# Conflicts: # apps/desktop/e2e/archived-hidden-session-recoverable.spec.ts # apps/desktop/e2e/bot-chat-message-agent-friendly-name.spec.ts # apps/desktop/e2e/bot-mailbox-unreadable-ticket.spec.ts # apps/desktop/e2e/bot-mode-roster-localized.spec.ts # apps/desktop/e2e/bot-mode-row-click-mirrors-registry.spec.ts # apps/desktop/e2e/bot-mode-tab-shows-bot-name.spec.ts # apps/desktop/e2e/bot-roster-group-row-organisation.spec.ts # apps/desktop/e2e/bot-roster-ignores-infra-dirs.spec.ts # apps/desktop/e2e/bot-roster-timestamp-meta.spec.ts # apps/desktop/e2e/bot-roster-user-sections.spec.ts # apps/desktop/e2e/bot-routines-pane-narrow.spec.ts # apps/desktop/e2e/bot-row-open-recent-session.spec.ts # apps/desktop/e2e/bot-tile-ignores-ambient-composer-model.spec.ts # apps/desktop/e2e/group-composer-auto-grow.spec.ts # apps/desktop/e2e/group-create-gate-remote-roster.spec.ts # apps/desktop/e2e/group-prompt-renamed-primary-handle.spec.ts # apps/desktop/e2e/hosted-room-backend-continuity.spec.ts # apps/desktop/e2e/hosted-room-legacy-store-migration.spec.ts # apps/desktop/e2e/settings-scope-chips-bot-title.spec.ts # apps/desktop/e2e/worktree-branch-status.spec.ts # apps/desktop/electron/backend-probes.test.ts # apps/desktop/electron/connection-apply.test.ts # apps/desktop/electron/desktop-electron-pin.test.ts # apps/desktop/electron/desktop-uninstall.test.ts # apps/desktop/electron/gateway-file-download-transport.test.ts # apps/desktop/electron/gateway-stop-before-update.test.ts # apps/desktop/electron/github-api-auth.test.ts # apps/desktop/electron/registry-primary-profile-scope.test.ts # apps/desktop/electron/update-api-check.test.ts # apps/desktop/electron/update-handoff-marker.test.ts # apps/desktop/electron/venv-blocker-scan.test.ts # apps/desktop/scripts/after-extract.test.mjs # apps/desktop/scripts/local-pack-publish.test.mjs # apps/desktop/scripts/tasks-scroll.test.mjs # apps/desktop/src/app/settings/model-settings.test.tsx # apps/desktop/src/app/updates-overlay.blockers.test.tsx # apps/desktop/src/components/desktop-install-overlay.test.tsx # apps/desktop/src/lib/update-copy.test.ts # scripts/ci/check_os_marker_fakes.py # tests-js/desktop-mac-usage-descriptions.test.ts # tests-js/node-engine-alignment.test.ts # tests/agent/lsp/test_install_and_lint_fixes.py # tests/agent/test_command_token_source.py # tests/agent/test_compression_boundary_hook.py # tests/agent/test_create_openai_client_ssl_verify.py # tests/agent/test_custom_provider_ca_probes.py # tests/agent/test_endpoint_blackhole.py # tests/agent/test_estimator_parity.py # tests/agent/test_in_place_compaction.py # tests/agent/test_moa_loop_mode.py # tests/agent/test_model_metadata.py # tests/agent/test_skill_session_platform_gate.py # tests/agent/test_skill_utils.py # tests/agent/test_ssl_ca_guard.py # tests/computer_use/test_doctor.py # tests/cron/test_codex_execution_paths.py # tests/cron/test_cron_bot_chat_delivery.py # tests/cron/test_cron_script.py # tests/cron/test_media_delivery_parity.py # tests/cron/test_misfire_catchup.py # tests/cron/test_parallel_pool.py # tests/cron/test_recurring_eagain_redispatch.py # tests/gateway/test_choice_picker.py # tests/gateway/test_control_socket_windows_live.py # tests/gateway/test_dingtalk.py # tests/gateway/test_feishu.py # tests/gateway/test_feishu_onboard.py # tests/gateway/test_gateway_shutdown.py # tests/gateway/test_matrix.py # tests/gateway/test_model_command_custom_providers.py # tests/gateway/test_reasoning_command.py # tests/gateway/test_runtime_footer.py # tests/gateway/test_session.py # tests/gateway/test_session_hygiene.py # tests/gateway/test_status.py # tests/gateway/test_teams.py # tests/gateway/test_turn_lease.py # tests/gateway/test_whatsapp_connect.py # tests/hermes_cli/test_approvals_command.py # tests/hermes_cli/test_auth_store_lock_concurrent.py # tests/hermes_cli/test_backup.py # tests/hermes_cli/test_banner_git_state.py # tests/hermes_cli/test_certifi_repair.py # tests/hermes_cli/test_cmd_update.py # tests/hermes_cli/test_compat_manifest_targets.py # tests/hermes_cli/test_computer_use_cli.py # tests/hermes_cli/test_cpr_local_leak.py # tests/hermes_cli/test_dashboard_auth_gate.py # tests/hermes_cli/test_dashboard_procs_kill_grace.py # tests/hermes_cli/test_desktop_lifecycle_windows_live.py # tests/hermes_cli/test_doctor.py # tests/hermes_cli/test_doctor_command_install.py # tests/hermes_cli/test_fleet_config_migration_windows_live.py # tests/hermes_cli/test_gateway.py # tests/hermes_cli/test_gateway_platform_gating.py # tests/hermes_cli/test_gateway_restart_loop.py # tests/hermes_cli/test_gateway_task_probe.py # tests/hermes_cli/test_gateway_wsl.py # tests/hermes_cli/test_gui_command.py # tests/hermes_cli/test_install_cua_driver.py # tests/hermes_cli/test_kanban_db.py # tests/hermes_cli/test_lazy_command_exports.py # tests/hermes_cli/test_lazy_refresh_venv_repair.py # tests/hermes_cli/test_linux_desktop_entry.py # tests/hermes_cli/test_local_runtime.py # tests/hermes_cli/test_local_runtime_updates.py # tests/hermes_cli/test_managed_uv.py # tests/hermes_cli/test_mcp_reload_confirm_gate.py # tests/hermes_cli/test_nous_subscription.py # tests/hermes_cli/test_npm_engine.py # tests/hermes_cli/test_personality_none.py # tests/hermes_cli/test_pet_toggle.py # tests/hermes_cli/test_plan_reconciliation_windows_live.py # tests/hermes_cli/test_plugin_event_bus.py # tests/hermes_cli/test_plugin_manifest_v2.py # tests/hermes_cli/test_plugin_packs.py # tests/hermes_cli/test_plugins_cmd.py # tests/hermes_cli/test_plugins_cmd_enable_disable_nested.py # tests/hermes_cli/test_process_identity.py # tests/hermes_cli/test_profiles.py # tests/hermes_cli/test_profiles_sidebar_cache.py # tests/hermes_cli/test_pty_bridge.py # tests/hermes_cli/test_resolve_turn_limit.py # tests/hermes_cli/test_serve_runtime_inventory.py # tests/hermes_cli/test_session_vacuum_config.py # tests/hermes_cli/test_set_config_value.py # tests/hermes_cli/test_signal_handler_kanban_worker.py # tests/hermes_cli/test_slash_confirm_windows.py # tests/hermes_cli/test_stale_pid_guard.py # tests/hermes_cli/test_startup_fast_guards.py # tests/hermes_cli/test_status.py # tests/hermes_cli/test_telegram_managed_bot.py # tests/hermes_cli/test_tools_config.py # tests/hermes_cli/test_update_apply_shallow_count.py # tests/hermes_cli/test_update_autostash.py # tests/hermes_cli/test_update_concurrent_quarantine.py # tests/hermes_cli/test_update_fetch_failure_classifier.py # tests/hermes_cli/test_update_fleet_probe_resume_token.py # tests/hermes_cli/test_update_handoff_backend_reap.py # tests/hermes_cli/test_update_handoff_desktop_rebuild.py # tests/hermes_cli/test_update_head_moved_gate.py # tests/hermes_cli/test_update_host_obligation.py # tests/hermes_cli/test_update_import_guard.py # tests/hermes_cli/test_update_interrupted_recovery.py # tests/hermes_cli/test_update_inventory.py # tests/hermes_cli/test_update_launchd_unloaded_gateway.py # tests/hermes_cli/test_update_missing_configured_deps.py # tests/hermes_cli/test_update_modified_notice.py # tests/hermes_cli/test_update_multiplex_migration_hook.py # tests/hermes_cli/test_update_no_gateway_restart.py # tests/hermes_cli/test_update_orphan_backend_reap.py # tests/hermes_cli/test_update_parked_branch_guard.py # tests/hermes_cli/test_update_post_pull_syntax_guard.py # tests/hermes_cli/test_update_receipt.py # tests/hermes_cli/test_update_self_lock.py # tests/hermes_cli/test_update_shim_fail_closed.py # tests/hermes_cli/test_update_shim_self_lock.py # tests/hermes_cli/test_update_sqlite_remediation.py # tests/hermes_cli/test_update_stale_dashboard.py # tests/hermes_cli/test_update_stale_virtualenv.py # tests/hermes_cli/test_update_venv_health.py # tests/hermes_cli/test_update_venv_ownership_preflight.py # tests/hermes_cli/test_update_wedged_gateway.py # tests/hermes_cli/test_update_yes_flag.py # tests/hermes_cli/test_update_zip_two_phase.py # tests/hermes_cli/test_urllib_security.py # tests/hermes_cli/test_ux_messages_auth_config.py # tests/hermes_cli/test_ux_messages_startup.py # tests/hermes_cli/test_venv_holder_classifier.py # tests/hermes_cli/test_verify_console_scripts.py # tests/hermes_cli/test_verify_core_dependencies.py # tests/hermes_cli/test_web_server.py # tests/hermes_cli/test_web_server_console_ws.py # tests/hermes_cli/test_web_server_ws_ping.py # tests/hermes_cli/test_web_ui_build.py # tests/hermes_state/test_fts_rebuild_admission.py # tests/hermes_state/test_hermes_state.py # tests/plugins/memory/test_memory_lazy_install.py # tests/plugins/test_google_meet_plugin.py # tests/plugins/test_langfuse_plugin.py # tests/plugins/test_security_guidance_plugin.py # tests/plugins/test_transform_llm_output_hook.py # tests/scripts/desktop_update/test_desktop_update_windows_gateway_flag.py # tests/scripts/desktop_update/test_desktop_update_windows_python_handoff.py # tests/scripts/desktop_update/test_desktop_update_windows_timestamp.py # tests/scripts/install/test_install_clone_throttle_fallback.py # tests/scripts/install/test_install_lockfile_churn.py # tests/scripts/install/test_install_no_initial_commit.py # tests/scripts/install/test_install_sh_browser_install.py # tests/scripts/install/test_install_sh_node_prerelease.py # tests/scripts/install/test_install_sh_symlink_stomp.py # tests/scripts/install/test_install_sh_uv_lock_config.py # tests/scripts/install/test_install_unmerged_index.py # tests/scripts/test_contributor_map.py # tests/scripts/test_run_tests_parallel.py # tests/skills/test_competitor_news_monitor_skill.py # tests/skills/test_document_to_action_items_skill.py # tests/skills/test_google_workspace_setup.py # tests/skills/test_google_workspace_setup_deps.py # tests/skills/test_grounded_citations_skill.py # tests/skills/test_ip_as_logo_skill.py # tests/skills/test_live_dashboard_skill.py # tests/skills/test_mcp_oauth_remote_gateway_skill.py # tests/skills/test_office_document_skills.py # tests/skills/test_openclaw_migration.py # tests/skills/test_product_price_monitor_skill.py # tests/skills/test_scrollcraft_skill.py # tests/skills/test_setup_wizard_generator_skill.py # tests/skills/test_weekly_review_planning_skill.py # tests/test_engines_satisfiable.py # tests/test_fast_safe_load.py # tests/test_hermes_bootstrap.py # tests/test_hermes_constants.py # tests/test_hermes_logging.py # tests/test_managed_runtime_resolution.py # tests/test_model_tools_async_bridge.py # tests/test_packaging_build_guard.py # tests/test_packaging_metadata.py # tests/test_yaml_indent_consistency.py # tests/tools/test_approval_timeout_overflow.py # tests/tools/test_base_environment.py # tests/tools/test_bot_mode_dm.py # tests/tools/test_browser_chromium_check.py # tests/tools/test_browser_hardening.py # tests/tools/test_browser_homebrew_paths.py # tests/tools/test_browser_npx_warmup.py # tests/tools/test_browser_orphan_reaper.py # tests/tools/test_browser_real_profile.py # tests/tools/test_browser_use_cli.py # tests/tools/test_clipboard.py # tests/tools/test_code_execution.py # tests/tools/test_code_execution_modes.py # tests/tools/test_code_execution_windows_env.py # tests/tools/test_computer_use.py # tests/tools/test_delegate_liveness_timeout.py # tests/tools/test_execute_code_approval_cluster.py # tests/tools/test_execution_flag_detection.py # tests/tools/test_fal_common.py # tests/tools/test_file_operations.py # tests/tools/test_file_tools.py # tests/tools/test_file_tools_cwd_resolution.py # tests/tools/test_file_tools_live.py # tests/tools/test_lazy_deps.py # tests/tools/test_lazy_deps_durable_target.py # tests/tools/test_lazy_deps_managed.py # tests/tools/test_local_env_blocklist.py # tests/tools/test_local_tempdir.py # tests/tools/test_macos_protected_search.py # tests/tools/test_mcp_npx_cached_bin.py # tests/tools/test_oneshot_completion_linger.py # tests/tools/test_process_registry.py # tests/tools/test_read_file_schema_gating.py # tests/tools/test_skill_improvements.py # tests/tools/test_skills_sync.py # tests/tools/test_termux_api_detection.py # tests/tools/test_tirith_security.py # tests/tools/test_transcription_tools.py # tests/tools/test_tts_streaming.py # tests/tools/test_wake_word.py # tests/tui_gateway/test_compute_host_borrowed_lease.py # tests/tui_gateway/test_compute_host_turn_protocol.py # tests/tui_gateway/test_isolated_orphan_activity.py # tests/tui_gateway/test_protocol.py # tests/tui_gateway/test_slash_worker_profile_home.py # tests/tui_gateway/test_subprocess_encoding.py # tests/tui_gateway/test_tui_gateway_server.py # ui-tui/src/__tests__/terminalParity.test.ts # ui-tui/src/__tests__/termuxComposerLayout.test.ts # ui-tui/src/__tests__/textInputFastEcho.test.ts
545 lines
23 KiB
Python
545 lines
23 KiB
Python
"""Tests for the bundled Nous dashboard-auth plugin.
|
|
|
|
Covers four shapes from Phase 4 of ``.hermes/plans/2026-05-21-dashboard-oauth-auth.md``:
|
|
|
|
1. Plugin entry-point registration gating (env var checks).
|
|
2. ``start_login`` shape (PKCE/state, authorize URL parameters).
