Files
goclaw/internal/oauth/openai_claims_test.go
T
Kai (Tam Nhu) Tran 30708ae79d feat(providers): support Codex OAuth pools with inherited routing defaults
* feat(auth): support named chatgpt oauth providers

- add provider-scoped ChatGPT OAuth routes and CLI support

- persist refresh tokens per provider and reject provider-type collisions

- wire provider OAuth setup flows in the dashboard and setup UI

Refs #448

* feat(agent): add chatgpt oauth account routing

- add agent other_config routing for manual and round-robin selection

- reuse routed provider resolution across resolver and pending loaders

- add router, parser, and agent advanced dialog coverage for multi-account use

Refs #448

* docs(api): describe chatgpt oauth routing

- document named-provider ChatGPT OAuth auth routes

- describe agent-side account routing and round-robin behavior

- update OpenAPI agent config schema and provider type enum

Refs #448

* fix(store): add missing agent key context helpers

* feat(ui): clarify chatgpt oauth account setup and routing

* docs(providers): align chatgpt oauth alias examples

* feat(agent): add codex pool activity dashboard

* fix(providers): harden codex oauth alias setup

* feat(codex-pool): improve routing dashboard UX

- redesign the Codex/OpenAI pool page around saved-pool checkpoints and live evidence

- add clearer selection, attention, and recent-proof states for pool members

- make the lower panels fill the remaining desktop viewport while staying responsive

* fix(store): resolve context helper merge duplication

* feat(oauth): add codex pool quota and observation APIs

- add quota inspection and observation endpoints for ChatGPT Subscription (OAuth) providers

- teach codex routing to surface pool activity, observation metadata, and quota-aware readiness

- extend tests and HTTP docs/OpenAPI for the new pool monitoring flows

* feat(web): add codex pool quota monitor and controls

- add provider quota fetching, readiness badges, and live routing evidence on the account pool page

- redesign pool setup and activity panels for multi-account management with localized copy updates

- keep the live monitor internally scrollable and compact the account cards for better viewport fit

* fix(web): clarify pool routing labels

- rename the recent request badge from Direct to Selected

- restore compact quota bars in the live pool cards

* feat(codex-pool): add runtime health dashboard

- derive per-provider success and failure health from routed Codex traces

- surface routing, quota, and recent request evidence in the pool UI

- align provider alias guidance and owner access with the dashboard role model

* docs(auth): document tenant scoping and key roles

* fix(auth): harden tenant and codex pool access control

* fix(providers): align codex pool runtime defaults

* feat(ui): tighten codex pool responsive layout

* feat(chatgpt-oauth): refine codex pool management UX

* feat(chatgpt-oauth): surface quota bars on provider pages

- add compact quota bars to Codex provider rows and provider detail

- fetch quota only for ready visible provider rows and ready detail aliases

- fix managed-member detail visibility and tighten provider locale copy
2026-03-27 09:35:57 +07:00

84 lines
2.2 KiB
Go

package oauth
import (
"encoding/base64"
"encoding/json"
"testing"
"time"
)
func TestParseOpenAIJWTMetadataNestedClaims(t *testing.T) {
token := testJWT(t, map[string]any{
"https://api.openai.com/auth": map[string]any{
"chatgpt_account_id": "acct_nested",
"chatgpt_plan_type": "team",
},
})
metadata, ok := parseOpenAIJWTMetadata(token)
if !ok {
t.Fatal("parseOpenAIJWTMetadata() = false, want true")
}
if metadata.AccountID != "acct_nested" {
t.Fatalf("AccountID = %q, want acct_nested", metadata.AccountID)
}
if metadata.PlanType != "team" {
t.Fatalf("PlanType = %q, want team", metadata.PlanType)
}
}
func TestParseOpenAIJWTMetadataFlatClaims(t *testing.T) {
token := testJWT(t, map[string]any{
"https://api.openai.com/auth.chatgpt_account_id": "acct_flat",
"https://api.openai.com/auth.chatgpt_plan_type": "plus",
})
metadata, ok := parseOpenAIJWTMetadata(token)
if !ok {
t.Fatal("parseOpenAIJWTMetadata() = false, want true")
}
if metadata.AccountID != "acct_flat" {
t.Fatalf("AccountID = %q, want acct_flat", metadata.AccountID)
}
if metadata.PlanType != "plus" {
t.Fatalf("PlanType = %q, want plus", metadata.PlanType)
}
}
func TestMergeOAuthSettingsPreservesExistingMetadata(t *testing.T) {
existing := OAuthSettings{
ExpiresAt: time.Now().Add(-time.Hour).Unix(),
Scopes: "openid profile",
AccountID: "acct_keep",
PlanType: "team",
}
settings := mergeOAuthSettings(existing, &OpenAITokenResponse{
AccessToken: "not-a-jwt",
ExpiresIn: 3600,
}, time.Now().Add(time.Hour))
if settings.AccountID != "acct_keep" {
t.Fatalf("AccountID = %q, want acct_keep", settings.AccountID)
}
if settings.PlanType != "team" {
t.Fatalf("PlanType = %q, want team", settings.PlanType)
}
if settings.Scopes != "openid profile" {
t.Fatalf("Scopes = %q, want openid profile", settings.Scopes)
}
}
func testJWT(t *testing.T, payload map[string]any) string {
t.Helper()
header, err := json.Marshal(map[string]string{"alg": "none", "typ": "JWT"})
if err != nil {
t.Fatalf("marshal header: %v", err)
}
body, err := json.Marshal(payload)
if err != nil {
t.Fatalf("marshal payload: %v", err)
}
return base64.RawURLEncoding.EncodeToString(header) + "." + base64.RawURLEncoding.EncodeToString(body) + "."
}