Files
openclaw-studio/tests/unit/connectionPanel-close.test.ts
T
George Pickett 732b994120 Harden agent id validation, session keys, agent-state rollback, and gateway/auth reliability
Centralize OpenClaw agent id validation in a new module
(src/lib/agents/agentIds.ts) and route every gateway, cron, ssh, and
intent path through it. Tighten the safe-id regex to match the gateway's
64-char normalization and reserve "main" from UI creation.

Add symlink-aware boundary checks and move rollback to
trash/restoreAgentStateLocally and the SSH equivalent so a failed move
never leaves the filesystem half-migrated, and restore refuses symlinks
that escape stateDir.

Validate session keys (hasMalformedAgentSessionKey,
sessionKeyBelongsToAgent) and cron job fields before trusting gateway
output, and compare cron agent ids case-insensitively.

Refactor applyGatewayConfigPatch and exec-approvals retry to fetch the
snapshot inside the retry callback, eliminating a stale-baseHash race.

Harden the control-plane adapter: stop() now waits on in-flight start,
times out hung sockets, and ignores stale ws event handlers via a
connection epoch.

Close a WebSocket upgrade auth bypass in server/index.js by routing
upgrades through accessGate.allowUpgrade, make access-gate cookie values
URL-safe and stop reconstructing redirect URLs from Host headers, and
apply the access gate to all non-token requests rather than only /api/.

Read media via realpath + boundary re-check, enforce MAX_MEDIA_BYTES on
remote SSH responses, and whitelist response MIME types. Clean up SSE
streams on client abort.

Normalize localhost gateway URLs in studio-settings so token hints only
apply when the draft URL matches, and write settings atomically.

Make the Playwright port configurable (PLAYWRIGHT_PORT, default 3100)
to avoid colliding with the running dev server, and ignore .worktrees
in eslint.

Add unit tests for the new agentIds module, gateway connect profile,
disconnect-like errors, local gateway, and studio settings store, and
extend existing tests to cover the new validation, rollback, retry, and
normalization paths.
2026-06-22 10:06:22 -07:00

91 lines
2.6 KiB
TypeScript

import { createElement } from "react";
import { afterEach, describe, expect, it, vi } from "vitest";
import { cleanup, fireEvent, render, screen } from "@testing-library/react";
import { ConnectionPanel } from "@/features/agents/components/ConnectionPanel";
const buildProps = () => ({
savedGatewayUrl: "ws://127.0.0.1:18789",
draftGatewayUrl: "ws://127.0.0.1:18789",
token: "token",
hasStoredToken: true,
localGatewayDefaults: null,
localGatewayDefaultsHasToken: false,
hasUnsavedChanges: false,
status: "disconnected" as const,
statusReason: null,
error: null,
testResult: null,
saving: false,
testing: false,
disconnecting: false,
onGatewayUrlChange: vi.fn(),
onTokenChange: vi.fn(),
onSaveSettings: vi.fn(),
onTestConnection: vi.fn(),
onDisconnect: vi.fn(),
});
describe("ConnectionPanel close control", () => {
afterEach(() => {
cleanup();
});
it("renders close control and calls handler when provided", () => {
const onClose = vi.fn();
const props = buildProps();
render(
createElement(ConnectionPanel, {
...props,
onClose,
})
);
fireEvent.click(screen.getByTestId("gateway-connection-close"));
expect(onClose).toHaveBeenCalledTimes(1);
});
it("does not render close control when handler is missing", () => {
render(createElement(ConnectionPanel, buildProps()));
expect(screen.queryByTestId("gateway-connection-close")).not.toBeInTheDocument();
});
it("renders semantic gateway status class markers", () => {
const { rerender } = render(
createElement(ConnectionPanel, {
...buildProps(),
})
);
const disconnected = screen.getByText("Disconnected");
expect(disconnected).toHaveAttribute("data-status", "disconnected");
expect(disconnected).toHaveClass("ui-badge-status-disconnected");
rerender(
createElement(ConnectionPanel, {
...buildProps(),
status: "connected",
})
);
const connected = screen.getByText("Connected");
expect(connected).toHaveAttribute("data-status", "connected");
expect(connected).toHaveClass("ui-badge-status-connected");
});
it("disables connection actions while disconnecting", () => {
render(
createElement(ConnectionPanel, {
...buildProps(),
status: "connected",
disconnecting: true,
})
);
expect(screen.getByRole("button", { name: "Save settings" })).toBeDisabled();
expect(screen.getByRole("button", { name: "Test connection" })).toBeDisabled();
expect(screen.getByRole("button", { name: "Disconnecting…" })).toBeDisabled();
});
});