mirror of
https://github.com/MoonshotAI/kimi-code.git
synced 2026-07-23 16:14:46 +00:00
* test(server): add API surface snapshot guardrail
Boot startServer on port 0 and snapshot the documented v1 route table derived from /openapi.json paths, plus the reachability of doc/meta endpoints (/healthz, /openapi.json, /asyncapi.json, /). Gives later auth/--host phases an intentional diff when routes change. M0 makes no production behavior change.
* test(server): add e2e server harness with token support
Add test/helpers/serverHarness.ts: boot() wraps startServer with an isolated lock + home dir and returns a handle (server, address, baseUrl, wsUrl, token, close) plus authedFetch/authedWs that carry Authorization: Bearer <token> (and the kimi-code.bearer.<token> WS subprotocol). serviceOverrides is the generic DI seam later phases use to inject a fixed-token auth service; IAuthTokenService is not referenced yet. closeAll() tears down every booted server and socket. M0 makes no production behavior change; typecheck-only gate.
* feat(server): add privateFiles 0600 atomic write/read utility
* feat(server): add per-start tokenStore
* feat(server): add env-based bcrypt password hash utility
* feat(server): add IAuthTokenService DI seam
* feat(server): add global onRequest auth hook with bypass + redaction
* fix(server): stop reflecting Host header in /asyncapi.json
* feat(server): add WS bearer subprotocol constant and parser
* feat(server): enforce bearer token auth on WS upgrade
* feat(server): add Host header allowlist middleware
* feat(server): add Origin/CORS middleware
* feat(server): wire Host/Origin checks into HTTP and WS
* feat(server): wire token auth, Host/Origin, and WS auth into start.ts
* fix(server): create lock file with 0600 permissions
* fix(server): suppress debug routes on non-loopback binds
* feat(kimi-code): read server token and send Authorization on CLI calls
* feat(kimi-code): inject server token into /web URL fragment
* feat(server): add bindClassify for loopback/lan/public classification
* feat(kimi-code): register --host flag and pass it through the daemon
* feat(server): require password and TLS opt-out on non-loopback binds
* feat(server): rate-limit repeated auth failures on non-loopback binds
* feat(server): disable shutdown and terminals on public binds by default
* feat(server): add security response headers on non-loopback binds
* test(server): cover LAN/public host-exposure hardening end to end
* docs(server): add deployment security and threat-model guide
* changeset: minor kimi-code for server auth and host exposure
* feat(kimi-web): add server bearer-token auth support
* fix: repair CI for server auth and host exposure
- Replace native @node-rs/bcrypt with pure-JS bcryptjs so the ESM CLI
bundle and the SEA native bundle both build without native-addon
require issues (node-rs/bcrypt broke the ESM smoke and the SEA
check-bundle allowlist).
- Remove dead cleanup references (stopSpinner, authLogoBlinkTimer) in
apps/kimi-web App.vue that failed vue-tsc.
- Fix lint: drop empty spread fallbacks in the e2e auth-header merge,
void the intentionally-async WS upgrade listener, add missing
assertions to satisfy jest/expect-expect, and convert a ternary
statement to if/else.
- Send the bearer token in the snapshot perf/smoke tests so they pass
under the new global auth hook.
- Refresh the pnpmDeps hash in flake.nix for the updated lockfile.
* feat(server): persist bearer token and add rotate-token command
- persist the server bearer token in <home>/server.token (0600) and reuse it across restarts instead of per-start server-<pid>.token
- add `kimi server rotate-token` to regenerate the token; the token store reloads on mtime/inode change so rotation applies without restart
- print the token and Vite-style Local/Network URLs in the startup banner
- allow non-loopback binds with bearer-token-only auth (password now optional) and update SECURITY.md
- surface daemon boot failures immediately with the exit reason and log tail instead of waiting for the spawn timeout
* feat(server): print full token URLs and re-print links after rotate
- Drop the ready-panel border so token URLs print in full for copying; keep the Kimi sprite beside the title.
- Re-print Local/Network access links after `server rotate-token` (host/port from the lock).
- Extract shared access-URL helpers into access-urls.ts.
- Unify link and token colors between the banner and rotate-token.
* feat(server): dim URL #token= fragment and de-highlight token
- Render the `#token=…` fragment in a dim gray so the host/port stands out in the banner and rotate-token links.
