headroom/tests/test_copilot_macos_keychain.py
Tejas Chopra ff4a0c6bc6 fix(copilot): support subscription auth through Headroom
Route GitHub Copilot CLI subscription traffic through the Headroom
OpenAI-compatible proxy path and resolve the account-specific Copilot API
endpoint before launch.

Add source-aware Copilot token discovery for explicit Copilot env vars,
macOS Keychain, Windows Credential Manager, Linux Secret Service, credential
files, and generic GitHub fallbacks. Validate subscription candidates against
GitHub Copilot user metadata so generic GH_TOKEN/GITHUB_TOKEN values do not
shadow Copilot CLI auth.

Document the subscription command and platform status in README: macOS
Keychain auth reuse has been smoke-tested, while Windows, Linux, Docker, and
CI auth-discovery paths still need real OS validation.

Tests: .venv/bin/python -m pytest tests/test_copilot_auth.py
tests/test_copilot_macos_keychain.py tests/test_copilot_linux_secret.py
tests/test_cli/test_wrap_copilot.py tests/test_cli/test_wrap_persistent.py
tests/test_proxy_copilot_auth_hooks.py
2026-06-02 21:24:47 -07:00

90 lines
3 KiB
Python

from __future__ import annotations
from types import SimpleNamespace
import pytest
from headroom import copilot_macos_keychain
def test_read_copilot_oauth_token_uses_security(
monkeypatch: pytest.MonkeyPatch,
) -> None:
calls: list[list[str]] = []
def fake_run(command: list[str], **kwargs: object) -> SimpleNamespace:
calls.append(command)
assert kwargs["capture_output"] is True
assert kwargs["timeout"] == 5
return SimpleNamespace(returncode=0, stdout="gho-keychain\n")
monkeypatch.setattr(copilot_macos_keychain.sys, "platform", "darwin")
monkeypatch.setenv("GITHUB_COPILOT_KEYCHAIN_SERVICE", "GitHub Copilot")
monkeypatch.setenv("GITHUB_COPILOT_KEYCHAIN_ACCOUNT", "chopratejas")
monkeypatch.setattr(copilot_macos_keychain.subprocess, "run", fake_run)
assert copilot_macos_keychain.read_copilot_oauth_token(host="github.com") == "gho-keychain"
assert calls[0] == ["security", "find-generic-password", "-s", "GitHub Copilot", "-w"]
def test_read_copilot_oauth_token_returns_none_off_macos(
monkeypatch: pytest.MonkeyPatch,
) -> None:
monkeypatch.setattr(copilot_macos_keychain.sys, "platform", "linux")
assert copilot_macos_keychain.read_copilot_oauth_token() is None
def test_candidate_security_commands_include_account_specific_lookup() -> None:
commands = copilot_macos_keychain._candidate_security_commands(
"github.com",
["GitHub Copilot"],
["chopratejas"],
)
assert ["security", "find-generic-password", "-s", "GitHub Copilot", "-w"] in commands
assert [
"security",
"find-generic-password",
"-s",
"GitHub Copilot",
"-a",
"chopratejas",
"-w",
] in commands
def test_read_copilot_oauth_token_tries_copilot_cli_host_login_account(
monkeypatch: pytest.MonkeyPatch,
tmp_path,
) -> None:
calls: list[list[str]] = []
copilot_home = tmp_path / ".copilot"
copilot_home.mkdir()
(copilot_home / "config.json").write_text(
'{"lastLoggedInUser":{"host":"https://github.com","login":"chopratejas"}}',
encoding="utf-8",
)
def fake_run(command: list[str], **kwargs: object) -> object:
calls.append(command)
stdout = "gho-keychain\n" if command == expected else ""
return type("CompletedProcess", (), {"returncode": 0 if stdout else 44, "stdout": stdout})()
expected = [
"security",
"find-generic-password",
"-s",
"copilot-cli",
"-a",
"https://github.com:chopratejas",
"-w",
]
monkeypatch.setattr(copilot_macos_keychain.sys, "platform", "darwin")
monkeypatch.setenv("COPILOT_HOME", str(copilot_home))
monkeypatch.delenv("GITHUB_COPILOT_KEYCHAIN_SERVICE", raising=False)
monkeypatch.delenv("GITHUB_COPILOT_KEYCHAIN_ACCOUNT", raising=False)
monkeypatch.setattr(copilot_macos_keychain.subprocess, "run", fake_run)
assert copilot_macos_keychain.read_copilot_oauth_token(host="github.com") == "gho-keychain"
assert expected in calls