import assert from "node:assert/strict"; import { randomBytes } from "node:crypto"; import { mkdtemp, readFile, readdir, rm, writeFile } from "node:fs/promises"; import { createServer } from "node:net"; import { tmpdir } from "node:os"; import { join, resolve } from "node:path"; import { test } from "node:test"; import { unstable_dev } from "wrangler"; import { parse } from "jsonc-parser"; import { oauthBindings, oauthConfig } from "./fixtures/oauth-config.mjs"; import { parseInstallation } from "../control-plane/installation-metadata.ts"; import "./fixtures/config.mjs"; const A = "a".repeat(32), B = "b".repeat(32); const id = () => randomBytes(16).toString("hex"); const release = (digit = "1") => ({ version: `0.1.0-dev.${digit}`, sourceRevision: digit.repeat(40), artifactDigest: digit.repeat(64), }); const setCookie = (response, name) => response.headers .getSetCookie() .find((v) => v.startsWith(`${name}=`)) ?.split(";")[0]; async function freePort() { const server = createServer(); await new Promise((done) => server.listen(0, "127.0.0.1", done)); const { port } = server.address(); await new Promise((done) => server.close(done)); return port; } test( "native ownership registry isolates owners and preserves atomic metadata across replay and restart", { timeout: 120_000 }, async (t) => { const temporary = await mkdtemp(join(tmpdir(), "flarebot-ownership-")); const port = await freePort(); const origin = `http://127.0.0.1:${port}`; const configPath = join(temporary, "wrangler.json"); // Production routes rewrite the request host in Miniflare. These direct // localhost requests must retain the fixture's configured origin instead. const { routes: _productionRoutes, workers_dev: _productionWorkersDev, ...base } = parse(await readFile("wrangler.control-plane.jsonc", "utf8")); await writeFile( configPath, JSON.stringify({ ...base, name: "flarebot-ownership-test", main: resolve("tests/fixtures/ownership-worker.ts"), assets: { directory: resolve("dist/control-plane/client"), binding: "ASSETS", }, }), ); let bindings = oauthBindings(origin); const start = () => unstable_dev("tests/fixtures/ownership-worker.ts", { config: configPath, vars: bindings, local: true, ip: "127.0.0.1", port, inspectorPort: 0, persist: true, persistTo: temporary, logLevel: "error", experimental: { disableExperimentalWarning: true, watch: false }, }); let worker; t.after(async () => { await worker?.stop(); await rm(temporary, { recursive: true, force: true }); }); const logs = []; for (const method of ["log", "warn", "error"]) { const original = console[method]; t.mock.method(console, method, (...args) => { logs.push(args.map(String).join(" ")); original(...args); }); } const call = (path, options = {}) => fetch(`${origin}${path}`, { redirect: "manual", ...options, headers: { Origin: origin, ...options.headers }, }); const admin = async (path, body = {}, cookie = "") => ( await call(`/__test__/${path}`, { method: "POST", headers: { Cookie: cookie, "Content-Type": "application/json" }, body: JSON.stringify(body), }) ).json(); const form = (path, cookie, values, headers = {}) => call(path, { method: "POST", headers: { Cookie: cookie, "Content-Type": "application/x-www-form-urlencoded", ...headers, }, body: new URLSearchParams(values).toString(), }); async function login(mode = "normal") { const start = await form("/auth/start", "", {}); const location = new URL(start.headers.get("Location")); const code = id(); await admin("code", { code, challenge: location.searchParams.get("code_challenge"), mode, }); const callback = await call( `/auth/callback?state=${location.searchParams.get("state")}&code=${code}`, { headers: { Cookie: setCookie(start, "__Host-flarebot-oauth") } }, ); assert.equal(callback.headers.get("Location"), "/connect"); return setCookie(callback, "__Host-flarebot-control-session"); } const select = (cookie, accountId) => form("/api/account", cookie, { accountId }); const reserve = (cookie, requestId = id()) => form("/api/installations", cookie, { requestId }); const get = (cookie, installationId) => call(`/api/installations/${installationId}`, { headers: { Cookie: cookie }, }); const list = (cookie, query = "") => call(`/api/installations${query}`, { headers: { Cookie: cookie } }); const update = (cookie, record, changes, revision = record.revision) => admin( "metadata/update", { id: record.installationId, revision, changes }, cookie, ); const inspect = (cookie) => admin("metadata/inspect", {}, cookie); worker = await start(); const first = await login(); const second = await login("second-owner"); let record; const requestId = id(); await t.test( "real verified identity/account and strict browser mutation boundary", async () => { assert.equal((await reserve("")).status, 401); assert.equal((await list("")).status, 401); assert.equal((await reserve(first)).status, 400); // no selected account assert.equal((await select(first, A)).status, 200); assert.equal((await select(second, B)).status, 200); for (const field of [ "ownerSubject", "accountId", "desiredRelease", "accessToken", "messages", "runtimeOrigin", "installedRelease", "grantRef", ]) { const response = await form("/api/installations", first, { requestId, [field]: "private-content-sentinel", }); assert.equal(response.status, 400, field); } for (const values of [ [ ["requestId", requestId], ["requestId", id()], ], { requestId: "private-content-sentinel" }, { requestId: "a".repeat(3000) }, ]) assert.equal( (await form("/api/installations", first, values)).status, 400, ); for (const Origin of ["", "null", "https://evil.example"]) assert.equal( (await form("/api/installations", first, { requestId }, { Origin })) .status, 403, ); assert.equal( ( await call("/api/installations", { method: "POST", headers: { Cookie: first, "Content-Type": "application/json" }, body: JSON.stringify({ requestId }), }) ).status, 400, ); assert.deepEqual(await inspect(first), {}); const response = await reserve(first, requestId); assert.equal(response.status, 200); assert.equal(response.headers.get("Cache-Control"), "no-store"); assert.equal(response.headers.get("Referrer-Policy"), "no-referrer"); record = (await response.json()).installation; assert.match(record.installationId, /^[a-f0-9]{32}$/); assert.equal(record.ownerSubject, "verified-userinfo-subject"); assert.equal(record.accountId, A); assert.equal(record.status, "reserved"); assert.equal(record.desiredRelease, null); assert.equal(record.installedRelease, null); assert.equal(record.resources.runtimeOrigin, null); assert.equal( record.resources.workerName, `flarebot-${record.installationId}`, ); assert.equal( record.resources.sandboxApplicationName, `flarebot-shell-${record.installationId}`, ); assert.deepEqual(parseInstallation(record), record); }, ); await t.test( "concurrent duplicate and lost reply replay, account conflict and owner isolation", async () => { const responses = await Promise.all( Array.from({ length: 12 }, () => reserve(first, requestId)), ); for (const response of responses) assert.deepEqual((await response.json()).installation, record); const ignored = id(); await reserve(first, ignored); // caller lost/ignored successful reply const retried = (await (await reserve(first, ignored)).json()) .installation; assert.notEqual(retried.installationId, record.installationId); assert.equal( (await (await list(first)).json()).installations.length, 2, ); assert.equal((await select(first, B)).status, 200); assert.equal((await reserve(first, requestId)).status, 409); const otherAccount = (await (await reserve(first)).json()).installation; assert.equal(otherAccount.accountId, B); assert.equal((await select(first, A)).status, 200); const otherOwner = (await (await reserve(second, requestId)).json()) .installation; assert.notEqual(otherOwner.installationId, record.installationId); assert.equal((await get(second, record.installationId)).status, 404); assert.deepEqual( await (await get(second, record.installationId)).json(), await (await get(second, id())).json(), ); assert.deepEqual((await (await list(second)).json()).installations, [ otherOwner, ]); assert.equal( ( await update(second, record, { status: "installing", desiredRelease: release(), operationId: id(), }) ).error, "installation_not_found", ); assert.deepEqual( await admin( "metadata/wrong-owner", { subject: otherOwner.ownerSubject, id: record.installationId }, first, ), { ok: false, error: "installation_not_found" }, ); assert.deepEqual(await admin("metadata/private-rpc", {}, first), { exposed: false, }); assert.equal( ( await call(`/api/installations/${record.installationId}`, { method: "PATCH", headers: { Cookie: first }, body: "{}", }) ).status, 404, ); assert.equal( ( await call("/agents/installation-registry/personal", { headers: { Cookie: first }, }) ).status, 404, ); }, ); await t.test( "withdrawn account access blocks reservation but preserves identity reads", async () => { const before = await inspect(first); for (const mode of ["denied", "empty"]) { await admin("accounts", { mode }); const