refactor: major codebase cleanup - BDD comments, file splitting, bug fixes (#1350)

* style(tests): normalize BDD comments from '// #given' to '// given'

- Replace 4,668 Python-style BDD comments across 107 test files
- Patterns changed: // #given -> // given, // #when -> // when, // #then -> // then
- Also handles no-space variants: //#given -> // given

* fix(rules-injector): prefer output.metadata.filePath over output.title

- Extract file path resolution to dedicated output-path.ts module
- Prefer metadata.filePath which contains actual file path
- Fall back to output.title only when metadata unavailable
- Fixes issue where rules weren't injected when tool output title was a label

* feat(slashcommand): add optional user_message parameter

- Add user_message optional parameter for command arguments
- Model can now call: command='publish' user_message='patch'
- Improves error messages with clearer format guidance
- Helps LLMs understand correct parameter usage

* feat(hooks): restore compaction-context-injector hook

- Restore hook deleted in cbbc7bd0 for session compaction context
- Injects 7 mandatory sections: User Requests, Final Goal, Work Completed,
  Remaining Tasks, Active Working Context, MUST NOT Do, Agent Verification State
- Re-register in hooks/index.ts and main plugin entry

* refactor(background-agent): split manager.ts into focused modules

- Extract constants.ts for TTL values and internal types (52 lines)
- Extract state.ts for TaskStateManager class (204 lines)
- Extract spawner.ts for task creation logic (244 lines)
- Extract result-handler.ts for completion handling (265 lines)
- Reduce manager.ts from 1377 to 755 lines (45% reduction)
- Maintain backward compatible exports

* refactor(agents): split prometheus-prompt.ts into subdirectory

- Move 1196-line prometheus-prompt.ts to prometheus/ subdirectory
- Organize prompt sections into separate files for maintainability
- Update agents/index.ts exports

* refactor(delegate-task): split tools.ts into focused modules

- Extract categories.ts for category definitions and routing
- Extract executor.ts for task execution logic
- Extract helpers.ts for utility functions
- Extract prompt-builder.ts for prompt construction
- Reduce tools.ts complexity with cleaner separation of concerns

* refactor(builtin-skills): split skills.ts into individual skill files

- Move each skill to dedicated file in skills/ subdirectory
- Create barrel export for backward compatibility
- Improve maintainability with focused skill modules

* chore: update import paths and lockfile

- Update prometheus import path after refactor
- Update bun.lock

* fix(tests): complete BDD comment normalization

- Fix remaining #when/#then patterns missed by initial sed
- Affected: state.test.ts, events.test.ts