- De-highlight the standalone token; set it off with surrounding whitespace instead of color.
- Add splitTokenFragment helper.
* refactor(cli): polish server ready banner and rotate-token output
- move version onto the ready banner title line; drop the separate
Ready:/Version: rows and the startup-time metric
- reorder rotate-token output so the new token sits between the
invalidation note and the access links
- update server CLI tests for the new layout
* feat(server): warn on reuse and refine ready banner
- Warn when `server run` reuses an already-running daemon (its options are not applied) and show the running server's actual URLs.
- Show a `Network: off use --host 0.0.0.0 to enable` hint on loopback binds.
- Move the version onto the title line and drop the startup-time metric.
* fix(web): relabel auth dialog to token and cover full page
- Relabel the server auth dialog from "password" to "token"; the server accepts the bearer token, with the password only as a fallback.
- Make the auth dialog overlay fully opaque so it covers the whole page instead of revealing the login page underneath.
* fix: resolve CI failures on web auth PR
- Replace chalk.yellow named color with chalk.hex(darkColors.warning)
in the server reuse notice to satisfy the chalk named color guard.
- Update pnpmDeps hash in flake.nix to match the regenerated
pnpm-lock.yaml so the Nix build succeeds.
- Retry rmSync in ws-broadcast e2e teardown to ride out EBUSY /
ENOTEMPTY races while the server flushes files after close().
* test(server): update API surface snapshot for warnings route
The feat/web-auth branch adds GET /api/v1/sessions/{session_id}/warnings
(packages/server/src/routes/sessions.ts), so the API surface guardrail
snapshot needs to record the new documented v1 route.
393 lines
12 KiB
TypeScript
393 lines
12 KiB
TypeScript
/**
|
|
* `GET /api/v1/auth` + prompt-submit readiness-gate e2e tests (P2.1).
|
|
*
|
|
* Four fixture states cover acceptance:
|
|
* 1. **Empty config** → ready=false, providers_count=0; prompt
|
|
* submit blocked with `40110`.
|
|
* 2. **Manual provider, no key** → ready=false (key gate not met);
|
|
* prompt submit blocked with `40111`.
|
|
* 3. **Provider, no default** → ready=false (no default_model);
|
|
* prompt submit blocked with `40113`.
|
|
* 4. **Provider + key + model** → ready=true; prompt submit gets past the
|
|
* gate (and may fail downstream — that's
|
|
* out of scope here).
|
|
*
|
|
* **Bootstrap**: each test seeds `<bridgeHome>/config.toml` BEFORE calling
|
|
* `startServer` so KimiCore loads it on construction. The `homeDir` we pass
|
|
* via `coreProcessOptions.homeDir` is also what `AuthSummaryServiceImpl` uses to
|
|
* locate the credential dir — keeping the file paths in lockstep with prod.
|
|
*
|
|
* **Anti-corruption**: tests only use the public REST surface + `RunningServer`
|
|
* accessor. No reaching into `IPromptService._injectActiveForTest` like the
|
|
* lifecycle test — we want the real ensureReady → bridge.rpc.prompt path.
