Files
9router/tests
Nguyen Thanh Dat 92259214db fix(security): require proof that x-9r-real-ip came from the socket (GHSA-pjm4-8fpg-f9p6)
x-9r-real-ip and the Host fallback were trusted from client-controlled
headers whenever custom-server.js was not in the request path (npm run
start, start:bun), letting a remote caller pose as local to skip API key
auth and reach LOCAL_ONLY_PATHS (/api/mcp/*, /api/tunnel/enable,
/api/auth/reset-password).

custom-server.js now generates a per-process secret at boot and stamps it
as x-9r-peer-token on every request it sanitizes. hasTrustedPeerHeaders()
(src/lib/auth/trustedPeer.js) gates trust in x-9r-real-ip on that secret;
otherwise the guard falls back to Host only in development, and fails
closed in production. Same gate on loginLimiter.getClientIp() so a spoofed
header cannot rotate the login lockout bucket.

Also: fix isLoopbackHostname for IPv6 (::1, ::ffff:127.0.0.1) which the
old split(":")[0] reduced to empty string; route npm run start /
start:bun through custom-server.js (postbuild copies it into
.next/standalone, build-cli.js fails without it) so documented deployments
keep passwordless local access.
2026-08-14 16:33:58 +07:00
..

9Router Embeddings Tests

Unit tests for the /v1/embeddings endpoint implementation.

Setup

Install test dependencies from the tests/ directory:

cd tests/ && npm install

Running Tests

From the tests/ directory:

npm test

Or run vitest directly with npx:

npx vitest run --reporter=verbose --config ./vitest.config.js

Test Files

File What it tests
unit/embeddingsCore.test.js open-sse/handlers/embeddingsCore.js — core logic: body builder, URL router, headers, handler flow
unit/embeddings.cloud.test.js cloud/src/handlers/embeddings.js — cloud worker handler: auth, validation, rate limits, CORS

Coverage Summary (59 tests)

embeddingsCore.test.js (36 tests)

  • buildEmbeddingsBody: single string, array, encoding_format, default float
  • buildEmbeddingsUrl: openai, openrouter, openai-compatible-*, unsupported providers
  • buildEmbeddingsHeaders: per-provider header sets, fallback to accessToken
  • handleEmbeddingsCore input validation: missing, wrong type, null, empty
  • handleEmbeddingsCore success: response format, CORS, Content-Type, callbacks
  • handleEmbeddingsCore errors: 400/429/500, network error, invalid JSON
  • handleEmbeddingsCore token refresh: 401 retry, graceful fallback

embeddings.cloud.test.js (23 tests)

  • CORS OPTIONS: 200 response, empty body, correct headers
  • Authentication: missing key, bad format, old-format key, wrong key value, valid key
  • Body validation: invalid JSON, missing model, missing input, bad model
  • Happy path: single string, array, correct delegation, CORS header, machineId override
  • Rate limiting: all accounts rate-limited → 503 + Retry-After, no credentials → 400
  • Error propagation: non-fallback errors passed through, 429 exhausts accounts
  • machineId override: validates key, rejects wrong key