Replace the previous implementation with one that registers the Provider API catalog through pi's own provider layer instead of shipping a custom transport, cache file, and hand-maintained pricing table. - models: derive the catalog from the published command-code CLI package (context windows, reasoning efforts, image input, output limits, rates) and keep it as the offline baseline; scripts/sync-catalog.mjs regenerates it and supports --check - refresh: use refreshModels plus context.publish so pi persists the live /provider/v1/models listing in models-store.json and restores it offline - auth: /login browser transfer through a localhost callback server with a pasted-key fallback; $COMMAND_CODE_API_KEY, --api-key and auth.json keep working - streaming: pi's native openai-completions and anthropic-messages adapters; the generate-transport fallback and Oh My Pi branches are gone - keep the context-overflow rewrite that enables pi's compaction retry and the /commandcode-quota command - tests: 51 cases under tests/<module>/ covering models, catalog sync, auth, the callback server, overflow handling, quota, and the extension factory Verified against the live API: chat, tool round trip, image input and --thinking max on deepseek/deepseek-v4.1-flash, quota output, and catalog persistence in an interactive session.
79 lines
2.6 KiB
TypeScript
79 lines
2.6 KiB
TypeScript
import assert from "node:assert/strict"
|
|
import { test } from "node:test"
|
|
|
|
import { startAuthServer } from "../../src/auth-server.ts"
|
|
|
|
const STATE = "state-token-123"
|
|
|
|
function callbackUrl(port: number): string {
|
|
return `http://127.0.0.1:${port}/callback`
|
|
}
|
|
|
|
test("callback POST completes the login and closes the server", async () => {
|
|
const server = await startAuthServer({ expectedState: STATE, startPort: 0, portRange: 0 })
|
|
|
|
const response = await fetch(callbackUrl(server.port), {
|
|
method: "POST",
|
|
headers: { "content-type": "application/json", origin: "https://commandcode.ai" },
|
|
body: JSON.stringify({ apiKey: "user_abc", state: STATE, userId: "u1", userName: "tester", keyName: "cli" }),
|
|
})
|
|
|
|
assert.equal(response.status, 200)
|
|
assert.equal(response.headers.get("access-control-allow-origin"), "https://commandcode.ai")
|
|
assert.deepEqual(await server.waitForCallback, { apiKey: "user_abc", state: STATE })
|
|
})
|
|
|
|
test("browser preflight is answered for the Command Code origin", async () => {
|
|
const server = await startAuthServer({ expectedState: STATE, startPort: 0, portRange: 0 })
|
|
|
|
try {
|
|
const response = await fetch(callbackUrl(server.port), {
|
|
method: "OPTIONS",
|
|
headers: {
|
|
origin: "https://commandcode.ai",
|
|
"access-control-request-headers": "content-type",
|
|
},
|
|
})
|
|
|
|
assert.equal(response.status, 204)
|
|
assert.equal(response.headers.get("access-control-allow-private-network"), "true")
|
|
assert.equal(response.headers.get("access-control-allow-headers"), "content-type")
|
|
} finally {
|
|
server.close()
|
|
}
|
|
})
|
|
|
|
test("a mismatched state token is rejected without completing the login", async () => {
|
|
const server = await startAuthServer({ expectedState: STATE, startPort: 0, portRange: 0 })
|
|
let settled = false
|
|
void server.waitForCallback.then(() => {
|
|
settled = true
|
|
})
|
|
|
|
try {
|
|
const response = await fetch(callbackUrl(server.port), {
|
|
method: "POST",
|
|
headers: { "content-type": "application/json" },
|
|
body: JSON.stringify({ apiKey: "user_abc", state: "other-state" }),
|
|
})
|
|
|
|
assert.equal(response.status, 403)
|
|
assert.equal(settled, false)
|
|
} finally {
|
|
server.close()
|
|
}
|
|
})
|
|
|
|
test("an access_denied payload fails the wait instead of hanging", async () => {
|
|
const server = await startAuthServer({ expectedState: STATE, startPort: 0, portRange: 0 })
|
|
|
|
const rejection = assert.rejects(server.waitForCallback, /User cancelled/)
|
|
await fetch(callbackUrl(server.port), {
|
|
method: "POST",
|
|
headers: { "content-type": "application/json" },
|
|
body: JSON.stringify({ error: "access_denied", error_description: "User cancelled" }),
|
|
})
|
|
|
|
await rejection
|
|
})
|