5d0f86606a
deploy / deploy (push) Has been cancelled
generate / generate (push) Has been cancelled
nix-eval / nix-eval (push) Has been cancelled
nix-hashes / compute-hash (blacksmith-4vcpu-ubuntu-2404, x86_64-linux) (push) Has been cancelled
nix-hashes / compute-hash (blacksmith-4vcpu-ubuntu-2404-arm, aarch64-linux) (push) Has been cancelled
nix-hashes / compute-hash (macos-15-intel, x86_64-darwin) (push) Has been cancelled
nix-hashes / compute-hash (macos-latest, aarch64-darwin) (push) Has been cancelled
publish / version (push) Has been cancelled
storybook / storybook build (push) Has been cancelled
typecheck / typecheck (push) Has been cancelled
nix-hashes / update-hashes (push) Has been cancelled
publish / build-cli (push) Has been cancelled
publish / sign-cli-windows (push) Has been cancelled
publish / build-electron (map[bun_install_flags:--os=darwin --cpu=arm64 host:macos-26 platform_flag:--mac --arm64 target:aarch64-apple-darwin]) (push) Has been cancelled
publish / build-electron (map[bun_install_flags:--os=darwin --cpu=x64 host:macos-26-intel platform_flag:--mac --x64 target:x86_64-apple-darwin]) (push) Has been cancelled
publish / build-electron (map[host:blacksmith-4vcpu-ubuntu-2404 platform_flag:--linux target:x86_64-unknown-linux-gnu]) (push) Has been cancelled
publish / build-electron (map[host:blacksmith-4vcpu-ubuntu-2404-arm platform_flag:--linux --arm64 target:aarch64-unknown-linux-gnu]) (push) Has been cancelled
publish / build-electron (map[host:blacksmith-4vcpu-windows-2025 platform_flag:--win target:x86_64-pc-windows-msvc]) (push) Has been cancelled
publish / build-electron (map[host:windows-2025 platform_flag:--win --arm64 target:aarch64-pc-windows-msvc]) (push) Has been cancelled
publish / publish (push) Has been cancelled
73 lines
2.7 KiB
TypeScript
73 lines
2.7 KiB
TypeScript
import { test, expect, describe, afterEach } from "bun:test"
|
|
import { McpOAuthCallback } from "../../src/mcp/oauth-callback"
|
|
import { parseRedirectUri } from "../../src/mcp/oauth-provider"
|
|
|
|
describe("parseRedirectUri", () => {
|
|
test("returns defaults when no URI provided", () => {
|
|
const result = parseRedirectUri()
|
|
expect(result.port).toBe(19876)
|
|
expect(result.path).toBe("/mcp/oauth/callback")
|
|
})
|
|
|
|
test("parses port and path from URI", () => {
|
|
const result = parseRedirectUri("http://127.0.0.1:8080/oauth/callback")
|
|
expect(result.port).toBe(8080)
|
|
expect(result.path).toBe("/oauth/callback")
|
|
})
|
|
|
|
test("returns defaults for invalid URI", () => {
|
|
const result = parseRedirectUri("not-a-valid-url")
|
|
expect(result.port).toBe(19876)
|
|
expect(result.path).toBe("/mcp/oauth/callback")
|
|
})
|
|
})
|
|
|
|
describe("McpOAuthCallback.ensureRunning", () => {
|
|
afterEach(async () => {
|
|
await McpOAuthCallback.stop()
|
|
})
|
|
|
|
test("starts server with custom redirectUri port and path", async () => {
|
|
await McpOAuthCallback.ensureRunning("http://127.0.0.1:18000/custom/callback")
|
|
expect(McpOAuthCallback.isRunning()).toBe(true)
|
|
})
|
|
|
|
test("stops after the callback completes", async () => {
|
|
const redirectUri = "http://127.0.0.1:18003/custom/callback"
|
|
await McpOAuthCallback.ensureRunning(redirectUri)
|
|
const callback = McpOAuthCallback.waitForCallback("success")
|
|
|
|
const response = await fetch(`${redirectUri}?code=code&state=success`)
|
|
|
|
expect(response.status).toBe(200)
|
|
expect(await callback).toBe("code")
|
|
expect(McpOAuthCallback.isRunning()).toBe(false)
|
|
})
|
|
|
|
test("escapes provider error markup in callback HTML", async () => {
|
|
const redirectUri = "http://127.0.0.1:18001/custom/callback"
|
|
await McpOAuthCallback.ensureRunning(redirectUri)
|
|
|
|
const error = `<script>alert("xss" & 'more')</script>`
|
|
const response = await fetch(
|
|
`${redirectUri}?state=test&error=access_denied&error_description=${encodeURIComponent(error)}`,
|
|
)
|
|
const body = await response.text()
|
|
|
|
expect(response.headers.get("content-type")).toBe("text/html; charset=utf-8")
|
|
expect(body).toContain("<script>alert("xss" & 'more')</script>")
|
|
expect(body).not.toContain(error)
|
|
})
|
|
|
|
test("keeps normal provider errors readable", async () => {
|
|
const redirectUri = "http://127.0.0.1:18002/custom/callback"
|
|
await McpOAuthCallback.ensureRunning(redirectUri)
|
|
|
|
const response = await fetch(
|
|
`${redirectUri}?state=test&error=access_denied&error_description=${encodeURIComponent("The user denied access")}`,
|
|
)
|
|
|
|
expect(await response.text()).toContain('<div class="error">The user denied access</div>')
|
|
})
|
|
})
|