---------

Co-authored-by: justsisyphus <justsisyphus@users.noreply.github.com>
This commit is contained in:
YeonGyu-Kim
2026-02-01 16:47:50 +09:00
committed by GitHub
parent c83150d9ea
commit f146aeff0f
145 changed files with 10307 additions and 9562 deletions
+24 -24
View File
@@ -5,29 +5,29 @@ const nativeFetch = Bun.fetch.bind(Bun)
describe("findAvailablePort", () => {
it("returns the start port when it is available", async () => {
//#given
// given
const startPort = 19877
//#when
// when
const port = await findAvailablePort(startPort)
//#then
// then
expect(port).toBeGreaterThanOrEqual(startPort)
expect(port).toBeLessThan(startPort + 20)
})
it("skips busy ports and returns next available", async () => {
//#given
// given
const blocker = Bun.serve({
port: 19877,
hostname: "127.0.0.1",
fetch: () => new Response(),
})
//#when
// when
const port = await findAvailablePort(19877)
//#then
// then
expect(port).toBeGreaterThan(19877)
blocker.stop(true)
})
@@ -44,23 +44,23 @@ describe("startCallbackServer", () => {
})
it("starts server and returns port", async () => {
//#given - no preconditions
// given - no preconditions
//#when
// when
server = await startCallbackServer()
//#then
// then
expect(server.port).toBeGreaterThanOrEqual(19877)
expect(typeof server.waitForCallback).toBe("function")
expect(typeof server.close).toBe("function")
})
it("resolves callback with code and state from query params", async () => {
//#given
// given
server = await startCallbackServer()
const callbackUrl = `http://127.0.0.1:${server.port}/oauth/callback?code=test-code&state=test-state`
//#when
// when
// Use Promise.all to ensure fetch and waitForCallback run concurrently
// This prevents race condition where waitForCallback blocks before fetch starts
const [result, response] = await Promise.all([
@@ -68,7 +68,7 @@ describe("startCallbackServer", () => {
nativeFetch(callbackUrl)
])
//#then
// then
expect(result).toEqual({ code: "test-code", state: "test-state" })
expect(response.status).toBe(200)
const html = await response.text()
@@ -76,25 +76,25 @@ describe("startCallbackServer", () => {
})
it("returns 404 for non-callback routes", async () => {
//#given
// given
server = await startCallbackServer()
//#when
// when
const response = await nativeFetch(`http://127.0.0.1:${server.port}/other`)
//#then
// then
expect(response.status).toBe(404)
})
it("returns 400 and rejects when code is missing", async () => {
//#given
// given
server = await startCallbackServer()
const callbackRejection = server.waitForCallback().catch((e: Error) => e)
//#when
// when
const response = await nativeFetch(`http://127.0.0.1:${server.port}/oauth/callback?state=s`)
//#then
// then
expect(response.status).toBe(400)
const error = await callbackRejection
expect(error).toBeInstanceOf(Error)
@@ -102,14 +102,14 @@ describe("startCallbackServer", () => {
})
it("returns 400 and rejects when state is missing", async () => {
//#given
// given
server = await startCallbackServer()
const callbackRejection = server.waitForCallback().catch((e: Error) => e)
//#when
// when
const response = await nativeFetch(`http://127.0.0.1:${server.port}/oauth/callback?code=c`)
//#then
// then
expect(response.status).toBe(400)
const error = await callbackRejection
expect(error).toBeInstanceOf(Error)
@@ -117,15 +117,15 @@ describe("startCallbackServer", () => {
})
it("close stops the server immediately", async () => {
//#given
// given
server = await startCallbackServer()
const port = server.port
//#when
// when
server.close()
server = null
//#then
// then
try {
await nativeFetch(`http://127.0.0.1:${port}/oauth/callback?code=c&state=s`)
expect(true).toBe(false)
+12 -12
View File
@@ -27,7 +27,7 @@ function createStorage(initial: ClientCredentials | null):
describe("getOrRegisterClient", () => {
it("returns cached registration when available", async () => {