|
|
3. ``complete_login`` httpx-mocked happy path + error mapping.
|
|
4. ``verify_session`` JWT verification — RSA keypair, audience/issuer pinning,
|
|
``agent_instance_id`` cross-check, ``oauth_contract_version`` tolerance.
|
|
|
|
Also exercises ``revoke_session`` (no-op) and ``refresh_session``
|
|
(unconditional ``RefreshExpiredError``).
|
|
|
|
All HTTP is mocked: nothing in this file talks to a real Portal.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import base64
|
|
import json
|
|
import time
|
|
import urllib.parse
|
|
from typing import Any, Dict
|
|
from unittest.mock import MagicMock, patch
|
|
|
|
import httpx
|
|
import jwt
|
|
import pytest
|
|
from cryptography.hazmat.primitives import serialization
|
|
from cryptography.hazmat.primitives.asymmetric import rsa
|
|
|
|
import plugins.dashboard_auth.nous as nous_plugin
|
|
from hermes_cli.dashboard_auth import (
|
|
InvalidCodeError,
|
|
ProviderError,
|
|
Session,
|
|
assert_protocol_compliance,
|
|
)
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# RSA keypair fixture (module-scope — keygen is slow)
|
|
# ---------------------------------------------------------------------------
|
|
|
|
@pytest.fixture(scope="module")
|
|
def rsa_keypair() -> Dict[str, Any]:
|
|
"""Generate an RS256 keypair + matching JWK for verify_session tests."""
|
|
key = rsa.generate_private_key(public_exponent=65537, key_size=2048)
|
|
private_pem = key.private_bytes(
|
|
encoding=serialization.Encoding.PEM,
|
|
format=serialization.PrivateFormat.PKCS8,
|
|
encryption_algorithm=serialization.NoEncryption(),
|
|
).decode()
|
|
public_numbers = key.public_key().public_numbers()
|
|
|
|
def _b64url_uint(n: int) -> str:
|
|
length = (n.bit_length() + 7) // 8
|
|
return (
|
|
base64.urlsafe_b64encode(n.to_bytes(length, "big")).rstrip(b"=").decode()
|
|
)
|
|
|
|
jwk = {
|
|
"kty": "RSA",
|
|
"use": "sig",
|
|
"alg": "RS256",
|
|
"kid": "test-key-1",
|
|
"n": _b64url_uint(public_numbers.n),
|
|
"e": _b64url_uint(public_numbers.e),
|
|
}
|
|
return {"private_pem": private_pem, "jwk": jwk, "kid": jwk["kid"]}
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Token-mint helper
|
|
# ---------------------------------------------------------------------------
|
|
|
|
def _mint_token(
|
|
rsa_keypair: Dict[str, Any],
|
|
*,
|
|
iss: str = "https://portal.example.com",
|
|
aud: str = "agent:inst123",
|
|
sub: str = "usr_abc",
|
|
agent_instance_id: str | None = "inst123",
|
|
oauth_contract_version: Any = 1,
|
|
org_id: str | None = "org_xyz",
|
|
scope: str = "agent_dashboard:access",
|
|
ttl_seconds: int = 900,
|
|
extra_claims: Dict[str, Any] | None = None,
|
|
) -> str:
|
|
now = int(time.time())
|
|
claims = {
|
|
"iss": iss,
|
|
"aud": aud,
|
|
"sub": sub,
|
|
"iat": now,
|
|
"exp": now + ttl_seconds,
|
|
"scope": scope,
|
|
}
|
|
if agent_instance_id is not None:
|
|
claims["agent_instance_id"] = agent_instance_id
|
|
if oauth_contract_version is not None:
|
|
claims["oauth_contract_version"] = oauth_contract_version
|
|
if org_id is not None:
|
|
claims["org_id"] = org_id
|
|
if extra_claims:
|
|
claims.update(extra_claims)
|
|
return jwt.encode(
|
|
claims,
|
|
rsa_keypair["private_pem"],
|
|
algorithm="RS256",
|
|
headers={"kid": rsa_keypair["kid"]},
|
|
)
|
|
|
|
def _patched_jwks(provider: nous_plugin.NousDashboardAuthProvider, rsa_keypair):
|
|
"""Patch the provider's JWKS client to return our fixture key."""
|
|
fake_key = MagicMock()
|
|
fake_key.key = serialization.load_pem_private_key(
|
|
rsa_keypair["private_pem"].encode(), password=None
|
|
).public_key()
|
|
fake_client = MagicMock()
|
|
fake_client.get_signing_key_from_jwt.return_value = fake_key
|
|
provider._jwks_client = fake_client
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Provider construction
|
|
# ---------------------------------------------------------------------------
|
|
|
|
class TestConstruction:
|
|
def test_protocol_compliance(self):
|
|
assert_protocol_compliance(nous_plugin.NousDashboardAuthProvider)
|
|
|
|
def test_rejects_malformed_client_id(self):
|
|
with pytest.raises(ValueError, match="agent:"):
|
|
nous_plugin.NousDashboardAuthProvider(
|
|
client_id="hermes-dashboard", portal_url="https://x"
|
|
)
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Plugin entry point: env-gated registration
|
|
# ---------------------------------------------------------------------------
|
|
|
|
class TestPluginRegister:
|
|
def test_skips_when_client_id_missing(self, monkeypatch):
|
|
monkeypatch.delenv("HERMES_DASHBOARD_OAUTH_CLIENT_ID", raising=False)
|
|
monkeypatch.delenv("HERMES_DASHBOARD_PORTAL_URL", raising=False)
|
|
ctx = MagicMock()
|
|
nous_plugin.register(ctx)
|
|
ctx.register_dashboard_auth_provider.assert_not_called()
