Team Ai
Modelpublic

Felipe97/llama-cpp-compiled

sourceHugging Faceupdated 21d agoView on Hugging Face
0likes1.2kdownloads
sanitize-headers.test.ts80 linesDownload Raw Back to unit
1import { CORS_PROXY } from '$lib/constants';2import { sanitizeHeaders } from '$lib/utils/api-headers';3import { describe, expect, it } from 'vitest';4 5describe('sanitizeHeaders', () => {6	it('returns empty object for undefined input', () => {7		expect(sanitizeHeaders()).toEqual({});8	});9 10	it('passes through non-sensitive headers', () => {11		const headers = new Headers({ accept: 'text/html', 'content-type': 'application/json' });12 13		expect(sanitizeHeaders(headers)).toEqual({14			accept: 'text/html',15			'content-type': 'application/json'16		});17	});18 19	it('redacts known sensitive headers', () => {20		const headers = new Headers({21			authorization: 'Bearer secret',22			'content-type': 'application/json',23			'x-api-key': 'key-123'24		});25		const result = sanitizeHeaders(headers);26 27		expect(result.authorization).toBe('[redacted]');28		expect(result['x-api-key']).toBe('[redacted]');29		expect(result['content-type']).toBe('application/json');30	});31 32	it('partially redacts headers specified in partialRedactHeaders', () => {33		const headers = new Headers({ 'mcp-session-id': 'session-12345' });34		const partial = new Map([['mcp-session-id', 5]]);35 36		expect(sanitizeHeaders(headers, undefined, partial)['mcp-session-id']).toBe('....12345');37	});38 39	it('fully redacts mcp-session-id when no partialRedactHeaders is given', () => {40		const headers = new Headers({ 'mcp-session-id': 'session-12345' });41 42		expect(sanitizeHeaders(headers)['mcp-session-id']).toBe('[redacted]');43	});44 45	it('redacts extra headers provided by the caller', () => {46		const headers = new Headers({47			'content-type': 'application/json',48			'x-vendor-key': 'vendor-secret'49		});50		const result = sanitizeHeaders(headers, ['x-vendor-key']);51 52		expect(result['x-vendor-key']).toBe('[redacted]');53		expect(result['content-type']).toBe('application/json');54	});55 56	it('handles case-insensitive extra header names', () => {57		const headers = new Headers({ 'X-Custom-Token': 'token-value' });58		const result = sanitizeHeaders(headers, ['X-CUSTOM-TOKEN']);59 60		expect(result['x-custom-token']).toBe('[redacted]');61	});62 63	it('redacts proxied sensitive and custom target headers', () => {64		const proxiedAuthorization = `${CORS_PROXY.HEADER_PREFIX}authorization`;65		const proxiedSessionId = `${CORS_PROXY.HEADER_PREFIX}mcp-session-id`;66		const proxiedVendorKey = `${CORS_PROXY.HEADER_PREFIX}x-vendor-key`;67		const headers = new Headers({68			[proxiedAuthorization]: 'Bearer secret',69			[proxiedSessionId]: 'session-12345',70			[proxiedVendorKey]: 'vendor-secret'71		});72		const partial = new Map([['mcp-session-id', 5]]);73		const result = sanitizeHeaders(headers, ['x-vendor-key'], partial);74 75		expect(result[proxiedAuthorization]).toBe('[redacted]');76		expect(result[proxiedSessionId]).toBe('....12345');77		expect(result[proxiedVendorKey]).toBe('[redacted]');78	});79});80