From 08635aa527304bb7dbecc63876855171fcca0fce Mon Sep 17 00:00:00 2001 From: Rhys Sullivan <39114868+RhysSullivan@users.noreply.github.com> Date: Wed, 7 Oct 2026 23:24:37 -0700 Subject: [PATCH 1/3] Test the executor.sh v2 edge and reserved slugs --- apps/cloud/src/edge/marketing.test.ts | 271 +++++++++++++++++- .../core/api/src/account/org-slug.test.ts | 29 ++ 2 files changed, 299 insertions(+), 1 deletion(-) diff --git a/apps/cloud/src/edge/marketing.test.ts b/apps/cloud/src/edge/marketing.test.ts index b6af946dda..c36e090588 100644 --- a/apps/cloud/src/edge/marketing.test.ts +++ b/apps/cloud/src/edge/marketing.test.ts @@ -1,6 +1,15 @@ import { describe, expect, it } from "@effect/vitest"; -import { isMarketingPath, marketingProxyRequest } from "./marketing"; +import { + isMarketingPath, + isSignUpPath, + isV2Path, + marketingProxyRequest, + parseV2Edge, + v2EdgeResponse, + type V2Edge, + type V2Service, +} from "./marketing"; // On executor.sh the marketing middleware proxies an allow-list of paths to the // `executor-marketing` worker; everything else falls through to the auth-gated @@ -101,3 +110,263 @@ describe("marketingProxyRequest", () => { expect(marketingProxyRequest(new Request("https://executor.sh/login"))).toBeNull(); }); }); + +// v2 on executor.sh: sign-up redirects to v2, and a fixed list of exact paths +// is forwarded to v2's Worker. Everything else stays with v1. +describe("isV2Path", () => { + const forwarded = [ + "/.well-known/oauth-authorization-server/api/auth", + "/api/auth/.well-known/openid-configuration", + "/api/auth/callback/google", + "/api/auth/callback/github", + "/oauth/client-metadata.json", + "/git/acme/tools/info/refs", + "/git/acme/tools/git-upload-pack", + "/git/acme/tools/git-receive-pack", + "/.well-known/agent-skills/", + "/.well-known/agent-skills/index.json", + ]; + for (const pathname of forwarded) { + it(`forwards ${pathname} to v2`, () => { + expect(isV2Path(pathname)).toBe(true); + }); + } + + const v1Owned = [ + // v1's WorkOS callback has no provider segment. + "/api/auth/callback", + "/api/auth/callback/", + "/api/auth/callback/google/extra", + "/api/auth/login", + "/api/auth/me", + // v1's own issuer metadata and client metadata document. + "/.well-known/oauth-authorization-server", + "/.well-known/oauth-authorization-server/api/auth/extra", + "/.well-known/oauth-protected-resource/mcp", + "/api/auth/.well-known/openid-configuration/extra", + "/oauth/client-id-metadata.json", + "/oauth/client-metadata.json/extra", + // Git remotes need a path under /git/. + "/git", + "/gitlab/acme/tools/info/refs", + "/github", + "/.well-known/agent-skills", + "/.well-known/agent-skillset/index.json", + // Not yet: connected-account callback and marketing. + "/api/oauth/callback", + "/pricing", + // v1 dashboard, org pages and MCP, including org slugs that look similar. + "/", + "/login", + "/mcp", + "/acme/mcp", + "/gitops/mcp", + "/git-team/policies", + "/oauth-team/mcp", + "/api/connections", + ]; + for (const pathname of v1Owned) { + it(`leaves ${pathname} with v1`, () => { + expect(isV2Path(pathname)).toBe(false); + }); + } +}); + +describe("isSignUpPath", () => { + it("claims /sign-up and /signup only", () => { + expect(isSignUpPath("/sign-up")).toBe(true); + expect(isSignUpPath("/signup")).toBe(true); + expect(isSignUpPath("/sign-up/")).toBe(false); + expect(isSignUpPath("/signup/team")).toBe(false); + expect(isSignUpPath("/sign-in")).toBe(false); + expect(isSignUpPath("/signups")).toBe(false); + }); +}); + +describe("parseV2Edge", () => { + const service: V2Service = { fetch: () => Promise.resolve(new