fix(qa): 第五轮系统性质量保障缺陷修复 + 单元/集成测试

安全/鉴权:登出清服务端 httpOnly 令牌、登录 IP 限流前置 bcrypt、停用账号
令牌在 6 个内联 role handler 失效、admin/items 存在性 oracle 认证前置、
同意偏好 sanitize fail-closed、api-crypto 按 HTTP 方法判体。

CMS:workflow 状态更新+审计收进交互式 $transaction(失败即回滚)、编辑器
richtext 走 textarea 防换行损毁、array/object 子字段按作用域读写防污染、
about/contact/erp-upgrade 补 ISR revalidate 与路由映射。

UI/a11y:AnimatedCounter 入视口前显起点、CLS 累计上报、MetricCard 动画入
effect 并卸载取消 rAF、后台状态四态映射/搜索防抖+序号守卫/媒体单 input/
吞错改横幅/表单 label-aria 关联。

新增对应判别性单测与 pagination/rate-limit/client-ip/sanitize/validate-content-data
等模块及 tests-integration 真库集成层。
This commit is contained in:
2026-09-28 10:48:07 +08:00
parent 040951c0a3
commit a366bd1400
224 changed files with 8938 additions and 5579 deletions
@@ -36,6 +36,12 @@ jest.mock('@/lib/permissions', () => ({
requirePermission: mockRequirePermission,
}));
// Q-8:workflow POST 现会先 authenticateRequest 再探存在性;默认给有效会话。
const mockAuthenticateRequest = jest.fn<(request: NextRequest) => unknown>();
jest.mock('@/lib/auth', () => ({
authenticateRequest: mockAuthenticateRequest,
}));
jest.unmock('./route');
import { POST } from './route';
@@ -77,6 +83,7 @@ beforeEach(() => {
jest.clearAllMocks();
mockContentItemFindUnique.mockResolvedValue(mockItem);
mockContentItemFindUniqueOrThrow.mockResolvedValue(mockUpdatedItem);
mockAuthenticateRequest.mockReturnValue({ userId: 'user-1', username: 'editor', role: 'editor' });
});
describe('POST /api/admin/items/[id]/workflow', () => {
@@ -111,6 +118,16 @@ describe('POST /api/admin/items/[id]/workflow', () => {
expect(body.error).toBe('内容不存在');
});
// Q-8:匿名调用者不得用「404 vs 401」枚举 ID —— 认证须先于存在性探针。
it('rejects an unauthenticated workflow with 401 WITHOUT probing item existence', async () => {
mockAuthenticateRequest.mockReturnValue(null);
const request = createMockRequest({ action: 'submit' });
const response = await POST(request, { params: Promise.resolve({ id: 'item-1' }) });
expect(response.status).toBe(401);
expect(mockContentItemFindUnique).not.toHaveBeenCalled();
});
it('submit requires update permission', async () => {
mockAuthorized('update');
const request = createMockRequest({ action: 'submit' });