// The headless refresh never replaces a logged-in jar with one without a login // (release 16 slice XL, review L4). Playwright is replaced by a fake chromium // that answers per executable: nothing here launches a browser or loads x.com. // // Run with: pnpm --filter yt-dlp-transcript-common exec tsx --test social/xSessionBroker.test.ts import { test, after } from "node:test"; import assert from "node:assert/strict"; import { chmodSync, mkdtempSync, writeFileSync } from "node:fs"; import { mkdir, readFile, rm, writeFile } from "node:fs/promises"; import os from "node:os"; import path from "node:path"; import type { Paths } from "../lib/paths"; import type { ChromiumLike } from "./playwrightRuntime"; import { writeXBrowserRecord } from "./xBrowser"; import { refreshXCookies, xCookieFile, xProfileDir } from "./xSessionBroker"; const TMP = mkdtempSync(path.join(os.tmpdir(), "xl-broker-")); after(() => rm(TMP, { recursive: true, force: true })); // A stand-in for the system browser the profile records: it only has to be an // executable file. const SYSTEM_EXE = path.join(TMP, "chromium"); writeFileSync(SYSTEM_EXE, "#!/bin/sh\nexit 0\n"); chmodSync(SYSTEM_EXE, 0o755); type Cookie = { name: string; value: string; domain: string; path: string; expires: number; httpOnly: boolean; secure: boolean }; const cookie = (name: string, value: string): Cookie => ({ name, value, domain: ".x.com", path: "/", expires: 1_900_000_000, httpOnly: true, secure: true, }); // Answers launchPersistentContext by executable: "bundled" when the options // name none. An Error answer throws, as a launch that cannot open the profile. function fakeChromium(answers: Record) { const launches: string[] = []; const chromium = { launch: async () => { throw new Error("not used"); }, launchPersistentContext: async (_dir: string, opts: Record) => { const who = typeof opts.executablePath === "string" ? opts.executablePath : "bundled"; launches.push(who); const answer = answers[who]; if (answer instanceof Error) throw answer; const page = { goto: async () => undefined, waitForSelector: async () => undefined, waitForTimeout: async () => undefined, evaluate: async () => undefined, on: () => undefined, }; return { pages: () => [page], newPage: async () => page, cookies: async () => answer ?? [], addCookies: async () => undefined, close: async () => undefined, on: () => undefined, }; }, } as unknown as ChromiumLike; return { chromium, launches }; } let n = 0; async function corpus(opts: { jar?: "logged-in" | "logged-out"; recorded?: boolean }) { const paths = { transcriptsDir: path.join(TMP, `corpus-${++n}`) } as Paths; await mkdir(xProfileDir(paths), { recursive: true }); if (opts.recorded) { await writeXBrowserRecord( xProfileDir(paths), { kind: "system", executablePath: SYSTEM_EXE, from: "path" }, "Chromium 153", ); } if (opts.jar) { await writeFile( xCookieFile(paths), "# Netscape HTTP Cookie File\n" + (opts.jar === "logged-in" ? ".x.com\tTRUE\t/\tTRUE\t1900000000\tauth_token\tOLD-LOGIN\n" : ".x.com\tTRUE\t/\tTRUE\t1900000000\tguest_id\tg\n"), ); } return paths; } const jarText = (paths: Paths) => readFile(xCookieFile(paths), "utf8"); test("the bundled read has the login: written, the recorded browser never launched", async () => { const paths = await corpus({ jar: "logged-in", recorded: true }); const { chromium, launches } = fakeChromium({ bundled: [cookie("auth_token", "FRESH")] }); const status = await refreshXCookies(paths, { chromium }); assert.deepEqual(launches, ["bundled"]); assert.equal(status.looksAuthenticated, true); assert.match(await jarText(paths), /auth_token\tFRESH/); }); test("an EMPTY bundled read of a logged-in profile is read again with the recorded browser", async () => { const paths = await corpus({ jar: "logged-in", recorded: true }); const { chromium, launches } = fakeChromium({ bundled: [], [SYSTEM_EXE]: [cookie("auth_token", "FROM-SYSTEM"), cookie("ct0", "c")], }); const lines: string[] = []; await refreshXCookies(paths, { chromium, onLog: (l) => lines.push(l) }); assert.deepEqual(launches, ["bundled", SYSTEM_EXE]); assert.match(await jarText(paths), /auth_token\tFROM-SYSTEM/); assert.ok(lines.some((l) => /read no X login from a profile whose exported jar holds one/.test(l))); }); test("no read finds the login: the logged-in jar is KEPT and the refresh refuses", async () => { const paths = await corpus({ jar: "logged-in", recorded: true }); const before = await jarText(paths); const { chromium, launches } = fakeChromium({ bundled: [cookie("guest_id", "g")], [SYSTEM_EXE]: [] }); await assert.rejects( refreshXCookies(paths, { chromium }), /The profile gave no X login \(no auth_token\), so the logged-in cookie jar exported .* was kept, not replaced\./, ); assert.deepEqual(launches, ["bundled", SYSTEM_EXE]); assert.equal(await jarText(paths), before); }); test("no record to fall back on: the logged-in jar is kept all the same", async () => { const paths = await corpus({ jar: "logged-in" }); const before = await jarText(paths); const { chromium, launches } = fakeChromium({ bundled: [] }); await assert.rejects(refreshXCookies(paths, { chromium }), /was kept, not replaced/); assert.deepEqual(launches, ["bundled"]); assert.equal(await jarText(paths), before); }); test("a jar without a login is replaced as before (nothing to protect)", async () => { const paths = await corpus({ jar: "logged-out", recorded: true }); const { chromium, launches } = fakeChromium({ bundled: [cookie("guest_id", "new")] }); const status = await refreshXCookies(paths, { chromium }); assert.deepEqual(launches, ["bundled"]); assert.equal(status.looksAuthenticated, false); assert.match(await jarText(paths), /guest_id\tnew/); }); test("the bundled build cannot open the profile: the recorded browser reads it", async () => { const paths = await corpus({ jar: "logged-in", recorded: true }); const { chromium, launches } = fakeChromium({ bundled: new Error("profile is from a newer version"), [SYSTEM_EXE]: [cookie("auth_token", "VIA-RECORD")], }); await refreshXCookies(paths, { chromium }); assert.deepEqual(launches, ["bundled", SYSTEM_EXE]); assert.match(await jarText(paths), /auth_token\tVIA-RECORD/); });