test: prevent image snapshot payload leakage (#278)
This commit is contained in:
@@ -3,6 +3,7 @@ package task
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"go-admin/app/goauto/models"
|
||||
@@ -21,6 +22,28 @@ func TestImageSearchPriceAllowedRefusesCrossCurrency(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestImageSearchPayloadOnlyContainsImageMetadata(t *testing.T) {
|
||||
secret := `{"shopeeProductId":99,"representativeSybProductId":1,"maxPriceRatio":3,"referenceCurrency":"TWD","imageUrl":"https://example.invalid/ref.jpg","mediaType":"image/jpeg","sizeBytes":10,"sha256":"0123456789012345678901234567890101234567890123456789012345678901"}`
|
||||
record := models.CollectionTask{Source: models.CollectionTaskSourceImageSearch, RuleSnapshot: `{}`, ImageSearchSnapshot: &secret}
|
||||
payload, err := NewService(nil).payload(record, false)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
raw := string(payload.ImageSearch)
|
||||
if raw == "" || containsAny(raw, "shopeeProductId", "referenceCurrency") {
|
||||
t.Fatalf("internal snapshot fields leaked in Agent payload: %s", raw)
|
||||
}
|
||||
}
|
||||
|
||||
func containsAny(value string, needles ...string) bool {
|
||||
for _, needle := range needles {
|
||||
if strings.Contains(value, needle) {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func TestAutoLinkImageSearchDoesNotOverwriteManualAssociation(t *testing.T) {
|
||||
db := openTaskDatabase(t)
|
||||
manualPDD := models.PDDProduct{GoodsID: "manual-pdd", URL: "https://mobile.yangkeduo.com/goods.html?goods_id=manual-pdd", Status: "active"}
|
||||
|
||||
Reference in New Issue
Block a user