Files
OmniRoute/tests/integration/agent-bridge-bypass-flow.test.ts
anhtahaylove fde6241d41 test: close the database before removing temp DATA_DIR (#13290) (#13292)
* test: close the database before removing temp DATA_DIR (#13290)

Tests that set their own DATA_DIR and removed it in test.after() failed on
Windows with EPERM: nothing closed the SQLite connection, so the directory
still had an open handle and the -shm/-wal sidecars kept it locked. maxRetries
could not help because every retry hit the same open handle.

Adds tests/_setup/tempDataDir.ts with cleanupTempDataDir()/createTempDataDir(),
which close the DB singleton (lazily imported, so tests that never touch the
database do not pull in the DB layer) and then remove the directory
best-effort. Applies it to the five suites confirmed failing.

The helper's own test proves the ordering matters: skipping the close makes it
fail with 'cleanup must remove the directory'.

* test: close the database before removing temp DATA_DIR (15 more suites)

Converts the suites that measurably emitted EPERM during a full run to the
shared cleanupTempDataDir helper from #13292.

Measured on the same 15 files:
  base   -> 22 fail, 40 EPERM lines
  branch ->  7 fail, 10 EPERM lines

The 7 remaining failures are pre-existing and unrelated to teardown:
rtk-learn-discover-routes and executor-map-golden already fail on a clean
base (6 and 3 failures respectively).

* test: close the database before removing temp DATA_DIR (final 9 suites)

Completes the #13290 sweep. Two teardown shapes needed the helper:

- after()/t.after() hooks that removed DATA_DIR directly
- beforeEach() hooks that wiped DATA_DIR between tests while the previous
  test's connection was still open. These failed *before* the test body ran,
  so every test in the file reported the same EPERM path.

Three of them already called core.resetDbInstance() right before rmSync and
still leaked, which is the product-side connection leak tracked in #13303.

Measured per file, EPERM lines now 0 across all nine. Remaining failures are
pre-existing on a clean base (firefly 4->1, driverFactory 1, responses-* 1
each) and unrelated to teardown.

* test: add the missing cleanupTempDataDir import to two responses suites

The previous commit swapped rmSync for cleanupTempDataDir in these two files but
did not add the import, so both suites died with
ReferenceError: cleanupTempDataDir is not defined before running any test.

responses-parse-once-4041:            0 pass / 1 fail -> 4 pass / 0 fail
responses-route-early-keepalive-wiring: 0 pass / 1 fail -> 3 pass / 0 fail

Both now report 0 EPERM.

* test: close SQLite handles in three silently-leaking suites

These three suites requested DATA_DIR cleanup but the delete failed on
Windows because a SQLite connection was still open. They pass today, so
the leak is invisible: they carry state between tests and would surface
later as an unrelated-looking assertion, as #13303 already did in the
Firefly suite (a 500 instead of a 401).

agentbridge-mitm-router-key-6403 and agent-bridge-bypass-flow removed
their own temp dir in test.after() without closing the DB first; both now
use the shared cleanupTempDataDir helper, which closes the singleton
before removing the directory.

issue-agent-route-execution is a different case: it has no teardown at
all, so the connection stayed open until process exit and the
isolateDataDir cleanup hook then hit EPERM. It now closes the DB in
test.after().

Verified with a probe on fs.rmSync: all three reported a failed delete
before, and zero across three consecutive runs after, while the same
probe still reports four leaks in the Firefly suite.

* test: remove temp DATA_DIR in five suites that never cleaned up

These five suites create their own mkdtemp DATA_DIR, open the SQLite DB and
never remove the directory, so every run leaves a storage.sqlite behind in the
OS temp dir. Each dir is private to its suite, so this leaked disk space rather
than corrupting results - but the churn is pointless.

Each now closes the DB and removes its directory through the shared
cleanupTempDataDir helper.

Verified with an exit-time probe that lists storage.sqlite* still present in
DATA_DIR: it fired for these suites before the change and is silent after,
with the same test counts (22/14/5/3/3 passing).
2026-09-17 02:31:53 -03:00

