hermes-agent/tests
Ben Barclay 7857d8737c feat(dashboard-auth): RFC 8252 native desktop sign-in (system browser + PKCE, no webview/cookies)
The Desktop app can now sign in to a gated gateway using the user's SYSTEM
browser and OAuth 2.0 for Native Apps (RFC 8252) instead of an embedded
Electron BrowserWindow, and authenticates with bearer tokens it holds itself
instead of relying on HttpOnly browser session cookies.

Why brokered: the upstream IDP (Nous Portal) binds client_id to the gateway
instance and only permits redirect_uris on the gateway's own origin, so a
desktop loopback redirect can't be a direct Portal client. The gateway
therefore acts as the authorization server TO the desktop and an OAuth client
TO the Portal, reusing the existing PKCE start_login/complete_login provider
path unchanged.

Server (Ben's dashboard-auth lane):
- native_flow.py: in-memory broker — binds the desktop's PKCE challenge to a
  completed Session, mints a single-use, short-TTL, PKCE-verified gateway
  authorization code. Constant-time compare, single-use (consumed before the
  PKCE check so a wrong verifier can't be retried), capacity-bounded.
- routes.py: GET /auth/native/authorize (starts the brokered PKCE login,
  loopback-only redirect_uri, S256-only), POST /auth/native/token (loopback
  code + verifier -> tokens in the JSON body, never Set-Cookie), POST
  /auth/native/refresh (desktop-held RT rotation). /auth/callback branches to
  mint a loopback code + 302 to 127.0.0.1 when a broker_state rides the PKCE
  cookie; the cookie/SPA path is untouched.
- middleware.py: the gate accepts Authorization: Bearer <access_token>,
  verified via the same verify_session provider stack (no cookie set/read),
  with the same "provider unreachable -> 503, not logout" semantics.
- web_server.py /api/status: advertise auth_flows (["cookie","native_pkce"])
  so clients can detect the capability; native_pkce only when a brokerable
  OAuth provider is registered.

Desktop (Ben's lane):
- native-oauth.ts: pure PKCE/capability/URL/callback/token helpers.
- native-oauth-login.ts: loopback-listener orchestration (system browser via
  openExternal, ephemeral 127.0.0.1 listener, state/PKCE verification), all
  I/O injected for testability.
- main.ts: capability-gated oauth-login IPC — native flow when advertised,
  automatic fallback to the existing embedded-webview cookie flow otherwise;
  tokens stored encrypted (safeStorage/OS keychain), REST + ws-ticket
  authenticated by bearer, transparent refresh, logout clears both shapes.

Tests: 18 server pytest (broker unit + full authorize->callback->token E2E +
cookieless bearer auth of a gated route + ws-ticket mint + capability
advertisement + refresh); desktop node --test/vitest for both pure modules
(PKCE, capability detection, callback CSRF, loopback round trip, timeout,
browser-open failure). Electron project typechecks clean.

Docs: website/docs/guides/desktop-native-signin.md.
2026-07-22 06:50:50 -07:00
..
