fix(qoder): prevent signed request replay and surface upstream errors

This commit is contained in:
yiwen65
2026-09-22 14:58:31 +07:00
parent 0d50fe3610
commit 782c137b1f
6 changed files with 243 additions and 51 deletions

View File

@@ -236,7 +236,7 @@ describe("wrapQoderSSE billing detection", () => {
expect(wrapped.status).toBe(403);
});
it("passes through normal errors (non-billing) as wrapped SSE", async () => {
it("returns non-billing errors with their upstream HTTP status", async () => {
const errorEnv = JSON.stringify({
statusCodeValue: 500,
body: "Internal server error",
@@ -245,22 +245,11 @@ describe("wrapQoderSSE billing detection", () => {
const wrapped = await wrapQoderSSE(makeResponse([upstream]), "qoder/ultimate");
// Normal error: still 200 response, error text in SSE body
expect(wrapped.status).toBe(200);
expect(wrapped.ok).toBe(true);
const reader = wrapped.body.getReader();
const decoder = new TextDecoder();
let buf = "";
while (true) {
const { done, value } = await reader.read();
if (done) break;
buf += decoder.decode(value, { stream: true });
}
buf += decoder.decode();
expect(buf).toContain("[qoder error 500");
expect(buf).toContain("data: [DONE]");
expect(wrapped.status).toBe(500);
expect(wrapped.ok).toBe(false);
expect(await wrapped.json()).toEqual({
error: { message: "Internal server error", code: 500 },
});
});
it("passes through successful responses unchanged", async () => {

View File

@@ -0,0 +1,97 @@
import { afterEach, describe, expect, it, vi } from "vitest";
vi.mock("../../open-sse/services/qoderModels.js", () => ({
getQoderModelConfig: vi.fn(async () => ({ key: "auto", max_output_tokens: 32 })),
resolveQoderModels: vi.fn(),
isQoderPat: () => false,
resolveQoderCredentials: vi.fn(),
}));
const request = {
model: "auto",
body: { messages: [{ role: "user", content: "hello" }], max_tokens: 32 },
stream: true,
credentials: {
accessToken: "dt-test-token",
providerSpecificData: { userId: "test-user", machineId: "test-machine" },
},
};
function success() {
return new Response('data: {"statusCodeValue":200,"body":"[DONE]"}\n\n', {
headers: { "Content-Type": "text/event-stream" },
});
}
async function loadExecutor(fetchMock, useProxy = true) {
vi.resetModules();
for (const key of ["HTTP_PROXY", "HTTPS_PROXY", "ALL_PROXY", "NO_PROXY", "http_proxy", "https_proxy", "all_proxy", "no_proxy"]) {
vi.stubEnv(key, "");
}
if (useProxy) vi.stubEnv("HTTPS_PROXY", "http://proxy.test:3128");
// Exercise the real proxyAwareFetch: it captures fetch when imported.
vi.stubGlobal("fetch", fetchMock);
const { QoderExecutor } = await import("../../open-sse/executors/qoder.js");
return new QoderExecutor();
}
afterEach(() => {
vi.unstubAllGlobals();
vi.unstubAllEnvs();
});
describe("Qoder signed inference transport", () => {
it.each([null, { strictProxy: false }])("does not replay a signed POST after proxy response loss (%j)", async (proxyOptions) => {
const seen = new Set();
const fetchMock = vi.fn(async (_url, options) => {
const authorization = options.headers.Authorization;
if (seen.has(authorization)) {
return new Response('data: {"statusCodeValue":403,"body":"{\\"code\\":\\"103\\",\\"message\\":\\"Duplicate request\\"}"}\n\n');
}
seen.add(authorization);
throw new TypeError("response lost after upstream accepted request");
});
const executor = await loadExecutor(fetchMock);
await expect(executor.execute({ ...request, proxyOptions })).rejects.toThrow("response lost");
expect(fetchMock).toHaveBeenCalledTimes(1);
expect(fetchMock.mock.calls[0][1].dispatcher).toBeDefined();
if (proxyOptions) expect(proxyOptions.strictProxy).toBe(false);
});
it("generates a fresh COSY identity when the caller retries after transport failure", async () => {
const fetchMock = vi.fn()
.mockRejectedValueOnce(new TypeError("response lost"))
.mockResolvedValueOnce(success());
const executor = await loadExecutor(fetchMock);
await expect(executor.execute(request)).rejects.toThrow("response lost");
const result = await executor.execute(request);
expect(result.response.ok).toBe(true);
await result.response.text();
expect(fetchMock).toHaveBeenCalledTimes(2);
const ids = fetchMock.mock.calls.map(([, options]) => JSON.parse(
Buffer.from(options.headers.Authorization.split(".")[1], "base64").toString(),
).requestId);
expect(ids[0]).not.toBe(ids[1]);
});
it.each([true, false])("still supports successful inference with proxy=%s", async (useProxy) => {
const fetchMock = vi.fn(async () => success());
const executor = await loadExecutor(fetchMock, useProxy);
const result = await executor.execute(request);
expect(result.response.ok).toBe(true);
await result.response.text();
expect(fetchMock).toHaveBeenCalledTimes(1);
expect(!!fetchMock.mock.calls[0][1].dispatcher).toBe(useProxy);
});
it("preserves caller cancellation without replaying the request", async () => {
const controller = new AbortController();
const fetchMock = vi.fn(async (_url, options) => {
controller.abort();
throw options.signal.reason;
});
const executor = await loadExecutor(fetchMock);
await expect(executor.execute({ ...request, signal: controller.signal })).rejects.toMatchObject({ name: "AbortError" });
expect(fetchMock).toHaveBeenCalledTimes(1);
});
});

