# Conflicts: # apps/desktop/e2e/archived-hidden-session-recoverable.spec.ts # apps/desktop/e2e/bot-chat-message-agent-friendly-name.spec.ts # apps/desktop/e2e/bot-mailbox-unreadable-ticket.spec.ts # apps/desktop/e2e/bot-mode-roster-localized.spec.ts # apps/desktop/e2e/bot-mode-row-click-mirrors-registry.spec.ts # apps/desktop/e2e/bot-mode-tab-shows-bot-name.spec.ts # apps/desktop/e2e/bot-roster-group-row-organisation.spec.ts # apps/desktop/e2e/bot-roster-ignores-infra-dirs.spec.ts # apps/desktop/e2e/bot-roster-timestamp-meta.spec.ts # apps/desktop/e2e/bot-roster-user-sections.spec.ts # apps/desktop/e2e/bot-routines-pane-narrow.spec.ts # apps/desktop/e2e/bot-row-open-recent-session.spec.ts # apps/desktop/e2e/bot-tile-ignores-ambient-composer-model.spec.ts # apps/desktop/e2e/group-composer-auto-grow.spec.ts # apps/desktop/e2e/group-create-gate-remote-roster.spec.ts # apps/desktop/e2e/group-prompt-renamed-primary-handle.spec.ts # apps/desktop/e2e/hosted-room-backend-continuity.spec.ts # apps/desktop/e2e/hosted-room-legacy-store-migration.spec.ts # apps/desktop/e2e/settings-scope-chips-bot-title.spec.ts # apps/desktop/e2e/worktree-branch-status.spec.ts # apps/desktop/electron/backend-probes.test.ts # apps/desktop/electron/connection-apply.test.ts # apps/desktop/electron/desktop-electron-pin.test.ts # apps/desktop/electron/desktop-uninstall.test.ts # apps/desktop/electron/gateway-file-download-transport.test.ts # apps/desktop/electron/gateway-stop-before-update.test.ts # apps/desktop/electron/github-api-auth.test.ts # apps/desktop/electron/registry-primary-profile-scope.test.ts # apps/desktop/electron/update-api-check.test.ts # apps/desktop/electron/update-handoff-marker.test.ts # apps/desktop/electron/venv-blocker-scan.test.ts # apps/desktop/scripts/after-extract.test.mjs # apps/desktop/scripts/local-pack-publish.test.mjs # apps/desktop/scripts/tasks-scroll.test.mjs # apps/desktop/src/app/settings/model-settings.test.tsx # apps/desktop/src/app/updates-overlay.blockers.test.tsx # apps/desktop/src/components/desktop-install-overlay.test.tsx # apps/desktop/src/lib/update-copy.test.ts # scripts/ci/check_os_marker_fakes.py # tests-js/desktop-mac-usage-descriptions.test.ts # tests-js/node-engine-alignment.test.ts # tests/agent/lsp/test_install_and_lint_fixes.py # tests/agent/test_command_token_source.py # tests/agent/test_compression_boundary_hook.py # tests/agent/test_create_openai_client_ssl_verify.py # tests/agent/test_custom_provider_ca_probes.py # tests/agent/test_endpoint_blackhole.py # tests/agent/test_estimator_parity.py # tests/agent/test_in_place_compaction.py # tests/agent/test_moa_loop_mode.py # tests/agent/test_model_metadata.py # tests/agent/test_skill_session_platform_gate.py # tests/agent/test_skill_utils.py # tests/agent/test_ssl_ca_guard.py # tests/computer_use/test_doctor.py # tests/cron/test_codex_execution_paths.py # tests/cron/test_cron_bot_chat_delivery.py # tests/cron/test_cron_script.py # tests/cron/test_media_delivery_parity.py # tests/cron/test_misfire_catchup.py # tests/cron/test_parallel_pool.py # tests/cron/test_recurring_eagain_redispatch.py # tests/gateway/test_choice_picker.py # tests/gateway/test_control_socket_windows_live.py # tests/gateway/test_dingtalk.py # tests/gateway/test_feishu.py # tests/gateway/test_feishu_onboard.py # tests/gateway/test_gateway_shutdown.py # tests/gateway/test_matrix.py # tests/gateway/test_model_command_custom_providers.py # tests/gateway/test_reasoning_command.py # tests/gateway/test_runtime_footer.py # tests/gateway/test_session.py # tests/gateway/test_session_hygiene.py # tests/gateway/test_status.py # tests/gateway/test_teams.py # tests/gateway/test_turn_lease.py # tests/gateway/test_whatsapp_connect.py # tests/hermes_cli/test_approvals_command.py # tests/hermes_cli/test_auth_store_lock_concurrent.py # tests/hermes_cli/test_backup.py # tests/hermes_cli/test_banner_git_state.py # tests/hermes_cli/test_certifi_repair.py # tests/hermes_cli/test_cmd_update.py # tests/hermes_cli/test_compat_manifest_targets.py # tests/hermes_cli/test_computer_use_cli.py # tests/hermes_cli/test_cpr_local_leak.py # tests/hermes_cli/test_dashboard_auth_gate.py # tests/hermes_cli/test_dashboard_procs_kill_grace.py # tests/hermes_cli/test_desktop_lifecycle_windows_live.py # tests/hermes_cli/test_doctor.py # tests/hermes_cli/test_doctor_command_install.py # tests/hermes_cli/test_fleet_config_migration_windows_live.py # tests/hermes_cli/test_gateway.py # tests/hermes_cli/test_gateway_platform_gating.py # tests/hermes_cli/test_gateway_restart_loop.py # tests/hermes_cli/test_gateway_task_probe.py # tests/hermes_cli/test_gateway_wsl.py # tests/hermes_cli/test_gui_command.py # tests/hermes_cli/test_install_cua_driver.py # tests/hermes_cli/test_kanban_db.py # tests/hermes_cli/test_lazy_command_exports.py # tests/hermes_cli/test_lazy_refresh_venv_repair.py # tests/hermes_cli/test_linux_desktop_entry.py # tests/hermes_cli/test_local_runtime.py # tests/hermes_cli/test_local_runtime_updates.py # tests/hermes_cli/test_managed_uv.py # tests/hermes_cli/test_mcp_reload_confirm_gate.py # tests/hermes_cli/test_nous_subscription.py # tests/hermes_cli/test_npm_engine.py # tests/hermes_cli/test_personality_none.py # tests/hermes_cli/test_pet_toggle.py # tests/hermes_cli/test_plan_reconciliation_windows_live.py # tests/hermes_cli/test_plugin_event_bus.py # tests/hermes_cli/test_plugin_manifest_v2.py # tests/hermes_cli/test_plugin_packs.py # tests/hermes_cli/test_plugins_cmd.py # tests/hermes_cli/test_plugins_cmd_enable_disable_nested.py # tests/hermes_cli/test_process_identity.py # tests/hermes_cli/test_profiles.py # tests/hermes_cli/test_profiles_sidebar_cache.py # tests/hermes_cli/test_pty_bridge.py # tests/hermes_cli/test_resolve_turn_limit.py # tests/hermes_cli/test_serve_runtime_inventory.py # tests/hermes_cli/test_session_vacuum_config.py # tests/hermes_cli/test_set_config_value.py # tests/hermes_cli/test_signal_handler_kanban_worker.py # tests/hermes_cli/test_slash_confirm_windows.py # tests/hermes_cli/test_stale_pid_guard.py # tests/hermes_cli/test_startup_fast_guards.py # tests/hermes_cli/test_status.py # tests/hermes_cli/test_telegram_managed_bot.py # tests/hermes_cli/test_tools_config.py # tests/hermes_cli/test_update_apply_shallow_count.py # tests/hermes_cli/test_update_autostash.py # tests/hermes_cli/test_update_concurrent_quarantine.py # tests/hermes_cli/test_update_fetch_failure_classifier.py # tests/hermes_cli/test_update_fleet_probe_resume_token.py # tests/hermes_cli/test_update_handoff_backend_reap.py # tests/hermes_cli/test_update_handoff_desktop_rebuild.py # tests/hermes_cli/test_update_head_moved_gate.py # tests/hermes_cli/test_update_host_obligation.py # tests/hermes_cli/test_update_import_guard.py # tests/hermes_cli/test_update_interrupted_recovery.py # tests/hermes_cli/test_update_inventory.py # tests/hermes_cli/test_update_launchd_unloaded_gateway.py # tests/hermes_cli/test_update_missing_configured_deps.py # tests/hermes_cli/test_update_modified_notice.py # tests/hermes_cli/test_update_multiplex_migration_hook.py # tests/hermes_cli/test_update_no_gateway_restart.py # tests/hermes_cli/test_update_orphan_backend_reap.py # tests/hermes_cli/test_update_parked_branch_guard.py # tests/hermes_cli/test_update_post_pull_syntax_guard.py # tests/hermes_cli/test_update_receipt.py # tests/hermes_cli/test_update_self_lock.py # tests/hermes_cli/test_update_shim_fail_closed.py # tests/hermes_cli/test_update_shim_self_lock.py # tests/hermes_cli/test_update_sqlite_remediation.py # tests/hermes_cli/test_update_stale_dashboard.py # tests/hermes_cli/test_update_stale_virtualenv.py # tests/hermes_cli/test_update_venv_health.py # tests/hermes_cli/test_update_venv_ownership_preflight.py # tests/hermes_cli/test_update_wedged_gateway.py # tests/hermes_cli/test_update_yes_flag.py # tests/hermes_cli/test_update_zip_two_phase.py # tests/hermes_cli/test_urllib_security.py # tests/hermes_cli/test_ux_messages_auth_config.py # tests/hermes_cli/test_ux_messages_startup.py # tests/hermes_cli/test_venv_holder_classifier.py # tests/hermes_cli/test_verify_console_scripts.py # tests/hermes_cli/test_verify_core_dependencies.py # tests/hermes_cli/test_web_server.py # tests/hermes_cli/test_web_server_console_ws.py # tests/hermes_cli/test_web_server_ws_ping.py # tests/hermes_cli/test_web_ui_build.py # tests/hermes_state/test_fts_rebuild_admission.py # tests/hermes_state/test_hermes_state.py # tests/plugins/memory/test_memory_lazy_install.py # tests/plugins/test_google_meet_plugin.py # tests/plugins/test_langfuse_plugin.py # tests/plugins/test_security_guidance_plugin.py # tests/plugins/test_transform_llm_output_hook.py # tests/scripts/desktop_update/test_desktop_update_windows_gateway_flag.py # tests/scripts/desktop_update/test_desktop_update_windows_python_handoff.py # tests/scripts/desktop_update/test_desktop_update_windows_timestamp.py # tests/scripts/install/test_install_clone_throttle_fallback.py # tests/scripts/install/test_install_lockfile_churn.py # tests/scripts/install/test_install_no_initial_commit.py # tests/scripts/install/test_install_sh_browser_install.py # tests/scripts/install/test_install_sh_node_prerelease.py # tests/scripts/install/test_install_sh_symlink_stomp.py # tests/scripts/install/test_install_sh_uv_lock_config.py # tests/scripts/install/test_install_unmerged_index.py # tests/scripts/test_contributor_map.py # tests/scripts/test_run_tests_parallel.py # tests/skills/test_competitor_news_monitor_skill.py # tests/skills/test_document_to_action_items_skill.py # tests/skills/test_google_workspace_setup.py # tests/skills/test_google_workspace_setup_deps.py # tests/skills/test_grounded_citations_skill.py # tests/skills/test_ip_as_logo_skill.py # tests/skills/test_live_dashboard_skill.py # tests/skills/test_mcp_oauth_remote_gateway_skill.py # tests/skills/test_office_document_skills.py # tests/skills/test_openclaw_migration.py # tests/skills/test_product_price_monitor_skill.py # tests/skills/test_scrollcraft_skill.py # tests/skills/test_setup_wizard_generator_skill.py # tests/skills/test_weekly_review_planning_skill.py # tests/test_engines_satisfiable.py # tests/test_fast_safe_load.py # tests/test_hermes_bootstrap.py # tests/test_hermes_constants.py # tests/test_hermes_logging.py # tests/test_managed_runtime_resolution.py # tests/test_model_tools_async_bridge.py # tests/test_packaging_build_guard.py # tests/test_packaging_metadata.py # tests/test_yaml_indent_consistency.py # tests/tools/test_approval_timeout_overflow.py # tests/tools/test_base_environment.py # tests/tools/test_bot_mode_dm.py # tests/tools/test_browser_chromium_check.py # tests/tools/test_browser_hardening.py # tests/tools/test_browser_homebrew_paths.py # tests/tools/test_browser_npx_warmup.py # tests/tools/test_browser_orphan_reaper.py # tests/tools/test_browser_real_profile.py # tests/tools/test_browser_use_cli.py # tests/tools/test_clipboard.py # tests/tools/test_code_execution.py # tests/tools/test_code_execution_modes.py # tests/tools/test_code_execution_windows_env.py # tests/tools/test_computer_use.py # tests/tools/test_delegate_liveness_timeout.py # tests/tools/test_execute_code_approval_cluster.py # tests/tools/test_execution_flag_detection.py # tests/tools/test_fal_common.py # tests/tools/test_file_operations.py # tests/tools/test_file_tools.py # tests/tools/test_file_tools_cwd_resolution.py # tests/tools/test_file_tools_live.py # tests/tools/test_lazy_deps.py # tests/tools/test_lazy_deps_durable_target.py # tests/tools/test_lazy_deps_managed.py # tests/tools/test_local_env_blocklist.py # tests/tools/test_local_tempdir.py # tests/tools/test_macos_protected_search.py # tests/tools/test_mcp_npx_cached_bin.py # tests/tools/test_oneshot_completion_linger.py # tests/tools/test_process_registry.py # tests/tools/test_read_file_schema_gating.py # tests/tools/test_skill_improvements.py # tests/tools/test_skills_sync.py # tests/tools/test_termux_api_detection.py # tests/tools/test_tirith_security.py # tests/tools/test_transcription_tools.py # tests/tools/test_tts_streaming.py # tests/tools/test_wake_word.py # tests/tui_gateway/test_compute_host_borrowed_lease.py # tests/tui_gateway/test_compute_host_turn_protocol.py # tests/tui_gateway/test_isolated_orphan_activity.py # tests/tui_gateway/test_protocol.py # tests/tui_gateway/test_slash_worker_profile_home.py # tests/tui_gateway/test_subprocess_encoding.py # tests/tui_gateway/test_tui_gateway_server.py # ui-tui/src/__tests__/terminalParity.test.ts # ui-tui/src/__tests__/termuxComposerLayout.test.ts # ui-tui/src/__tests__/textInputFastEcho.test.ts
251 lines
11 KiB
Python
251 lines
11 KiB
Python
"""Regression coverage for required Codex identity and account headers.
|
|
|
|
The official Codex endpoint must receive Hermes' own harness identity, rather
|
|
than the historical first-party compatibility identity. Live endpoint
|
|
acceptance is a separate smoke test; these tests verify request construction.