acp fix(titles): use active runtime for gateway sessions 2026-07-16 22:54:09 -07:00
acp_adapter
agent fix(secrets): scope BWS-injected provider keys 2026-07-22 04:39:17 -07:00
ci ci: live-updating PR review comment with structured job statuses 2026-07-20 16:48:25 -04:00
cli test: update mock assertions for conversation_history kwarg 2026-07-22 10:00:39 +05:30
computer_use fix(computer-use): sanitize env on the 4 remaining cua-driver spawn sites (#59165) 2026-07-05 14:48:20 -07:00
cron test(cron): accept target_model kwarg in codex-path resolver stub 2026-07-19 09:57:21 -07:00
dashboard fix(dashboard): use loopback host for in-container WebSocket client (#58993) [salvage #59682] (#60092) 2026-07-07 18:33:28 +10:00
docker test(docker): cover tini -g legacy entrypoint boot path 2026-07-18 01:11:03 -07:00
e2e test(e2e): stub reset-notice session info to deflake test_new_resets_session (#60175) 2026-07-07 04:28:12 -07:00
fakes
fixtures/plugins/example-dashboard/dashboard
gateway fix(secrets): harden encrypted Bitwarden cache 2026-07-22 04:40:07 -07:00
hermes_cli feat(dashboard-auth): RFC 8252 native desktop sign-in (system browser + PKCE, no webview/cookies) 2026-07-22 06:50:50 -07:00
hermes_state fix(state): heal alternation at the ACP / CLI-resume / TUI-resume restore sites too 2026-07-17 06:53:38 -07:00
honcho_plugin fix(ci): make tests, workflows, and attribution reliable under load (#66373) 2026-07-17 20:55:24 +00:00
integration fix: remove dead f-string prefixes via ruff F541 (216 sites) (#52336) 2026-07-05 13:42:46 -07:00
manual
openviking_plugin fix(openviking): align session context with shared profile contract 2026-07-22 14:12:50 +05:30
plugins fix(openviking): align session context with shared profile contract 2026-07-22 14:12:50 +05:30
providers feat(nous): send top-level session_id for provider sticky routing (#69253) 2026-07-22 04:39:20 -07:00
run_agent feat(nous): send top-level session_id for provider sticky routing (#69253) 2026-07-22 04:39:20 -07:00
scripts fix(ci): make tests, workflows, and attribution reliable under load (#66373) 2026-07-17 20:55:24 +00:00
secret_sources feat(secrets): orchestrator-level preserve_existing + profile aliasing (#69058) 2026-07-22 03:20:45 -07:00
skills feat(skills): bundle docx, xlsx, and pdf office skills; refresh powerpoint (#68595) 2026-07-21 05:39:23 -07:00
state fix(state): extend search-path FTS self-heal to the CJK/trigram branch 2026-07-21 12:40:48 -07:00
stress fix: remove dead f-string prefixes via ruff F541 (216 sites) (#52336) 2026-07-05 13:42:46 -07:00
tools fix(secrets): harden encrypted Bitwarden cache 2026-07-22 04:40:07 -07:00
tui_gateway test(themes): E2E live skin switch — config write → skin.changed broadcast 2026-07-21 21:00:43 -05:00
website
__init__.py
conftest.py fix(ci): make tests, workflows, and attribution reliable under load (#66373) 2026-07-17 20:55:24 +00:00
run_interrupt_test.py
test_account_usage.py
test_atomic_replace_symlinks.py fix(config): preserve owner on atomic writes (#56644) 2026-07-03 14:27:34 +10:00
test_background_review_list_shapes.py fix(background-review): guard summarize against list-shaped tool responses (#59437) 2026-07-06 03:28:30 -07:00
test_background_review_session_isolation.py test(review): add integration guards for the two isolation wirings (review) 2026-07-01 16:21:39 +05:30
test_base_url_hostname.py
test_batch_runner_checkpoint.py
test_bitwarden_secrets.py fix(secrets): unify encrypted-cache fallback with the merged stale-cache path 2026-07-22 04:40:07 -07:00
test_cli_file_drop.py
test_cli_manual_compress.py
test_cli_skin_integration.py
test_code_skew.py
test_command_secret_source.py feat(secrets): rework command source as a registered SecretSource — no provider selector 2026-07-22 04:39:28 -07:00