View File

@@ -0,0 +1,81 @@
import { describe, it, expect, vi } from "vitest";
import { __test__ } from "../../open-sse/executors/qoder.js";
const { wrapQoderSSE } = __test__;
const duplicate = '{"code":"103","message":"Duplicate request"}';
const frame = (statusCodeValue, body) => `data: ${JSON.stringify({ statusCodeValue, body })}\n\n`;
function upstream(chunks, { keepOpen = false } = {}) {
const cancel = vi.fn();
const response = new Response(new ReadableStream({
start(controller) {
for (const chunk of chunks) controller.enqueue(new TextEncoder().encode(chunk));
if (!keepOpen) controller.close();
},
cancel,
}));
return { response, cancel };
}
describe("Qoder first-frame errors", () => {
it.each([
["one chunk", [frame(403, duplicate)]],
["fragmented frame", [frame(403, duplicate).slice(0, 35), frame(403, duplicate).slice(35)]],
["heartbeat prefix", [": keepalive\r\n\r\n", frame(403, duplicate)]],
["prefix and frame in one chunk", [": keepalive\n\nevent: message\n" + frame(403, duplicate)]],
["EOF without newline", [frame(403, duplicate).trimEnd()]],
["object body", [frame(403, JSON.parse(duplicate))]],
])("surfaces duplicate-request errors as HTTP 403: %s", async (_name, chunks) => {
const { response } = upstream(chunks);
const wrapped = await wrapQoderSSE(response, "qoder/kmodel_latest");
expect(wrapped.status).toBe(403);
expect(wrapped.ok).toBe(false);
expect(wrapped.headers.get("content-type")).toBe("application/json");
const body = await wrapped.json();
expect(body.error.message).toBe(duplicate);
expect(body).not.toHaveProperty("choices");
});
it("cancels the upstream keepalive immediately after an error", async () => {
const { response, cancel } = upstream([": keepalive\n\n", frame(403, duplicate)], { keepOpen: true });
const wrapped = await wrapQoderSSE(response, "qoder/kmodel_latest");
expect(wrapped.status).toBe(403);
expect(cancel).toHaveBeenCalledOnce();
});
it.each([401, 429, 500, 503])("preserves non-billing HTTP status %s", async (status) => {
const { response } = upstream([frame(status, "upstream failure")]);
const wrapped = await wrapQoderSSE(response, "qoder/auto");
expect(wrapped.status).toBe(status);
expect((await wrapped.json()).error.message).toBe("upstream failure");
});
it.each([0, 302, 600, 403.5])("maps invalid error status %s to 502", async (status) => {
const { response } = upstream([frame(status, "invalid upstream status")]);
const wrapped = await wrapQoderSSE(response, "qoder/auto");
expect(wrapped.status).toBe(502);
});
it("replays successful frames after a heartbeat without losing or duplicating content", async () => {
const first = JSON.stringify({ choices: [{ delta: { content: "hello" } }] });
const second = JSON.stringify({ choices: [{ delta: { content: "world" } }] });
const { response } = upstream([": keepalive\n\n", frame(200, first) + frame(200, second) + "data: [DONE]\n\n"]);
const wrapped = await wrapQoderSSE(response, "qoder/auto");
expect(wrapped.status).toBe(200);
expect(await wrapped.text()).toBe(`data: ${first}\n\ndata: ${second}\n\ndata: [DONE]\n\n`);
});
it("starts forwarding success without waiting for the upstream to close", async () => {
const inner = JSON.stringify({ choices: [{ delta: { content: "hello" } }] });
const { response, cancel } = upstream([": keepalive\n\n", frame(200, inner)], { keepOpen: true });
const wrapped = await wrapQoderSSE(response, "qoder/auto");
const reader = wrapped.body.getReader();
try {
const { value } = await reader.read();
expect(new TextDecoder().decode(value)).toBe(`data: ${inner}\n\n`);
} finally {
await reader.cancel();
}
expect(cancel).toHaveBeenCalledOnce();
});
});

