@@ -1163,24 +1163,24 @@ describe('User-Agent header', () => {
11631163 expect ( headers . get ( 'User-Agent' ) ) . toMatch ( / ^ a p i o p s - c l i \/ \d + \. \d + \. \d + / ) ;
11641164 } ) ;
11651165
1166- it ( 'should include User-Agent header with correct format' , async ( ) => {
1166+ it ( 'should include User-Agent header on unauthenticated (skipAuth) blob requests' , async ( ) => {
1167+ // First fetch: authenticated APIM call returns an openapi-link SAS URL
11671168 fetchSpy . mockResolvedValueOnce (
1168- makeResponse ( 200 , {
1169- value : [ { name : 'api-1' } ] ,
1170- } )
1169+ makeResponse ( 200 , { link : 'https://example.blob.core.windows.net/spec.json?sig=abc' } )
1170+ ) ;
1171+ // Second fetch: unauthenticated blob download (skipAuth=true)
1172+ fetchSpy . mockResolvedValueOnce (
1173+ new Response ( 'openapi: 3.0.0' , { status : 200 , headers : { 'Content-Type' : 'text/plain' } } )
11711174 ) ;
11721175
1173- const results : unknown [ ] = [ ] ;
1174- for await ( const item of client . listResources ( testContext , ResourceType . Api ) ) {
1175- results . push ( item ) ;
1176- }
1176+ await client . getApiSpecification ( testContext , 'test-api' ) ;
11771177
1178- expect ( fetchSpy ) . toHaveBeenCalledTimes ( 1 ) ;
1179- const [ _url , init ] = fetchSpy . mock . calls [ 0 ] as [ string , RequestInit ] ;
1180- const headers = new Headers ( init ?. headers ) ;
1181- const userAgent = headers . get ( 'User-Agent' ) ;
1182- expect ( userAgent ) . toBeTruthy ( ) ;
1183- expect ( userAgent ) . toContain ( 'apiops-cli/' ) ;
1184- expect ( userAgent ) . toMatch ( / \d + \. \d + \. \d + / ) ;
1178+ // The second call is the skipAuth blob fetch — verify it still carries User-Agent
1179+ expect ( fetchSpy ) . toHaveBeenCalledTimes ( 2 ) ;
1180+ const [ _blobUrl , blobInit ] = fetchSpy . mock . calls [ 1 ] as [ string , RequestInit ] ;
1181+ const blobHeaders = new Headers ( blobInit ?. headers ) ;
1182+ expect ( blobHeaders . get ( 'User-Agent' ) ) . toMatch ( / ^ a p i o p s - c l i \/ \d + \. \d + \. \d + / ) ;
1183+ // Authorization must NOT be set on the unauthenticated call
1184+ expect ( blobHeaders . get ( 'Authorization' ) ) . toBeNull ( ) ;
11851185 } ) ;
11861186} ) ;
0 commit comments