|
|
|
|
``_codex_cloudflare_headers`` in ``agent.auxiliary_client`` centralizes the
|
|
header set so the primary chat client (``run_agent.AIAgent.__init__`` +
|
|
``_apply_client_headers_for_base_url``) and the auxiliary client paths
|
|
(``_build_codex_client`` and the ``raw_codex`` branch of ``resolve_provider_client``)
|
|
all emit the same headers.
|
|
|
|
These tests pin:
|
|
- the required Hermes originator
|
|
- the versioned Hermes User-Agent
|
|
- ``ChatGPT-Account-ID`` extraction from the OAuth JWT (canonical casing,
|
|
from codex-rs ``auth.rs``)
|
|
- graceful handling of malformed tokens (drop the account-ID header, don't
|
|
raise)
|
|
- primary-client wiring at both entry points in ``run_agent.py``
|
|
- aux-client wiring at both entry points in ``agent/auxiliary_client.py``
|
|
"""
|
|
from __future__ import annotations
|
|
|
|
import base64
|
|
import json
|
|
from unittest.mock import MagicMock, patch
|
|
|
|
from hermes_cli import __version__
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Fixtures
|
|
# ---------------------------------------------------------------------------
|
|
|
|
def _make_codex_jwt(
|
|
account_id: str = "acct-test-123",
|
|
data_residency: str | None = None,
|
|
compute_residency: str | None = None,
|
|
) -> str:
|
|
"""Build a syntactically valid Codex-style JWT with the account_id claim."""
|
|
def b64url(data: bytes) -> str:
|
|
return base64.urlsafe_b64encode(data).rstrip(b"=").decode()
|
|
header = b64url(b'{"alg":"RS256","typ":"JWT"}')
|
|
auth_claims: dict = {
|
|
"chatgpt_account_id": account_id,
|
|
"chatgpt_plan_type": "plus",
|
|
}
|
|
if data_residency is not None:
|
|
auth_claims["chatgpt_data_residency"] = data_residency
|
|
if compute_residency is not None:
|
|
auth_claims["chatgpt_compute_residency"] = compute_residency
|
|
claims = {
|
|
"sub": "user-xyz",
|
|
"exp": 9999999999,
|
|
"https://api.openai.com/auth": auth_claims,
|
|
}
|
|
payload = b64url(json.dumps(claims).encode())
|
|
sig = b64url(b"fake-sig")
|
|
return f"{header}.{payload}.{sig}"
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# _codex_cloudflare_headers — the shared helper
|
|
# ---------------------------------------------------------------------------
|
|
|
|
class TestCodexCloudflareHeaders:
|
|
|
|
def test_user_agent_advertises_hermes_version(self):
|
|
from agent.auxiliary_client import _codex_cloudflare_headers
|
|
headers = _codex_cloudflare_headers(_make_codex_jwt())
|
|
assert headers["User-Agent"] == f"HermesAgent/{__version__}"
|
|
assert headers["originator"] == "hermes-agent"
|
|
|
|
|
|
|
|
|
|
|
|
def test_jwt_without_chatgpt_account_id_claim(self):
|
|
"""A valid JWT that lacks the account_id claim should still return headers."""
|
|
from agent.auxiliary_client import _codex_cloudflare_headers
|
|
import base64 as _b64, json as _json
|
|
|
|
def b64url(data: bytes) -> str:
|
|
return _b64.urlsafe_b64encode(data).rstrip(b"=").decode()
|
|
payload = b64url(_json.dumps({"sub": "user-xyz", "exp": 9999999999}).encode())
|
|
token = f"{b64url(b'{}')}.{payload}.{b64url(b'sig')}"
|
|
headers = _codex_cloudflare_headers(token)
|
|
assert headers["originator"] == "hermes-agent"
|
|
assert "ChatGPT-Account-ID" not in headers
|
|
|
|
def test_residency_header_from_jwt_claims(self, monkeypatch):
|
|
"""#23896: residency-enforced workspaces 401 without x-openai-internal-codex-residency.
