mirror of
https://github.com/DayuanJiang/next-ai-draw-io.git
synced 2026-10-07 02:07:47 +08:00
Found by the second PR review: - With AWS_BEARER_TOKEN_BEDROCK set on the server, a request with the user's AWS keys ran on the server's token: the Bedrock SDK prefers it. Checked with Bedrock: invalid user keys used to get an answer. - An OpenAI key with the official URL filled in (the settings form does that) went to the Responses API. Back to main's rule: a configured base URL uses Chat Completions. - A user's Ollama key went to the server's OLLAMA_BASE_URL, for chat and for the model list. Like every other provider, it goes to the user's base URL or Ollama Cloud. - The server's keyless Ollama and EdgeOne were not counted in the quota. - AI_MODEL models on the server's keys ran on any provider with a server key, not only on AI_PROVIDER. - A user's Azure key without a base URL used the server's resource name. - The admin panel's Test button failed whenever access codes were set. - DeepSeek's errors in the stream (plain text) were shown as they were, without a hint and also on the server's keys. Bedrock's throttling in the stream was not recognised as a rate limit. - The EdgeOne function accepted text/plain; x=application/json, which other sites can send without a CORS preflight. - Desktop app: a launch that found the old port taken for a moment (the previous version still quitting after an update) remembered the new port for good. The new port is kept only when Windows reserves the old one. A failed read of the presets file moved it aside as corrupt, and a save could then replace the presets. Switching presets on the same port now reloads the page. The dev launcher no longer misses a preset change made before or during a restart.
63 lines
2.2 KiB
TypeScript
63 lines
2.2 KiB
TypeScript
// @vitest-environment node
|
|
import { describe, expect, it } from "vitest"
|
|
import { onRequest } from "@/edge-functions/api/edgeai/chat/completions"
|
|
|
|
function request(headers: Record<string, string>): Request {
|
|
return new Request("http://localhost/api/edgeai/chat/completions", {
|
|
method: "POST",
|
|
headers,
|
|
// Non-streaming requests return a mock reply without calling AI
|
|
body: JSON.stringify({ messages: [{ role: "user", content: "hi" }] }),
|
|
})
|
|
}
|
|
|
|
const json = { "Content-Type": "application/json" }
|
|
|
|
describe("EdgeOne chat completions function", () => {
|
|
it("sends no CORS headers", async () => {
|
|
const res = await onRequest({ request: request(json), env: {} })
|
|
expect(res.status).toBe(200)
|
|
expect(res.headers.get("access-control-allow-origin")).toBeNull()
|
|
})
|
|
|
|
it("rejects non-JSON requests", async () => {
|
|
const res = await onRequest({
|
|
request: request({ "Content-Type": "text/plain" }),
|
|
env: {},
|
|
})
|
|
expect(res.status).toBe(400)
|
|
// A plain-text type that only mentions JSON needs no CORS preflight
|
|
const disguised = await onRequest({
|
|
request: request({
|
|
"Content-Type": "text/plain; x=application/json",
|
|
}),
|
|
env: {},
|
|
})
|
|
expect(disguised.status).toBe(400)
|
|
const withCharset = await onRequest({
|
|
request: request({
|
|
"Content-Type": "application/json; charset=utf-8",
|
|
}),
|
|
env: {},
|
|
})
|
|
expect(withCharset.status).toBe(200)
|
|
})
|
|
|
|
it("checks the access code when ACCESS_CODE_LIST is set", async () => {
|
|
const env = { ACCESS_CODE_LIST: "secret" }
|
|
const missing = await onRequest({ request: request(json), env })
|
|
expect(missing.status).toBe(401)
|
|
|
|
const ok = await onRequest({
|
|
request: request({ ...json, "x-access-code": "secret" }),
|
|
env,
|
|
})
|
|
expect(ok.status).toBe(200)
|
|
})
|
|
|
|
it("lets requests through when env is unavailable", async () => {
|
|
const res = await onRequest({ request: request(json) })
|
|
expect(res.status).toBe(200)
|
|
})
|
|
})
|