import { describe, it, afterEach, mock } from 'node:test'; import assert from 'node:assert/strict'; import axios from 'axios'; import { checkRequiredEnv, verifyGiteaToken, verifyCommentToken, verifyLLM, fetchLLMModels, runPreflight } from '../preflight.js'; const LLM_ENV_KEYS = [ 'CLI_PROXY_API', 'CLI_PROXY_API_KEY', 'CLI_PROXY_API_MODEL', 'INPUT_CLI_PROXY_API', 'INPUT_CLI_PROXY_API_KEY', 'MODEL', 'OPENCODE_MODEL', 'INPUT_MODEL', ]; function clearLLMEnv() { for (const k of LLM_ENV_KEYS) delete process.env[k]; } afterEach(() => { mock.restoreAll(); clearLLMEnv(); }); describe('checkRequiredEnv', () => { it('reports all missing values when nothing is provided', () => { const result = checkRequiredEnv({ token: '', repo: '', pr: '' }); assert.equal(result.ok, false); assert.deepEqual(result.missing, ['GITEA_TOKEN', 'GITEA_REPOSITORY', 'PR_NUMBER', 'CLI_PROXY_API']); }); it('reports only the missing ones', () => { process.env.CLI_PROXY_API = 'https://proxy.example'; const result = checkRequiredEnv({ token: 't', repo: '', pr: '5' }); assert.equal(result.ok, false); assert.deepEqual(result.missing, ['GITEA_REPOSITORY']); }); it('ok when all required values are provided', () => { process.env.CLI_PROXY_API = 'https://proxy.example'; const result = checkRequiredEnv({ token: 't', repo: 'owner/repo', pr: '5' }); assert.equal(result.ok, true); assert.deepEqual(result.missing, []); }); }); describe('verifyGiteaToken', () => { it('ok when repo endpoint returns successfully', async () => { let capturedUrl, capturedOpts; mock.method(axios, 'get', async (url, opts) => { capturedUrl = url; capturedOpts = opts; return { data: { full_name: 'owner/repo' } }; }); const result = await verifyGiteaToken('tok', 'owner/repo'); assert.equal(result.ok, true); assert.ok(capturedUrl.includes('/api/v1/repos/owner/repo')); assert.equal(capturedOpts.headers['Authorization'], 'token tok'); }); it('fails with HTTP status when token is invalid', async () => { mock.method(axios, 'get', async () => { const e = new Error('Unauthorized'); e.response = { status: 401 }; throw e; }); const result = await verifyGiteaToken('bad', 'owner/repo'); assert.equal(result.ok, false); assert.match(result.error, /HTTP 401/); }); }); describe('verifyCommentToken', () => { it('skips when no comment token is provided', async () => { const result = await verifyCommentToken(''); assert.deepEqual(result, { ok: true, skipped: true }); }); it('ok when /user returns successfully', async () => { let capturedUrl, capturedOpts; mock.method(axios, 'get', async (url, opts) => { capturedUrl = url; capturedOpts = opts; return { data: { login: 'bot' } }; }); const result = await verifyCommentToken('ctok'); assert.equal(result.ok, true); assert.ok(capturedUrl.endsWith('/api/v1/user')); assert.equal(capturedOpts.headers['Authorization'], 'token ctok'); }); it('fails when comment token is invalid', async () => { mock.method(axios, 'get', async () => { const e = new Error('Unauthorized'); e.response = { status: 401 }; throw e; }); const result = await verifyCommentToken('bad'); assert.equal(result.ok, false); assert.match(result.error, /HTTP 401/); }); }); describe('fetchLLMModels', () => { it('returns the model ids on HTTP 200', async () => { let capturedUrl, capturedHeaders; const result = await fetchLLMModels({ baseURL: 'https://proxy.example/', apiKey: 'tok', fetchImpl: async (url, opts) => { capturedUrl = url; capturedHeaders = opts.headers; return { status: 200, ok: true, json: async () => ({ data: [{ id: 'gpt-5.5' }, { slug: 'gpt-5.4-mini' }, 'custom-model'] }) }; }, }); assert.deepEqual(result, { ok: true, slugs: ['gpt-5.5', 'gpt-5.4-mini', 'custom-model'] }); assert.equal(capturedUrl, 'https://proxy.example/v1/models'); assert.equal(capturedHeaders.Authorization, 'Bearer tok'); }); it('reports an auth failure on HTTP 401', async () => { const result = await fetchLLMModels({ baseURL: 'https://proxy.example', apiKey: 'revoked', fetchImpl: async () => ({ status: 401, ok: false, json: async () => ({}) }), }); assert.equal(result.ok, false); assert.match(result.error, /HTTP 401/); assert.match(result.error, /CLIProxyAPI/); }); it('fails when the base URL is missing', async () => { const result = await fetchLLMModels({ baseURL: '', apiKey: 'tok', fetchImpl: async () => ({ status: 200, ok: true, json: async () => ({}) }) }); assert.equal(result.ok, false); assert.match(result.error, /CLI_PROXY_API/); }); }); describe('verifyLLM', () => { it('fails when no CLIProxyAPI is configured', async () => { clearLLMEnv(); const result = await verifyLLM(); assert.equal(result.ok, false); assert.match(result.error, /CLIProxyAPI/); }); it('passes when the configured model is in the proxy model list', async () => { clearLLMEnv(); process.env.CLI_PROXY_API = 'https://proxy.example'; process.env.CLI_PROXY_API_KEY = 'secret'; process.env.MODEL = 'gpt-5.4-mini'; const result = await verifyLLM({ fetchLLMModelsFn: async () => ({ ok: true, slugs: ['gpt-5.5', 'gpt-5.4-mini'] }), }); assert.equal(result.ok, true); assert.equal(result.provider, 'cliproxyapi'); assert.equal(result.command, null); assert.equal(result.model, 'gpt-5.4-mini'); assert.deepEqual(result.models, ['gpt-5.5', 'gpt-5.4-mini']); }); it('passes when no model is specified and the proxy is reachable', async () => { clearLLMEnv(); process.env.CLI_PROXY_API = 'https://proxy.example'; process.env.CLI_PROXY_API_KEY = 'secret'; const result = await verifyLLM({ fetchLLMModelsFn: async () => ({ ok: true, slugs: ['gpt-5.5', 'gpt-5.4-mini'] }), }); assert.equal(result.ok, true); assert.equal(result.provider, 'cliproxyapi'); assert.equal(result.command, null); assert.equal(result.model, null); assert.deepEqual(result.models, ['gpt-5.5', 'gpt-5.4-mini']); }); it('fails when proxy auth is invalid', async () => { clearLLMEnv(); process.env.CLI_PROXY_API = 'https://proxy.example'; process.env.MODEL = 'gpt-5.4-mini'; const result = await verifyLLM({ fetchLLMModelsFn: async () => ({ ok: false, error: 'CLIProxyAPI 認證失效(HTTP 401)——API key 已被撤銷或過期,請更新 CLI_PROXY_API_KEY secret' }), }); assert.equal(result.ok, false); assert.equal(result.provider, 'cliproxyapi'); assert.match(result.error, /HTTP 401/); assert.match(result.error, /CLI_PROXY_API_KEY/); }); it('fails when the configured model is not in the proxy available list', async () => { clearLLMEnv(); process.env.CLI_PROXY_API = 'https://proxy.example'; process.env.MODEL = 'gpt-9-imaginary'; const result = await verifyLLM({ fetchLLMModelsFn: async () => ({ ok: true, slugs: ['gpt-5.5', 'gpt-5.4-mini'] }), }); assert.equal(result.ok, false); assert.match(result.error, /不在 CLIProxyAPI 可用清單/); assert.match(result.error, /gpt-9-imaginary/); }); it('fails when the configured model name is invalid', async () => { clearLLMEnv(); process.env.CLI_PROXY_API = 'https://proxy.example'; process.env.MODEL = 'gpt-5.5; rm -rf /'; const result = await verifyLLM({ fetchLLMModelsFn: async () => ({ ok: true, slugs: ['gpt-5.5'] }), }); assert.equal(result.ok, false); assert.equal(result.provider, 'cliproxyapi'); assert.match(result.error, /無效的 model 參數/); }); }); describe('runPreflight', () => { function makeDeps(overrides = {}) { return { checkEnv: () => ({ ok: true, missing: [] }), verifyToken: async () => ({ ok: true }), verifyComment: async () => ({ ok: true }), verifyRemote: () => ({ ok: true }), verifyLLMFn: async () => ({ ok: true, provider: 'cliproxyapi', command: null, model: 'gpt-5.5', models: ['gpt-5.5'] }), ...overrides, }; } it('returns false and stops early when required env is missing', async () => { const result = await runPreflight(); assert.equal(result, false); }); it('returns true when every verification step succeeds', async () => { process.env.CLI_PROXY_API = 'https://proxy.example'; const result = await runPreflight('/ws', makeDeps()); assert.equal(result, true); }); it('returns true when the comment token check is skipped', async () => { process.env.CLI_PROXY_API = 'https://proxy.example'; const result = await runPreflight('/ws', makeDeps({ verifyComment: async () => ({ ok: true, skipped: true }), })); assert.equal(result, true); }); it('returns false when the Gitea token check fails', async () => { process.env.CLI_PROXY_API = 'https://proxy.example'; let remoteCalled = false; const result = await runPreflight('/ws', makeDeps({ verifyToken: async () => ({ ok: false, error: 'HTTP 401' }), verifyRemote: () => { remoteCalled = true; return { ok: true }; }, })); assert.equal(result, false); assert.equal(remoteCalled, false, 'should stop before later checks'); }); it('returns false when the comment token check fails', async () => { process.env.CLI_PROXY_API = 'https://proxy.example'; const result = await runPreflight('/ws', makeDeps({ verifyComment: async () => ({ ok: false, error: 'HTTP 401' }), })); assert.equal(result, false); }); it('returns false when git remote access fails', async () => { process.env.CLI_PROXY_API = 'https://proxy.example'; let llmCalled = false; const result = await runPreflight('/ws', makeDeps({ verifyRemote: () => ({ ok: false, error: 'auth failed' }), verifyLLMFn: async () => { llmCalled = true; return { ok: true }; }, })); assert.equal(result, false); assert.equal(llmCalled, false, 'should stop before the LLM check'); }); it('returns false when LLM verification fails', async () => { process.env.CLI_PROXY_API = 'https://proxy.example'; const result = await runPreflight('/ws', makeDeps({ verifyLLMFn: async () => ({ ok: false, error: 'CLIProxyAPI 驗證失敗' }), })); assert.equal(result, false); }); it('passes the workspace through to the remote-access check', async () => { process.env.CLI_PROXY_API = 'https://proxy.example'; let captured; await runPreflight('/custom/ws', makeDeps({ verifyRemote: (ws) => { captured = ws; return { ok: true }; }, })); assert.equal(captured, '/custom/ws'); }); });