|
|
*/
|
|
|
|
import { mkdtempSync, rmSync, writeFileSync } from 'node:fs';
|
|
import { tmpdir } from 'node:os';
|
|
import { join } from 'node:path';
|
|
|
|
import { pino } from 'pino';
|
|
import { afterEach, beforeEach, describe, expect, it } from 'vitest';
|
|
|
|
import { authSummarySchema, type AuthSummary } from '@moonshot-ai/protocol';
|
|
|
|
import { IRestGateway, startServer, type RunningServer } from '../src';
|
|
import { fixedTokenAuth } from './helpers/serverHarness';
|
|
|
|
let tmpDir: string;
|
|
let lockPath: string;
|
|
let bridgeHome: string;
|
|
let server: RunningServer | undefined;
|
|
|
|
beforeEach(() => {
|
|
tmpDir = mkdtempSync(join(tmpdir(), 'kimi-server-auth-test-'));
|
|
lockPath = join(tmpDir, 'lock');
|
|
bridgeHome = mkdtempSync(join(tmpdir(), 'kimi-server-auth-home-'));
|
|
});
|
|
|
|
afterEach(async () => {
|
|
try {
|
|
await server?.close();
|
|
} catch {
|
|
// ignore
|
|
}
|
|
server = undefined;
|
|
rmSync(tmpDir, { recursive: true, force: true });
|
|
rmSync(bridgeHome, { recursive: true, force: true });
|
|
});
|
|
|
|
async function bootDaemon(): Promise<RunningServer> {
|
|
server = await startServer({
|
|
serviceOverrides: [fixedTokenAuth()],
|
|
host: '127.0.0.1',
|
|
port: 0,
|
|
lockPath,
|
|
logger: pino({ level: 'silent' }),
|
|
coreProcessOptions: { homeDir: bridgeHome },
|
|
});
|
|
return server;
|
|
}
|
|
|
|
function appOf(r: RunningServer): {
|
|
inject: (req: unknown) => Promise<{ statusCode: number; json: () => unknown }>;
|
|
} {
|
|
const app = r.services.invokeFunction((a) => {
|
|
const gw = a.get(IRestGateway);
|
|
return gw.app as unknown as {
|
|
inject: (req: unknown) => Promise<{ statusCode: number; json: () => unknown }>;
|
|
};
|
|
});
|
|
// Auto-attach the fixed bearer token so the M5.1 auth hook passes. A
|
|
// caller-supplied `authorization` header wins, so explicit token tests keep
|
|
// working; every other header (Range, content-type, …) is preserved.
|
|
return {
|
|
inject(req: unknown) {
|
|
const q = req as { headers?: Record<string, string | string[] | undefined> };
|
|
return app.inject({
|
|
...q,
|
|
headers: { authorization: 'Bearer test-token', ...q.headers },
|
|
});
|
|
},
|
|
};
|
|
}
|
|
|
|
function envelopeOf<T>(body: unknown): {
|
|
code: number;
|
|
msg: string;
|
|
data: T | null;
|
|
request_id: string;
|
|
details?: unknown;
|
|
} {
|
|
return body as {
|
|
code: number;
|
|
msg: string;
|
|
data: T | null;
|
|
request_id: string;
|
|
details?: unknown;
|
|
};
|
|
}
|
|
|
|
/**
|
|
* Seed `<bridgeHome>/config.toml` BEFORE server boot. Path layout matches
|
|
* `resolveConfigPath({homeDir})` exactly so KimiCore + AuthSummaryService
|
|
* load the same file.
|
|
*/
|
|
function seedConfig(toml: string): void {
|
|
writeFileSync(join(bridgeHome, 'config.toml'), toml, 'utf-8');
|
|
}
|
|
|
|
async function createSession(r: RunningServer): Promise<string> {
|
|
const res = await appOf(r).inject({
|
|
method: 'POST',
|
|
url: '/api/v1/sessions',
|
|
payload: { metadata: { cwd: join(tmpDir, 'workspace') } },
|
|
});
|
|
const env = envelopeOf<{ id: string }>(res.json());
|
|
if (env.code !== 0 || env.data === null) {
|
|
throw new Error(`create session failed: ${JSON.stringify(env)}`);
|
|
}
|
|
return env.data.id;
|
|
}
|
|
|
|
/* -------------------------------------------------------------------- */
|
|
/* GET /v1/auth — readiness snapshot */
|
|
/* -------------------------------------------------------------------- */
|
|
|
|
describe('GET /api/v1/auth — readiness probe (P2.1 D2)', () => {
|
|
it('returns ready=false + zero providers on empty config', async () => {
|
|
const r = await bootDaemon();