// #given
// given
const storage = createStorage({
clientId: "cached-client",
clientSecret: "cached-secret",
@@ -36,7 +36,7 @@ describe("getOrRegisterClient", () => {
throw new Error("fetch should not be called")
}
// #when
// when
const result = await getOrRegisterClient({
registrationEndpoint: "https://server.example.com/register",
serverIdentifier: "server-1",
@@ -47,7 +47,7 @@ describe("getOrRegisterClient", () => {
fetch: fetchMock,
})
// #then
// then
expect(result).toEqual({
clientId: "cached-client",
clientSecret: "cached-secret",
@@ -55,7 +55,7 @@ describe("getOrRegisterClient", () => {
})
it("registers client and stores credentials when endpoint available", async () => {
// #given
// given
const storage = createStorage(null)
let fetchCalled = false
const fetchMock: DcrFetch = async (
@@ -85,7 +85,7 @@ describe("getOrRegisterClient", () => {
}
}
// #when
// when
const result = await getOrRegisterClient({
registrationEndpoint: "https://server.example.com/register",
serverIdentifier: "server-2",
@@ -96,7 +96,7 @@ describe("getOrRegisterClient", () => {
fetch: fetchMock,
})
// #then
// then
expect(fetchCalled).toBe(true)
expect(result).toEqual({
clientId: "registered-client",
@@ -110,7 +110,7 @@ describe("getOrRegisterClient", () => {
})
it("uses config client id when registration endpoint missing", async () => {
// #given
// given
const storage = createStorage(null)
let fetchCalled = false
const fetchMock: DcrFetch = async () => {
@@ -121,7 +121,7 @@ describe("getOrRegisterClient", () => {
}
}
// #when
// when
const result = await getOrRegisterClient({
registrationEndpoint: undefined,
serverIdentifier: "server-3",
@@ -133,19 +133,19 @@ describe("getOrRegisterClient", () => {
fetch: fetchMock,
})
// #then
// then
expect(fetchCalled).toBe(false)
expect(result).toEqual({ clientId: "config-client" })
})
it("falls back to config client id when registration fails", async () => {
// #given
// given
const storage = createStorage(null)
const fetchMock: DcrFetch = async () => {
throw new Error("network error")
}
// #when
// when
const result = await getOrRegisterClient({
registrationEndpoint: "https://server.example.com/register",
serverIdentifier: "server-4",
@@ -157,7 +157,7 @@ describe("getOrRegisterClient", () => {
fetch: fetchMock,
})
// #then
// then
expect(result).toEqual({ clientId: "fallback-client" })
expect(storage.getLastSet()).toBeNull()
})
+15 -15
View File
@@ -13,7 +13,7 @@ describe("discoverOAuthServerMetadata", () => {
})
test("returns endpoints from PRM + AS discovery", () => {
// #given
// given
const resource = "https://mcp.example.com"
const prmUrl = new URL("/.well-known/oauth-protected-resource", resource).toString()
const authServer = "https://auth.example.com"
@@ -39,9 +39,9 @@ describe("discoverOAuthServerMetadata", () => {
}
Object.defineProperty(globalThis, "fetch", { value: fetchMock, configurable: true })
// #when
// when
return discoverOAuthServerMetadata(resource).then((result) => {
// #then
// then
expect(result).toEqual({
authorizationEndpoint: "https://auth.example.com/authorize",
tokenEndpoint: "https://auth.example.com/token",
@@ -53,7 +53,7 @@ describe("discoverOAuthServerMetadata", () => {
})
test("falls back to RFC 8414 when PRM returns 404", () => {
// #given
// given
const resource = "https://mcp.example.com"
const prmUrl = new URL("/.well-known/oauth-protected-resource", resource).toString()
const asUrl = new URL("/.well-known/oauth-authorization-server", resource).toString()
@@ -77,9 +77,9 @@ describe("discoverOAuthServerMetadata", () => {
}
Object.defineProperty(globalThis, "fetch", { value: fetchMock, configurable: true })
// #when
// when
return discoverOAuthServerMetadata(resource).then((result) => {
// #then
// then
expect(result).toEqual({
authorizationEndpoint: "https://mcp.example.com/authorize",
tokenEndpoint: "https://mcp.example.com/token",
