|
1 | 1 | import { describe, expect, it } from "bun:test"; |
2 | 2 |
|
3 | | -const { validateServerName, validateRegionName, toKebabCase, sanitizeTermValue, jsonEscape } = await import( |
4 | | - "../shared/ui.js" |
5 | | -); |
| 3 | +const { validateServerName, validateRegionName, validateModelId, toKebabCase, sanitizeTermValue, jsonEscape } = |
| 4 | + await import("../shared/ui.js"); |
6 | 5 |
|
7 | 6 | // ── validateServerName ────────────────────────────────────────────── |
8 | 7 |
|
@@ -63,6 +62,44 @@ describe("validateRegionName", () => { |
63 | 62 | }); |
64 | 63 | }); |
65 | 64 |
|
| 65 | +// ── validateModelId ───────────────────────────────────────────────── |
| 66 | + |
| 67 | +describe("validateModelId", () => { |
| 68 | + it("accepts valid model IDs", () => { |
| 69 | + expect(validateModelId("anthropic/claude-3")).toBe(true); |
| 70 | + expect(validateModelId("openai/gpt-4o")).toBe(true); |
| 71 | + expect(validateModelId("moonshotai/kimi-k2.5")).toBe(true); |
| 72 | + expect(validateModelId("google/gemini-pro")).toBe(true); |
| 73 | + expect(validateModelId("meta-llama/llama-3.1-8b:free")).toBe(true); |
| 74 | + }); |
| 75 | + |
| 76 | + it("rejects empty string", () => { |
| 77 | + expect(validateModelId("")).toBe(false); |
| 78 | + }); |
| 79 | + |
| 80 | + it("rejects model IDs without provider prefix", () => { |
| 81 | + expect(validateModelId("claude-3")).toBe(false); |
| 82 | + }); |
| 83 | + |
| 84 | + it("rejects shell injection attempts", () => { |
| 85 | + expect(validateModelId('"; curl attacker.com; "')).toBe(false); |
| 86 | + expect(validateModelId("$(whoami)")).toBe(false); |
| 87 | + expect(validateModelId("`id`/model")).toBe(false); |
| 88 | + expect(validateModelId("provider/model; rm -rf /")).toBe(false); |
| 89 | + expect(validateModelId("provider/model\ninjection")).toBe(false); |
| 90 | + }); |
| 91 | + |
| 92 | + it("rejects model IDs with spaces", () => { |
| 93 | + expect(validateModelId("provider/model name")).toBe(false); |
| 94 | + }); |
| 95 | + |
| 96 | + it("rejects model IDs starting with non-alphanumeric", () => { |
| 97 | + expect(validateModelId("-provider/model")).toBe(false); |
| 98 | + expect(validateModelId("/model")).toBe(false); |
| 99 | + expect(validateModelId("provider/-model")).toBe(false); |
| 100 | + }); |
| 101 | +}); |
| 102 | + |
66 | 103 | // ── toKebabCase ───────────────────────────────────────────────────── |
67 | 104 |
|
68 | 105 | describe("toKebabCase", () => { |
|
0 commit comments