|
|
const res = await appOf(r).inject({ method: 'GET', url: '/api/v1/auth' });
|
|
expect(res.statusCode).toBe(200);
|
|
const env = envelopeOf<AuthSummary>(res.json());
|
|
expect(env.code).toBe(0);
|
|
const summary = authSummarySchema.parse(env.data);
|
|
expect(summary).toEqual({
|
|
ready: false,
|
|
providers_count: 0,
|
|
default_model: null,
|
|
managed_provider: null,
|
|
});
|
|
});
|
|
|
|
it('returns ready=false when provider exists but default_model missing', async () => {
|
|
seedConfig(
|
|
[
|
|
'[providers.x]',
|
|
'type = "kimi"',
|
|
'api_key = "sk-test"',
|
|
'',
|
|
'[models.x]',
|
|
'provider = "x"',
|
|
'model = "x"',
|
|
'max_context_size = 1000',
|
|
'',
|
|
].join('\n'),
|
|
);
|
|
const r = await bootDaemon();
|
|
const res = await appOf(r).inject({ method: 'GET', url: '/api/v1/auth' });
|
|
const env = envelopeOf<AuthSummary>(res.json());
|
|
const summary = authSummarySchema.parse(env.data);
|
|
expect(summary.ready).toBe(false);
|
|
expect(summary.providers_count).toBe(1);
|
|
expect(summary.default_model).toBeNull();
|
|
});
|
|
|
|
it('returns ready=true when provider + api_key + default_model are all set', async () => {
|
|
seedConfig(
|
|
[
|
|
'default_model = "x"',
|
|
'',
|
|
'[providers.x]',
|
|
'type = "kimi"',
|
|
'api_key = "sk-test"',
|
|
'',
|
|
'[models.x]',
|
|
'provider = "x"',
|
|
'model = "x"',
|
|
'max_context_size = 1000',
|
|
'',
|
|
].join('\n'),
|
|
);
|
|
const r = await bootDaemon();
|
|
const res = await appOf(r).inject({ method: 'GET', url: '/api/v1/auth' });
|
|
const env = envelopeOf<AuthSummary>(res.json());
|
|
const summary = authSummarySchema.parse(env.data);
|
|
expect(summary).toEqual({
|
|
ready: true,
|
|
providers_count: 1,
|
|
default_model: 'x',
|
|
managed_provider: null,
|
|
});
|
|
});
|
|
|
|
it('surfaces managed_provider.unauthenticated when config has managed:kimi-code but no cached token', async () => {
|
|
seedConfig(
|
|
[
|
|
'[providers."managed:kimi-code"]',
|
|
'type = "kimi"',
|
|
'base_url = "https://example/v1"',
|
|
'',
|
|
'[providers."managed:kimi-code".oauth]',
|
|
'storage = "file"',
|
|
'key = "oauth/kimi-code"',
|
|
'',
|
|
].join('\n'),
|
|
);
|
|
const r = await bootDaemon();
|
|
const res = await appOf(r).inject({ method: 'GET', url: '/api/v1/auth' });
|
|
const env = envelopeOf<AuthSummary>(res.json());
|
|
const summary = authSummarySchema.parse(env.data);
|
|
expect(summary.managed_provider).toEqual({
|
|
name: 'managed:kimi-code',
|
|
status: 'unauthenticated',
|
|
});
|
|
// ready is still false — no default_model, even though provider exists
|
|
expect(summary.ready).toBe(false);
|
|
});
|
|
});
|
|
|
|
/* -------------------------------------------------------------------- */
|
|
/* POST /sessions/{sid}/prompts — readiness gate */
|
|
/* -------------------------------------------------------------------- */
|
|
|
|
describe('POST /api/v1/sessions/{sid}/prompts — readiness gate (P2.1 D1)', () => {
|
|
it('returns 40110 with details=null on empty config', async () => {
|
|
const r = await bootDaemon();
|
|
const sid = await createSession(r);
|
|
const res = await appOf(r).inject({
|
|
method: 'POST',
|
|
url: `/api/v1/sessions/${sid}/prompts`,
|
|
payload: {
|
|
content: [{ type: 'text', text: 'hello' }],
|
|
model: 'x',
|
|
thinking: 'off',
|
|
permission_mode: 'manual',
|
|
plan_mode: false,
|
|
},
|
|
});
|
|
const env = envelopeOf<unknown>(res.json());
|
|
expect(env.code).toBe(40110);
|
|
expect(env.data).toBeNull();
|
|
expect(env.details).toBeNull();
|
|
});
|
|
|
|
it('returns 40111 with details.provider_id when manual provider has no api_key', async () => {
|
|
seedConfig(
|
|
