Download src/gateway/server/plugin-route-runtime-scopes.test.ts from SaylorTwift/openclaw: direct link, hf CLI and curl.
- Browser
- Download file 3.17 kB
-
https://huggingface.co/SaylorTwift/openclaw/resolve/main/src/gateway/server/plugin-route-runtime-scopes.test.ts
- Command line
-
hf download hf://SaylorTwift/openclaw/src/gateway/server/plugin-route-runtime-scopes.test.ts
-
curl -L -o plugin-route-runtime-scopes.test.ts https://huggingface.co/SaylorTwift/openclaw/resolve/main/src/gateway/server/plugin-route-runtime-scopes.test.ts
3.17 kB
| /** | |
| * Plugin route runtime-scope regression tests for trusted-proxy headers. | |
| */ | |
| import type { IncomingMessage } from "node:http"; | |
| import { describe, expect, it } from "vitest"; | |
| import { createExpectedBroadOperatorScopes } from "../scope-expectations.test-support.js"; | |
| import { resolvePluginRouteRuntimeOperatorScopes } from "./plugin-route-runtime-scopes.js"; | |
| function createReq(headers: Record<string, string> = {}): IncomingMessage { | |
| return { headers } as IncomingMessage; | |
| } | |
| describe("resolvePluginRouteRuntimeOperatorScopes", () => { | |
| it("preserves declared trusted-proxy scopes when the header is present", () => { | |
| expect( | |
| resolvePluginRouteRuntimeOperatorScopes(createReq({ "x-openclaw-scopes": "operator.read" }), { | |
| authMethod: "trusted-proxy", | |
| trustDeclaredOperatorScopes: true, | |
| }), | |
| ).toEqual(["operator.read"]); | |
| }); | |
| it("keeps trusted-proxy plugin routes on write scope when the header is absent", () => { | |
| expect( | |
| resolvePluginRouteRuntimeOperatorScopes(createReq(), { | |
| authMethod: "trusted-proxy", | |
| trustDeclaredOperatorScopes: true, | |
| }), | |
| ).toEqual(["operator.write"]); | |
| }); | |
| it("keeps shared-secret bearer plugin routes on write scope even when scopes are declared", () => { | |
| expect( | |
| resolvePluginRouteRuntimeOperatorScopes( | |
| createReq({ | |
| authorization: "Bearer secret", | |
| "x-openclaw-scopes": "operator.admin,operator.write", | |
| }), | |
| { authMethod: "token", trustDeclaredOperatorScopes: false }, | |
| ), | |
| ).toEqual(["operator.write"]); | |
| }); | |
| it("does not trust caller-declared admin scopes on plugin routes for mode=none requests", () => { | |
| expect( | |
| resolvePluginRouteRuntimeOperatorScopes( | |
| createReq({ "x-openclaw-scopes": "operator.admin,operator.write" }), | |
| { authMethod: "none", trustDeclaredOperatorScopes: true }, | |
| ), | |
| ).toEqual(["operator.write"]); | |
| }); | |
| it("restores trusted default operator scopes for shared-secret bearer routes opting into trusted-operator surface", () => { | |
| expect( | |
| resolvePluginRouteRuntimeOperatorScopes( | |
| createReq({ | |
| authorization: "Bearer secret", | |
| }), | |
| { authMethod: "token", trustDeclaredOperatorScopes: false }, | |
| "trusted-operator", | |
| ), | |
| ).toEqual(createExpectedBroadOperatorScopes()); | |
| }); | |
| it("restores trusted default operator scopes for trusted-proxy routes opting into trusted-operator when scopes header is absent", () => { | |
| expect( | |
| resolvePluginRouteRuntimeOperatorScopes( | |
| createReq(), | |
| { authMethod: "trusted-proxy", trustDeclaredOperatorScopes: true }, | |
| "trusted-operator", | |
| ), | |
| ).toEqual(createExpectedBroadOperatorScopes()); | |
| }); | |
| it("preserves trusted-proxy declared scopes for routes opting into trusted-operator surface", () => { | |
| expect( | |
| resolvePluginRouteRuntimeOperatorScopes( | |
| createReq({ "x-openclaw-scopes": "operator.admin,operator.write" }), | |
| { authMethod: "trusted-proxy", trustDeclaredOperatorScopes: true }, | |
| "trusted-operator", | |
| ), | |
| ).toEqual(["operator.admin", "operator.write"]); | |
| }); | |
| }); | |