feat(backend): cover/file/pages endpoints — immutable URLs, Range, disk+redis caches
This commit is contained in:
@@ -144,6 +144,23 @@ func loginAs(t *testing.T, h http.Handler, user, pass string) string {
|
||||
return v.Token
|
||||
}
|
||||
|
||||
func TestDeleteUnsafePath403(t *testing.T) {
|
||||
st, _, h, booksDir := setupAPI(t)
|
||||
atok := adminToken(t, h)
|
||||
lib, _ := newLibrary(t, st, h, atok, booksDir, "libs")
|
||||
id, e := st.InsertBook(context.Background(), lib.ID, "../../x.cbz", "x", "cbz", 1, 1, 0)
|
||||
if e != nil {
|
||||
t.Fatal(e)
|
||||
}
|
||||
w := do(h, "DELETE", "/api/books/"+itoa(id), atok, nil)
|
||||
if w.Code != 403 {
|
||||
t.Fatalf("unsafe delete want 403 got %d %s", w.Code, w.Body)
|
||||
}
|
||||
if _, e := st.GetBook(context.Background(), id); e != nil { // 403 提前返回,行必须保留
|
||||
t.Fatalf("row must survive: %v", e)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAbsBookPathTraversalRejected(t *testing.T) {
|
||||
root := "/data/books/lib" // 纯路径逻辑,不碰文件系统,无需 DB
|
||||
for _, bad := range []string{"../../etc/passwd", "a/../../../etc/x", "../sibling"} {
|
||||
|
||||
Reference in New Issue
Block a user