|
|
# Skip reason is surfaced for the gate's fail-closed message.
|
|
assert "HERMES_DASHBOARD_OAUTH_CLIENT_ID" in nous_plugin.LAST_SKIP_REASON
|
|
|
|
def test_registers_with_default_portal_url_when_only_client_id_set(
|
|
self, monkeypatch
|
|
):
|
|
"""Phase 7 follow-up: HERMES_DASHBOARD_PORTAL_URL is optional —
|
|
defaults to the production Nous Portal. The user shouldn't have
|
|
to set it for the common production deployment path."""
|
|
monkeypatch.setenv("HERMES_DASHBOARD_OAUTH_CLIENT_ID", "agent:inst1")
|
|
monkeypatch.delenv("HERMES_DASHBOARD_PORTAL_URL", raising=False)
|
|
ctx = MagicMock()
|
|
nous_plugin.register(ctx)
|
|
ctx.register_dashboard_auth_provider.assert_called_once()
|
|
registered = ctx.register_dashboard_auth_provider.call_args.args[0]
|
|
assert isinstance(registered, nous_plugin.NousDashboardAuthProvider)
|
|
assert registered._portal_url == "https://portal.nousresearch.com"
|
|
# Skip reason cleared on successful registration.
|
|
assert nous_plugin.LAST_SKIP_REASON == ""
|
|
|
|
def test_empty_portal_url_env_uses_default(self, monkeypatch):
|
|
"""Explicit empty string still falls back to the production
|
|
default — same handling as 'unset' so an empty Fly secret can't
|
|
accidentally point the dashboard at nowhere."""
|
|
monkeypatch.setenv("HERMES_DASHBOARD_OAUTH_CLIENT_ID", "agent:inst1")
|
|
monkeypatch.setenv("HERMES_DASHBOARD_PORTAL_URL", "")
|
|
ctx = MagicMock()
|
|
nous_plugin.register(ctx)
|
|
registered = ctx.register_dashboard_auth_provider.call_args.args[0]
|
|
assert registered._portal_url == "https://portal.nousresearch.com"
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Plugin entry point: config.yaml + env-override precedence
|
|
# ---------------------------------------------------------------------------
|
|
|
|
class TestConfigYamlSource:
|
|
"""``dashboard.oauth.{client_id,portal_url}`` in ``config.yaml`` is the
|
|
canonical surface for these settings. ``HERMES_DASHBOARD_OAUTH_CLIENT_ID``
|
|
and ``HERMES_DASHBOARD_PORTAL_URL`` are operator overrides that win when
|
|
set — this is the contract Fly.io's platform-secret injection relies on,
|
|
and the contract that lets local devs experiment without setting env
|
|
vars.
|
|
|
|
Each test pins exactly one tier of the precedence chain so a regression
|
|
that flips the order is caught:
|
|
|
|
env (when truthy) > config.yaml (when truthy) > plugin default
|
|
"""
|
|
|
|
@pytest.fixture
|
|
def patch_config(self, monkeypatch):
|
|
"""Yield a callable that replaces ``hermes_cli.config.load_config``
|
|
with a stub returning the given dict. Tests pass the intended
|
|
``dashboard.oauth`` block; the stub returns the wrapping structure."""
|
|
|
|
def _set(oauth_block: Dict[str, Any] | None) -> None:
|
|
cfg = {}
|
|
if oauth_block is not None:
|
|
cfg = {"dashboard": {"oauth": oauth_block}}
|
|
monkeypatch.setattr(
|
|
"hermes_cli.config.load_config", lambda: cfg
|
|
)
|
|
|
|
return _set
|
|
|
|
def test_config_yaml_only_client_id_registers(self, patch_config, monkeypatch):
|
|
"""No env var, only config.yaml — plugin reads from config and
|
|
registers successfully. This is the path Teknium's review pushed
|
|
for (".env is for secrets only")."""
|
|
monkeypatch.delenv("HERMES_DASHBOARD_OAUTH_CLIENT_ID", raising=False)
|
|
monkeypatch.delenv("HERMES_DASHBOARD_PORTAL_URL", raising=False)
|
|
patch_config({"client_id": "agent:from-config"})
|
|
ctx = MagicMock()
|
|
nous_plugin.register(ctx)
|
|
ctx.register_dashboard_auth_provider.assert_called_once()
|
|
registered = ctx.register_dashboard_auth_provider.call_args.args[0]
|
|
assert registered._client_id == "agent:from-config"
|
|
# Defaults to production portal URL when neither config nor env
|
|
# specifies one.
|
|
assert registered._portal_url == "https://portal.nousresearch.com"
|
|
|
|
def test_env_overrides_config_client_id(self, patch_config, monkeypatch):
|
|
"""Env wins. Critical for Fly.io: the Portal injects
|
|
HERMES_DASHBOARD_OAUTH_CLIENT_ID at deploy time and we MUST
|
|
honour it even if a stale config.yaml ships in the image."""