@@ -91,7 +91,7 @@ describe("discoverOAuthServerMetadata", () => {
})
test("throws when both PRM and AS discovery return 404", () => {
// #given
// given
const resource = "https://mcp.example.com"
const prmUrl = new URL("/.well-known/oauth-protected-resource", resource).toString()
const asUrl = new URL("/.well-known/oauth-authorization-server", resource).toString()
@@ -104,15 +104,15 @@ describe("discoverOAuthServerMetadata", () => {
}
Object.defineProperty(globalThis, "fetch", { value: fetchMock, configurable: true })
// #when
// when
const result = discoverOAuthServerMetadata(resource)
// #then
// then
return expect(result).rejects.toThrow("OAuth authorization server metadata not found")
})
test("throws when AS metadata is malformed", () => {
// #given
// given
const resource = "https://mcp.example.com"
const prmUrl = new URL("/.well-known/oauth-protected-resource", resource).toString()
const authServer = "https://auth.example.com"
@@ -131,15 +131,15 @@ describe("discoverOAuthServerMetadata", () => {
}
Object.defineProperty(globalThis, "fetch", { value: fetchMock, configurable: true })
// #when
// when
const result = discoverOAuthServerMetadata(resource)
// #then
// then
return expect(result).rejects.toThrow("token_endpoint")
})
test("caches discovery results per resource URL", () => {
// #given
// given
const resource = "https://mcp.example.com"
const prmUrl = new URL("/.well-known/oauth-protected-resource", resource).toString()
const authServer = "https://auth.example.com"
@@ -164,11 +164,11 @@ describe("discoverOAuthServerMetadata", () => {
}
Object.defineProperty(globalThis, "fetch", { value: fetchMock, configurable: true })
// #when
// when
return discoverOAuthServerMetadata(resource)
.then(() => discoverOAuthServerMetadata(resource))
.then(() => {
// #then
// then
expect(calls).toEqual([prmUrl, asUrl])
})
})
+36 -36
View File
@@ -6,49 +6,49 @@ import type { OAuthTokenData } from "./storage"
describe("McpOAuthProvider", () => {
describe("generateCodeVerifier", () => {
it("returns a base64url-encoded 32-byte random string", () => {
//#given
// given
const verifier = generateCodeVerifier()
//#when
// when
const decoded = Buffer.from(verifier, "base64url")
//#then
// then
expect(decoded.length).toBe(32)
expect(verifier).toMatch(/^[A-Za-z0-9_-]+$/)
})
it("produces unique values on each call", () => {
//#given
// given
const first = generateCodeVerifier()
//#when
// when
const second = generateCodeVerifier()
//#then
// then
expect(first).not.toBe(second)
})
})
describe("generateCodeChallenge", () => {
it("returns SHA256 base64url digest of the verifier", () => {
//#given
// given
const verifier = "test-verifier-value"
const expected = createHash("sha256").update(verifier).digest("base64url")
//#when
// when
const challenge = generateCodeChallenge(verifier)
//#then
// then
expect(challenge).toBe(expected)
})
})
describe("buildAuthorizationUrl", () => {
it("builds URL with all required PKCE parameters", () => {
//#given
// given
const endpoint = "https://auth.example.com/authorize"
//#when
// when
const url = buildAuthorizationUrl(endpoint, {
clientId: "my-client",
redirectUri: "http://127.0.0.1:8912/callback",
@@ -58,7 +58,7 @@ describe("McpOAuthProvider", () => {
resource: "https://mcp.example.com",
})
//#then
// then
const parsed = new URL(url)
expect(parsed.origin + parsed.pathname).toBe("https://auth.example.com/authorize")
expect(parsed.searchParams.get("response_type")).toBe("code")
@@ -72,10 +72,10 @@ describe("McpOAuthProvider", () => {
})
it("omits scope when empty", () => {
//#given
// given
const endpoint = "https://auth.example.com/authorize"
//#when
// when
const url = buildAuthorizationUrl(endpoint, {
clientId: "my-client",
redirectUri: "http://127.0.0.1:8912/callback",
@@ -84,16 +84,16 @@ describe("McpOAuthProvider", () => {
scopes: [],
})
