Adds long-lived API-key (ksk_) authentication for Kiro/AWS CodeWhisperer and a direct claude:kiro / kiro:claude translation route that avoids the lossy OpenAI two-hop pivot. - translator: claude-to-kiro request + kiro-to-claude response translators, registered on the exact source:target pair (direct route ahead of the OpenAI pivot in index.js). claude-to-kiro uses shared schema constants (ROLE/CLAUDE_BLOCK/DEFAULT_IMAGE_MIME) per app convention. - auth: POST /api/oauth/kiro/api-key imports + validates a key via ListAvailableProfiles, persists authMethod="api_key" (no refresh token). - executor: send tokentype: API_KEY header and try *.amazonaws.com hosts first for api-key creds; OAuth keeps kiro.dev first. - fix: never inject the default placeholder profileArn for api-key auth (CodeWhisperer 403s an ARN not owned by the key's account). - ui: API Key method in the Kiro connect modal; surface api-key accounts on the Quota Tracker and provider count. - stream: env-overridable TTFT vs stall timeouts + Kiro keepalive frame. - tests: claude-kiro-direct + kiro-profile-arn (11 tests). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Cursor <cursoragent@cursor.com>
9Router Embeddings Tests
Unit tests for the /v1/embeddings endpoint implementation.
Setup
Vitest must be installed globally or in /tmp/node_modules (due to npm workspace hoisting from the root Next.js project):
cd /tmp && npm install vitest
Running Tests
cd tests/
NODE_PATH=/tmp/node_modules /tmp/node_modules/.bin/vitest run --reporter=verbose --config ./vitest.config.js
Or using the package script (from the tests/ directory):
npm test
Test Files
| File | What it tests |
|---|---|
unit/embeddingsCore.test.js |
open-sse/handlers/embeddingsCore.js — core logic: body builder, URL router, headers, handler flow |
unit/embeddings.cloud.test.js |
cloud/src/handlers/embeddings.js — cloud worker handler: auth, validation, rate limits, CORS |
Coverage Summary (59 tests)
embeddingsCore.test.js (36 tests)
buildEmbeddingsBody: single string, array, encoding_format, default floatbuildEmbeddingsUrl: openai, openrouter, openai-compatible-*, unsupported providersbuildEmbeddingsHeaders: per-provider header sets, fallback to accessTokenhandleEmbeddingsCoreinput validation: missing, wrong type, null, emptyhandleEmbeddingsCoresuccess: response format, CORS, Content-Type, callbackshandleEmbeddingsCoreerrors: 400/429/500, network error, invalid JSONhandleEmbeddingsCoretoken refresh: 401 retry, graceful fallback
embeddings.cloud.test.js (23 tests)
- CORS OPTIONS: 200 response, empty body, correct headers
- Authentication: missing key, bad format, old-format key, wrong key value, valid key
- Body validation: invalid JSON, missing model, missing input, bad model
- Happy path: single string, array, correct delegation, CORS header, machineId override
- Rate limiting: all accounts rate-limited → 503 + Retry-After, no credentials → 400
- Error propagation: non-fallback errors passed through, 429 exhausts accounts
- machineId override: validates key, rejects wrong key