|
|
monkeypatch.setenv("HERMES_DASHBOARD_OAUTH_CLIENT_ID", "agent:from-env")
|
|
patch_config({"client_id": "agent:from-config"})
|
|
ctx = MagicMock()
|
|
nous_plugin.register(ctx)
|
|
registered = ctx.register_dashboard_auth_provider.call_args.args[0]
|
|
assert registered._client_id == "agent:from-env", (
|
|
"env var must override config.yaml — Fly secret injection "
|
|
"depends on this precedence"
|
|
)
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# start_login
|
|
# ---------------------------------------------------------------------------
|
|
|
|
class TestStartLogin:
|
|
@pytest.fixture
|
|
def provider(self):
|
|
return nous_plugin.NousDashboardAuthProvider(
|
|
client_id="agent:inst1", portal_url="https://portal.example.com"
|
|
)
|
|
|
|
def test_redirect_url_targets_portal_authorize(self, provider):
|
|
result = provider.start_login(
|
|
redirect_uri="https://hermes.fly.dev/auth/callback"
|
|
)
|
|
assert result.redirect_url.startswith(
|
|
"https://portal.example.com/oauth/authorize?"
|
|
)
|
|
|
|
def test_authorize_url_has_required_params(self, provider):
|
|
result = provider.start_login(
|
|
redirect_uri="https://hermes.fly.dev/auth/callback"
|
|
)
|
|
parsed = urllib.parse.urlparse(result.redirect_url)
|
|
params = dict(urllib.parse.parse_qsl(parsed.query))
|
|
assert params["response_type"] == "code"
|
|
assert params["client_id"] == "agent:inst1"
|
|
assert params["redirect_uri"] == "https://hermes.fly.dev/auth/callback"
|
|
assert params["scope"] == "agent_dashboard:access"
|
|
assert params["code_challenge_method"] == "S256"
|
|
assert "state" in params
|
|
assert "code_challenge" in params
|
|
|
|
def test_code_verifier_in_cookie_payload_43_to_128_chars(self, provider):
|
|
result = provider.start_login(
|
|
redirect_uri="https://hermes.fly.dev/auth/callback"
|
|
)
|
|
assert "hermes_session_pkce" in result.cookie_payload
|
|
pkce = result.cookie_payload["hermes_session_pkce"]
|
|
# Shape: ``state=…;verifier=…`` (matches stub-provider convention so
|
|
# the auth-route layer's parser works uniformly across providers).
|
|
parts = dict(seg.split("=", 1) for seg in pkce.split(";") if "=" in seg)
|
|
verifier = parts["verifier"]
|
|
# RFC 7636 §4.1
|
|
assert 43 <= len(verifier) <= 128
|
|
|
|
def test_state_in_cookie_payload_matches_url_param(self, provider):
|
|
result = provider.start_login(
|
|
redirect_uri="https://hermes.fly.dev/auth/callback"
|
|
)
|
|
parsed = urllib.parse.urlparse(result.redirect_url)
|
|
params = dict(urllib.parse.parse_qsl(parsed.query))
|
|
pkce = result.cookie_payload["hermes_session_pkce"]
|
|
parts = dict(seg.split("=", 1) for seg in pkce.split(";") if "=" in seg)
|
|
assert parts["state"] == params["state"]
|
|
|
|
def test_two_calls_produce_different_state_and_verifier(self, provider):
|
|
a = provider.start_login(
|
|
redirect_uri="https://hermes.fly.dev/auth/callback"
|
|
)
|
|
b = provider.start_login(
|
|
redirect_uri="https://hermes.fly.dev/auth/callback"
|
|
)
|
|
assert a.cookie_payload["hermes_session_pkce"] != b.cookie_payload[
|
|
"hermes_session_pkce"
|
|
]
|
|
|
|
def test_allows_http_with_arbitrary_host(self, provider):
|
|
# http:// is permitted for any host now, not just localhost — the
|
|
# Portal-side check is authoritative on which redirect_uris are
|
|
# accepted; this client-side fast-fail must not reject self-hosted
|
|
# dashboards reached over plain HTTP (LAN IPs, internal hostnames,
|
|
# TLS-terminating reverse proxies). Should not raise.
|
|
provider.start_login(redirect_uri="http://hermes.fly.dev/auth/callback")
|
|
provider.start_login(redirect_uri="http://192.168.1.50:8080/auth/callback")
|
|
provider.start_login(redirect_uri="http://my-internal-host/auth/callback")
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# complete_login (httpx mocked)
|
|
# ---------------------------------------------------------------------------
|
|
|
|
class TestCompleteLogin:
|
|
@pytest.fixture
|
|
def provider(self, rsa_keypair):
|
|
p = nous_plugin.NousDashboardAuthProvider(
|
|
client_id="agent:inst123", portal_url="https://portal.example.com"
|
|
)
|
|
_patched_jwks(p, rsa_keypair)
|
|
return p
|
|
|
|
def _mock_post(self, status_code: int, body: Any, *, ctype: str = "application/json"):
|
|
resp = MagicMock(spec=httpx.Response)
|
|
resp.status_code = status_code
|
|
if isinstance(body, dict):
|
|
resp.text = json.dumps(body)
|
|
resp.json = MagicMock(return_value=body)
|
|
else:
