mirror of
https://github.com/Nezumi-2711/9router.git
synced 2026-09-22 13:38:31 +00:00
feat(oauth): zed/trae/windsurf providers + harden callback proxies
- zed live model discovery; codebuddy-intl handler; remove duplicate workbuddy - split oauth providers.js into per-provider files (facade re-export) - fold 5 standard refresh providers into config-driven generic - hide trae/windsurf from registry (no tool calling support) - fix login-CSRF + SSRF on trae/windsurf/zed local callback proxies via loopback-origin guard + strict state validation + apiOrigins allowlist - move zed RSA private key transit to POST body; redact proxy logs Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
783e271c16
commit
8e04fe1734
@@ -113,6 +113,43 @@ describe("parseGrokCliBilling", () => {
|
||||
expect(parsed.exhausted).toBe(false);
|
||||
});
|
||||
|
||||
it("maps creditUsagePercent to a single Weekly SuperGrok bar (not productUsage)", () => {
|
||||
const parsed = parseGrokCliBilling(
|
||||
{
|
||||
config: {
|
||||
currentPeriod: {
|
||||
type: "USAGE_PERIOD_TYPE_WEEKLY",
|
||||
start: "2026-07-17T12:42:26.494595+00:00",
|
||||
end: "2026-07-24T12:42:26.494595+00:00",
|
||||
},
|
||||
creditUsagePercent: 99.0,
|
||||
onDemandCap: { val: 0 },
|
||||
onDemandUsed: { val: 0 },
|
||||
productUsage: [
|
||||
{ product: "GrokBuild", usagePercent: 97.0 },
|
||||
{ product: "GrokImagine", usagePercent: 2.0 },
|
||||
],
|
||||
isUnifiedBillingUser: true,
|
||||
prepaidBalance: { val: 0 },
|
||||
billingPeriodStart: "2026-07-17T12:42:26.494595+00:00",
|
||||
billingPeriodEnd: "2026-07-24T12:42:26.494595+00:00",
|
||||
},
|
||||
},
|
||||
{ subscriptionTier: "XPremiumPlus", hasGrokCodeAccess: true },
|
||||
);
|
||||
// Single shared-pool bar from creditUsagePercent
|
||||
expect(parsed.quotas["Weekly SuperGrok"]).toMatchObject({
|
||||
used: 99,
|
||||
total: 100,
|
||||
remainingPercentage: 1,
|
||||
resetAt: "2026-07-24T12:42:26.494Z",
|
||||
unlimited: false,
|
||||
});
|
||||
// productUsage must NOT become independent quota bars
|
||||
expect(Object.keys(parsed.quotas)).toEqual(["Weekly SuperGrok"]);
|
||||
expect(parsed.exhausted).toBe(false);
|
||||
});
|
||||
|
||||
it("maps current monthly fields and snake-case subscription tier", () => {
|
||||
const parsed = parseGrokCliBilling({
|
||||
monthlyLimit: { val: 1000 },
|
||||
|
||||
@@ -0,0 +1,146 @@
|
||||
/**
|
||||
* Generic OAuth2 token refresh — config-driven profiles.
|
||||
*
|
||||
* Verifies refreshAccessToken() handles the 5 foldable providers
|
||||
* (qwen, iflow, github, kimi, claude) via a REFRESH_PROFILES table,
|
||||
* while preserving the legacy generic path for unknown providers.