response = await reserve(first); assert.equal(response.status, 400); assert.equal((await response.json()).error, "account_denied"); assert.deepEqual(await inspect(first), before); assert.equal((await get(first, record.installationId)).status, 200); assert.equal((await list(first)).status, 200); } await admin("accounts", { mode: "normal" }); }, ); await t.test( "private CAS pins desired release, assigns resource identity and preserves verified installed release", async () => { const start = { status: "installing", operationId: id(), desiredRelease: release(), }; for (const changes of [ { ...start, ownerSubject: "forged" }, { ...start, accountId: B }, { ...start, resources: { workerName: "another-worker" } }, { ...start, desiredRelease: { ...release(), accessToken: "oauth-secret-sentinel", }, }, { ...start, resources: { sandboxNamespaceId: A, memories: "private-content-sentinel", }, }, { ...start, installedRelease: { ...release(), installedAt: Date.now() }, }, { ...start, errorCode: "private-provider-error" }, { ...start, grantRef: id() }, { ...start, progress: "provider-private-error" }, { ...start, progress: { accessToken: "secret" } }, { ...start, progress: "complete" }, ]) assert.equal( (await update(first, record, changes)).error, "invalid_metadata", ); assert.deepEqual( (await (await get(first, record.installationId)).json()).installation, record, ); const racers = await Promise.all([ update(first, record, start), update(first, record, start), ]); assert.equal(racers.filter((r) => r.ok).length, 1); assert.equal(racers.find((r) => !r.ok).error, "installation_conflict"); const original = record; record = racers.find((r) => r.ok).value; assert.equal(record.revision, original.revision + 1); assert.equal(record.installedRelease, null); assert.equal( (await update(first, original, start)).error, "installation_conflict", ); assert.equal( (await update(first, record, { desiredRelease: release("2") })).error, "installation_conflict", ); assert.equal( (await update(first, record, { operationId: id() })).error, "installation_conflict", ); assert.equal( (await update(first, record, { status: "ready" })).error, "invalid_metadata", ); assert.equal( ( await update(first, record, { resources: { runtimeOrigin: "https://evil.example" }, }) ).error, "invalid_metadata", ); record = ( await update(first, record, { resources: { personalAgentNamespaceId: A, sandboxNamespaceId: B, sandboxApplicationId: "01234567-89ab-cdef-0123-456789abcdef", runtimeOrigin: `https://flarebot-${record.installationId}.customer.workers.dev`, }, }) ).value; for (const [key, value] of Object.entries(record.resources).filter( ([key]) => !key.endsWith("Name"), )) { assert.equal( (await update(first, record, { resources: { [key]: null } })).error, "installation_conflict", ); assert.equal( ( await update(first, record, { resources: { [key]: key === "runtimeOrigin" ? `https://flarebot-${record.installationId}.other.workers.dev` : "c".repeat(32), }, }) ).error, "installation_conflict", ); } record = (await update(first, record, { status: "ready" })).value; assert.equal(record.status, "ready"); assert.equal(record.progress, "complete"); assert.deepEqual(record.installedRelease, { ...release(), installedAt: record.updatedAt, }); const installed = record.installedRelease; record = ( await update(first, record, { status: "updating", operationId: id(), desiredRelease: release("2"), }) ).value; assert.deepEqual(record.installedRelease, installed); assert.equal(record.progress, "preparing"); record = ( await update(first, record, { status: "failed", errorCode: "health_failed", }) ).value; assert.deepEqual(record.installedRelease, installed); assert.equal(record.desiredRelease.version, "0.1.0-dev.2"); assert.equal(record.progress, "preparing"); record = ( await update(first, record, { status: "updating", operationId: id(), desiredRelease: release("2"), }) ).value; assert.equal(record.errorCode, null); record = (await update(first, record, { status: "ready" })).value; assert.equal(record.installedRelease.version, "0.1.0-dev.2"); assert.deepEqual( (await (await reserve(first, requestId)).json()).installation, record, ); }, ); await t.test( "recursive storage/export allowlist rejects corrupted fields without disclosing content", async () => { for (const invalid of [ { ...record, conversations: "private-content-sentinel" }, { ...record, resources: { ...record.resources, accessToken: "oauth-secret-sentinel", }, }, { ...record, desiredRelease: { ...record.desiredRelease, rawError: "private-provider-error", }, }, { ...record, installedRelease: { ...record.installedRelease, modelKey: "private-model-key-sentinel", }, }, ]) { assert.throws(() => parseInstallation(invalid), /invalid_metadata/); await admin( "metadata/put", { id: record.installationId, value: invalid }, first, ); for (const response of [ await get(first, record.installationId), await list(first), ]) { assert.equal(response.status, 400); const body = await response.text(); assert.ok(!body.includes("sentinel")); assert.ok(!body.includes("private-provider-error")); } await admin( "metadata/put", { id: record.installationId, value: record }, first, ); } const snapshot = JSON.stringify(await inspect(first)); for (const marker of [ "oauth-secret-sentinel", "private-content-sentinel", "private-model-key-sentinel", "private-provider-error", "grantRef", "accessToken", "messages", "modelKey", ]) assert.ok(!snapshot.includes(marker), marker); assert.ok( Object.keys(await inspect(first)).every((key) => /^(installation|request):[a-f0-9]{32}$/.test(key), ), ); }, ); await t.test( "plural owner listing is bounded and uses validated exclusive cursors", async () => { await Promise.all(Array.from({ length: 49 }, () => reserve(first))); const one = await (await list(first)).json(); assert.equal(one.installations.length, 50); assert.match(one.nextCursor, /^[a-f0-9]{32}$/); const two = await ( await list(first, `?cursor=${one.nextCursor}`) ).json(); assert.equal(two.installations.length, 2); assert.equal(two.nextCursor, null); assert.equal( new Set( [...one.installations, ...two.installations].map( (r) => r.installationId, ), ).size, 52, ); for (const query of [ "?subject=forged", "?cursor=bad", `?cursor=${id()}&cursor=${id()}`, ]) assert.equal((await list(first, query)).status, 400); }, ); await t.test( "identity reads outlive deployment grant; real restart retains ownership and replay", async () => { const { principal } = await admin("inspect", {}, first); await admin("expire", { kind: "grant", ref: principal.grantRef }); assert.equal((await reserve(first)).status, 401); assert.equal((await get(first, record.installationId)).status, 200); assert.equal((await list(first)).status, 200); const calls = await admin("metadata/network", {}, first); assert.ok(calls.length > 0); assert.ok( calls.every( (path) => path === "https://api.cloudflare.com/client/v4/accounts", ), ); await worker.stop(); const configuration = oauthConfig(origin); delete configuration.oauthCapabilities; bindings = { ...oauthBindings(origin), FLAREBOT_CONTROL_PLANE: JSON.stringify(configuration), }; worker = await start(); assert.deepEqual( (await (await get(first, record.installationId)).json()).installation, record, ); assert.equal((await list(first)).status, 200); assert.equal((await reserve(first)).status, 401); await worker.stop(); bindings = oauthBindings(origin); worker = await start(); const reconnected = await login(); assert.equal((await select(reconnected, A)).status, 200); assert.deepEqual( (await (await reserve(reconnected, requestId)).json()).installation, record, ); assert.equal((await get(second, record.installationId)).status, 404); await admin("expire", { kind: "session", ref: reconnected.split("=")[1], }); assert.equal( (await get(reconnected, record.installationId)).status, 401, ); for (const marker of [ "oauth-secret-sentinel", "private-content-sentinel", "private-model-key-sentinel", "private-provider-error", ]) assert.ok(!logs.join("\n").includes(marker), marker); }, ); }, ); test("production exports private native registry only in publisher bundle", async () => { const control = await readFile("dist/control-plane/worker/index.js", "utf8"); assert.match(control, /InstallationRegistry/); assert.ok(!control.includes("/__test__/")); assert.ok(!control.includes("fixtureInspect")); const customer = await readFile("dist/release/worker/index.js", "utf8"); assert.ok(!customer.includes("InstallationRegistry")); for (const entry of await readdir("dist/control-plane/client/assets")) { const source = await readFile( `dist/control-plane/client/assets/${entry}`, "utf8", ); assert.ok(!source.includes("InstallationRegistry")); // The owner-scoped status UI consumes public metadata, including its owner // identity. Authority resolution and credential storage remain server-only. for (const privateName of [ "authenticatedPrincipal", "selectedDeploymentGrant", "AuthVault", "FLAREBOT_CREDENTIAL_ENCRYPTION_KEY", ]) assert.ok(!source.includes(privateName), privateName); } });