Skip to content

Commit c43141c

Browse files
committed
chore(deps): pin xai-provider to npm 0.1.1
1 parent 83c2aed commit c43141c

3 files changed

Lines changed: 33 additions & 3 deletions

File tree

‎bun.lock‎

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -90,7 +90,7 @@
9090
"@corbits/codex-provider": "github:corbitsdev/corbits-codex-provider",
9191
"@corbits/oauth-core": "github:corbitsdev/corbits-oauth-core",
9292
"@corbits/openai-responses": "github:corbitsdev/corbits-openai-responses",
93-
"@corbits/xai-provider": "github:corbitsdev/corbits-xai-provider",
93+
"@corbits/xai-provider": "0.1.1",
9494
"@intx/agent": "workspace:*",
9595
"@intx/authz": "workspace:*",
9696
"@intx/crypto": "0.3.0",

‎src/auth/xai/auth-headers.test.ts‎

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
import { describe, expect, test } from "bun:test";
2+
3+
import { xaiAuthHeadersForToken } from "./auth-headers.js";
4+
5+
function accessTokenWithSub(sub: string): string {
6+
const segment = (obj: Record<string, unknown>): string =>
7+
Buffer.from(JSON.stringify(obj), "utf8").toString("base64url");
8+
return `${segment({ alg: "none" })}.${segment({ sub })}.sig`;
9+
}
10+
11+
describe("xaiAuthHeadersForToken", () => {
12+
test("lifts a clean JWT sub into x-grok-user-id", () => {
13+
const headers = xaiAuthHeadersForToken({
14+
access: accessTokenWithSub("user-123"),
15+
});
16+
expect(headers["x-grok-user-id"]).toBe("user-123");
17+
expect(headers.authorization).toBe(
18+
`Bearer ${accessTokenWithSub("user-123")}`,
19+
);
20+
});
21+
22+
test("omits x-grok-user-id when the JWT sub carries CR, LF, or NUL", () => {
23+
for (const sub of ["user\r123", "user\n123", "user\u0000123"]) {
24+
const headers = xaiAuthHeadersForToken({
25+
access: accessTokenWithSub(sub),
26+
});
27+
expect("x-grok-user-id" in headers).toBe(false);
28+
}
29+
});
30+
});

0 commit comments

Comments
 (0)