|
||||
*/
|
||||
|
||||
import { describe, it, expect, vi, beforeEach, afterEach } from "vitest";
|
||||
|
||||
const originalFetch = global.fetch;
|
||||
|
||||
function mockFetchOnce(payload, { ok = true, status = 200 } = {}) {
|
||||
const fn = vi.fn().mockResolvedValue({
|
||||
ok,
|
||||
status,
|
||||
json: () => Promise.resolve(payload),
|
||||
text: () => Promise.resolve(JSON.stringify(payload)),
|
||||
});
|
||||
global.fetch = fn;
|
||||
return fn;
|
||||
}
|
||||
|
||||
describe("refreshAccessToken — config-driven profiles", () => {
|
||||
beforeEach(() => { vi.clearAllMocks(); vi.resetModules(); global.fetch = originalFetch; });
|
||||
afterEach(() => { global.fetch = originalFetch; });
|
||||
|
||||
it("qwen: form body + clientId, surfaces resource_url as providerSpecificData", async () => {
|
||||
const fm = mockFetchOnce({
|
||||
access_token: "qw-acc",
|
||||
refresh_token: "qw-refresh-rotated",
|
||||
expires_in: 7200,
|
||||
resource_url: "https://dashscope.aliyuncs.com",
|
||||
});
|
||||
const { refreshAccessToken } = await import("open-sse/services/tokenRefresh/providers.js");
|
||||
|
||||
const out = await refreshAccessToken("qwen", "qw-old-refresh", {}, console);
|
||||
|
||||
expect(out).toEqual({
|
||||
accessToken: "qw-acc",
|
||||
refreshToken: "qw-refresh-rotated",
|
||||
expiresIn: 7200,
|
||||
providerSpecificData: { resourceUrl: "https://dashscope.aliyuncs.com" },
|
||||
});
|
||||
const [url, init] = fm.mock.calls[0];
|
||||
expect(init.method).toBe("POST");
|
||||
expect(init.headers["Content-Type"]).toBe("application/x-www-form-urlencoded");
|
||||
const body = new URLSearchParams(init.body);
|
||||
expect(body.get("grant_type")).toBe("refresh_token");
|
||||
expect(body.get("refresh_token")).toBe("qw-old-refresh");
|
||||
expect(body.get("client_id")).toBeTruthy();
|
||||
});
|
||||
|
||||
it("iflow: Basic Auth header from clientId:clientSecret, form body keeps client_secret", async () => {
|
||||
const fm = mockFetchOnce({ access_token: "if-acc", refresh_token: "if-rot", expires_in: 3600 });
|
||||
const { refreshAccessToken } = await import("open-sse/services/tokenRefresh/providers.js");
|
||||
|
||||
await refreshAccessToken("iflow", "if-old", {}, console);
|
||||
|
||||
const [, init] = fm.mock.calls[0];
|
||||
expect(init.headers["Authorization"]).toMatch(/^Basic /);
|
||||
const body = new URLSearchParams(init.body);
|
||||
expect(body.get("client_id")).toBeTruthy();
|
||||
expect(body.get("client_secret")).toBeTruthy();
|
||||
});
|
||||
|
||||
it("github: omits client_secret when config has none", async () => {
|
||||
const fm = mockFetchOnce({ access_token: "gh-acc", expires_in: 28800 });
|
||||
const { refreshAccessToken } = await import("open-sse/services/tokenRefresh/providers.js");
|
||||
|
||||
const out = await refreshAccessToken("github", "gh-old", {}, console);
|
||||
|
||||
const body = new URLSearchParams(fm.mock.calls[0][1].body);
|
||||
expect(body.get("client_secret")).toBeNull();
|
||||
expect(out.accessToken).toBe("gh-acc");
|
||||
expect(out.refreshToken).toBe("gh-old");
|
||||
});
|
||||
|
||||
it("kimi: merges X-Msh-* headers from credentials.providerSpecificData.deviceId", async () => {
|
||||
const fm = mockFetchOnce({ access_token: "km-acc", expires_in: 86400 });
|
||||
const { refreshAccessToken } = await import("open-sse/services/tokenRefresh/providers.js");
|
||||
|
||||
await refreshAccessToken("kimi", "km-old", {
|
||||
providerSpecificData: { deviceId: "dev-xyz" },
|
||||
}, console);
|
||||
|
||||
const headers = fm.mock.calls[0][1].headers;
|
||||
// Kimi's buildKimiHeaders must contribute at least one X-Msh- header
|
||||
const mshKeys = Object.keys(headers).filter((k) => k.toLowerCase().startsWith("x-msh-"));
