feat(backend): cover/file/pages endpoints — immutable URLs, Range, disk+redis caches

This commit is contained in:
2026-09-05 00:48:40 +08:00
parent 249619b857
commit 0946f6be5a
5 changed files with 340 additions and 3 deletions
+17
View File
@@ -144,6 +144,23 @@ func loginAs(t *testing.T, h http.Handler, user, pass string) string {
return v.Token
}
func TestDeleteUnsafePath403(t *testing.T) {
st, _, h, booksDir := setupAPI(t)
atok := adminToken(t, h)
lib, _ := newLibrary(t, st, h, atok, booksDir, "libs")
id, e := st.InsertBook(context.Background(), lib.ID, "../../x.cbz", "x", "cbz", 1, 1, 0)
if e != nil {
t.Fatal(e)
}
w := do(h, "DELETE", "/api/books/"+itoa(id), atok, nil)
if w.Code != 403 {
t.Fatalf("unsafe delete want 403 got %d %s", w.Code, w.Body)
}
if _, e := st.GetBook(context.Background(), id); e != nil { // 403 提前返回,行必须保留
t.Fatalf("row must survive: %v", e)
}
}
func TestAbsBookPathTraversalRejected(t *testing.T) {
root := "/data/books/lib" // 纯路径逻辑,不碰文件系统,无需 DB
for _, bad := range []string{"../../etc/passwd", "a/../../../etc/x", "../sibling"} {