[
|
|
'default_model = "x"',
|
|
'',
|
|
'[providers.x]',
|
|
'type = "kimi"',
|
|
'# no api_key',
|
|
'',
|
|
'[models.x]',
|
|
'provider = "x"',
|
|
'model = "x"',
|
|
'max_context_size = 1000',
|
|
'',
|
|
].join('\n'),
|
|
);
|
|
const r = await bootDaemon();
|
|
const sid = await createSession(r);
|
|
const res = await appOf(r).inject({
|
|
method: 'POST',
|
|
url: `/api/v1/sessions/${sid}/prompts`,
|
|
payload: {
|
|
content: [{ type: 'text', text: 'hello' }],
|
|
model: 'x',
|
|
thinking: 'off',
|
|
permission_mode: 'manual',
|
|
plan_mode: false,
|
|
},
|
|
});
|
|
const env = envelopeOf<unknown>(res.json());
|
|
expect(env.code).toBe(40111);
|
|
expect(env.data).toBeNull();
|
|
expect(env.details).toEqual({ provider_id: 'x' });
|
|
});
|
|
|
|
it('returns 40113 with details.model_id when default_model alias does not resolve', async () => {
|
|
seedConfig(
|
|
[
|
|
'default_model = "missing-alias"',
|
|
'',
|
|
'[providers.x]',
|
|
'type = "kimi"',
|
|
'api_key = "sk-test"',
|
|
'',
|
|
'[models.x]',
|
|
'provider = "x"',
|
|
'model = "x"',
|
|
'max_context_size = 1000',
|
|
'',
|
|
].join('\n'),
|
|
);
|
|
const r = await bootDaemon();
|
|
const sid = await createSession(r);
|
|
const res = await appOf(r).inject({
|
|
method: 'POST',
|
|
url: `/api/v1/sessions/${sid}/prompts`,
|
|
payload: {
|
|
content: [{ type: 'text', text: 'hello' }],
|
|
model: 'x',
|
|
thinking: 'off',
|
|
permission_mode: 'manual',
|
|
plan_mode: false,
|
|
},
|
|
});
|
|
const env = envelopeOf<unknown>(res.json());
|
|
expect(env.code).toBe(40113);
|
|
expect(env.data).toBeNull();
|
|
expect(env.details).toEqual({ model_id: 'missing-alias' });
|
|
});
|
|
|
|
it('returns 40113 when default_model is unset (no model_id detail)', async () => {
|
|
seedConfig(
|
|
[
|
|
'[providers.x]',
|
|
'type = "kimi"',
|
|
'api_key = "sk-test"',
|
|
'',
|
|
'[models.x]',
|
|
'provider = "x"',
|
|
'model = "x"',
|
|
'max_context_size = 1000',
|
|
'',
|
|
].join('\n'),
|
|
);
|
|
const r = await bootDaemon();
|
|
const sid = await createSession(r);
|
|
const res = await appOf(r).inject({
|
|
method: 'POST',
|
|
url: `/api/v1/sessions/${sid}/prompts`,
|
|
payload: {
|
|
content: [{ type: 'text', text: 'hello' }],
|
|
model: 'x',
|
|
thinking: 'off',
|
|
permission_mode: 'manual',
|
|
plan_mode: false,
|
|
},
|
|
});
|
|
const env = envelopeOf<unknown>(res.json());
|
|
expect(env.code).toBe(40113);
|
|
// No model_id in details when default is simply unset — clients should
|
|
// route to "select a model" UX rather than "this alias is broken".
|
|
expect(env.details).toBeNull();
|
|
});
|
|
|
|
it('passes the readiness gate when provider + key + default_model are all set', async () => {
|
|
seedConfig(
|
|
[
|
|
'default_model = "x"',
|
|
'',
|
|
'[providers.x]',
|
|
'type = "kimi"',
|
|
'api_key = "sk-test"',
|
|
'',
|
|
'[models.x]',
|
|
'provider = "x"',
|
|
'model = "x"',
|
|
'max_context_size = 1000',
|
|
'',
|
|
].join('\n'),
|
|
);
|
|
const r = await bootDaemon();
|
|
const sid = await createSession(r);
|
|
const res = await appOf(r).inject({
|
|
method: 'POST',
|
|
url: `/api/v1/sessions/${sid}/prompts`,
|
|
payload: {
|
|
content: [{ type: 'text', text: 'hello' }],
|
|
model: 'x',
|
|
thinking: 'off',
|
|
permission_mode: 'manual',
|
|
plan_mode: false,
|
|
},
|
|
});
|
|
const env = envelopeOf<unknown>(res.json());
|
|
// The gate passes; bridge.rpc.prompt then runs against the test fixture
|
|
// which has no real model wired up. We assert the readiness codes are
|
|
// NOT what we see — anything beyond P2.1's scope is "out of band".
|
|
expect([40110, 40111, 40112, 40113]).not.toContain(env.code);
|
|
});
|
|
});
|