-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathselfhosted_auth_headers_test.go
More file actions
134 lines (112 loc) · 4.55 KB
/
Copy pathselfhosted_auth_headers_test.go
File metadata and controls
134 lines (112 loc) · 4.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
// Copyright 2025 AxonFlow
// SPDX-License-Identifier: MIT
//
// selfhosted_auth_headers_test.go - Auth header verification tests
//
// These tests verify that auth headers are:
// - Sent when credentials are provided
// - NOT sent when credentials are not provided (community/self-hosted mode)
//
// Run with:
// go test -v -run TestAuthHeaders
package axonflow
import (
"encoding/base64"
"encoding/json"
"net/http"
"net/http/httptest"
"testing"
)
// ============================================================
// AUTH HEADERS TESTS - Community Mode (no credentials)
// ============================================================
// TestAuthHeaders_DefaultsToCommunityCreds verifies that Basic auth with
// "community:" is sent when no credentials are configured (community mode).
func TestAuthHeaders_DefaultsToCommunityCreds(t *testing.T) {
receivedAuthHeader := ""
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
receivedAuthHeader = r.Header.Get("Authorization")
w.Header().Set("Content-Type", "application/json")
json.NewEncoder(w).Encode(map[string]interface{}{
"success": true,
"data": map[string]string{"answer": "test"},
})
}))
defer server.Close()
// Create client WITHOUT credentials — should default to "community"
client := NewClient(AxonFlowConfig{
Endpoint: server.URL,
Cache: CacheConfig{Enabled: false},
})
_, _ = client.ProxyLLMCall("user", "query", "chat", nil)
// Basic auth with community: should always be sent
expectedAuth := "Basic " + base64.StdEncoding.EncodeToString([]byte("community:"))
if receivedAuthHeader != expectedAuth {
t.Errorf("Expected Basic auth with community default, got '%s'", receivedAuthHeader)
}
t.Log("✅ Basic auth correctly sent with community default")
}
// ============================================================
// AUTH HEADERS TESTS - Enterprise Mode (with credentials)
// ============================================================
// TestAuthHeaders_OAuth2Basic verifies OAuth2 Basic auth header
// is sent when ClientID + ClientSecret are configured
func TestAuthHeaders_OAuth2Basic(t *testing.T) {
receivedAuthHeader := ""
receivedLicenseHeader := ""
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
receivedAuthHeader = r.Header.Get("Authorization")
receivedLicenseHeader = r.Header.Get("X-License-Key")
w.Header().Set("Content-Type", "application/json")
json.NewEncoder(w).Encode(map[string]interface{}{
"success": true,
"data": map[string]string{"answer": "test"},
})
}))
defer server.Close()
// Create client WITH OAuth2 credentials
client := NewClient(AxonFlowConfig{
Endpoint: server.URL,
ClientID: "my-client",
ClientSecret: "my-secret",
Cache: CacheConfig{Enabled: false},
})
_, _ = client.ProxyLLMCall("user", "query", "chat", nil)
// Should send Authorization: Basic header (OAuth2-style)
expectedBasic := "Basic " + base64.StdEncoding.EncodeToString([]byte("my-client:my-secret"))
if receivedAuthHeader != expectedBasic {
t.Errorf("Expected Authorization '%s', got '%s'", expectedBasic, receivedAuthHeader)
}
// Should NOT send X-License-Key when using OAuth2
if receivedLicenseHeader != "" {
t.Errorf("Expected no X-License-Key when using OAuth2, got '%s'", receivedLicenseHeader)
}
t.Log("✅ OAuth2 Basic auth header correctly sent")
}
// TestAuthHeaders_ClientIDWithoutSecret verifies Basic auth with empty
// secret is sent when only ClientID is configured (community mode with custom tenant).
func TestAuthHeaders_ClientIDWithoutSecret(t *testing.T) {
receivedAuthHeader := ""
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
receivedAuthHeader = r.Header.Get("Authorization")
w.Header().Set("Content-Type", "application/json")
json.NewEncoder(w).Encode(map[string]interface{}{
"success": true,
"data": map[string]string{"answer": "test"},
})
}))
defer server.Close()
// Create client with only ClientID (no ClientSecret)
client := NewClient(AxonFlowConfig{
Endpoint: server.URL,
ClientID: "my-client",
Cache: CacheConfig{Enabled: false},
})
_, _ = client.ProxyLLMCall("user", "query", "chat", nil)
// Should send Basic auth with empty secret — server uses clientId as tenant
expectedAuth := "Basic " + base64.StdEncoding.EncodeToString([]byte("my-client:"))
if receivedAuthHeader != expectedAuth {
t.Errorf("Expected Basic auth with clientId and empty secret, got '%s'", receivedAuthHeader)
}
t.Log("✅ Basic auth correctly sent with clientId and empty secret")
}