mod.isMcpHttpActive, "function");
|
|
});
|
|
|
|
// ── Source-level invariant: StreamableSession type has lastActivityAt ─────────
|
|
|
|
test("StreamableSession type includes lastActivityAt field", () => {
|
|
const typeBlock = src.match(/type StreamableSession\s*=\s*\{([^}]+)\}/);
|
|
assert.ok(typeBlock, "StreamableSession type definition must exist");
|
|
assert.ok(
|
|
typeBlock[1].includes("lastActivityAt"),
|
|
"StreamableSession must have lastActivityAt field"
|
|
);
|
|
});
|
|
|
|
// ── Source-level invariant: sweep uses lastActivityAt not startedAt ───────────
|
|
|
|
test("sweep interval compares against lastActivityAt, not startedAt", () => {
|
|
const sweepBlock = src.match(
|
|
/_mcpSessionSweep\s*=\s*setInterval\(\(\)\s*=>\s*\{([\s\S]*?)\},\s*60_000\)/
|
|
);
|
|
assert.ok(sweepBlock, "sweep interval block must exist");
|
|
assert.ok(
|
|
sweepBlock[1].includes("session.lastActivityAt"),
|
|
"sweep must check session.lastActivityAt"
|
|
);
|
|
assert.ok(!sweepBlock[1].includes("session.startedAt"), "sweep must NOT check session.startedAt");
|
|
});
|
|
|
|
// ── Source-level invariant: MCP_SESSION_IDLE_MS constant ─────────────────────
|
|
|
|
test("MCP_SESSION_IDLE_MS is 5 minutes (5 * 60 * 1000)", () => {
|
|
assert.ok(src.includes("5 * 60 * 1000"), "idle timeout should be 5 * 60 * 1000");
|
|
});
|
|
|
|
// ── Source-level invariant: createStreamableSession sets lastActivityAt ───────
|
|
|
|
test("createStreamableSession initializes lastActivityAt to Date.now()", () => {
|
|
const fnBlock = src.match(/function createStreamableSession\(\)[\s\S]*?return session;\s*\}/);
|
|
assert.ok(fnBlock, "createStreamableSession function must exist");
|
|
assert.ok(
|
|
fnBlock[0].includes("lastActivityAt: Date.now()"),
|
|
"createStreamableSession must set lastActivityAt: Date.now()"
|
|
);
|
|
});
|
|
|
|
// ── Source-level invariant: handleStreamableRequest updates lastActivityAt ────
|
|
|
|
test("handleStreamableRequest updates lastActivityAt on every request", () => {
|
|
const fnBlock = src.match(
|
|
/async function handleStreamableRequest[\s\S]*?(?=\n(?:async )?function |\nexport )/
|
|
);
|
|
assert.ok(fnBlock, "handleStreamableRequest function must exist");
|
|
assert.ok(
|
|
fnBlock[0].includes("session.lastActivityAt = Date.now()"),
|
|
"handleStreamableRequest must update session.lastActivityAt on each request"
|
|
);
|
|
});
|
|
|
|
// ── Behavioral: getMcpHttpStatus returns expected shape when idle ─────────────
|
|
|
|
test("getMcpHttpStatus returns active-session state with no active sessions", () => {
|
|
mod.shutdownMcpHttp();
|
|
const status = mod.getMcpHttpStatus();
|
|
assert.equal(typeof status.online, "boolean");
|
|
assert.equal(status.online, false);
|
|
assert.equal(status.transport, null);
|
|
assert.equal(status.startedAt, null);
|
|
assert.equal(status.uptime, null);
|
|
});
|
|
|
|
test("isMcpHttpTransportReady treats enabled lazy HTTP transports as ready", () => {
|
|
mod.shutdownMcpHttp();
|
|
const status = mod.getMcpHttpStatus();
|
|
assert.equal(status.online, false);
|
|
assert.equal(mod.isMcpHttpTransportReady(true, "streamable-http"), true);
|
|
assert.equal(mod.isMcpHttpTransportReady(true, "sse"), true);
|
|
assert.equal(mod.isMcpHttpTransportReady(true, "stdio"), false);
|
|
assert.equal(mod.isMcpHttpTransportReady(false, "streamable-http"), false);
|
|
});
|
|
|
|
// ── Behavioral: isMcpHttpActive is false after shutdown ──────────────────────
|
|
|
|
test("isMcpHttpActive returns false when no transports are active", () => {
|
|
mod.shutdownMcpHttp();
|
|
assert.equal(mod.isMcpHttpActive(), false);
|
|
});
|
|
|
|
// ── Behavioral: shutdownMcpHttp is idempotent ────────────────────────────────
|
|
|
|
test("shutdownMcpHttp can be called multiple times without error", () => {
|
|
mod.shutdownMcpHttp();
|
|
mod.shutdownMcpHttp();
|
|
mod.shutdownMcpHttp();
|
|
assert.equal(mod.isMcpHttpActive(), false);
|
|
});
|
|
|
|
// ── Source-level invariant: sweep interval is 60 seconds ─────────────────────
|
|
|
|
test("sweep interval runs every 60 seconds", () => {
