From 1884e3a063262f611a7e679795ef6a016eafce8d Mon Sep 17 00:00:00 2001 From: "MUH. IQRAM BAHRING" Date: Sat, 19 Sep 2026 11:47:15 +0800 Subject: [PATCH] test(cline): align auth-header test with upstream WorkOS-JWT-only prefixing Upstream f6e7cabe stopped workos:-prefixing opaque tokens (ClinePass API keys like clp_...), so getClineAccessToken now only prefixes WorkOS JWTs. The fork's test asserted the old unconditional-prefix behavior. --- tests/unit/cline-data-envelope.test.js | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/tests/unit/cline-data-envelope.test.js b/tests/unit/cline-data-envelope.test.js index cecbac36..e6c7bb33 100644 --- a/tests/unit/cline-data-envelope.test.js +++ b/tests/unit/cline-data-envelope.test.js @@ -53,9 +53,15 @@ describe("cline auth header shape", () => { expect(buildClineHeaders("sk_abc", {}, { isApiKey: true }).Authorization).toBe("Bearer sk_abc"); }); - it("prefixes OAuth tokens with workos:", () => { - expect(buildClineHeaders("tok123").Authorization).toBe("Bearer workos:tok123"); - expect(buildClineHeaders("workos:tok123").Authorization).toBe("Bearer workos:tok123"); + it("prefixes WorkOS JWT OAuth tokens with workos:", () => { + const jwt = "eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.sig"; + expect(buildClineHeaders(jwt).Authorization).toBe(`Bearer workos:${jwt}`); + expect(buildClineHeaders(`workos:${jwt}`).Authorization).toBe(`Bearer workos:${jwt}`); + }); + + it("does not workos:-prefix opaque tokens (API keys, clp_…)", () => { + expect(buildClineHeaders("tok123").Authorization).toBe("Bearer tok123"); + expect(buildClineHeaders("clp_abc123").Authorization).toBe("Bearer clp_abc123"); }); it("sends Cline product identity headers (free-model gate)", () => {