|
|
chatgpt_data_residency wins; chatgpt_compute_residency is the fallback; and the two
|
|
models-catalog probes (picker via httpx, context-length via model_metadata_http) send it on the
|
|
wire — not just the shared helper."""
|
|
import sys
|
|
|
|
from agent import model_metadata
|
|
from agent.auxiliary_client import _codex_cloudflare_headers
|
|
from hermes_cli import codex_models
|
|
|
|
both = _make_codex_jwt(data_residency="us", compute_residency="eu")
|
|
assert _codex_cloudflare_headers(both)["x-openai-internal-codex-residency"] == "us"
|
|
compute_only = _make_codex_jwt(compute_residency="eu")
|
|
|
|
sent: list[dict] = []
|
|
|
|
class _FakeResp:
|
|
status_code = 200
|
|
|
|
def json(self):
|
|
# Non-empty so the newest-client request is accepted and each site makes one call
|
|
# (an empty answer would legitimately trigger the 0.0.0 sentinel fallback).
|
|
return {"models": [{"slug": "gpt-5.5", "visibility": "list"}]}
|
|
|
|
class _FakeHttp:
|
|
@staticmethod
|
|
def get(url, headers=None, timeout=None, verify=None, **kwargs):
|
|
sent.append(dict(headers or {}))
|
|
return _FakeResp()
|
|
|
|
monkeypatch.setitem(sys.modules, "httpx", _FakeHttp)
|
|
codex_models._fetch_models_from_api(access_token=compute_only)
|
|
# The context-length probe goes through the shared model_metadata_http seam.
|
|
from agent import model_metadata_http
|
|
monkeypatch.setattr(model_metadata_http, "get", _FakeHttp.get)
|
|
monkeypatch.setattr(model_metadata, "_codex_oauth_context_cache", {})
|
|
model_metadata._fetch_codex_oauth_context_lengths_with_source(compute_only)
|
|
|
|
assert len(sent) == 2
|
|
for headers in sent:
|
|
assert headers["x-openai-internal-codex-residency"] == "eu"
|
|
assert headers["ChatGPT-Account-ID"] == "acct-test-123"
|
|
|
|
def test_no_residency_claim_omits_header(self):
|
|
"""Control: tokens without the claim, and malformed tokens, never carry the header."""
|
|
from agent.auxiliary_client import _codex_cloudflare_headers
|
|
for token in [_make_codex_jwt(), "not-a-jwt", "", "only.one", " ", "...."]:
|
|
headers = _codex_cloudflare_headers(token)
|
|
assert "x-openai-internal-codex-residency" not in headers
|
|
assert headers["originator"] == "hermes-agent"
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Primary chat client wiring (run_agent.AIAgent)
|
|
# ---------------------------------------------------------------------------
|
|
|
|
class TestPrimaryClientWiring:
|
|
|
|
def test_apply_client_headers_on_base_url_change(self):
|
|
"""Credential-rotation / base-url change path must also emit codex headers."""
|
|
from run_agent import AIAgent
|
|
token = _make_codex_jwt("acct-rotation")
|
|
with patch("agent.process_bootstrap.OpenAI") as mock_openai:
|
|
mock_openai.return_value = MagicMock()
|
|
agent = AIAgent(
|
|
api_key="placeholder-openrouter-key",
|
|
base_url="https://openrouter.ai/api/v1",
|
|
provider="openrouter",
|
|
model="anthropic/claude-sonnet-4.6",
|
|
quiet_mode=True,
|
|
skip_context_files=True,
|
|
skip_memory=True,
|
|
)
|
|
# Simulate rotation into a Codex credential
|
|
agent._client_kwargs["api_key"] = token
|
|
agent._apply_client_headers_for_base_url(
|
|
"https://chatgpt.com/backend-api/codex"
|
|
)
|
|
headers = agent._client_kwargs.get("default_headers") or {}
|
|
assert headers.get("originator") == "hermes-agent"
|
|
assert headers.get("ChatGPT-Account-ID") == "acct-rotation"
|
|
assert headers.get("User-Agent") == f"HermesAgent/{__version__}"
|
|
|
|
def test_apply_client_headers_clears_codex_headers_off_chatgpt(self):
|
|
"""Switching AWAY from chatgpt.com must drop the codex headers."""
