Files
gstack/browse/test/extension-token.test.ts
T
Garry Tan dcaea52800 v1.91.7.0 feat: add functional QA and pre-publication docs checks (#2983)
* feat: add surface-aware exploratory QA and ship documentation gates

* test: preserve delegated QA setup authority after main integration

* fix(qa): clarify exploration order and preserve report artifacts

* test(qa): follow the shared setup reference directly

* refactor(ship): make verification and recovery routes explicit

* test(ship): align evidence and review guards with explicit routes

* fix(workflows): clarify ship recovery and functional QA evidence

* fix(workflows): clarify approval recovery and full QA coverage

* refactor(workflows): order review transactions and clarify ship state

* fix(ship): clarify final verification and fail closed at publication

* fix(evals): attribute native atomic documentation writes

* fix(ship): clarify recovery and documentation lifecycle guidance

* fix(test): preserve observed native placeholder styling in CI

* fix(codex): report watchdog timeouts without a process-exit race

* Checkpoint functional QA implementation and workflow validation repairs

* Fix documentation and shared-review fixture contracts

* docs: clarify judge reuse and evaluation supervision

* test: align review evidence and selected case contracts

* test: verify append-only documentation checkpoints and recovery

* fix: qualify QA workflows and CI validation repairs

* fix: launch shared-libs fixture scripts on Windows

* fix: qualify QA deadlines, fixture isolation, and shard cleanup

* fix: preserve qualified QA and cancellation repairs

* fix: enforce functional fixture authority and share strict event decoding

* fix: retain free-test evidence and explain recovery

* fix: reject malformed native evidence after decoder consolidation

* test: use reliable capture for telemetry privacy filters

* test: refresh measured quick coverage and document validation costs

* Fix native fixture receipts and preserve VM validation evidence

* Align negative judge controls with upstream clarity policy

* Fix report-only QA preparation and public evidence handling

* Clarify QA-only preparation and current-report preservation

* Stream Ship quality judgments with an explicit 64k response contract

* Validate compact judge reasoning locally with supported wire schema

* Align functional QA fixture instructions with evidence acceptance

* Bind native browser diagnostics to execution evidence and align review verdicts

* Preserve native diagnostic line boundaries

* Serialize functional QA evidence from native captures

* Keep large QA evidence fixture payload out of Windows argv
2026-09-29 06:07:35 -07:00