//#then
// then
const parsed = new URL(url)
expect(parsed.searchParams.has("scope")).toBe(false)
})
it("omits resource when undefined", () => {
//#given
// given
const endpoint = "https://auth.example.com/authorize"
//#when
// when
const url = buildAuthorizationUrl(endpoint, {
clientId: "my-client",
redirectUri: "http://127.0.0.1:8912/callback",
@@ -101,7 +101,7 @@ describe("McpOAuthProvider", () => {
state: "state-value",
})
//#then
// then
const parsed = new URL(url)
expect(parsed.searchParams.has("resource")).toBe(false)
})
@@ -109,43 +109,43 @@ describe("McpOAuthProvider", () => {
describe("constructor and basic methods", () => {
it("stores serverUrl and optional clientId and scopes", () => {
//#given
// given
const options = {
serverUrl: "https://mcp.example.com",
clientId: "my-client",
scopes: ["openid"],
}
//#when
// when
const provider = new McpOAuthProvider(options)
//#then
// then
expect(provider.tokens()).toBeNull()
expect(provider.clientInformation()).toBeNull()
expect(provider.codeVerifier()).toBeNull()
})
it("defaults scopes to empty array", () => {
//#given
// given
const options = { serverUrl: "https://mcp.example.com" }
//#when
// when
const provider = new McpOAuthProvider(options)
//#then
// then
expect(provider.redirectUrl()).toBe("http://127.0.0.1:19877/callback")
})
})
describe("saveCodeVerifier / codeVerifier", () => {
it("stores and retrieves code verifier", () => {
//#given
// given
const provider = new McpOAuthProvider({ serverUrl: "https://mcp.example.com" })
//#when
// when
provider.saveCodeVerifier("my-verifier")
//#then
// then
expect(provider.codeVerifier()).toBe("my-verifier")
})
})
@@ -172,7 +172,7 @@ describe("McpOAuthProvider", () => {
})
it("persists and loads token data via storage", () => {
//#given
// given
const provider = new McpOAuthProvider({ serverUrl: "https://mcp.example.com" })
const tokenData: OAuthTokenData = {
accessToken: "access-token-123",
@@ -180,11 +180,11 @@ describe("McpOAuthProvider", () => {
expiresAt: 1710000000,
}
//#when
// when
const saved = provider.saveTokens(tokenData)
const loaded = provider.tokens()
//#then
// then
expect(saved).toBe(true)
expect(loaded).toEqual(tokenData)
})
@@ -192,7 +192,7 @@ describe("McpOAuthProvider", () => {
describe("redirectToAuthorization", () => {
it("throws when no client information is set", async () => {
//#given
// given
const provider = new McpOAuthProvider({ serverUrl: "https://mcp.example.com" })
const metadata = {
authorizationEndpoint: "https://auth.example.com/authorize",
@@ -200,23 +200,23 @@ describe("McpOAuthProvider", () => {
resource: "https://mcp.example.com",
}
//#when
// when
const result = provider.redirectToAuthorization(metadata)
//#then
// then
await expect(result).rejects.toThrow("No client information available")
})
})
describe("redirectUrl", () => {
it("returns localhost callback URL with default port", () => {
//#given
// given
const provider = new McpOAuthProvider({ serverUrl: "https://mcp.example.com" })
//#when
// when
const url = provider.redirectUrl()
//#then
// then
expect(url).toBe("http://127.0.0.1:19877/callback")
})
})
@@ -3,118 +3,118 @@ import { addResourceToParams, getResourceIndicator } from "./resource-indicator"
describe("getResourceIndicator", () => {
it("returns URL unchanged when already normalized", () => {
// #given
// given
const url = "https://mcp.example.com"
// #when
// when
const result = getResourceIndicator(url)
// #then
// then
expect(result).toBe("https://mcp.example.com")
})
it("strips trailing slash", () => {
// #given
// given
const url = "https://mcp.example.com/"
// #when
// when
const result = getResourceIndicator(url)
// #then
// then
expect(result).toBe("https://mcp.example.com")
})
it("strips query parameters", () => {
// #given
// given
const url = "https://mcp.example.com/v1?token=abc&debug=true"
// #when
// when
