Add SAML 2.0 as a second SSO protocol alongside OIDC under a unified authMode/ssoType model. SP flows via @node-saml/node-saml: AuthnRequest generation, ACS POST assertion handling, SP metadata export, and admin config test endpoint. Replay-protected via saml_state cookie (httpOnly, SameSite=Lax) matched against InResponseTo; wantAssertionsSigned enforced. - src/lib/auth/saml.js: SAML instance builder, X.509 cert formatter, claim pickers - 4 routes under src/app/api/auth/saml/: start, acs, metadata, test - settingsRepo: ssoType + saml* defaults; login/status routes dispatch by type - profile page: SSO protocol switcher, IdP metadata XML + cert uploaders - login page: dynamic SAML sign-in button; Header: SAML user badge
9Router Embeddings Tests
Unit tests for the /v1/embeddings endpoint implementation.
Setup
Install test dependencies from the tests/ directory:
cd tests/ && npm install
Running Tests
From the tests/ directory:
npm test
Or run vitest directly with npx:
npx vitest run --reporter=verbose --config ./vitest.config.js
Test Files
| File | What it tests |
|---|---|
unit/embeddingsCore.test.js |
open-sse/handlers/embeddingsCore.js — core logic: body builder, URL router, headers, handler flow |
unit/embeddings.cloud.test.js |
cloud/src/handlers/embeddings.js — cloud worker handler: auth, validation, rate limits, CORS |
Coverage Summary (59 tests)
embeddingsCore.test.js (36 tests)
buildEmbeddingsBody: single string, array, encoding_format, default floatbuildEmbeddingsUrl: openai, openrouter, openai-compatible-*, unsupported providersbuildEmbeddingsHeaders: per-provider header sets, fallback to accessTokenhandleEmbeddingsCoreinput validation: missing, wrong type, null, emptyhandleEmbeddingsCoresuccess: response format, CORS, Content-Type, callbackshandleEmbeddingsCoreerrors: 400/429/500, network error, invalid JSONhandleEmbeddingsCoretoken refresh: 401 retry, graceful fallback
embeddings.cloud.test.js (23 tests)
- CORS OPTIONS: 200 response, empty body, correct headers
- Authentication: missing key, bad format, old-format key, wrong key value, valid key
- Body validation: invalid JSON, missing model, missing input, bad model
- Happy path: single string, array, correct delegation, CORS header, machineId override
- Rate limiting: all accounts rate-limited → 503 + Retry-After, no credentials → 400
- Error propagation: non-fallback errors passed through, 429 exhausts accounts
- machineId override: validates key, rejects wrong key