167 lines
6.1 KiB
TypeScript

/**
* Integration tests: AgentBridge bypass patterns flow
*
* Covers:
* - POST /api/tools/agent-bridge/bypass → stores user patterns
* - GET /api/tools/agent-bridge/bypass → shows default + user patterns
* - DELETE /api/tools/agent-bridge/bypass?pattern=X → removes a pattern
*/
import test from "node:test";
import assert from "node:assert/strict";
import fs from "node:fs";
import os from "node:os";
import path from "node:path";
import { cleanupTempDataDir } from "../_setup/tempDataDir.ts";
const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-ab-bypass-"));
process.env.DATA_DIR = TEST_DATA_DIR;
process.env.DISABLE_SQLITE_AUTO_BACKUP = "true";
const core = await import("../../src/lib/db/core.ts");
const { seedDefaultBypassPatterns } = await import("../../src/lib/db/agentBridgeBypass.ts");
const bypassRoute = await import("../../src/app/api/tools/agent-bridge/bypass/route.ts");
const DEFAULT_PATTERNS = [".bank.", ".gov.", "okta.com", "auth0.com"];
function resetDb() {
core.resetDbInstance();
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true, maxRetries: 5, retryDelay: 100 });
fs.mkdirSync(TEST_DATA_DIR, { recursive: true });
}
test.beforeEach(() => {
resetDb();
seedDefaultBypassPatterns(DEFAULT_PATTERNS);
});
test.after(async () => {
await cleanupTempDataDir(TEST_DATA_DIR);
});
// ── POST patterns ──────────────────────────────────────────────────────────
test("POST /bypass: stores user patterns", async () => {
const res = await bypassRoute.POST(
new Request("http://localhost/api/tools/agent-bridge/bypass", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({ patterns: ["*.mycompany.com", "internal.corp"] }),
})
);
assert.equal(res.status, 200);
const body = (await res.json()) as {
ok: boolean;
patterns: Array<{ pattern: string; source: string }>;
};
assert.equal(body.ok, true);
assert.ok(Array.isArray(body.patterns));
const userPatterns = body.patterns.filter((p) => p.source === "user");
assert.equal(userPatterns.length, 2);
});
test("POST /bypass: invalid body returns 400", async () => {
const res = await bypassRoute.POST(
new Request("http://localhost/", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({ patterns: "not-an-array" }),
})
);
assert.equal(res.status, 400);
const body = (await res.json()) as Record<string, unknown>;
const errMsg = (body.error as Record<string, unknown>)?.message as string;
assert.ok(!errMsg.includes("at /"), "stack trace leaked in 400 error");
});
// ── GET patterns ───────────────────────────────────────────────────────────
test("GET /bypass: shows default + user patterns", async () => {
// Add user patterns first
await bypassRoute.POST(
new Request("http://localhost/", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({ patterns: ["*.mycompany.com"] }),
})
);
const res = await bypassRoute.GET();
assert.equal(res.status, 200);
const body = (await res.json()) as { patterns: Array<{ pattern: string; source: string }> };
assert.ok(Array.isArray(body.patterns));
const sources = new Set(body.patterns.map((p) => p.source));
assert.ok(sources.has("default"), "No default patterns in response");
assert.ok(sources.has("user"), "No user patterns in response");
const defaultPatterns = body.patterns.filter((p) => p.source === "default");
assert.ok(defaultPatterns.length >= DEFAULT_PATTERNS.length);
});
test("GET /bypass: error response does not leak stack trace", async () => {
const res = await bypassRoute.GET();
const text = await res.text();
assert.ok(!text.includes("at /"), "stack trace leaked in GET /bypass response");
});
// ── DELETE pattern ─────────────────────────────────────────────────────────
test("DELETE /bypass?pattern=X: removes a user pattern", async () => {
// Add two patterns
await bypassRoute.POST(
new Request("http://localhost/", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({ patterns: ["*.mycompany.com", "internal.corp"] }),
})
);
// Delete one
const deleteRes = await bypassRoute.DELETE(
new Request("http://localhost/api/tools/agent-bridge/bypass?pattern=internal.corp", {
method: "DELETE",
})
);
assert.equal(deleteRes.status, 200);
const deleteBody = (await deleteRes.json()) as {
ok: boolean;
patterns: Array<{ pattern: string; source: string }>;
};
assert.equal(deleteBody.ok, true);
// Verify it's gone
const remaining = deleteBody.patterns.filter(
(p) => p.source === "user" && p.pattern === "internal.corp"
);
assert.equal(remaining.length, 0, "Deleted pattern still present");
// Other pattern still present
const kept = deleteBody.patterns.filter(
(p) => p.source === "user" && p.pattern === "*.mycompany.com"
);
assert.equal(kept.length, 1, "Remaining user pattern is missing");
});
test("DELETE /bypass: missing pattern param returns 400", async () => {
const res = await bypassRoute.DELETE(
new Request("http://localhost/api/tools/agent-bridge/bypass", {
method: "DELETE",
})
);
assert.equal(res.status, 400);
const body = (await res.json()) as Record<string, unknown>;
const errMsg = (body.error as Record<string, unknown>)?.message as string;
assert.ok(!errMsg.includes("at /"), "stack trace leaked in DELETE 400");
});
test("DELETE /bypass?pattern=X: no-op when pattern not in user list", async () => {
const res = await bypassRoute.DELETE(
new Request("http://localhost/api/tools/agent-bridge/bypass?pattern=not-in-list.com", {
method: "DELETE",
})
);
assert.equal(res.status, 200);
const body = (await res.json()) as { ok: boolean };
assert.equal(body.ok, true);
});