const result = getResourceIndicator(url)
// #then
// then
expect(result).toBe("https://mcp.example.com/v1")
})
it("strips fragment", () => {
// #given
// given
const url = "https://mcp.example.com/v1#section"
// #when
// when
const result = getResourceIndicator(url)
// #then
// then
expect(result).toBe("https://mcp.example.com/v1")
})
it("strips query and trailing slash together", () => {
// #given
// given
const url = "https://mcp.example.com/api/?key=val"
// #when
// when
const result = getResourceIndicator(url)
// #then
// then
expect(result).toBe("https://mcp.example.com/api")
})
it("preserves path segments", () => {
// #given
// given
const url = "https://mcp.example.com/org/project/v2"
// #when
// when
const result = getResourceIndicator(url)
// #then
// then
expect(result).toBe("https://mcp.example.com/org/project/v2")
})
it("preserves port number", () => {
// #given
// given
const url = "https://mcp.example.com:8443/api/"
// #when
// when
const result = getResourceIndicator(url)
// #then
// then
expect(result).toBe("https://mcp.example.com:8443/api")
})
})
describe("addResourceToParams", () => {
it("sets resource parameter on empty params", () => {
// #given
// given
const params = new URLSearchParams()
const resource = "https://mcp.example.com"
// #when
// when
addResourceToParams(params, resource)
// #then
// then
expect(params.get("resource")).toBe("https://mcp.example.com")
})
it("adds resource alongside existing parameters", () => {
// #given
// given
const params = new URLSearchParams({ grant_type: "authorization_code" })
const resource = "https://mcp.example.com/v1"
// #when
// when
addResourceToParams(params, resource)
// #then
// then
expect(params.get("grant_type")).toBe("authorization_code")
expect(params.get("resource")).toBe("https://mcp.example.com/v1")
})
it("overwrites existing resource parameter", () => {
// #given
// given
const params = new URLSearchParams({ resource: "https://old.example.com" })
const resource = "https://new.example.com"
// #when
// when
addResourceToParams(params, resource)
// #then
// then
expect(params.get("resource")).toBe("https://new.example.com")
expect(params.getAll("resource")).toHaveLength(1)
})
+15 -15
View File
@@ -4,57 +4,57 @@ import { McpOauthSchema } from "./schema"
describe("McpOauthSchema", () => {
test("parses empty oauth config", () => {
//#given
// given
const input = {}
//#when
// when
const result = McpOauthSchema.parse(input)
//#then
// then
expect(result).toEqual({})
})
test("parses oauth config with clientId", () => {
//#given
// given
const input = { clientId: "client-123" }
//#when
// when
const result = McpOauthSchema.parse(input)
//#then
// then
expect(result).toEqual({ clientId: "client-123" })
})
test("parses oauth config with scopes", () => {
//#given
// given
const input = { scopes: ["openid", "profile"] }
//#when
// when
const result = McpOauthSchema.parse(input)
//#then
// then
expect(result).toEqual({ scopes: ["openid", "profile"] })
})
test("rejects non-string clientId", () => {
//#given
// given
const input = { clientId: 123 }
//#when
// when
const result = McpOauthSchema.safeParse(input)
//#then
// then
expect(result.success).toBe(false)
})
test("rejects non-string scopes", () => {
//#given
// given
const input = { scopes: ["openid", 42] }
//#when
// when
const result = McpOauthSchema.safeParse(input)
//#then
// then
expect(result.success).toBe(false)
})
})
+54 -54
View File
@@ -3,24 +3,24 @@ import { isStepUpRequired, mergeScopes, parseWwwAuthenticate } from "./step-up"
describe("parseWwwAuthenticate", () => {
it("parses scope from simple Bearer header", () => {
// #given
// given
const header = 'Bearer scope="read write"'
// #when
// when
const result = parseWwwAuthenticate(header)
// #then
// then
expect(result).toEqual({ requiredScopes: ["read", "write"] })
})
it("parses scope with error fields", () => {
