From cda1978bc6ca63e1f3a07a477e81c0fa287ea411 Mon Sep 17 00:00:00 2001 From: QiuSW <105186638@qq.com> Date: Tue, 15 Sep 2026 09:36:40 +0800 Subject: [PATCH] test: prevent image snapshot payload leakage (#278) --- .../app/goauto/task/image_search_link_test.go | 23 +++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/server/app/goauto/task/image_search_link_test.go b/server/app/goauto/task/image_search_link_test.go index 2b8a7f5..34c39cb 100644 --- a/server/app/goauto/task/image_search_link_test.go +++ b/server/app/goauto/task/image_search_link_test.go @@ -3,6 +3,7 @@ package task import ( "context" "encoding/json" + "strings" "testing" "go-admin/app/goauto/models" @@ -21,6 +22,28 @@ func TestImageSearchPriceAllowedRefusesCrossCurrency(t *testing.T) { } } +func TestImageSearchPayloadOnlyContainsImageMetadata(t *testing.T) { + secret := `{"shopeeProductId":99,"representativeSybProductId":1,"maxPriceRatio":3,"referenceCurrency":"TWD","imageUrl":"https://example.invalid/ref.jpg","mediaType":"image/jpeg","sizeBytes":10,"sha256":"0123456789012345678901234567890101234567890123456789012345678901"}` + record := models.CollectionTask{Source: models.CollectionTaskSourceImageSearch, RuleSnapshot: `{}`, ImageSearchSnapshot: &secret} + payload, err := NewService(nil).payload(record, false) + if err != nil { + t.Fatal(err) + } + raw := string(payload.ImageSearch) + if raw == "" || containsAny(raw, "shopeeProductId", "referenceCurrency") { + t.Fatalf("internal snapshot fields leaked in Agent payload: %s", raw) + } +} + +func containsAny(value string, needles ...string) bool { + for _, needle := range needles { + if strings.Contains(value, needle) { + return true + } + } + return false +} + func TestAutoLinkImageSearchDoesNotOverwriteManualAssociation(t *testing.T) { db := openTaskDatabase(t) manualPDD := models.PDDProduct{GoodsID: "manual-pdd", URL: "https://mobile.yangkeduo.com/goods.html?goods_id=manual-pdd", Status: "active"}