|
||||
expect(mshKeys.length).toBeGreaterThan(0);
|
||||
});
|
||||
|
||||
it("claude: JSON body, client_id only (no client_secret)", async () => {
|
||||
const fm = mockFetchOnce({ access_token: "cl-acc", refresh_token: "cl-rot", expires_in: 3600 });
|
||||
const { refreshAccessToken } = await import("open-sse/services/tokenRefresh/providers.js");
|
||||
|
||||
await refreshAccessToken("claude", "cl-old", {}, console);
|
||||
|
||||
const [, init] = fm.mock.calls[0];
|
||||
expect(init.headers["Content-Type"]).toBe("application/json");
|
||||
const parsed = JSON.parse(init.body);
|
||||
expect(parsed.grant_type).toBe("refresh_token");
|
||||
expect(parsed.client_id).toBeTruthy();
|
||||
expect(parsed).not.toHaveProperty("client_secret");
|
||||
});
|
||||
|
||||
it("returns null on non-ok response", async () => {
|
||||
mockFetchOnce({ error: "invalid_grant" }, { ok: false, status: 400 });
|
||||
const { refreshAccessToken } = await import("open-sse/services/tokenRefresh/providers.js");
|
||||
const out = await refreshAccessToken("qwen", "dead", {}, console);
|
||||
expect(out).toBeNull();
|
||||
});
|
||||
|
||||
it("returns null when refreshToken missing", async () => {
|
||||
const { refreshAccessToken } = await import("open-sse/services/tokenRefresh/providers.js");
|
||||
const out = await refreshAccessToken("qwen", "", {}, console);
|
||||
expect(out).toBeNull();
|
||||
});
|
||||
|
||||
it("dedupes concurrent calls with same refresh token (same dedupKey)", async () => {
|
||||
const fm = mockFetchOnce({ access_token: "dd-acc", expires_in: 3600 });
|
||||
const { refreshAccessToken } = await import("open-sse/services/tokenRefresh/providers.js");
|
||||
const creds = { providerSpecificData: { deviceId: "d" } };
|
||||
await Promise.all([
|
||||
refreshAccessToken("kimi", "dup-refresh", creds, console),
|
||||
refreshAccessToken("kimi", "dup-refresh", creds, console),
|
||||
]);
|
||||
expect(fm).toHaveBeenCalledTimes(1);
|
||||
});
|
||||
});
|
||||
|
||||
describe("refreshAccessToken — legacy generic path (no profile)", () => {
|
||||
beforeEach(() => { vi.clearAllMocks(); vi.resetModules(); global.fetch = originalFetch; });
|
||||
afterEach(() => { global.fetch = originalFetch; });
|
||||
|
||||
it("still works for an unprofiled provider via config.refreshUrl/clientId/clientSecret", async () => {
|
||||
const fm = mockFetchOnce({ access_token: "gen-acc", expires_in: 3600 });
|
||||
const { refreshAccessToken } = await import("open-sse/services/tokenRefresh/providers.js");
|
||||
|
||||
await refreshAccessToken("cline", "gen-old", {}, console);
|
||||
|
||||
const body = new URLSearchParams(fm.mock.calls[0][1].body);
|
||||
expect(body.get("grant_type")).toBe("refresh_token");
|
||||
expect(body.get("client_id")).toBeTruthy();
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,198 @@
|
||||
import { describe, it, expect } from "vitest";
|
||||
import {
|
||||
resolveWsModelId,
|
||||
buildGetChatMessageRequest,
|
||||
grpcWebFrame,
|
||||
decodeCompletionChunk,
|
||||
default as WindsurfExecutor,
|
||||
} from "open-sse/executors/windsurf.js";
|
||||
import { PROVIDERS } from "open-sse/config/providers.js";
|
||||
|
||||
// ─── Protobuf helpers for building expected wire bytes in tests ──────────────
|
||||
|
||||
function encodeVarint(value) {
|
||||
const bytes = [];
|
||||
let v = value >>> 0;
|
||||
while (v > 0x7f) { bytes.push((v & 0x7f) | 0x80); v >>>= 7; }
|
||||
bytes.push(v & 0x7f);
|
||||
return new Uint8Array(bytes);
|
||||
}
|
||||
function encodeLenField(fieldNum, payload) {
|
||||
const tag = encodeVarint((fieldNum << 3) | 2);
|
||||
const len = encodeVarint(payload.length);
|
||||
