Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
179 lines
5.5 KiB
TypeScript
179 lines
5.5 KiB
TypeScript
// Chutes tests cover oauth plugin behavior.
|
|
import { describe, expect, it, vi } from "vitest";
|
|
import { loginChutes } from "./oauth.js";
|
|
|
|
function boundedErrorResponse(
|
|
body: string,
|
|
status = 500,
|
|
): {
|
|
response: Response;
|
|
cancel: ReturnType<typeof vi.fn>;
|
|
releaseLock: ReturnType<typeof vi.fn>;
|
|
text: ReturnType<typeof vi.fn>;
|
|
} {
|
|
const encoded = new TextEncoder().encode(body);
|
|
let read = false;
|
|
const cancel = vi.fn(async () => undefined);
|
|
const releaseLock = vi.fn();
|
|
const text = vi.fn(async () => {
|
|
throw new Error("response.text() should not be called");
|
|
});
|
|
const response = {
|
|
ok: false,
|
|
status,
|
|
headers: new Headers(),
|
|
body: {
|
|
getReader: () => ({
|
|
read: async () => {
|
|
if (read) {
|
|
return { done: true, value: undefined };
|
|
}
|
|
read = true;
|
|
return { done: false, value: encoded };
|
|
},
|
|
cancel,
|
|
releaseLock,
|
|
}),
|
|
},
|
|
text,
|
|
} as unknown as Response;
|
|
|
|
return { response, cancel, releaseLock, text };
|
|
}
|
|
|
|
describe("chutes plugin OAuth", () => {
|
|
it("rejects unsafe token lifetimes before storing credentials", async () => {
|
|
const fetchFn = vi.fn(async (input: RequestInfo | URL) => {
|
|
const url =
|
|
typeof input === "string" ? input : input instanceof URL ? input.toString() : input.url;
|
|
if (url === "https://api.chutes.ai/idp/token") {
|
|
return new Response(
|
|
'{"access_token":"at_unsafe","refresh_token":"rt_unsafe","expires_in":1e309}',
|
|
{ status: 200, headers: { "Content-Type": "application/json" } },
|
|
);
|
|
}
|
|
return new Response("not found", { status: 404 });
|
|
});
|
|
|
|
await expect(
|
|
loginChutes({
|
|
app: {
|
|
clientId: "cid_test",
|
|
redirectUri: "http://127.0.0.1:1456/oauth-callback",
|
|
scopes: ["openid"],
|
|
},
|
|
manual: true,
|
|
createState: () => "state_test",
|
|
onAuth: vi.fn(async () => {}),
|
|
onPrompt: vi.fn(
|
|
async () => "http://127.0.0.1:1456/oauth-callback?code=code_test&state=state_test",
|
|
),
|
|
fetchFn,
|
|
}),
|
|
).rejects.toThrow("Chutes token exchange returned invalid expires_in");
|
|
});
|
|
|
|
it("bounds token exchange error bodies without requiring response.text()", async () => {
|
|
const errorResponse = boundedErrorResponse(
|
|
`${"chutes token unavailable ".repeat(1024)}tail-marker`,
|
|
502,
|
|
);
|
|
const fetchFn = vi.fn(async (input: RequestInfo | URL) => {
|
|
const url =
|
|
typeof input === "string" ? input : input instanceof URL ? input.toString() : input.url;
|
|
if (url === "https://api.chutes.ai/idp/token") {
|
|
return errorResponse.response;
|
|
}
|
|
return new Response("not found", { status: 404 });
|
|
});
|
|
|
|
let error: unknown;
|
|
try {
|
|
await loginChutes({
|
|
app: {
|
|
clientId: "cid_test",
|
|
redirectUri: "http://127.0.0.1:1456/oauth-callback",
|
|
scopes: ["openid"],
|
|
},
|
|
manual: true,
|
|
createState: () => "state_test",
|
|
onAuth: vi.fn(async () => {}),
|
|
onPrompt: vi.fn(
|
|
async () => "http://127.0.0.1:1456/oauth-callback?code=code_test&state=state_test",
|
|
),
|
|
fetchFn,
|
|
});
|
|
} catch (caught) {
|
|
error = caught;
|
|
}
|
|
|
|
expect(error).toBeInstanceOf(Error);
|
|
const message = (error as Error).message;
|
|
expect(message).toContain("Chutes token exchange failed: chutes token unavailable");
|
|
expect(message).not.toContain("tail-marker");
|
|
expect(errorResponse.text).not.toHaveBeenCalled();
|
|
expect(errorResponse.cancel).toHaveBeenCalledTimes(1);
|
|
expect(errorResponse.releaseLock).toHaveBeenCalledTimes(1);
|
|
});
|
|
|
|
it("cancels oversized token exchange JSON body via the 16 MiB provider cap", async () => {
|
|
const ONE_MIB = 1024 * 1024;
|
|
const TOTAL_CHUNKS = 32;
|
|
const chunk = new Uint8Array(ONE_MIB);
|
|
|
|
let bytesPulled = 0;
|
|
let canceled = false;
|
|
const oversizedTokenJson = new Response(
|
|
new ReadableStream<Uint8Array>({
|
|
pull(controller) {
|
|
if (bytesPulled >= TOTAL_CHUNKS * ONE_MIB) {
|
|
controller.close();
|
|
return;
|
|
}
|
|
bytesPulled += chunk.length;
|
|
controller.enqueue(chunk);
|
|
},
|
|
cancel() {
|
|
canceled = true;
|
|
},
|
|
}),
|
|
{ status: 200, headers: { "Content-Type": "application/json" } },
|
|
);
|
|
|
|
const fetchFn = vi.fn(async (input: RequestInfo | URL) => {
|
|
const url =
|
|
typeof input === "string" ? input : input instanceof URL ? input.toString() : input.url;
|
|
if (url === "https://api.chutes.ai/idp/userinfo") {
|
|
return new Response(JSON.stringify({ login: "test", name: "Test" }), {
|
|
status: 200,
|
|
headers: { "Content-Type": "application/json" },
|
|
});
|
|
}
|
|
if (url === "https://api.chutes.ai/idp/token") {
|
|
return oversizedTokenJson;
|
|
}
|
|
return new Response("not found", { status: 404 });
|
|
});
|
|
|
|
await expect(
|
|
loginChutes({
|
|
app: {
|
|
clientId: "cid_test",
|
|
redirectUri: "http://127.0.0.1:1456/oauth-callback",
|
|
scopes: ["openid"],
|
|
},
|
|
manual: true,
|
|
createState: () => "state_test",
|
|
onAuth: vi.fn(async () => {}),
|
|
onPrompt: vi.fn(
|
|
async () => "http://127.0.0.1:1456/oauth-callback?code=code_test&state=state_test",
|
|
),
|
|
fetchFn,
|
|
}),
|
|
).rejects.toThrow(/Chutes token exchange: JSON response exceeds 16777216 bytes/);
|
|
|
|
expect(canceled).toBe(true);
|
|
expect(bytesPulled).toBeLessThan(TOTAL_CHUNKS * ONE_MIB);
|
|
});
|
|
});
|