|
|
assert.ok(
|
|
src.includes("}, 60_000)") || src.includes("}, 60000)"),
|
|
"sweep interval must be 60_000ms (60 seconds)"
|
|
);
|
|
});
|
|
|
|
// ── Source-level invariant: sweep timer is unref'd so it doesn't block exit ───
|
|
|
|
test("sweep timer is unref'd to avoid preventing process exit", () => {
|
|
assert.ok(
|
|
src.includes("_mcpSessionSweep") && src.includes(".unref?.()"),
|
|
"sweep timer must be unref'd"
|
|
);
|
|
});
|
|
|
|
// ── Source-level invariant: sweep calls closeStreamableSession for idle ───────
|
|
|
|
test("sweep closes idle sessions via closeStreamableSession", () => {
|
|
const sweepBlock = src.match(
|
|
/_mcpSessionSweep\s*=\s*setInterval\(\(\)\s*=>\s*\{([\s\S]*?)\},\s*60_000\)/
|
|
);
|
|
assert.ok(sweepBlock, "sweep block must exist");
|
|
assert.ok(
|
|
sweepBlock[1].includes("closeStreamableSession(sessionId)"),
|
|
"sweep must call closeStreamableSession for idle sessions"
|
|
);
|
|
});
|
|
|
|
// ── Behavioral: shutdownMcpHttp clears all sessions ─────────────────────────
|
|
|
|
test("shutdownMcpHttp clears all sessions and makes isMcpHttpActive false", () => {
|
|
mod.shutdownMcpHttp();
|
|
assert.equal(mod.isMcpHttpActive(), false);
|
|
const before = mod.getMcpHttpStatus();
|
|
assert.equal(before.online, false);
|
|
assert.equal(before.transport, null);
|
|
});
|
|
|
|
// ── Behavioral: handleMcpStreamableHTTP rejects request without session id ───
|
|
|
|
test("handleMcpStreamableHTTP rejects non-initialize request without session id", async () => {
|
|
mod.shutdownMcpHttp();
|
|
const req = new Request("http://localhost/api/mcp/stream", {
|
|
method: "POST",
|
|
headers: { "Content-Type": "application/json" },
|
|
body: JSON.stringify({ jsonrpc: "2.0", method: "tools/list", id: 1 }),
|
|
});
|
|
const res = await mod.handleMcpStreamableHTTP(req);
|
|
assert.equal(res.status, 400);
|
|
const body = await res.json();
|
|
assert.ok(body.error);
|
|
assert.ok(body.error.message.includes("Mcp-Session-Id"));
|
|
});
|
|
|
|
// ── Behavioral: handleMcpStreamableHTTP creates session on initialize ────────
|
|
|
|
test("handleMcpStreamableHTTP creates a session on initialize request", async () => {
|
|
mod.shutdownMcpHttp();
|
|
assert.equal(mod.isMcpHttpActive(), false);
|
|
|
|
const initReq = new Request("http://localhost/api/mcp/stream", {
|
|
method: "POST",
|
|
headers: { "Content-Type": "application/json" },
|
|
body: JSON.stringify({
|
|
jsonrpc: "2.0",
|
|
method: "initialize",
|
|
id: 1,
|
|
params: {
|
|
protocolVersion: "2025-03-26",
|
|
capabilities: {},
|
|
clientInfo: { name: "test-client", version: "1.0.0" },
|
|
},
|
|
}),
|
|
});
|
|
const res = await mod.handleMcpStreamableHTTP(initReq);
|
|
assert.ok(res.status >= 200, "should get a response");
|
|
if (res.headers.get("mcp-session-id")) {
|
|
assert.equal(mod.isMcpHttpActive(), true);
|
|
const status = mod.getMcpHttpStatus();
|
|
assert.equal(status.online, true);
|
|
assert.equal(status.transport, "streamable-http");
|
|
assert.ok(status.startedAt !== null);
|
|
mod.shutdownMcpHttp();
|
|
assert.equal(mod.isMcpHttpActive(), false);
|
|
}
|
|
});
|
|
|
|
// ── Behavioral: getMcpHttpStatus reflects transport state ────────────────────
|
|
|
|
test("getMcpHttpStatus returns streamable-http transport when session exists", async () => {
|
|
mod.shutdownMcpHttp();
|
|
const initReq = new Request("http://localhost/api/mcp/stream", {
|
|
method: "POST",
|
|
headers: { "Content-Type": "application/json" },
|
|
body: JSON.stringify({
|
|
jsonrpc: "2.0",
|
|
method: "initialize",
|
|
id: 1,
|
|
params: {
|
|
protocolVersion: "2025-03-26",
|
|
capabilities: {},
|
|
clientInfo: { name: "test-client", version: "1.0.0" },
|
|
},
|
|
}),
|
|
});
|
|
const res = await mod.handleMcpStreamableHTTP(initReq);
|
|
const sessionId = res.headers.get("mcp-session-id");
|
|
if (sessionId) {
|
|
const status = mod.getMcpHttpStatus();
|
|
assert.equal(status.online, true);
|
|
assert.equal(status.transport, "streamable-http");
|
|
assert.ok(typeof status.uptime === "string");
|
|