test_copilot_initiator.py fix(copilot): set x-initiator per turn so user prompts bill as premium requests (salvage #4097) (#58544) 2026-07-05 00:44:15 -07:00
test_ctx_halving_fix.py chore: restore test_ctx_halving_fix.py to main 2026-07-14 03:58:54 +05:30
test_delegate_cascade_49148.py
test_dispatch_session_id.py
test_empty_model_fallback.py feat(models): catalog-labeled silent default — GLM-5.2 marked "default": true in the model catalog 2026-07-15 00:10:31 -07:00
test_empty_session_hygiene.py
test_env_loader_applied_homes.py fix(secrets): mark _APPLIED_HOMES only after a real fetch attempt (#40597) (#69056) 2026-07-22 03:20:25 -07:00
test_env_loader_op_bootstrap.py fix(secrets): make 1Password bootstrap token reliable outside systemd 2026-07-06 04:58:07 -07:00
test_env_loader_secret_sources.py test(secrets): match real ApplyReport shape in isolation test 2026-07-22 04:39:17 -07:00
test_evidence_store.py
test_fast_safe_load.py
test_gateway_streaming_nested_config.py fix(gateway): normalize YAML boolean streaming mode and keep enabled a mode-only alias 2026-07-20 05:39:09 -07:00
test_get_tool_definitions_cache_isolation.py
test_hermes_bootstrap.py
test_hermes_constants.py fix(dashboard): keep custom themes visible after embedded chat starts (#60601) 2026-07-18 00:34:54 -04:00
test_hermes_home_profile_warning.py
test_hermes_logging.py fix(logging): drive rotating file handlers through an async QueueListener 2026-07-05 11:44:53 +05:30
test_hermes_state.py perf(state): external-content FTS + tool-row-free trigram index (schema v23) (#65798) 2026-07-22 04:42:50 -07:00
test_hermes_state_compression_locks.py fix(ci): make tests, workflows, and attribution reliable under load (#66373) 2026-07-17 20:55:24 +00:00
test_hermes_state_wal_fallback.py
test_honcho_client_concurrency.py
test_honcho_client_config.py feat(honcho): make latency-adding paths configurable 2026-07-16 12:48:48 -07:00
test_honcho_session_context.py
test_honcho_startup_fail_open.py fix(ci): make tests, workflows, and attribution reliable under load (#66373) 2026-07-17 20:55:24 +00:00
test_install_autostash_conflict_recovery.py test: add happy-path + no-markers coverage for autostash recovery 2026-07-18 19:18:03 +05:30
test_install_diverged_update.py
test_install_lockfile_churn.py
test_install_no_initial_commit.py
test_install_ps1_ascii_only.py fix(install): keep install.ps1 pure ASCII so Windows PowerShell 5.1 doesn't misparse it 2026-07-18 18:40:59 -04:00
test_install_ps1_native_stderr_eap.py
test_install_ps1_node_path_for_npm.py test(installer): guard Ensure-NodeExeOnPath wiring in install.ps1 2026-07-07 21:17:34 +07:00
test_install_ps1_python_fallback_venv.py
test_install_ps1_uv_powershell_host.py
test_install_ps1_web_server_syntax_probe.py fix(install): guard Windows desktop installs against broken web_server 2026-07-05 19:35:30 -07:00
test_install_sh_browser_install.py
test_install_sh_install_method_stamp.py
test_install_sh_node_global_prefix.py
test_install_sh_pythonpath_sanitization.py
test_install_sh_root_fhs_uv_python_path.py
test_install_sh_setup_wizard_tty_probe.py
test_install_sh_symlink_stomp.py
test_install_sh_termux_network_prereqs.py
test_install_unmerged_index.py
test_ipv4_preference.py
test_lazy_session_regressions.py
test_lint_config.py
test_live_system_guard_self_test.py fix(tests): make the live-system-guard canary fail closed 2026-07-21 12:15:46 +05:30
test_mcp_serve.py refactor: consolidate gateway session metadata into state.db (#58899) 2026-07-05 14:01:03 -07:00
test_mini_swe_runner.py
test_minimax_model_validation.py
test_minimax_oauth.py
test_minisweagent_path.py
test_model_forces_max_completion_tokens.py