Response(null)) }; + + it("needs both the binding and an absolute sign-up URL", () => { + expect(parseV2Edge(undefined, "https://v2.executor.sh/login?mode=signup")).toBeNull(); + expect(parseV2Edge(service, undefined)).toBeNull(); + expect(parseV2Edge(service, "/login?mode=signup")).toBeNull(); + expect(parseV2Edge(service, "javascript:alert(1)")).toBeNull(); + expect(parseV2Edge(service, "https://v2.executor.sh/login?mode=signup")?.signUpUrl.href).toBe( + "https://v2.executor.sh/login?mode=signup", + ); + }); +}); + +describe("v2EdgeResponse", () => { + const SIGN_UP_URL = "https://v2.executor.sh/login?mode=signup"; + + /** A v2 service that records what it receives and answers with `respond`. */ + const recordingService = (respond: (request: Request) => Promise | Response) => { + const received: Request[] = []; + const service: V2Service = { + fetch: async (request) => { + received.push(request); + return respond(request); + }, + }; + return { received, service }; + }; + + const edgeWith = (service: V2Service): V2Edge => { + const edge = parseV2Edge(service, SIGN_UP_URL); + if (edge === null) return expect.unreachable("edge settings must parse"); + return edge; + }; + + it("redirects sign-up to v2's configured sign-up page, ignoring the query", async () => { + const { received, service } = recordingService(() => new Response(null)); + const edge = edgeWith(service); + + for (const url of ["https://executor.sh/sign-up", "https://executor.sh/signup?ref=docs"]) { + const response = await v2EdgeResponse(new Request(url), edge); + expect(response?.status).toBe(302); + expect(response?.headers.get("location")).toBe(SIGN_UP_URL); + } + expect(received).toHaveLength(0); + }); + + it("follows the configured sign-up URL", async () => { + const edge = parseV2Edge( + { fetch: () => Promise.resolve(new Response(null)) }, + "https://app.executor.sh/sign-up", + ); + if (edge === null) return expect.unreachable("edge settings must parse"); + + const response = await v2EdgeResponse(new Request("https://executor.sh/signup"), edge); + expect(response?.headers.get("location")).toBe("https://app.executor.sh/sign-up"); + }); + + it("leaves non-GET sign-up requests with v1", () => { + const edge = edgeWith(recordingService(() => new Response(null)).service); + expect( + v2EdgeResponse(new Request("https://executor.sh/sign-up", { method: "POST" }), edge), + ).toBeNull(); + }); + + it("only acts on executor.sh", () => { + const edge = edgeWith(recordingService(() => new Response(null)).service); + expect(v2EdgeResponse(new Request("http://executor-cloud.localhost/sign-up"), edge)).toBeNull(); + expect( + v2EdgeResponse(new Request("https://v2.executor.sh/api/auth/callback/google"), edge), + ).toBeNull(); + }); + + it("leaves v1 paths with v1", () => { + const { received, service } = recordingService(() => new Response(null)); + const edge = edgeWith(service); + expect( + v2EdgeResponse(new Request("https://executor.sh/api/auth/callback?code=c"), edge), + ).toBeNull(); + expect(v2EdgeResponse(new Request("https://executor.sh/gitlab/x/info/refs"), edge)).toBeNull(); + expect(received).toHaveLength(0); + }); + + it("forwards with the public host, path and query, and returns v2's redirect unfollowed", async () => { + const { received, service } = recordingService( + () => + new Response(null, { + status: 302, + headers: { location: "https://app.executor.sh/api/auth/callback/google?code=c&state=s" }, + }), + ); + + const response = await v2EdgeResponse( + new