assert.ok(status.uptime.endsWith("s"));
|
|
}
|
|
mod.shutdownMcpHttp();
|
|
});
|
|
|
|
// ── Behavioral: shutdownMcpHttp cleans up sessions created via initialize ────
|
|
|
|
test("shutdownMcpHttp removes sessions created via handleMcpStreamableHTTP", async () => {
|
|
mod.shutdownMcpHttp();
|
|
const initReq = new Request("http://localhost/api/mcp/stream", {
|
|
method: "POST",
|
|
headers: { "Content-Type": "application/json" },
|
|
body: JSON.stringify({
|
|
jsonrpc: "2.0",
|
|
method: "initialize",
|
|
id: 1,
|
|
params: {
|
|
protocolVersion: "2025-03-26",
|
|
capabilities: {},
|
|
clientInfo: { name: "test-client", version: "1.0.0" },
|
|
},
|
|
}),
|
|
});
|
|
const res = await mod.handleMcpStreamableHTTP(initReq);
|
|
const sessionId = res.headers.get("mcp-session-id");
|
|
if (sessionId) {
|
|
assert.equal(mod.isMcpHttpActive(), true);
|
|
mod.shutdownMcpHttp();
|
|
assert.equal(mod.isMcpHttpActive(), false);
|
|
const status = mod.getMcpHttpStatus();
|
|
assert.equal(status.online, false);
|
|
assert.equal(status.transport, null);
|
|
const staleReq = new Request("http://localhost/api/mcp/stream", {
|
|
method: "POST",
|
|
headers: {
|
|
"Content-Type": "application/json",
|
|
"mcp-session-id": sessionId,
|
|
},
|
|
body: JSON.stringify({ jsonrpc: "2.0", method: "tools/list", id: 2 }),
|
|
});
|
|
const staleRes = await mod.handleMcpStreamableHTTP(staleReq);
|
|
// MCP spec (2025-03-26 / 2025-11-25, Session Management): a terminated/unknown
|
|
// session id MUST return 404 Not Found so the client re-initializes (issue #5169).
|
|
assert.equal(staleRes.status, 404);
|
|
}
|
|
});
|
|
|
|
// ── Behavioral: handleMcpStreamableHTTP rejects unknown session id ───────────
|
|
|
|
test("handleMcpStreamableHTTP rejects request with unknown session id", async () => {
|
|
mod.shutdownMcpHttp();
|
|
const req = new Request("http://localhost/api/mcp/stream", {
|
|
method: "POST",
|
|
headers: {
|
|
"Content-Type": "application/json",
|
|
"mcp-session-id": "nonexistent-session-id",
|
|
},
|
|
body: JSON.stringify({ jsonrpc: "2.0", method: "tools/list", id: 1 }),
|
|
});
|
|
const res = await mod.handleMcpStreamableHTTP(req);
|
|
// Per MCP spec, a present-but-unknown session id MUST yield 404 (not 400), so
|
|
// the client knows to start a fresh session rather than hard-fail (issue #5169).
|
|
assert.equal(res.status, 404);
|
|
const body = await res.json();
|
|
assert.ok(body.error);
|
|
assert.ok(body.error.message.includes("Unknown"));
|
|
});
|
|
|
|
// ── Regression #5169: unknown/expired session → HTTP 404 (not 400) ───────────
|
|
|
|
test("handleMcpStreamableHTTP returns 404 (not 400) for an unknown session id", async () => {
|
|
mod.shutdownMcpHttp();
|
|
const req = new Request("http://localhost/api/mcp/stream", {
|
|
method: "POST",
|
|
headers: {
|
|
"Content-Type": "application/json",
|
|
"mcp-session-id": "expired-or-unknown-session",
|
|
},
|
|
body: JSON.stringify({ jsonrpc: "2.0", method: "tools/list", id: 7 }),
|
|
});
|
|
const res = await mod.handleMcpStreamableHTTP(req);
|
|
// The 400-vs-404 distinction is the whole bug: clients only re-initialize on 404.
|
|
assert.equal(res.status, 404);
|
|
const body = await res.json();
|
|
assert.equal(body.jsonrpc, "2.0");
|
|
assert.equal(body.error.code, -32000);
|
|
assert.ok(body.error.message.includes("Mcp-Session-Id"));
|
|
});
|
|
|
|
// ── Guard: a *missing* session id on a non-initialize request stays 400 ───────
|
|
|
|
test("handleMcpStreamableHTTP keeps 400 for a missing session id (non-initialize)", async () => {
|
|
mod.shutdownMcpHttp();
|
|
const req = new Request("http://localhost/api/mcp/stream", {
|
|
method: "POST",
|
|
headers: { "Content-Type": "application/json" },
|
|
body: JSON.stringify({ jsonrpc: "2.0", method: "tools/list", id: 8 }),
|
|
});
|
|
const res = await mod.handleMcpStreamableHTTP(req);
|
|
// Spec reserves 400 for a *missing* session id on non-initialize requests —
|
|
// only the *present-but-unknown* case changed to 404. This must NOT regress.
|
|
assert.equal(res.status, 400);
|
|
});
|