Files
adolf/extensions/google/oauth.http.test.ts
alvis bedb527145
Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Vendor OpenClaw source as Adolf fork baseline
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11),
free to diverge. Tree copied sans upstream .git; upstream remote added for
future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19.
Preserves docs/ARCHITECTURE.md.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
2026-07-05 09:36:54 +00:00

173 lines
6.3 KiB
TypeScript
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
// Google tests cover oauth.http body-byte-cap for the Gemini CLI OAuth
// token-exchange/identity calls.
import http from "node:http";
import type { AddressInfo } from "node:net";
import { readResponseWithLimit } from "openclaw/plugin-sdk/response-limit-runtime";
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
import { TOKEN_URL } from "./oauth.shared.js";
const fetchWithSsrFGuardMock = vi.fn();
const releaseMock = vi.fn(async () => undefined);
vi.mock("openclaw/plugin-sdk/ssrf-runtime", async () => {
const actual = await vi.importActual<typeof import("openclaw/plugin-sdk/ssrf-runtime")>(
"openclaw/plugin-sdk/ssrf-runtime",
);
return {
...actual,
fetchWithSsrFGuard: (params: unknown) => fetchWithSsrFGuardMock(params),
};
});
const { fetchWithTimeout } = await import("./oauth.http.js");
describe("oauth.http fetchWithTimeout body byte cap", () => {
beforeEach(() => {
fetchWithSsrFGuardMock.mockReset();
releaseMock.mockClear();
});
afterEach(() => {
vi.restoreAllMocks();
});
it("caps oversized response body at 16 MiB with labeled overflow error", async () => {
// Build a Response with a body that exceeds the 16 MiB cap.
// 1 MiB chunks × 18 chunks = 18 MiB queued; the bounded reader reads
// up to the 16 MiB cap (16 chunks = 16777216 bytes) and one extra
// chunk before throwing on overflow, so the labeled `size` is the
// cap plus the trailing chunk: 16777216 + 1048576 = 17825792 bytes.
const CHUNK = 1024 * 1024;
let sent = 0;
const body = new ReadableStream({
pull(controller) {
if (sent < 18) {
controller.enqueue(new Uint8Array(CHUNK));
sent++;
} else {
controller.close();
}
},
});
fetchWithSsrFGuardMock.mockResolvedValue({
response: new Response(body, {
status: 200,
headers: { "content-type": "application/json" },
}),
finalUrl: TOKEN_URL,
release: releaseMock,
});
await expect(fetchWithTimeout(TOKEN_URL, { method: "POST" })).rejects.toThrow(
/google HTTP fetch: body exceeds 16777216 bytes \(got 17825792\)/,
);
expect(releaseMock).toHaveBeenCalledOnce();
});
it("returns a Response for normal-size bodies", async () => {
fetchWithSsrFGuardMock.mockResolvedValue({
response: new Response('{"access_token":"abc","expires_in":3600}', {
status: 200,
headers: { "content-type": "application/json" },
}),
finalUrl: TOKEN_URL,
release: releaseMock,
});
const res = await fetchWithTimeout(TOKEN_URL, { method: "POST" });
expect(res.status).toBe(200);
expect(await res.json()).toEqual({ access_token: "abc", expires_in: 3600 });
expect(releaseMock).toHaveBeenCalledOnce();
});
});
// Real-wire loopback proof. These tests bypass `fetchWithSsrFGuard` (which
// blocks 127.0.0.1 by design) and exercise `readResponseWithLimit` directly
// against a real `http.createServer` listener — the same helper that
// `fetchWithTimeout` calls inside its try/finally block. Captured vitest
// output for these two tests is the ClawSweeper "real behavior proof" required
// before merge.
describe("oauth.http bounded-read real wire proof (loopback http.createServer)", () => {
it("caps an oversized body streamed chunked over real wire", async () => {
const CHUNK = 1024 * 1024;
const MAX = 16 * 1024 * 1024;
const TOTAL = 18 * 1024 * 1024;
const server = http.createServer((req, res) => {
res.writeHead(200, { "content-type": "application/octet-stream" });
let sent = 0;
const tick = setInterval(() => {
if (sent < 18) {
res.write(Buffer.alloc(CHUNK));
sent++;
} else {
clearInterval(tick);
res.end();
}
}, 1);
});
await new Promise<void>((resolve, reject) => {
server.once("error", reject);
server.listen(0, "127.0.0.1", () => resolve());
});
const port = (server.address() as AddressInfo).port;
let captured: Error | undefined;
try {
const response = await fetch(`http://127.0.0.1:${port}/`);
// Wire framing merges TCP packets, so the exact reported size varies by
// runtime. The stable invariant is that the cap fires after MAX.
try {
await readResponseWithLimit(response, MAX, {
onOverflow: ({ size, maxBytes }) =>
new Error(`real wire: body exceeds ${maxBytes} bytes (got ${size})`),
});
} catch (err) {
captured = err as Error;
}
expect(captured).toBeInstanceOf(Error);
const match = captured!.message.match(/real wire: body exceeds \d+ bytes \(got (\d+)\)/);
expect(match).not.toBeNull();
const got = Number(match![1]);
expect(got).toBeGreaterThan(MAX);
// Print to vitest stdout for PR-body real behavior proof capture.
console.log(
`[oauth.http loopback proof] oversized path: cap=${MAX} reported=${got} server_total=${TOTAL}`,
);
} finally {
await new Promise<void>((resolve) => {
server.close(() => resolve());
});
}
});
it("returns a Buffer for normal-size responses on real wire", async () => {
const bodyText = '{"access_token":"loopback","expires_in":3600}';
const server = http.createServer((req, res) => {
res.writeHead(200, { "content-type": "application/json" });
res.end(bodyText);
});
await new Promise<void>((resolve, reject) => {
server.once("error", reject);
server.listen(0, "127.0.0.1", () => resolve());
});
const port = (server.address() as AddressInfo).port;
try {
const response = await fetch(`http://127.0.0.1:${port}/`);
const body = await readResponseWithLimit(response, 16 * 1024 * 1024, {
onOverflow: ({ size, maxBytes }) =>
new Error(`real wire: body exceeds ${maxBytes} bytes (got ${size})`),
});
expect(body.byteLength).toBe(Buffer.byteLength(bodyText, "utf8"));
expect(new TextDecoder("utf-8").decode(body)).toBe(bodyText);
console.log(
`[oauth.http loopback proof] normal path: cap=16777216 returned=${body.byteLength} body=${JSON.stringify(new TextDecoder("utf-8").decode(body))}`,
);
} finally {
await new Promise<void>((resolve) => {
server.close(() => resolve());
});
}
});
});