Request("https://executor.sh/api/auth/callback/google?code=c&state=s"), + edgeWith(service), + ); + + expect(response?.status).toBe(302); + expect(response?.headers.get("location")).toBe( + "https://app.executor.sh/api/auth/callback/google?code=c&state=s", + ); + expect(received).toHaveLength(1); + expect(received[0]?.url).toBe("https://executor.sh/api/auth/callback/google?code=c&state=s"); + expect(received[0]?.redirect).toBe("manual"); + }); + + it("strips v1's cookies and client forwarding headers but keeps Authorization", async () => { + const { received, service } = recordingService(() => new Response("ok")); + + await v2EdgeResponse( + new Request("https://executor.sh/git/acme/tools/info/refs?service=git-upload-pack", { + headers: { + authorization: "Basic dXNlcjp0b2tlbg==", + cookie: "wos-session=sealed; ph_id=1", + "git-protocol": "version=2", + "x-forwarded-host": "attacker.example", + "x-forwarded-proto": "http", + }, + }), + edgeWith(service), + ); + + const forwarded = received[0]; + expect(forwarded?.headers.get("authorization")).toBe("Basic dXNlcjp0b2tlbg=="); + expect(forwarded?.headers.get("git-protocol")).toBe("version=2"); + expect(forwarded?.headers.has("cookie")).toBe(false); + expect(forwarded?.headers.has("x-forwarded-host")).toBe(false); + expect(forwarded?.headers.has("x-forwarded-proto")).toBe(false); + expect(new URL(forwarded?.url ?? "").search).toBe("?service=git-upload-pack"); + }); + + it("returns v2's response unchanged, status and body stream included", async () => { + const upstream = new Response("not found", { + status: 404, + headers: { "content-type": "text/plain", "www-authenticate": 'Basic realm="git"' }, + }); + const { service } = recordingService(() => upstream); + + const response = await v2EdgeResponse( + new Request("https://executor.sh/git/acme/tools/info/refs"), + edgeWith(service), + ); + + expect(response).toBe(upstream); + }); + + it("streams a git push body to v2 without buffering it, preserving the method", async () => { + const encoder = new TextEncoder(); + let source: ReadableStreamDefaultController | undefined; + const body = new ReadableStream({ + start(controller) { + source = controller; + controller.enqueue(encoder.encode("first-pack-chunk")); + }, + }); + // v2 reads the first chunk while the client is still sending: a buffering + // edge would wait for the end of the body and never reach v2. + const { received, service } = recordingService(async (request) => { + const reader = request.body?.getReader(); + if (reader === undefined) return new Response("no body", { status: 500 }); + const first = await reader.read(); + source?.enqueue(encoder.encode("second-pack-chunk")); + source?.close(); + const second = await reader.read(); + const done = await reader.read(); + const decoder = new TextDecoder(); + return new Response( + `${decoder.decode(first.value)}|${decoder.decode(second.value)}|${done.done}`, + ); + }); + + const response = await v2EdgeResponse( + new Request("https://executor.sh/git/acme/tools/git-receive-pack", { + method: "POST", + headers: { "content-type": "application/x-git-receive-pack-request" }, + body, + // @ts-expect-error -- Node's fetch needs `duplex` for a stream body; workerd does not. + duplex: "half", + }), + edgeWith(service), + ); + + expect(received[0]?.method).toBe("POST"); + expect(received[0]?.headers.get("content-type")).toBe("application/x-git-receive-pack-request"); + expect(await response?.text()).toBe("first-pack-chunk|second-pack-chunk|true"); + }); +}); diff --git a/packages/core/api/src/account/org-slug.test.ts b/packages/core/api/src/account/org-slug.test.ts index 28e5a1d6f6..c00d755bf3 100644 --- a/packages/core/api/src/account/org-slug.test.ts +++ b/packages/core/api/src/account/org-slug.test.ts @@ -88,6 +88,35 @@ describe("isValidOrgSlug", () => { expect(RESERVED_ORG_SLUGS.has(critical), critical).toBe(true); } }); + + it("reserves the root segments the executor.sh edge gives to v2", () => { + // `/git//` and the other forwarded or redirected roots would + // otherwise read as an org's console URL (`//...