|
|
resp.text = body
|
|
# _parse_json_body bails on non-application/json before .json()
|
|
# is called, but be safe for callers that pass a non-dict body
|
|
# with ctype=application/json.
|
|
resp.json = MagicMock(side_effect=ValueError("not json"))
|
|
resp.headers = {"content-type": ctype}
|
|
return resp
|
|
|
|
def test_happy_path_returns_session(self, provider, rsa_keypair):
|
|
access_token = _mint_token(rsa_keypair)
|
|
mock_resp = self._mock_post(
|
|
200,
|
|
{
|
|
"access_token": access_token,
|
|
"token_type": "Bearer",
|
|
"refresh_token": "rt_initial_value",
|
|
},
|
|
)
|
|
with patch("plugins.dashboard_auth._shared.httpx.post", return_value=mock_resp):
|
|
session = provider.complete_login(
|
|
code="abc",
|
|
state="state-val",
|
|
code_verifier="vfy",
|
|
redirect_uri="https://hermes.fly.dev/auth/callback",
|
|
)
|
|
assert isinstance(session, Session)
|
|
assert session.user_id == "usr_abc"
|
|
assert session.provider == "nous"
|
|
assert session.access_token == access_token
|
|
# The dashboard auth-code grant now issues a refresh token (NAS #293);
|
|
# complete_login must surface it so the middleware persists it.
|
|
assert session.refresh_token == "rt_initial_value"
|
|
assert session.org_id == "org_xyz"
|
|
assert session.email == ""
|
|
assert session.display_name == ""
|
|
|
|
def test_400_raises_invalid_code(self, provider):
|
|
mock_resp = self._mock_post(400, {"error": "invalid_grant"})
|
|
with patch("plugins.dashboard_auth._shared.httpx.post", return_value=mock_resp):
|
|
with pytest.raises(InvalidCodeError, match="invalid_grant"):
|
|
provider.complete_login(
|
|
code="bad", state="s", code_verifier="v",
|
|
redirect_uri="https://hermes.fly.dev/auth/callback",
|
|
)
|
|
|
|
def test_500_raises_provider_error(self, provider):
|
|
mock_resp = self._mock_post(500, "internal server error", ctype="text/plain")
|
|
mock_resp.text = "internal server error"
|
|
with patch("plugins.dashboard_auth._shared.httpx.post", return_value=mock_resp):
|
|
with pytest.raises(ProviderError, match="500"):
|
|
provider.complete_login(
|
|
code="x", state="s", code_verifier="v",
|
|
redirect_uri="https://hermes.fly.dev/auth/callback",
|
|
)
|
|
|
|
def test_missing_access_token_raises(self, provider):
|
|
mock_resp = self._mock_post(200, {"token_type": "Bearer"})
|
|
with patch("plugins.dashboard_auth._shared.httpx.post", return_value=mock_resp):
|
|
with pytest.raises(ProviderError, match="access_token"):
|
|
provider.complete_login(
|
|
code="x", state="s", code_verifier="v",
|
|
redirect_uri="https://hermes.fly.dev/auth/callback",
|
|
)
|
|
|
|
def test_unexpected_token_type_raises(self, provider, rsa_keypair):
|
|
access_token = _mint_token(rsa_keypair)
|
|
mock_resp = self._mock_post(
|
|
200, {"access_token": access_token, "token_type": "DPoP"}
|
|
)
|
|
with patch("plugins.dashboard_auth._shared.httpx.post", return_value=mock_resp):
|
|
with pytest.raises(ProviderError, match="token_type"):
|
|
provider.complete_login(
|
|
code="x", state="s", code_verifier="v",
|
|
redirect_uri="https://hermes.fly.dev/auth/callback",
|
|
)
|
|
|
|
def test_network_error_raises_provider_error(self, provider):
|
|
with patch(
|
|
"plugins.dashboard_auth._shared.httpx.post",
|
|
side_effect=httpx.ConnectError("conn refused"),
|
|
):
|
|
with pytest.raises(ProviderError, match="unreachable"):
|
|
provider.complete_login(
|
|
code="x", state="s", code_verifier="v",
|
|
redirect_uri="https://hermes.fly.dev/auth/callback",
|
|
)
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# verify_session
|
|
# ---------------------------------------------------------------------------
|
|
|
|
class TestVerifySession:
|
|
@pytest.fixture
|
|
def provider(self, rsa_keypair):
|
|
p = nous_plugin.NousDashboardAuthProvider(
|
|
client_id="agent:inst123", portal_url="https://portal.example.com"
|
|
)
|
|
_patched_jwks(p, rsa_keypair)
|
|
return p
|
|
|
|
def test_expired_token_returns_none(self, provider, rsa_keypair):
|
|
token = _mint_token(rsa_keypair, ttl_seconds=-1)
|
|
assert provider.verify_session(access_token=token) is None
|
|
|
|
def test_wrong_audience_raises_provider_error(self, provider, rsa_keypair):
|
|
token = _mint_token(rsa_keypair, aud="agent:other-instance")
|
|
with pytest.raises(ProviderError, match="verification failed"):
|
|
provider.verify_session(access_token=token)
|
|
|
|
def test_verification_failure_message_surfaces_token_claims(
|
|
self, provider, rsa_keypair
|
|
):
|
|
"""Operators need to see the actual iss/aud the token carries to debug
|
|
config drift between HERMES_DASHBOARD_PORTAL_URL/CLIENT_ID and Portal."""
