mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-18 21:22:28 +03:00
* fix(providers): test token-backed web sessions * fix(providers): restrict token-web-session test dispatch to validated providers Narrow shouldUseApiKeyConnectionTest to the token-kind web-session providers that actually have a token-aware connection validator (deepseek-web, kimi-web, tinycms-web, copilot-m365-web, copilot-web, zai-web). WEB_SESSION_CREDENTIAL_REQUIREMENTS marks more providers as kind: "token" than have a matching validator in SPECIALTY_VALIDATORS (hailuo-web, microsoft-designer-web, t3-chat-web, promptql) — those were falling through to the generic cookie-based validateWebCookieProvider probe, which sends the stored credential as a Cookie header and treats most non-401/403 responses as valid, so an invalid token could be reported as a healthy connection. Add regression coverage for hailuo-web and promptql (plus microsoft-designer-web and t3-chat-web) proving they stay off the API-key test path, and for every currently validated token-kind provider proving they still use it. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com> --------- Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>