`). + for (const claimed of [ + "git", + "oauth", + "api", + "app", + "mcp", + "docs", + "sign-up", + "signup", + "pricing", + "blog", + ]) { + expect(isValidOrgSlug(claimed), claimed).toBe(false); + } + // Look-alikes stay claimable. + for (const lookalike of ["gitlab", "git-team", "github", "apps", "oauth-co", "blogs"]) { + expect(isValidOrgSlug(lookalike), lookalike).toBe(true); + } + }); + + it("never mints a reserved edge slug for an org name", async () => { + const slug = await generateOrgSlug("Git", async () => false); + expect(slug).not.toBe("git"); + expect(slug).toMatch(/^git-[a-z2-9]{4}$/); + }); }); describe("generateOrgSlug", () => { From 2f2a2f015ed1b59a9dc3fa4a9eaf1ef1c2a33410 Mon Sep 17 00:00:00 2001 From: Rhys Sullivan <39114868+RhysSullivan@users.noreply.github.com> Date: Wed, 7 Oct 2026 23:34:18 -0700 Subject: [PATCH 2/3] Test that broken edge settings fail only edge requests --- apps/cloud/src/edge/marketing.test.ts | 105 ++++++++++++++++++-------- 1 file changed, 73 insertions(+), 32 deletions(-) diff --git a/apps/cloud/src/edge/marketing.test.ts b/apps/cloud/src/edge/marketing.test.ts index c36e090588..899d2c73e1 100644 --- a/apps/cloud/src/edge/marketing.test.ts +++ b/apps/cloud/src/edge/marketing.test.ts @@ -7,7 +7,6 @@ import { marketingProxyRequest, parseV2Edge, v2EdgeResponse, - type V2Edge, type V2Service, } from "./marketing"; @@ -186,14 +185,26 @@ describe("isSignUpPath", () => { describe("parseV2Edge", () => { const service: V2Service = { fetch: () => Promise.resolve(new Response(null)) }; - it("needs both the binding and an absolute sign-up URL", () => { - expect(parseV2Edge(undefined, "https://v2.executor.sh/login?mode=signup")).toBeNull(); - expect(parseV2Edge(service, undefined)).toBeNull(); - expect(parseV2Edge(service, "/login?mode=signup")).toBeNull(); - expect(parseV2Edge(service, "javascript:alert(1)")).toBeNull(); - expect(parseV2Edge(service, "https://v2.executor.sh/login?mode=signup")?.signUpUrl.href).toBe( - "https://v2.executor.sh/login?mode=signup", + it("is off when neither setting is present", () => { + expect(parseV2Edge(undefined, undefined)).toBeNull(); + }); + + it("refuses a binding or sign-up URL set without the other", () => { + expect(typeof parseV2Edge(undefined, "https://v2.executor.sh/login?mode=signup")).toBe( + "string", ); + expect(typeof parseV2Edge(service, undefined)).toBe("string"); + }); + + it("refuses a sign-up URL that is not absolute http(s)", () => { + expect(typeof parseV2Edge(service, "/login?mode=signup")).toBe("string"); + expect(typeof parseV2Edge(service, "javascript:alert(1)")).toBe("string"); + }); + + it("parses both settings", () => { + const edge = parseV2Edge(service, "https://v2.executor.sh/login?mode=signup"); + if (edge === null || typeof edge === "string") return expect.unreachable("settings must parse"); + expect(edge.signUpUrl.href).toBe("https://v2.executor.sh/login?mode=signup"); }); }); @@ -212,18 +223,11 @@ describe("v2EdgeResponse", () => { return { received, service }; }; - const edgeWith = (service: V2Service): V2Edge => { - const edge = parseV2Edge(service, SIGN_UP_URL); - if (edge === null) return expect.unreachable("edge settings must parse"); - return