const out = new Uint8Array(tag.length + len.length + payload.length);
|
||||
out.set(tag, 0); out.set(len, tag.length); out.set(payload, tag.length + len.length);
|
||||
return out;
|
||||
}
|
||||
function encodeStringField(fieldNum, str) {
|
||||
return encodeLenField(fieldNum, new TextEncoder().encode(str));
|
||||
}
|
||||
|
||||
describe("windsurf MODEL_ALIAS_MAP", () => {
|
||||
it("maps SWE models to snake-case wire names", () => {
|
||||
expect(resolveWsModelId("swe-1.6-fast")).toBe("swe-1-6-fast");
|
||||
expect(resolveWsModelId("swe-1.5")).toBe("swe-1-5");
|
||||
});
|
||||
it("maps Claude 4.5 to MODEL_PRIVATE_* aliases", () => {
|
||||
expect(resolveWsModelId("claude-sonnet-4.5")).toBe("MODEL_PRIVATE_2");
|
||||
expect(resolveWsModelId("claude-opus-4.5")).toBe("MODEL_CLAUDE_4_5_OPUS");
|
||||
});
|
||||
it("applies default effort level for bare gpt-5.x ids", () => {
|
||||
expect(resolveWsModelId("gpt-5.5")).toBe("gpt-5-5-medium");
|
||||
expect(resolveWsModelId("gpt-5.4")).toBe("gpt-5-4-medium");
|
||||
});
|
||||
it("passes through unknown ids as-is", () => {
|
||||
expect(resolveWsModelId("custom-model")).toBe("custom-model");
|
||||
});
|
||||
});
|
||||
|
||||
describe("grpcWebFrame", () => {
|
||||
it("prepends a 5-byte header: 0x00 flag + big-endian length", () => {
|
||||
const payload = new Uint8Array([1, 2, 3, 4, 5]);
|
||||
const frame = grpcWebFrame(payload);
|
||||
expect(frame[0]).toBe(0x00);
|
||||
const view = new DataView(frame.buffer);
|
||||
expect(view.getUint32(1, false)).toBe(5); // big-endian length
|
||||
expect(Array.from(frame.slice(5))).toEqual([1, 2, 3, 4, 5]);
|
||||
});
|
||||
it("encodes empty payload as a 5-byte frame", () => {
|
||||
const frame = grpcWebFrame(new Uint8Array(0));
|
||||
expect(frame.length).toBe(5);
|
||||
expect(frame[0]).toBe(0x00);
|
||||
});
|
||||
});
|
||||
|
||||
describe("buildGetChatMessageRequest", () => {
|
||||
it("emits metadata (field 1), cascade_id (2), model (3), messages (4+)", () => {
|
||||
const payload = buildGetChatMessageRequest("sk-ws-test", "swe-1.6", [
|
||||
{ role: "user", content: "hello" },
|
||||
]);
|
||||
expect(payload.length).toBeGreaterThan(10);
|
||||
// First byte 0x0a = field 1, wire type 2 (length-delimited) → metadata present
|
||||
expect(payload[0]).toBe(0x0a);
|
||||
});
|
||||
|
||||
it("embeds the apiKey inside the metadata sub-message", () => {
|
||||
const payload = buildGetChatMessageRequest("sk-ws-secret", "gpt-5", []);
|
||||
// The metadata bytes are the first length-delimited field — should contain the key.
|
||||
const asString = new TextDecoder().decode(payload);
|
||||
expect(asString).toContain("sk-ws-secret");
|
||||
// And the IDE identification fields.
|
||||
expect(asString).toContain("windsurf");
|
||||
expect(asString).toContain("3.14.0");
|
||||
});
|
||||
|
||||
it("appends one field-4 message per chat message", () => {
|
||||
// Proper top-level protobuf field counter (byte 0x22 collides with content bytes).
|
||||
const countField = (buf, target) => {
|
||||
let offset = 0;
|
||||
let count = 0;
|
||||
while (offset < buf.length) {
|
||||
let result = 0, shift = 0;
|
||||
while (offset < buf.length) {
|
||||
const b = buf[offset++];
|
||||
result |= (b & 0x7f) << shift;
|
||||
if ((b & 0x80) === 0) break;
|
||||
shift += 7;
|
||||
}
|
||||
const fieldNum = result >>> 3;
|
||||
const wireType = result & 0x07;
|
||||
if (wireType === 2) {
|
||||
let len = 0, ls = 0;
|
||||
while (offset < buf.length) {
|
||||
const b = buf[offset++];
|
||||
len |= (b & 0x7f) << ls;
|
||||
if ((b & 0x80) === 0) break;
|
||||
ls += 7;
|
||||
}
|
||||
if (fieldNum === target) count++;
|
||||
offset += len;
|
||||
} else if (wireType === 0) {
|
||||