test_model_picker_scroll.py
test_model_tools.py fix(toolsets): preserve core tools when a posture toolset is in disabled_toolsets (#57315) 2026-07-05 14:51:49 -07:00
test_model_tools_async_bridge.py
test_ollama_num_ctx.py
test_onepassword_secrets.py fix(secrets): pass OP_LOAD_DESKTOP_APP_SETTINGS through to the op child env 2026-07-22 03:19:32 -07:00
test_output_cap_parsing.py
test_packaging_metadata.py
test_plugin_skills.py
test_plugin_utils.py
test_process_loop_event_loop_warning.py
test_profile_isolation_runtime.py
test_project_metadata.py fix(nemo-relay): align dynamic plugin configuration 2026-07-13 17:01:08 -06:00
test_pty_keepalive_ws.py fix(dashboard): scope chat attach tokens by session (#60745) 2026-07-16 19:48:47 -04:00
test_pty_session.py feat(pty): periodic reaper wired into dashboard lifespan 2026-07-07 15:15:37 -07:00
test_retry_utils.py refactor(retry): single-source Z.AI overload short-attempts + drop change-detector assert 2026-07-07 11:57:01 +05:30
test_run_tests_parallel.py fix(ci): make tests, workflows, and attribution reliable under load (#66373) 2026-07-17 20:55:24 +00:00
test_sanitize_tool_error.py
test_session_workspace_binding.py feat(sessions): workspace_key grouping helper + tests 2026-07-12 05:07:52 -04:00
test_setup_temporary_outputs.py
test_slash_worker_watchdog.py test(tui): keep watchdog checks behavior-focused 2026-07-18 04:15:13 -07:00
test_sql_injection.py
test_stale_utils_module_import.py
test_state_db_malformed_repair.py perf(state): external-content FTS + tool-row-free trigram index (schema v23) (#65798) 2026-07-22 04:42:50 -07:00
test_subprocess_home_isolation.py
test_telegram_polling_progress_ptb.py test(telegram): gate slots premise assert on runtimes without instance __dict__ 2026-07-14 21:25:44 -07:00
test_termux_all_extra_compat.py
test_timezone.py
test_tini_shim.py test(docker): cover tini -g legacy entrypoint boot path 2026-07-18 01:11:03 -07:00
test_toolset_distributions.py
test_toolsets.py feat(mcp): adopt mcp__server__tool naming convention 2026-07-05 13:40:21 -07:00
test_trajectory_compressor.py
test_trajectory_compressor_async.py
test_transform_llm_output_hook.py
test_transform_tool_result_hook.py
test_tui_entry_mcp_owner.py fix(tui): gate the shared-owner MCP discovery wait on the stdio TUI flag 2026-07-21 12:43:27 -07:00
test_tui_gateway_loop_noise.py
test_tui_gateway_queue_on_busy.py fix(tui_gateway): prevent resume stalls during submit and teardown (#66573) 2026-07-18 14:51:06 -04:00
test_tui_gateway_server.py fix(desktop): scope model options by profile (#62795) 2026-07-22 09:40:50 -04:00
test_tui_gateway_ws.py
test_tui_mcp_late_refresh.py
test_utils_truthy_values.py
test_wal_checkpoint_strategy.py fix(state): use PASSIVE checkpoint for periodic WAL flush to prevent B-tree corruption 2026-07-15 04:55:46 -07:00
test_web_server.py feat(serve): add secure Desktop SSH bootstrap contract 2026-07-16 14:43:14 +02:00
test_web_server_sessiondb_eventloop.py Merge pull request #65893 from NousResearch/bb/salvage-63082-sessiondb-offload 2026-07-16 15:23:32 -04:00
test_wheel_locales_e2e.py fix(packaging): graft web_dist in MANIFEST.in and add sdist regression test 2026-07-21 12:41:41 -07:00
test_windows_subprocess_no_window_flags.py fix(windows): share one bounded, tree-killing git probe across both call sites (#68997) 2026-07-21 20:18:43 -05:00
test_yaml_indent_consistency_31999.py
test_yuanbao_integration.py
test_yuanbao_markdown.py
test_yuanbao_pipeline.py perf(yuanbao): bounded-concurrency inbound media resolve 2026-07-08 08:05:45 -07:00
test_yuanbao_proto.py
test_yuanbao_reconnect_set_active.py fix(yuanbao): restore active singleton after WS reconnect 2026-07-05 00:41:34 -07:00
test_yuanbao_shutdown.py