|
| 1 | +import { randomBytes } from "node:crypto"; |
| 2 | + |
| 3 | +import { expect } from "@effect/vitest"; |
| 4 | +import { connectEmulator } from "@executor-js/emulate"; |
| 5 | +import { Effect } from "effect"; |
| 6 | +import { composePluginApi } from "@executor-js/api/server"; |
| 7 | +import { openApiHttpPlugin } from "@executor-js/plugin-openapi/api"; |
| 8 | +import { |
| 9 | + AuthTemplateSlug, |
| 10 | + ConnectionName, |
| 11 | + IntegrationSlug, |
| 12 | + OAuthClientSlug, |
| 13 | +} from "@executor-js/sdk/shared"; |
| 14 | + |
| 15 | +import { createEmulatorInstance } from "../src/emulator-instance"; |
| 16 | +import { scenario } from "../src/scenario"; |
| 17 | +import { Api, Browser, Mcp, Target } from "../src/services"; |
| 18 | + |
| 19 | +const api = composePluginApi([openApiHttpPlugin()] as const); |
| 20 | + |
| 21 | +scenario( |
| 22 | + "OAuth optional scopes · the integration partitions scopes and completes an authenticated connection", |
| 23 | + { timeout: 180_000 }, |
| 24 | + Effect.scoped( |
| 25 | + Effect.gen(function* () { |
| 26 | + const target = yield* Target; |
| 27 | + const browser = yield* Browser; |
| 28 | + const mcp = yield* Mcp; |
| 29 | + const { client: makeClient } = yield* Api; |
| 30 | + const identity = yield* target.newIdentity(); |
| 31 | + const client = yield* makeClient(api, identity); |
| 32 | + const session = mcp.session(identity); |
| 33 | + expect((yield* session.call("execute", { code: "return true;" })).ok).toBe(true); |
| 34 | + const base = yield* createEmulatorInstance("github", "optional-scopes"); |
| 35 | + const emulator = yield* Effect.promise(() => |
| 36 | + connectEmulator({ baseUrl: base, service: "github" }), |
| 37 | + ); |
| 38 | + yield* Effect.promise(() => emulator.seed({ users: [{ login: "optional-scope-user" }] })); |
| 39 | + const slug = IntegrationSlug.make(`optional-${randomBytes(4).toString("hex")}`); |
| 40 | + const app = OAuthClientSlug.make(`${slug}-app`); |
| 41 | + yield* Effect.addFinalizer(() => |
| 42 | + client.openapi.removeSpec({ params: { slug } }).pipe(Effect.orDie), |
| 43 | + ); |
| 44 | + yield* Effect.addFinalizer(() => |
| 45 | + client.oauth |
| 46 | + .removeClient({ params: { slug: app }, payload: { owner: "org" } }) |
| 47 | + .pipe(Effect.orDie), |
| 48 | + ); |
| 49 | + // GitHub supplies the real OAuth transport and protected resource. The test |
| 50 | + // verifies Executor's partitioning contract; it does not claim that GitHub |
| 51 | + // implements HubSpot's optional-grant policy. |
| 52 | + const authorizationUrl = `${base}/login/oauth/authorize`; |
| 53 | + const tokenUrl = `${base}/login/oauth/access_token`; |
| 54 | + yield* client.openapi.addSpec({ |
| 55 | + payload: { |
| 56 | + slug, |
| 57 | + baseUrl: base, |
| 58 | + spec: { |
| 59 | + kind: "blob", |
| 60 | + value: JSON.stringify({ |
| 61 | + openapi: "3.0.3", |
| 62 | + info: { title: "Optional scope API", version: "1" }, |
| 63 | + paths: { |
| 64 | + "/user": { |
| 65 | + get: { |
| 66 | + operationId: "getUser", |
| 67 | + security: [{ oauth: ["read:user"] }], |
| 68 | + responses: { "200": { description: "Authenticated user" } }, |
| 69 | + }, |
| 70 | + }, |
| 71 | + }, |
| 72 | + components: { |
| 73 | + securitySchemes: { |
| 74 | + oauth: { |
| 75 | + type: "oauth2", |
| 76 | + flows: { |
| 77 | + authorizationCode: { |
| 78 | + authorizationUrl, |
| 79 | + tokenUrl, |
| 80 | + scopes: { |
| 81 | + "read:user": "Read user", |
| 82 | + "user:email": "Read email when granted", |
| 83 | + }, |
| 84 | + }, |
| 85 | + }, |
| 86 | + }, |
| 87 | + }, |
| 88 | + }, |
| 89 | + }), |
| 90 | + }, |
