Files
OmniRoute/tests/unit/base-executor-buildheaders-extra-keys-8493.test.ts
Diego Rodrigues de Sa e Souza b6975537c1 fix(providers): remove the chipotle/pepper provider (#13131) (#13913)
* fix(providers): remove the chipotle/pepper provider (#13131)

amelia.chipotle.com (the reverse-engineered Amelia chat-widget backend
chipotle/pepper-1 talked to) now returns 404 on every route, including
root, from its Azure Application Gateway — confirmed live 2026-09-15.
This regressed from a WS handshake timeout (#4037, June 2026) to a
fully decommissioned host, so the upstream protocol cannot be fixed.
Owner decided to retire the provider entirely (Option B), following
the phind/kluster quiet-removal precedent: no REMOVED_PROVIDERS.md
entry (reserved for operator takedowns), just a one-line note under
FREE_TIERS.md "Removed / no free tier".

Removed every surface: executor, registry entry, executors/index.ts
and providers/index.ts wiring, noauth provider catalog entry,
ProviderIcon generic-fallback set, the autoCombo exclusion-list
comment, the chipotle_error code from the sanitizer allowlist,
PROVIDER_REFERENCE.md (regenerated), and every doc/test reference.

Regression test: tests/unit/issue-13131-chipotle-provider-removed.test.ts
asserts the provider is fully gone from the executor registry, the
provider REGISTRY and the noauth catalog, and that the executor module
no longer resolves — not a live-network repro (flaky/third-party).

Several existing tests used "chipotle" only as a generic noAuth-provider
example (proxy scoping, error classification, onboarding, fallback
text) with no chipotle-specific behavior under test; those were
re-pointed at another still-existing noAuth provider
(cloudflare-playground / duckduckgo-web) rather than weakened.

* test(providers): document the agnes-cn/chipotle count coincidence (#13131)

provider-node-reserved-prefix.test.ts's REGISTRY id+alias walk was
already red on the base tip (414 vs. expected 412) from agnes-cn
(#13399, +id/+alias). Removing chipotle's REGISTRY id/alias in this
PR nets it back to 412, making the test pass again without a numeric
edit — record why in a comment so it doesn't read as an untracked
coincidence later.
2026-09-17 13:22:09 -03:00

39 lines
1.4 KiB
TypeScript

import test from "node:test";
import assert from "node:assert/strict";
import { BaseExecutor } from "../../open-sse/executors/base.ts";
/**
* Generic BaseExecutor consumer — no buildHeaders() override — representing
* every provider (xai, cliproxyapi, mimocode, ninerouter,
* gitlab, ...) that relies on BaseExecutor.buildHeaders() as-is.
*
* Regression guard for #8467/#8493: resolveEffectiveKey() already rotates to
* an extra key when the primary apiKey is empty, but the header-write gate in
* buildHeaders() tested the raw `credentials.apiKey` instead of the resolved
* `effectiveKey` — so with an empty primary + populated extras, no
* Authorization header was ever written, even though a valid key existed.
*/
class GenericExecutor extends BaseExecutor {
constructor() {
super("generic-provider", {
baseUrls: ["https://default.example/v1/chat/completions"],
});
}
async transformRequest(model: string, body: unknown, stream: boolean) {
return body;
}
}
test("buildHeaders: writes Authorization from the rotated extra key when primary apiKey is empty (#8467/#8493)", () => {
const executor = new GenericExecutor();
const headers = executor.buildHeaders({
apiKey: "",
connectionId: "generic-empty-primary",
providerSpecificData: { extraApiKeys: ["sk-extra-only"] },
});
assert.equal(headers["Authorization"], "Bearer sk-extra-only");
});