189 lines
6.8 KiB
TypeScript

/**
* Live behavioral tests for the v1.62 token-bootstrap contract:
*
* - GET /health NEVER carries a token — not in headed mode, not for a
* chrome-extension:// Origin (the two pre-v1.62 carve-outs). IRON-RULE
* regression tests.
* - POST /extension-token releases the token ONLY to the pinned extension
* Origin (chrome-extension://GSTACK_EXTENSION_ID) with a loopback Host.
* - Host arrives with a port ('127.0.0.1:34567') and must be parsed to a
* hostname, not compared literally (amendment C9). 'localhost:34567'
* is accepted too.
* - The tunnel surface 404s /extension-token (not in TUNNEL_PATHS).
*
* Uses the buildFetchHandler factory (same pattern as server-factory.test.ts)
* so no listener/browser is needed. Real-HTTP coverage (Host header set by
* the network stack) lives in pair-agent-e2e.test.ts.
*/
import { describe, test, expect, beforeEach, afterAll } from 'bun:test';
import * as crypto from 'crypto';
import * as fs from 'node:fs';
import * as os from 'node:os';
import * as path from 'node:path';
import {
buildFetchHandler,
GSTACK_EXTENSION_ID,
type ServerConfig,
} from '../src/server';
import { __resetRegistry } from '../src/token-registry';
import { BrowserManager } from '../src/browser-manager';
import { resolveConfig } from '../src/config';
const PINNED_ORIGIN = `chrome-extension://${GSTACK_EXTENSION_ID}`;
const fixtureDir = fs.realpathSync(fs.mkdtempSync(path.join(os.tmpdir(), 'gstack-extension-token-')));
const fixtureConfig = resolveConfig({ BROWSE_STATE_FILE: path.join(fixtureDir, 'state/browse.json') });
afterAll(() => {
fs.rmSync(fixtureDir, { recursive: true, force: true });
});
function makeConfig(overrides: Partial<ServerConfig> = {}): ServerConfig {
const token = 'ext-token-test-' + crypto.randomBytes(16).toString('hex');
return {
authToken: token,
browsePort: 34567,
idleTimeoutMs: 1_800_000,
config: fixtureConfig,
browserManager: new BrowserManager(),
ownsTerminalAgent: false,
startTime: Date.now(),
...overrides,
};
}
function headedBrowserManager(): BrowserManager {
const bm = new BrowserManager();
// connectionMode is private; force the headed value the old /health
// carve-out keyed on.
(bm as any).connectionMode = 'headed';
return bm;
}
function tokenRequest(headers: Record<string, string>): Request {
// Direct handler invocation — no network stack to synthesize Host, so
// every test sets it explicitly (Bun.serve always delivers one).
return new Request('http://127.0.0.1:34567/extension-token', {
method: 'POST',
headers,
});
}
describe('GET /health never carries a token (IRON RULE)', () => {
beforeEach(() => __resetRegistry());
test('headed mode: no token field in the body', async () => {
const handle = buildFetchHandler(makeConfig({ browserManager: headedBrowserManager() }));
const resp = await handle.fetchLocal(new Request('http://127.0.0.1:34567/health'), null);
expect(resp.status).toBe(200);
const body = await resp.json() as any;
expect(body.token).toBeUndefined();
expect(body.mode).toBe('headed');
});
test('chrome-extension Origin (even the pinned one): no token field', async () => {
const handle = buildFetchHandler(makeConfig());
const resp = await handle.fetchLocal(new Request('http://127.0.0.1:34567/health', {
headers: { Origin: PINNED_ORIGIN },
}), null);
expect(resp.status).toBe(200);
const body = await resp.json() as any;
expect(body.token).toBeUndefined();
});
test('headed mode AND pinned chrome-extension Origin together: still no token', async () => {
const handle = buildFetchHandler(makeConfig({ browserManager: headedBrowserManager() }));
const resp = await handle.fetchLocal(new Request('http://127.0.0.1:34567/health', {
headers: { Origin: PINNED_ORIGIN },
}), null);
const body = await resp.json() as any;
expect(body.token).toBeUndefined();
});
});
describe('POST /extension-token pinned-origin bootstrap', () => {
beforeEach(() => __resetRegistry());
test('pinned Origin + Host with port → 200 with the token', async () => {
const cfg = makeConfig();
const handle = buildFetchHandler(cfg);
const resp = await handle.fetchLocal(tokenRequest({
Origin: PINNED_ORIGIN,
Host: '127.0.0.1:34567',
}), null);
expect(resp.status).toBe(200);
const body = await resp.json() as any;
expect(body.token).toBe(cfg.authToken);
});
test("Host 'localhost:34567' is accepted too (C9 hostname parse)", async () => {
const cfg = makeConfig();
const handle = buildFetchHandler(cfg);
const resp = await handle.fetchLocal(tokenRequest({
Origin: PINNED_ORIGIN,
Host: 'localhost:34567',
}), null);
expect(resp.status).toBe(200);
const body = await resp.json() as any;
expect(body.token).toBe(cfg.authToken);
});
test('wrong extension Origin → 403, no token, no detail', async () => {
const handle = buildFetchHandler(makeConfig());
const resp = await handle.fetchLocal(tokenRequest({
Origin: 'chrome-extension://aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa',
Host: '127.0.0.1:34567',
}), null);
expect(resp.status).toBe(403);
const body = await resp.json() as any;
expect(body.token).toBeUndefined();
// No detail about WHICH check failed
expect(JSON.stringify(body)).not.toContain('origin');
expect(JSON.stringify(body)).not.toContain('host');
});
test('missing Origin → 403', async () => {
const handle = buildFetchHandler(makeConfig());
const resp = await handle.fetchLocal(tokenRequest({
Host: '127.0.0.1:34567',
}), null);
expect(resp.status).toBe(403);
});
test('web-page Origin → 403 (DNS-rebinding page cannot mint a token)', async () => {
const handle = buildFetchHandler(makeConfig());
const resp = await handle.fetchLocal(tokenRequest({
Origin: 'http://evil.example.com',
Host: '127.0.0.1:34567',
}), null);
expect(resp.status).toBe(403);
});
test('non-loopback Host → 403 even with the pinned Origin', async () => {
const handle = buildFetchHandler(makeConfig());
const resp = await handle.fetchLocal(tokenRequest({
Origin: PINNED_ORIGIN,
Host: 'evil.example.com:34567',
}), null);
expect(resp.status).toBe(403);
});
test('malformed Host → 403, not a crash', async () => {
const handle = buildFetchHandler(makeConfig());
const resp = await handle.fetchLocal(tokenRequest({
Origin: PINNED_ORIGIN,
Host: ':::not a host:::',
}), null);
expect(resp.status).toBe(403);
});
test('tunnel surface 404s /extension-token (not in TUNNEL_PATHS)', async () => {
const handle = buildFetchHandler(makeConfig());
const resp = await handle.fetchTunnel(tokenRequest({
Origin: PINNED_ORIGIN,
Host: '127.0.0.1:34567',
}), null);
expect(resp.status).toBe(404);
});
});