x-9r-real-ip and the Host fallback were trusted from client-controlled
headers whenever custom-server.js was not in the request path (npm run
start, start:bun), letting a remote caller pose as local to skip API key
auth and reach LOCAL_ONLY_PATHS (/api/mcp/*, /api/tunnel/enable,
/api/auth/reset-password).
custom-server.js now generates a per-process secret at boot and stamps it
as x-9r-peer-token on every request it sanitizes. hasTrustedPeerHeaders()
(src/lib/auth/trustedPeer.js) gates trust in x-9r-real-ip on that secret;
otherwise the guard falls back to Host only in development, and fails
closed in production. Same gate on loginLimiter.getClientIp() so a spoofed
header cannot rotate the login lockout bucket.
Also: fix isLoopbackHostname for IPv6 (::1, ::ffff:127.0.0.1) which the
old split(":")[0] reduced to empty string; route npm run start /
start:bun through custom-server.js (postbuild copies it into
.next/standalone, build-cli.js fails without it) so documented deployments
keep passwordless local access.
9Router Embeddings Tests
Unit tests for the /v1/embeddings endpoint implementation.
Setup
Install test dependencies from the tests/ directory:
cd tests/ && npm install
Running Tests
From the tests/ directory:
npm test
Or run vitest directly with npx:
npx vitest run --reporter=verbose --config ./vitest.config.js
Test Files
| File | What it tests |
|---|---|
unit/embeddingsCore.test.js |
open-sse/handlers/embeddingsCore.js — core logic: body builder, URL router, headers, handler flow |
unit/embeddings.cloud.test.js |
cloud/src/handlers/embeddings.js — cloud worker handler: auth, validation, rate limits, CORS |
Coverage Summary (59 tests)
embeddingsCore.test.js (36 tests)
buildEmbeddingsBody: single string, array, encoding_format, default floatbuildEmbeddingsUrl: openai, openrouter, openai-compatible-*, unsupported providersbuildEmbeddingsHeaders: per-provider header sets, fallback to accessTokenhandleEmbeddingsCoreinput validation: missing, wrong type, null, emptyhandleEmbeddingsCoresuccess: response format, CORS, Content-Type, callbackshandleEmbeddingsCoreerrors: 400/429/500, network error, invalid JSONhandleEmbeddingsCoretoken refresh: 401 retry, graceful fallback
embeddings.cloud.test.js (23 tests)
- CORS OPTIONS: 200 response, empty body, correct headers
- Authentication: missing key, bad format, old-format key, wrong key value, valid key
- Body validation: invalid JSON, missing model, missing input, bad model
- Happy path: single string, array, correct delegation, CORS header, machineId override
- Rate limiting: all accounts rate-limited → 503 + Retry-After, no credentials → 400
- Error propagation: non-fallback errors passed through, 429 exhausts accounts
- machineId override: validates key, rejects wrong key