View File

@@ -506,14 +506,14 @@ describe("wrapQoderSSE", () => {
// Regression for review finding #3: chunks could leak past [DONE] when
// the success branch had no doneEmitted guard. We synthesize an error
// envelope (which sets doneEmitted=true) followed by a valid envelope
// envelope after content (which sets doneEmitted=true), followed by a valid envelope
// and assert the second envelope is NOT forwarded.
it("does not forward chunks after [DONE] has been emitted", async () => {
const errorEnv = JSON.stringify({ statusCodeValue: 500, body: "boom" });
const validInner = JSON.stringify({ choices: [{ delta: { content: "leak" } }] });
const validEnv = JSON.stringify({ statusCodeValue: 200, body: validInner });
const wrapped = await wrapQoderSSE(
makeResponse([`data: ${errorEnv}\n\ndata: ${validEnv}\n\n`]),
makeResponse([envelope(JSON.stringify({ choices: [{ delta: { content: "hi" } }] })) + `data: ${errorEnv}\n\ndata: ${validEnv}\n\n`]),
"qoder/auto",
);
const out = await drain(wrapped);
@@ -539,12 +539,13 @@ describe("wrapQoderSSE", () => {
expect(() => JSON.parse(dataLine.slice("data: ".length))).not.toThrow();
});
it("upstream error envelope produces an error chunk + [DONE]", async () => {
it("upstream first-frame error envelope produces an HTTP error", async () => {
const env = JSON.stringify({ statusCodeValue: 503, body: "service unavailable" });
const wrapped = await wrapQoderSSE(makeResponse([`data: ${env}\n\n`]), "qoder/lite");
const out = await drain(wrapped);
expect(out).toContain("[qoder error 503");
expect(out).toContain("data: [DONE]\n\n");
expect(wrapped.status).toBe(503);
expect(await wrapped.json()).toEqual({
error: { message: "service unavailable", code: 503 },
});
});
it("non-ok responses are returned unchanged (no transform)", async () => {