// #given
// given
const header = 'Bearer error="insufficient_scope", scope="admin"'
// #when
// when
const result = parseWwwAuthenticate(header)
// #then
// then
expect(result).toEqual({
requiredScopes: ["admin"],
error: "insufficient_scope",
@@ -28,14 +28,14 @@ describe("parseWwwAuthenticate", () => {
})
it("parses all fields including error_description", () => {
// #given
// given
const header =
'Bearer realm="example", error="insufficient_scope", error_description="Need admin access", scope="admin write"'
// #when
// when
const result = parseWwwAuthenticate(header)
// #then
// then
expect(result).toEqual({
requiredScopes: ["admin", "write"],
error: "insufficient_scope",
@@ -44,180 +44,180 @@ describe("parseWwwAuthenticate", () => {
})
it("returns null for non-Bearer scheme", () => {
// #given
// given
const header = 'Basic realm="example"'
// #when
// when
const result = parseWwwAuthenticate(header)
// #then
// then
expect(result).toBeNull()
})
it("returns null when no scope parameter present", () => {
// #given
// given
const header = 'Bearer error="invalid_token"'
// #when
// when
const result = parseWwwAuthenticate(header)
// #then
// then
expect(result).toBeNull()
})
it("returns null for empty scope value", () => {
// #given
// given
const header = 'Bearer scope=""'
// #when
// when
const result = parseWwwAuthenticate(header)
// #then
// then
expect(result).toBeNull()
})
it("returns null for bare Bearer with no params", () => {
// #given
// given
const header = "Bearer"
// #when
// when
const result = parseWwwAuthenticate(header)
// #then
// then
expect(result).toBeNull()
})
it("handles case-insensitive Bearer prefix", () => {
// #given
// given
const header = 'bearer scope="read"'
// #when
// when
const result = parseWwwAuthenticate(header)
// #then
// then
expect(result).toEqual({ requiredScopes: ["read"] })
})
it("parses single scope value", () => {
// #given
// given
const header = 'Bearer scope="admin"'
// #when
// when
const result = parseWwwAuthenticate(header)
// #then
// then
expect(result).toEqual({ requiredScopes: ["admin"] })
})
})
describe("mergeScopes", () => {
it("merges new scopes into existing", () => {
// #given
// given
const existing = ["read", "write"]
const required = ["admin", "write"]
// #when
// when
const result = mergeScopes(existing, required)
// #then
// then
expect(result).toEqual(["read", "write", "admin"])
})
it("returns required when existing is empty", () => {
// #given
// given
const existing: string[] = []
const required = ["read", "write"]
// #when
// when
const result = mergeScopes(existing, required)
// #then
// then
expect(result).toEqual(["read", "write"])
})
it("returns existing when required is empty", () => {
// #given
// given
const existing = ["read"]
const required: string[] = []
// #when
// when
const result = mergeScopes(existing, required)
// #then
// then
expect(result).toEqual(["read"])
})
it("deduplicates identical scopes", () => {
// #given
// given
const existing = ["read", "write"]
const required = ["read", "write"]
// #when
// when
const result = mergeScopes(existing, required)
// #then
// then
expect(result).toEqual(["read", "write"])
})
})
describe("isStepUpRequired", () => {
it("returns step-up info for 403 with WWW-Authenticate", () => {
// #given
// given
const statusCode = 403
const headers = { "www-authenticate": 'Bearer scope="admin"' }
// #when
// when
const result = isStepUpRequired(statusCode, headers)
// #then
// then
expect(result).toEqual({ requiredScopes: ["admin"] })
})
it("returns null for non-403 status", () => {
// #given
// given
const statusCode = 401
const headers = { "www-authenticate": 'Bearer scope="admin"' }
// #when
// when
const result = isStepUpRequired(statusCode, headers)
// #then
// then
expect(result).toBeNull()
})
it("returns null when no WWW-Authenticate header", () => {