|
|
from run_agent import AIAgent
|
|
token = _make_codex_jwt()
|
|
with patch("agent.process_bootstrap.OpenAI") as mock_openai:
|
|
mock_openai.return_value = MagicMock()
|
|
agent = AIAgent(
|
|
api_key=token,
|
|
base_url="https://chatgpt.com/backend-api/codex",
|
|
provider="openai-codex",
|
|
model="gpt-5.4",
|
|
quiet_mode=True,
|
|
skip_context_files=True,
|
|
skip_memory=True,
|
|
)
|
|
# Sanity: headers are set initially
|
|
assert "originator" in (agent._client_kwargs.get("default_headers") or {})
|
|
agent._apply_client_headers_for_base_url(
|
|
"https://api.anthropic.com"
|
|
)
|
|
# default_headers should be popped for anthropic base
|
|
assert "default_headers" not in agent._client_kwargs
|
|
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Auxiliary client wiring (agent.auxiliary_client)
|
|
# ---------------------------------------------------------------------------
|
|
|
|
class TestAuxiliaryClientWiring:
|
|
def test_build_codex_client_passes_codex_headers(self, monkeypatch):
|
|
"""_build_codex_client builds the OpenAI client used for compression /
|
|
vision / title generation when routed through Codex. Must emit codex
|
|
headers."""
|
|
from agent import auxiliary_client
|
|
token = _make_codex_jwt("acct-aux-try-codex")
|
|
|
|
# Force _select_pool_entry to return "no pool" so we fall through to
|
|
# _read_codex_access_token.
|
|
monkeypatch.setattr(
|
|
auxiliary_client, "_select_pool_entry",
|
|
lambda provider: (False, None),
|
|
)
|
|
monkeypatch.setattr(
|
|
auxiliary_client, "_read_codex_access_token",
|
|
lambda: token,
|
|
)
|
|
with patch("agent.auxiliary_client.OpenAI") as mock_openai:
|
|
mock_openai.return_value = MagicMock()
|
|
client, model = auxiliary_client._build_codex_client("gpt-5.4")
|
|
assert client is not None
|
|
headers = mock_openai.call_args.kwargs.get("default_headers") or {}
|
|
assert headers.get("originator") == "hermes-agent"
|
|
assert headers.get("ChatGPT-Account-ID") == "acct-aux-try-codex"
|
|
assert headers.get("User-Agent") == f"HermesAgent/{__version__}"
|
|
|
|
def test_resolve_provider_client_raw_codex_passes_codex_headers(self, monkeypatch):
|
|
"""The ``raw_codex=True`` branch (used by the main agent loop for direct
|
|
responses.stream() access) must also emit codex headers."""
|
|
from agent import auxiliary_client
|
|
token = _make_codex_jwt("acct-aux-raw-codex")
|
|
monkeypatch.setattr(
|
|
auxiliary_client, "_read_codex_access_token",
|
|
lambda: token,
|
|
)
|
|
with patch("agent.auxiliary_client.OpenAI") as mock_openai:
|
|
mock_openai.return_value = MagicMock()
|
|
client, model = auxiliary_client.resolve_provider_client(
|
|
"openai-codex", model="gpt-5.4", raw_codex=True,
|
|
)
|
|
assert client is not None
|
|
headers = mock_openai.call_args.kwargs.get("default_headers") or {}
|
|
assert headers.get("originator") == "hermes-agent"
|
|
assert headers.get("ChatGPT-Account-ID") == "acct-aux-raw-codex"
|
|
assert headers.get("User-Agent") == f"HermesAgent/{__version__}"
|