|
|
token = _mint_token(rsa_keypair, iss="https://evil.example")
|
|
with pytest.raises(ProviderError) as excinfo:
|
|
provider.verify_session(access_token=token)
|
|
msg = str(excinfo.value)
|
|
# Both the observed (token) and expected (configured) values appear.
|
|
assert "'https://evil.example'" in msg
|
|
assert "'https://portal.example.com'" in msg # configured portal URL
|
|
|
|
def test_agent_instance_id_mismatch_rejected(self, provider, rsa_keypair):
|
|
token = _mint_token(rsa_keypair, agent_instance_id="some-other-id")
|
|
with pytest.raises(ProviderError, match="agent_instance_id mismatch"):
|
|
provider.verify_session(access_token=token)
|
|
|
|
def test_contract_version_missing_warns_but_succeeds(
|
|
self, provider, rsa_keypair, caplog
|
|
):
|
|
import logging
|
|
token = _mint_token(rsa_keypair, oauth_contract_version=None)
|
|
with caplog.at_level(logging.WARNING, logger="plugins.dashboard_auth.nous"):
|
|
session = provider.verify_session(access_token=token)
|
|
assert session is not None
|
|
assert any(
|
|
"oauth_contract_version" in r.message for r in caplog.records
|
|
)
|
|
|
|
def test_jwks_unreachable_raises_provider_error(self, provider, rsa_keypair):
|
|
token = _mint_token(rsa_keypair)
|
|
# Replace the patched client so it raises.
|
|
bad_client = MagicMock()
|
|
bad_client.get_signing_key_from_jwt.side_effect = jwt.PyJWKClientError(
|
|
"fetch failed"
|
|
)
|
|
provider._jwks_client = bad_client
|
|
with pytest.raises(ProviderError, match="JWKS"):
|
|
provider.verify_session(access_token=token)
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# refresh_session + revoke_session
|
|
# ---------------------------------------------------------------------------
|
|
|
|
class TestRefreshAndRevoke:
|
|
@pytest.fixture
|
|
def provider(self, rsa_keypair):
|
|
p = nous_plugin.NousDashboardAuthProvider(
|
|
client_id="agent:inst123", portal_url="https://portal.example.com"
|
|
)
|
|
_patched_jwks(p, rsa_keypair)
|
|
return p
|
|
|
|
def _mock_post(self, status_code, body, *, ctype="application/json"):
|
|
resp = MagicMock(spec=httpx.Response)
|
|
resp.status_code = status_code
|
|
if isinstance(body, dict):
|
|
resp.text = json.dumps(body)
|
|
resp.json = MagicMock(return_value=body)
|
|
else:
|
|
resp.text = body
|
|
resp.json = MagicMock(side_effect=ValueError("not json"))
|
|
resp.headers = {"content-type": ctype}
|
|
return resp
|
|
|
|
def test_refresh_happy_path_returns_rotated_session(self, provider, rsa_keypair):
|
|
# Portal returns a fresh access token AND a rotated refresh token.
|
|
access_token = _mint_token(rsa_keypair)
|
|
mock_resp = self._mock_post(
|
|
200,
|
|
{
|
|
"access_token": access_token,
|
|
"token_type": "Bearer",
|
|
"refresh_token": "rt_rotated_value",
|
|
},
|
|
)
|
|
with patch(
|
|
"plugins.dashboard_auth._shared.httpx.post", return_value=mock_resp
|
|
) as mock_post:
|
|
session = provider.refresh_session(refresh_token="rt_old_value")
|
|
|
|
assert isinstance(session, Session)
|
|
assert session.access_token == access_token
|
|
# The ROTATED refresh token must be surfaced so the middleware can
|
|
# persist it back to the cookie.
|
|
assert session.refresh_token == "rt_rotated_value"
|
|
assert session.provider == "nous"
|
|
|
|
# Posts grant_type=refresh_token with the RT in BOTH the body (Portal's
|
|
# schema requires it there) and the X-Refresh-Token header (log
|
|
# redaction). Verified against the live preview deploy.
|
|
_, kwargs = mock_post.call_args
|
|
assert kwargs["data"]["grant_type"] == "refresh_token"
|
|
assert kwargs["data"]["client_id"] == "agent:inst123"
|
|
assert kwargs["data"]["refresh_token"] == "rt_old_value"
|
|
assert kwargs["headers"]["x-nous-refresh-token"] == "rt_old_value"
|