Phase C of vendor-agnostic model-access (ADR 0050/0054). Two TypeScript runtime modules: - anthropic-manager: the refresh token is sealed at rest to the manager node's own key (atrest.ts, envelope encryption over X25519) and opened ONLY on the manager node. adopt seals the first envelope; refresh opens it, calls the Anthropic OAuth token endpoint, re-seals a rotated refresh token, and hands the control plane only the access token plus the opaque envelope. Also polls licence-grain usage (ADR 0054). - anthropic-consumer: writes the delivered access token to ~/.claude/.credentials.json, access-token-only, atomically (the refresh token is never delivered); reports session-grain usage from the CLI transcripts; a fail-closed identity guard (expected-uuid plumbing is a flagged TODO). Both run as scheduled containers (ADR 0053). Pure logic covered by node --test fixtures (at-rest round-trip, credential strip, transcript sum, refresh merge). Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
44 lines
1.6 KiB
TypeScript
44 lines
1.6 KiB
TypeScript
import { test } from "node:test";
|
|
import assert from "node:assert/strict";
|
|
|
|
import { grantFromRefresh, flattenUsage } from "../client.ts";
|
|
|
|
test("an empty refresh response never clobbers a good grant", () => {
|
|
assert.equal(grantFromRefresh({}, 1000), null);
|
|
});
|
|
|
|
test("a refresh with an access token yields an access-token-only grant and epoch expiry", () => {
|
|
const out = grantFromRefresh(
|
|
{ access_token: "at-new", expires_in: 3600, refresh_token: "rt-rotated", subscription_type: "pro" },
|
|
1_000_000,
|
|
);
|
|
assert.ok(out);
|
|
assert.equal(out!.access.accessToken, "at-new");
|
|
assert.equal(out!.access.expiresAt, 1_000_000 + 3600 * 1000);
|
|
assert.equal(out!.access.subscriptionType, "pro");
|
|
// The rotated refresh token is reported separately, for the manager to re-seal — never put in the
|
|
// holder grant.
|
|
assert.equal(out!.rotatedRefresh, "rt-rotated");
|
|
assert.ok(!("refreshToken" in (out!.access as object)));
|
|
});
|
|
|
|
test("a refresh that did not rotate the refresh token reports none to re-seal", () => {
|
|
const out = grantFromRefresh({ access_token: "at-new" }, 0);
|
|
assert.ok(out);
|
|
assert.equal(out!.rotatedRefresh, null);
|
|
});
|
|
|
|
test("usage flattens the vendor windows to the ADR 0054 grain", () => {
|
|
const r = flattenUsage({
|
|
five_hour: { utilization: 42, resets_at: "2026-01-01T00:00:00Z" },
|
|
seven_day: { utilization: 10 },
|
|
seven_day_sonnet: { utilization: 5 },
|
|
extra_usage: { utilization: 1 },
|
|
});
|
|
assert.equal(r.sessionPct, 42);
|
|
assert.equal(r.sessionResetsAt, "2026-01-01T00:00:00Z");
|
|
assert.equal(r.weeklyPct, 10);
|
|
assert.equal(r.sonnetPct, 5);
|
|
assert.equal(r.extraPct, 1);
|
|
});
|