| 91 | + authenticationTemplate: [ |
| 92 | + { |
| 93 | + slug: "oauth", |
| 94 | + kind: "oauth2", |
| 95 | + authorizationUrl: `${authorizationUrl}?optional_scope=user%3Aemail`, |
| 96 | + tokenUrl, |
| 97 | + scopes: ["read:user", "user:email"], |
| 98 | + }, |
| 99 | + ], |
| 100 | + }, |
| 101 | + }); |
| 102 | + yield* client.oauth.createClient({ |
| 103 | + payload: { |
| 104 | + owner: "org", |
| 105 | + slug: app, |
| 106 | + grant: "authorization_code", |
| 107 | + authorizationUrl, |
| 108 | + tokenUrl, |
| 109 | + clientId: "optional-test-client", |
| 110 | + clientSecret: "optional-test-secret", |
| 111 | + originIntegration: slug, |
| 112 | + }, |
| 113 | + }); |
| 114 | + const started = yield* client.oauth.start({ |
| 115 | + payload: { |
| 116 | + owner: "org", |
| 117 | + client: app, |
| 118 | + clientOwner: "org", |
| 119 | + name: ConnectionName.make("main"), |
| 120 | + integration: slug, |
| 121 | + template: AuthTemplateSlug.make("oauth"), |
| 122 | + }, |
| 123 | + }); |
| 124 | + if (started.status !== "redirect") |
| 125 | + return yield* Effect.die("Expected authorization redirect"); |
| 126 | + |
| 127 | + yield* Effect.addFinalizer(() => |
| 128 | + client.oauth.cancel({ payload: { state: started.state } }).pipe(Effect.orDie), |
| 129 | + ); |
| 130 | + const url = new URL(started.authorizationUrl); |
| 131 | + expect(url.searchParams.get("scope")).toBe("read:user"); |
| 132 | + expect(url.searchParams.get("optional_scope")).toBe("user:email"); |
| 133 | + yield* browser.session(identity, async ({ page, step }) => { |
| 134 | + await step("Review and approve the OAuth consent request", async () => { |
| 135 | + await page.goto(started.authorizationUrl); |
| 136 | + await page.getByRole("button", { name: /optional-scope-user/ }).click(); |
| 137 | + await page.getByText("Connected", { exact: true }).waitFor({ timeout: 30_000 }); |
| 138 | + }); |
| 139 | + }); |
| 140 | + yield* Effect.addFinalizer(() => |
| 141 | + client.connections |
| 142 | + .remove({ |
| 143 | + params: { owner: "org", integration: slug, name: ConnectionName.make("main") }, |
| 144 | + }) |
| 145 | + .pipe(Effect.orDie), |
| 146 | + ); |
| 147 | + const catalog = yield* client.tools.list({ query: { integration: slug } }); |
| 148 | + const tool = catalog.find((entry) => entry.name.endsWith("getUser")); |
| 149 | + if (!tool) |
| 150 | + return yield* Effect.die( |
| 151 | + `Authenticated getUser tool missing: ${catalog.map((entry) => entry.name).join(", ")}`, |
| 152 | + ); |
| 153 | + let result = yield* session.call("execute", { |
| 154 | + code: `const path = ${JSON.stringify(String(tool.address))}.split(".").slice(1); let call = tools; for (const part of path) call = call[part]; return await call({});`, |
| 155 | + }); |
| 156 | + for (let attempts = 0; result.text.includes("executionId:") && attempts < 10; attempts += 1) |
| 157 | + result = yield* session.approvePaused(result.text); |
| 158 | + expect(result.ok).toBe(true); |
| 159 | + expect(result.text).toContain("optional-scope-user"); |
| 160 | + const ledger = yield* Effect.promise(() => emulator.ledger.list()); |
| 161 | + const authorize = ledger.find( |
| 162 | + (entry) => entry.method === "GET" && entry.path.endsWith("/login/oauth/authorize"), |
| 163 | + ); |
| 164 | + expect(new URLSearchParams(authorize?.query).get("optional_scope")).toBe("user:email"); |
| 165 | + expect( |
| 166 | + ledger |
| 167 | + .filter((entry) => entry.path === "/user" && entry.response.status === 200) |
| 168 | + .map((entry) => entry.identity.user?.login), |
| 169 | + ).toContain("optional-scope-user"); |
| 170 | + }), |
| 171 | + ), |
| 172 | +); |
0 commit comments