test: prevent image snapshot payload leakage (#278)

This commit is contained in:
QiuSW
2026-09-15 09:37:01 +08:00
parent c80d0c91d5
commit cda1978bc6
@@ -3,6 +3,7 @@ package task
import (
"context"
"encoding/json"
"strings"
"testing"
"go-admin/app/goauto/models"
@@ -21,6 +22,28 @@ func TestImageSearchPriceAllowedRefusesCrossCurrency(t *testing.T) {
}
}
func TestImageSearchPayloadOnlyContainsImageMetadata(t *testing.T) {
secret := `{"shopeeProductId":99,"representativeSybProductId":1,"maxPriceRatio":3,"referenceCurrency":"TWD","imageUrl":"https://example.invalid/ref.jpg","mediaType":"image/jpeg","sizeBytes":10,"sha256":"0123456789012345678901234567890101234567890123456789012345678901"}`
record := models.CollectionTask{Source: models.CollectionTaskSourceImageSearch, RuleSnapshot: `{}`, ImageSearchSnapshot: &secret}
payload, err := NewService(nil).payload(record, false)
if err != nil {
t.Fatal(err)
}
raw := string(payload.ImageSearch)
if raw == "" || containsAny(raw, "shopeeProductId", "referenceCurrency") {
t.Fatalf("internal snapshot fields leaked in Agent payload: %s", raw)
}
}
func containsAny(value string, needles ...string) bool {
for _, needle := range needles {
if strings.Contains(value, needle) {
return true
}
}
return false
}
func TestAutoLinkImageSearchDoesNotOverwriteManualAssociation(t *testing.T) {
db := openTaskDatabase(t)
manualPDD := models.PDDProduct{GoodsID: "manual-pdd", URL: "https://mobile.yangkeduo.com/goods.html?goods_id=manual-pdd", Status: "active"}