Files
next-ai-draw-io/tests/unit/edgeone-function.test.ts
T
dayuan.jiang d5f31cb253 fix(server): use the keys the user sent, and more review fixes
Found by the second PR review:
- With AWS_BEARER_TOKEN_BEDROCK set on the server, a request with the
  user's AWS keys ran on the server's token: the Bedrock SDK prefers it.
  Checked with Bedrock: invalid user keys used to get an answer.
- An OpenAI key with the official URL filled in (the settings form does
  that) went to the Responses API. Back to main's rule: a configured base
  URL uses Chat Completions.
- A user's Ollama key went to the server's OLLAMA_BASE_URL, for chat and
  for the model list. Like every other provider, it goes to the user's
  base URL or Ollama Cloud.
- The server's keyless Ollama and EdgeOne were not counted in the quota.
- AI_MODEL models on the server's keys ran on any provider with a server
  key, not only on AI_PROVIDER.
- A user's Azure key without a base URL used the server's resource name.
- The admin panel's Test button failed whenever access codes were set.
- DeepSeek's errors in the stream (plain text) were shown as they were,
  without a hint and also on the server's keys. Bedrock's throttling in
  the stream was not recognised as a rate limit.
- The EdgeOne function accepted text/plain; x=application/json, which
  other sites can send without a CORS preflight.
- Desktop app: a launch that found the old port taken for a moment (the
  previous version still quitting after an update) remembered the new
  port for good. The new port is kept only when Windows reserves the old
  one. A failed read of the presets file moved it aside as corrupt, and a
  save could then replace the presets. Switching presets on the same port
  now reloads the page. The dev launcher no longer misses a preset change
  made before or during a restart.
2026-10-05 10:52:37 +09:00

63 lines
2.2 KiB
TypeScript

// @vitest-environment node
import { describe, expect, it } from "vitest"
import { onRequest } from "@/edge-functions/api/edgeai/chat/completions"
function request(headers: Record<string, string>): Request {
return new Request("http://localhost/api/edgeai/chat/completions", {
method: "POST",
headers,
// Non-streaming requests return a mock reply without calling AI
body: JSON.stringify({ messages: [{ role: "user", content: "hi" }] }),
})
}
const json = { "Content-Type": "application/json" }
describe("EdgeOne chat completions function", () => {
it("sends no CORS headers", async () => {
const res = await onRequest({ request: request(json), env: {} })
expect(res.status).toBe(200)
expect(res.headers.get("access-control-allow-origin")).toBeNull()
})
it("rejects non-JSON requests", async () => {
const res = await onRequest({
request: request({ "Content-Type": "text/plain" }),
env: {},
})
expect(res.status).toBe(400)
// A plain-text type that only mentions JSON needs no CORS preflight
const disguised = await onRequest({
request: request({
"Content-Type": "text/plain; x=application/json",
}),
env: {},
})
expect(disguised.status).toBe(400)
const withCharset = await onRequest({
request: request({
"Content-Type": "application/json; charset=utf-8",
}),
env: {},
})
expect(withCharset.status).toBe(200)
})
it("checks the access code when ACCESS_CODE_LIST is set", async () => {
const env = { ACCESS_CODE_LIST: "secret" }
const missing = await onRequest({ request: request(json), env })
expect(missing.status).toBe(401)
const ok = await onRequest({
request: request({ ...json, "x-access-code": "secret" }),
env,
})
expect(ok.status).toBe(200)
})
it("lets requests through when env is unavailable", async () => {
const res = await onRequest({ request: request(json) })
expect(res.status).toBe(200)
})
})