feat(agent-browser): add opt-in preview data injection

This commit is contained in:
brother7 committed 2026-08-26 22:38:44 +08:00
1 parent 14fec70108
commit 38d63a9b7b
11 files changed
+1024 -3

No files matched your search

+39
View File
@@ -128,6 +128,45 @@ describe('Agent Browser Host API routes', () => {
.toHaveBeenCalledWith('agent-browser:show', expect.objectContaining({ browserId: 'browser-1' }));
});
it('forwards only an explicit data-injection opt-in to the browser service', async () => {
const projectPath = await temporaryProject('niancode-agent-browser-preview-route-');
const open = vi.fn().mockResolvedValue(snapshot(projectPath));
const response = createResponse();
await handleAgentBrowserRoutes(
createRequest('POST', {
project_path: projectPath,
url: 'http://127.0.0.1:5173',
inject_project_data: true,
}),
response.res,
new URL('http://127.0.0.1/api/agent-browser/open'),
context(projectPath, { open }),
);
expect(response.res.statusCode).toBe(200);
expect(open).toHaveBeenCalledWith(expect.objectContaining({
injectProjectData: true,
}));
const ordinaryResponse = createResponse();
await handleAgentBrowserRoutes(
createRequest('POST', {
project_path: projectPath,
url: 'http://127.0.0.1:5173',
inject_project_data: 'true',
}),
ordinaryResponse.res,
new URL('http://127.0.0.1/api/agent-browser/open'),
context(projectPath, { open }),
);
expect(ordinaryResponse.res.statusCode).toBe(200);
expect(open).toHaveBeenLastCalledWith(expect.not.objectContaining({
injectProjectData: expect.anything(),
}));
});
it('rejects viewport bounds from an agent-only Host API request', async () => {
const projectPath = await temporaryProject('niancode-agent-browser-untrusted-bounds-');
const open = vi.fn();