fix(qa): 第五轮系统性质量保障缺陷修复 + 单元/集成测试
安全/鉴权:登出清服务端 httpOnly 令牌、登录 IP 限流前置 bcrypt、停用账号 令牌在 6 个内联 role handler 失效、admin/items 存在性 oracle 认证前置、 同意偏好 sanitize fail-closed、api-crypto 按 HTTP 方法判体。 CMS:workflow 状态更新+审计收进交互式 $transaction(失败即回滚)、编辑器 richtext 走 textarea 防换行损毁、array/object 子字段按作用域读写防污染、 about/contact/erp-upgrade 补 ISR revalidate 与路由映射。 UI/a11y:AnimatedCounter 入视口前显起点、CLS 累计上报、MetricCard 动画入 effect 并卸载取消 rAF、后台状态四态映射/搜索防抖+序号守卫/媒体单 input/ 吞错改横幅/表单 label-aria 关联。 新增对应判别性单测与 pagination/rate-limit/client-ip/sanitize/validate-content-data 等模块及 tests-integration 真库集成层。
This commit is contained in:
@@ -36,6 +36,12 @@ jest.mock('@/lib/permissions', () => ({
|
||||
requirePermission: mockRequirePermission,
|
||||
}));
|
||||
|
||||
// Q-8:workflow POST 现会先 authenticateRequest 再探存在性;默认给有效会话。
|
||||
const mockAuthenticateRequest = jest.fn<(request: NextRequest) => unknown>();
|
||||
jest.mock('@/lib/auth', () => ({
|
||||
authenticateRequest: mockAuthenticateRequest,
|
||||
}));
|
||||
|
||||
jest.unmock('./route');
|
||||
|
||||
import { POST } from './route';
|
||||
@@ -77,6 +83,7 @@ beforeEach(() => {
|
||||
jest.clearAllMocks();
|
||||
mockContentItemFindUnique.mockResolvedValue(mockItem);
|
||||
mockContentItemFindUniqueOrThrow.mockResolvedValue(mockUpdatedItem);
|
||||
mockAuthenticateRequest.mockReturnValue({ userId: 'user-1', username: 'editor', role: 'editor' });
|
||||
});
|
||||
|
||||
describe('POST /api/admin/items/[id]/workflow', () => {
|
||||
@@ -111,6 +118,16 @@ describe('POST /api/admin/items/[id]/workflow', () => {
|
||||
expect(body.error).toBe('内容不存在');
|
||||
});
|
||||
|
||||
// Q-8:匿名调用者不得用「404 vs 401」枚举 ID —— 认证须先于存在性探针。
|
||||
it('rejects an unauthenticated workflow with 401 WITHOUT probing item existence', async () => {
|
||||
mockAuthenticateRequest.mockReturnValue(null);
|
||||
const request = createMockRequest({ action: 'submit' });
|
||||
const response = await POST(request, { params: Promise.resolve({ id: 'item-1' }) });
|
||||
|
||||
expect(response.status).toBe(401);
|
||||
expect(mockContentItemFindUnique).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it('submit requires update permission', async () => {
|
||||
mockAuthorized('update');
|
||||
const request = createMockRequest({ action: 'submit' });
|
||||
|
||||
Reference in New Issue
Block a user