edge; - }; - it("redirects sign-up to v2's configured sign-up page, ignoring the query", async () => { const { received, service } = recordingService(() => new Response(null)); - const edge = edgeWith(service); for (const url of ["https://executor.sh/sign-up", "https://executor.sh/signup?ref=docs"]) { - const response = await v2EdgeResponse(new Request(url), edge); + const response = await v2EdgeResponse(new Request(url), service, SIGN_UP_URL); expect(response?.status).toBe(302); expect(response?.headers.get("location")).toBe(SIGN_UP_URL); } @@ -231,38 +235,71 @@ describe("v2EdgeResponse", () => { }); it("follows the configured sign-up URL", async () => { - const edge = parseV2Edge( + const response = await v2EdgeResponse( + new Request("https://executor.sh/signup"), { fetch: () => Promise.resolve(new Response(null)) }, "https://app.executor.sh/sign-up", ); - if (edge === null) return expect.unreachable("edge settings must parse"); - - const response = await v2EdgeResponse(new Request("https://executor.sh/signup"), edge); expect(response?.headers.get("location")).toBe("https://app.executor.sh/sign-up"); }); it("leaves non-GET sign-up requests with v1", () => { - const edge = edgeWith(recordingService(() => new Response(null)).service); + const { service } = recordingService(() => new Response(null)); + expect( + v2EdgeResponse( + new Request("https://executor.sh/sign-up", { method: "POST" }), + service, + SIGN_UP_URL, + ), + ).toBeNull(); + }); + + it("answers edge requests with a 500 on a broken setting and leaves other paths with v1", async () => { + const { received, service } = recordingService(() => new Response(null)); + const response = await v2EdgeResponse( + new Request("https://executor.sh/sign-up"), + service, + "/relative", + ); + expect(response?.status).toBe(500); expect( - v2EdgeResponse(new Request("https://executor.sh/sign-up", { method: "POST" }), edge), + v2EdgeResponse(new Request("https://executor.sh/acme/mcp"), service, "/relative"), + ).toBeNull(); + expect(received).toHaveLength(0); + }); + + it("is off without settings", () => { + expect( + v2EdgeResponse(new Request("https://executor.sh/sign-up"), undefined, undefined), ).toBeNull(); }); it("only acts on executor.sh", () => { - const edge = edgeWith(recordingService(() => new Response(null)).service); - expect(v2EdgeResponse(new Request("http://executor-cloud.localhost/sign-up"), edge)).toBeNull(); + const { service } = recordingService(() => new Response(null)); + expect( + v2EdgeResponse(new Request("http://executor-cloud.localhost/sign-up"), service, SIGN_UP_URL), + ).toBeNull(); expect( - v2EdgeResponse(new Request("https://v2.executor.sh/api/auth/callback/google"), edge), + v2EdgeResponse( + new Request("https://v2.executor.sh/api/auth/callback/google"), + service, + SIGN_UP_URL, + ), ).toBeNull(); }); it("leaves v1 paths with v1", () => { const { received, service } = recordingService(() => new Response(null)); - const edge = edgeWith(service); expect( - v2EdgeResponse(new Request("https://executor.sh/api/auth/callback?code=c"), edge), + v2EdgeResponse( + new Request("https://executor.sh/api/auth/callback?code=c"), + service, + SIGN_UP_URL, + ), + ).toBeNull(); + expect( + v2EdgeResponse(new Request("https://executor.sh/gitlab/x/info/refs"), service, SIGN_UP_URL), ).toBeNull(); - expect(v2EdgeResponse(new Request("https://executor.sh/gitlab/x/info/refs"), edge)).toBeNull(); expect(received).toHaveLength(0); }); @@ -277,7 +314,8 @@ describe("v2EdgeResponse", () => { const response = await v2EdgeResponse( new