// #given
// given
const statusCode = 403
const headers = { "content-type": "application/json" }
// #when
// when
const result = isStepUpRequired(statusCode, headers)
// #then
// then
expect(result).toBeNull()
})
it("handles capitalized WWW-Authenticate header", () => {
// #given
// given
const statusCode = 403
const headers = { "WWW-Authenticate": 'Bearer scope="read write"' }
// #when
// when
const result = isStepUpRequired(statusCode, headers)
// #then
// then
expect(result).toEqual({ requiredScopes: ["read", "write"] })
})
it("returns null for 403 with unparseable WWW-Authenticate", () => {
// #given
// given
const statusCode = 403
const headers = { "www-authenticate": 'Basic realm="example"' }
// #when
// when
const result = isStepUpRequired(statusCode, headers)
// #then
// then
expect(result).toBeNull()
})
})
+18 -18
View File
@@ -36,7 +36,7 @@ describe("mcp-oauth storage", () => {
})
test("should save tokens with {host}/{resource} key and set 0600 permissions", () => {
// #given
// given
const token: OAuthTokenData = {
accessToken: "access-1",
refreshToken: "refresh-1",
@@ -44,13 +44,13 @@ describe("mcp-oauth storage", () => {
clientInfo: { clientId: "client-1", clientSecret: "secret-1" },
}
// #when
// when
const success = saveToken("https://example.com:443", "mcp/v1", token)
const storagePath = getMcpOauthStoragePath()
const parsed = JSON.parse(readFileSync(storagePath, "utf-8")) as Record<string, OAuthTokenData>
const mode = statSync(storagePath).mode & 0o777
// #then
// then
expect(success).toBe(true)
expect(Object.keys(parsed)).toEqual(["example.com/mcp/v1"])
expect(parsed["example.com/mcp/v1"].accessToken).toBe("access-1")
@@ -58,41 +58,41 @@ describe("mcp-oauth storage", () => {
})
test("should load a saved token", () => {
// #given
// given
const token: OAuthTokenData = { accessToken: "access-2", refreshToken: "refresh-2" }
saveToken("api.example.com", "resource-a", token)
// #when
// when
const loaded = loadToken("api.example.com:8443", "resource-a")
// #then
// then
expect(loaded).toEqual(token)
})
test("should delete a token", () => {
// #given
// given
const token: OAuthTokenData = { accessToken: "access-3" }
saveToken("api.example.com", "resource-b", token)
// #when
// when
const success = deleteToken("api.example.com", "resource-b")
const loaded = loadToken("api.example.com", "resource-b")
// #then
// then
expect(success).toBe(true)
expect(loaded).toBeNull()
})
test("should list tokens by host", () => {
// #given
// given
saveToken("api.example.com", "resource-a", { accessToken: "access-a" })
saveToken("api.example.com", "resource-b", { accessToken: "access-b" })
saveToken("other.example.com", "resource-c", { accessToken: "access-c" })
// #when
// when
const entries = listTokensByHost("api.example.com:5555")
// #then
// then
expect(Object.keys(entries).sort()).toEqual([
"api.example.com/resource-a",
"api.example.com/resource-b",
@@ -101,23 +101,23 @@ describe("mcp-oauth storage", () => {
})
test("should handle missing storage file", () => {
// #given
// given
const storagePath = getMcpOauthStoragePath()
if (existsSync(storagePath)) {
rmSync(storagePath, { force: true })
}
// #when
// when
const loaded = loadToken("api.example.com", "resource-a")
const entries = listTokensByHost("api.example.com")
// #then
// then
expect(loaded).toBeNull()
expect(entries).toEqual({})
})
test("should handle invalid JSON", () => {
// #given
// given
const storagePath = getMcpOauthStoragePath()
const dir = join(storagePath, "..")
if (!existsSync(dir)) {
@@ -125,11 +125,11 @@ describe("mcp-oauth storage", () => {
}
writeFileSync(storagePath, "{not-valid-json", "utf-8")
// #when
// when
const loaded = loadToken("api.example.com", "resource-a")
const entries = listTokensByHost("api.example.com")
// #then
// then
expect(loaded).toBeNull()
expect(entries).toEqual({})
})