import { test } from "node:test"; import assert from "node:assert/strict"; import { authorizeWorkerRequest, getWorkerToken, workerEndpointEnabled, } from "./workerToken"; // Run with: node_modules/.bin/tsx --test common/lib/workerToken.test.ts // // THE 503 BRANCH HAD NO COVERAGE ANYWHERE, and it is the one that decides // whether an instance is an open transcription server. The e2e suite cannot // reach it: the test server boots with WORKER_TOKEN=test-worker-token // (editor/package.json, dev:test) and one server serves the whole suite, so no // spec can observe the endpoint disabled without restarting it. That left the // most consequential of the three answers — "unset means OFF, not means open" — // asserted by nothing at all. // // `getWorkerToken()` reads `process.env` on every call, never at import, which // is exactly what makes this testable: set the variable, ask, restore. Each // test restores in a `finally` so a failure cannot leak a token into the next. function withToken(value: string | undefined, fn: () => T): T { const before = process.env.WORKER_TOKEN; if (value === undefined) delete process.env.WORKER_TOKEN; else process.env.WORKER_TOKEN = value; try { return fn(); } finally { if (before === undefined) delete process.env.WORKER_TOKEN; else process.env.WORKER_TOKEN = before; } } // UNSET IS OFF, AND OFF IS 503 — never 401 and never ok. The distinction is the // whole opt-in: 401 would tell a scanner "there is a secret here, guess it", // and ok would make every instance that never set the variable a public // transcription server. test("no token configured: every request is 503, whatever it carries", () => { withToken(undefined, () => { assert.equal(getWorkerToken(), ""); assert.equal(workerEndpointEnabled(), false); for (const header of [ null, "", "Bearer anything", "Bearer ", "Basic dXNlcjpwYXNz", ]) { const auth = authorizeWorkerRequest(header); assert.equal(auth.ok, false); assert.equal(auth.ok === false && auth.status, 503); assert.match( auth.ok === false ? auth.error : "", /disabled \(set WORKER_TOKEN to enable\)/, ); } }); }); // An EMPTY string is unset. `WORKER_TOKEN=` in a compose file is a variable // somebody meant to fill in, not a secret of length zero that every caller // matches. test("an empty token is not a token", () => { withToken("", () => { assert.equal(workerEndpointEnabled(), false); const auth = authorizeWorkerRequest("Bearer "); assert.equal(auth.ok === false && auth.status, 503); }); }); test("token configured: a missing or malformed header is 401", () => { withToken("s3cret", () => { assert.equal(workerEndpointEnabled(), true); for (const header of [null, "", "s3cret", "Basic s3cret", "Bearer"]) { const auth = authorizeWorkerRequest(header); assert.equal(auth.ok, false); assert.equal(auth.ok === false && auth.status, 401); assert.match(auth.ok === false ? auth.error : "", /missing bearer token/); } }); }); // A WRONG TOKEN IS 401 AND NOT 503: the surface is on, the caller is not // welcome. Lengths that differ are checked before timingSafeEqual, which throws // on mismatched buffers — a prefix of the real token is the case that proves it. test("token configured: a mismatched token is 401, at any length", () => { withToken("s3cret", () => { for (const bad of ["wrong", "s3cre", "s3crets", "S3CRET", "s3cret "]) { const auth = authorizeWorkerRequest(`Bearer ${bad}`); assert.equal(auth.ok, false); assert.equal(auth.ok === false && auth.status, 401); assert.match(auth.ok === false ? auth.error : "", /invalid worker token/); } }); }); test("token configured: the matching token is accepted", () => { withToken("s3cret", () => { assert.deepEqual(authorizeWorkerRequest("Bearer s3cret"), { ok: true }); // The scheme is case-insensitive — a worker written against `bearer` is not // a different caller. assert.deepEqual(authorizeWorkerRequest("bearer s3cret"), { ok: true }); // Several spaces after the scheme are still one separator — `\s+` eats // them all, so leading whitespace in the value is not a different token. // TRAILING whitespace is: it lands inside the capture and mismatches. assert.deepEqual(authorizeWorkerRequest("Bearer s3cret"), { ok: true }); }); }); // THE TOKEN IS READ PER CALL, never captured at import. `/api/test/worker-token` // leans on exactly this to unset and restore the variable inside a running // server, and a module-level cache would silently make that route a no-op. test("the token is read from the environment on every call", () => { withToken("first", () => { assert.deepEqual(authorizeWorkerRequest("Bearer first"), { ok: true }); process.env.WORKER_TOKEN = "second"; assert.equal(authorizeWorkerRequest("Bearer first").ok, false); assert.deepEqual(authorizeWorkerRequest("Bearer second"), { ok: true }); }); });