Request("https://executor.sh/api/auth/callback/google?code=c&state=s"), - edgeWith(service), + service, + SIGN_UP_URL, ); expect(response?.status).toBe(302); @@ -302,7 +340,8 @@ describe("v2EdgeResponse", () => { "x-forwarded-proto": "http", }, }), - edgeWith(service), + service, + SIGN_UP_URL, ); const forwarded = received[0]; @@ -323,7 +362,8 @@ describe("v2EdgeResponse", () => { const response = await v2EdgeResponse( new Request("https://executor.sh/git/acme/tools/info/refs"), - edgeWith(service), + service, + SIGN_UP_URL, ); expect(response).toBe(upstream); @@ -362,7 +402,8 @@ describe("v2EdgeResponse", () => { // @ts-expect-error -- Node's fetch needs `duplex` for a stream body; workerd does not. duplex: "half", }), - edgeWith(service), + service, + SIGN_UP_URL, ); expect(received[0]?.method).toBe("POST"); From 422c226de11e51291aaf54d0569b0c6feda62931 Mon Sep 17 00:00:00 2001 From: Rhys Sullivan <39114868+RhysSullivan@users.noreply.github.com> Date: Thu, 8 Oct 2026 06:34:21 -0700 Subject: [PATCH 3/3] Test the contract paths and the apps and experiments slugs --- apps/cloud/src/edge/marketing.test.ts | 12 ++++++------ packages/core/api/src/account/org-slug.test.ts | 12 +++++++++++- 2 files changed, 17 insertions(+), 7 deletions(-) diff --git a/apps/cloud/src/edge/marketing.test.ts b/apps/cloud/src/edge/marketing.test.ts index 899d2c73e1..d72ac1a06c 100644 --- a/apps/cloud/src/edge/marketing.test.ts +++ b/apps/cloud/src/edge/marketing.test.ts @@ -110,15 +110,13 @@ describe("marketingProxyRequest", () => { }); }); -// v2 on executor.sh: sign-up redirects to v2, and a fixed list of exact paths -// is forwarded to v2's Worker. Everything else stays with v1. +// v2 on executor.sh: sign-up redirects to v2, and a fixed list of paths is +// forwarded to v2's Worker. Everything else stays with v1. describe("isV2Path", () => { const forwarded = [ "/.well-known/oauth-authorization-server/api/auth", - "/api/auth/.well-known/openid-configuration", "/api/auth/callback/google", "/api/auth/callback/github", - "/oauth/client-metadata.json", "/git/acme/tools/info/refs", "/git/acme/tools/git-upload-pack", "/git/acme/tools/git-receive-pack", @@ -142,9 +140,11 @@ describe("isV2Path", () => { "/.well-known/oauth-authorization-server", "/.well-known/oauth-authorization-server/api/auth/extra", "/.well-known/oauth-protected-resource/mcp", - "/api/auth/.well-known/openid-configuration/extra", "/oauth/client-id-metadata.json", - "/oauth/client-metadata.json/extra", + // v2 does not serve OpenID configuration on executor.sh, and its client + // metadata document's move to executor.sh is pending. + "/api/auth/.well-known/openid-configuration", + "/oauth/client-metadata.json", // Git remotes need a path under /git/. "/git", "/gitlab/acme/tools/info/refs", diff --git a/packages/core/api/src/account/org-slug.test.ts b/packages/core/api/src/account/org-slug.test.ts index c00d755bf3..4dad5d5ecc 100644 --- a/packages/core/api/src/account/org-slug.test.ts +++ b/packages/core/api/src/account/org-slug.test.ts @@ -94,6 +94,8 @@ describe("isValidOrgSlug", () => { // otherwise read as an org's console URL (`//...`). for (const claimed of [ "git", + "apps", + "experiments", "oauth", "api", "app", @@ -107,7 +109,15 @@ describe("isValidOrgSlug", () => { expect(isValidOrgSlug(claimed), claimed).toBe(false); } // Look-alikes stay claimable. - for (const lookalike of ["gitlab", "git-team", "github", "apps", "oauth-co", "blogs"]) { + for (const lookalike of [ + "gitlab", + "git-team", + "github", + "app-team", + "experiment", + "oauth-co", + "blogs", + ]) { expect(isValidOrgSlug(lookalike), lookalike).toBe(true); } });