while (offset < buf.length) {
|
||||
const b = buf[offset++];
|
||||
if ((b & 0x80) === 0) break;
|
||||
}
|
||||
} else if (wireType === 1) {
|
||||
offset += 8;
|
||||
} else if (wireType === 5) {
|
||||
offset += 4;
|
||||
} else {
|
||||
break;
|
||||
}
|
||||
}
|
||||
return count;
|
||||
};
|
||||
const one = buildGetChatMessageRequest("k", "m", [{ role: "user", content: "a" }]);
|
||||
const two = buildGetChatMessageRequest("k", "m", [
|
||||
{ role: "user", content: "a" },
|
||||
{ role: "assistant", content: "b" },
|
||||
]);
|
||||
expect(countField(one, 4)).toBe(1);
|
||||
expect(countField(two, 4)).toBe(2);
|
||||
});
|
||||
});
|
||||
|
||||
describe("decodeCompletionChunk", () => {
|
||||
it("decodes a ContentChunk (field 1 → text)", () => {
|
||||
const chunk = encodeLenField(1, encodeStringField(1, "hello world"));
|
||||
const decoded = decodeCompletionChunk(chunk);
|
||||
expect(decoded).toEqual({ kind: "content", text: "hello world" });
|
||||
});
|
||||
|
||||
it("decodes an ErrorChunk (field 4 → message)", () => {
|
||||
const chunk = encodeLenField(4, encodeStringField(1, "quota exhausted"));
|
||||
const decoded = decodeCompletionChunk(chunk);
|
||||
expect(decoded).toEqual({ kind: "error", message: "quota exhausted" });
|
||||
});
|
||||
|
||||
it("decodes a DoneChunk (field 3 → UsageStats with prompt/completion tokens)", () => {
|
||||
// UsageStats: field 1 = prompt_tokens (varint), field 2 = completion_tokens (varint)
|
||||
const usage = new Uint8Array([...encodeVarint((1 << 3) | 0), ...encodeVarint(42), ...encodeVarint((2 << 3) | 0), ...encodeVarint(99)]);
|
||||
const doneChunk = encodeLenField(3, encodeLenField(1, usage));
|
||||
const decoded = decodeCompletionChunk(doneChunk);
|
||||
expect(decoded.kind).toBe("done");
|
||||
expect(decoded.promptTokens).toBe(42);
|
||||
expect(decoded.completionTokens).toBe(99);
|
||||
});
|
||||
|
||||
it("returns { kind: 'unknown' } for empty buffer", () => {
|
||||
expect(decodeCompletionChunk(new Uint8Array(0))).toEqual({ kind: "unknown" });
|
||||
});
|
||||
});
|
||||
|
||||
describe("WindsurfExecutor class", () => {
|
||||
it("constructor wires config from PROVIDERS.windsurf", () => {
|
||||
const ex = new WindsurfExecutor();
|
||||
expect(ex.provider).toBe("windsurf");
|
||||
expect(ex.config).toBeDefined();
|
||||
expect(ex.config.baseUrl).toContain("server.self-serve.windsurf.com");
|
||||
expect(typeof ex.execute).toBe("function");
|
||||
});
|
||||
|
||||
it("buildHeaders emits grpc-web+proto + Bearer token", () => {
|
||||
const ex = new WindsurfExecutor();
|
||||
const h = ex.buildHeaders({ accessToken: "sk-ws-abc" });
|
||||
expect(h["Content-Type"]).toBe("application/grpc-web+proto");
|
||||
expect(h.Accept).toBe("application/grpc-web+proto");
|
||||
expect(h["X-Grpc-Web"]).toBe("1");
|
||||
expect(h.Authorization).toBe("Bearer sk-ws-abc");
|
||||
expect(h["User-Agent"]).toMatch(/^windsurf\//);
|
||||
});
|
||||
|
||||
it("buildHeaders omits Authorization when no token", () => {
|
||||
const ex = new WindsurfExecutor();
|
||||
const h = ex.buildHeaders({});
|
||||
expect(h.Authorization).toBeUndefined();
|
||||
});
|
||||
|
||||
it("buildUrl returns the GetChatMessage endpoint", () => {
|
||||
const ex = new WindsurfExecutor();
|
||||
expect(ex.buildUrl()).toBe("https://server.self-serve.windsurf.com/exa.language_server_pb.LanguageServerService/GetChatMessage");
|
||||
});
|
||||
|
||||
it("PROVIDERS.windsurf baseUrl is the chat endpoint (registry in sync)", () => {
|
||||
expect(PROVIDERS.windsurf.baseUrl).toBe(
|
||||
"https://server.self-serve.windsurf.com/exa.language_server_pb.LanguageServerService/GetChatMessage"
|
||||
);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user