Files
9router/tests
decolua 64f58420db feat(i18n): add endpoint exposure notice across multiple languages
Added a new translation for the message "Endpoint is exposed without an API key." to various language files, enhancing user awareness regarding API security. This update ensures that users are informed about potential risks associated with unprotected endpoints in their respective languages.
2026-06-06 12:45:32 +07:00
..

9Router Embeddings Tests

Unit tests for the /v1/embeddings endpoint implementation.

Setup

Vitest must be installed globally or in /tmp/node_modules (due to npm workspace hoisting from the root Next.js project):

cd /tmp && npm install vitest

Running Tests

cd tests/
NODE_PATH=/tmp/node_modules /tmp/node_modules/.bin/vitest run --reporter=verbose --config ./vitest.config.js

Or using the package script (from the tests/ directory):

npm test

Test Files

File What it tests
unit/embeddingsCore.test.js open-sse/handlers/embeddingsCore.js — core logic: body builder, URL router, headers, handler flow
unit/embeddings.cloud.test.js cloud/src/handlers/embeddings.js — cloud worker handler: auth, validation, rate limits, CORS

Coverage Summary (59 tests)

embeddingsCore.test.js (36 tests)

  • buildEmbeddingsBody: single string, array, encoding_format, default float
  • buildEmbeddingsUrl: openai, openrouter, openai-compatible-*, unsupported providers
  • buildEmbeddingsHeaders: per-provider header sets, fallback to accessToken
  • handleEmbeddingsCore input validation: missing, wrong type, null, empty
  • handleEmbeddingsCore success: response format, CORS, Content-Type, callbacks
  • handleEmbeddingsCore errors: 400/429/500, network error, invalid JSON
  • handleEmbeddingsCore token refresh: 401 retry, graceful fallback

embeddings.cloud.test.js (23 tests)

  • CORS OPTIONS: 200 response, empty body, correct headers
  • Authentication: missing key, bad format, old-format key, wrong key value, valid key
  • Body validation: invalid JSON, missing model, missing input, bad model
  • Happy path: single string, array, correct delegation, CORS header, machineId override
  • Rate limiting: all accounts rate-limited → 503 + Retry-After, no credentials → 400
  • Error propagation: non-fallback errors passed through, 429 exhausts accounts
  • machineId override: validates key, rejects wrong key