fix: bump test mock version to 1.3.1 for version comparison
TallyNote release / linux-x64 (push) Successful in 6m15s
TallyNote release / linux-x64 (push) Successful in 6m15s
This commit is contained in:
+23
-23
@@ -59,10 +59,10 @@ describe("更新 API", () => {
|
|||||||
|
|
||||||
function mockRelease() {
|
function mockRelease() {
|
||||||
const digest = "c".repeat(64);
|
const digest = "c".repeat(64);
|
||||||
const asset = `tallynote-1.3.0-${detectPlatform().target}-glibc.tar.gz`;
|
const asset = `tallynote-1.3.1-${detectPlatform().target}-glibc.tar.gz`;
|
||||||
globalThis.fetch = (async (input: string | URL) => input.toString().endsWith("SHA256SUMS")
|
globalThis.fetch = (async (input: string | URL) => input.toString().endsWith("SHA256SUMS")
|
||||||
? new Response(`${digest} ${asset}\n`, { status: 200 })
|
? new Response(`${digest} ${asset}\n`, { status: 200 })
|
||||||
: new Response(JSON.stringify({ tag_name: "v1.3.0", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: asset, browser_download_url: `https://updates.example/${asset}` }] }), { status: 200 })) as typeof fetch;
|
: new Response(JSON.stringify({ tag_name: "v1.3.1", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: asset, browser_download_url: `https://updates.example/${asset}` }] }), { status: 200 })) as typeof fetch;
|
||||||
}
|
}
|
||||||
|
|
||||||
it("检查 release、创建受保护请求文件并拒绝重复任务", async () => {
|
it("检查 release、创建受保护请求文件并拒绝重复任务", async () => {
|
||||||
@@ -70,7 +70,7 @@ describe("更新 API", () => {
|
|||||||
mockRelease();
|
mockRelease();
|
||||||
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||||
expect(checked.statusCode).toBe(200);
|
expect(checked.statusCode).toBe(200);
|
||||||
expect(checked.json().latest).toMatchObject({ version: "1.3.0", compatible: true, integrityReady: true, isNewer: true });
|
expect(checked.json().latest).toMatchObject({ version: "1.3.1", compatible: true, integrityReady: true, isNewer: true });
|
||||||
expect(checked.headers["cache-control"]).toBe("no-store");
|
expect(checked.headers["cache-control"]).toBe("no-store");
|
||||||
const tooSoon = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
const tooSoon = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||||
expect(tooSoon.statusCode).toBe(429);
|
expect(tooSoon.statusCode).toBe(429);
|
||||||
@@ -82,15 +82,15 @@ describe("更新 API", () => {
|
|||||||
const otherChecked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: otherSession.cookies, "x-csrf-token": otherSession.csrf }, payload: {} });
|
const otherChecked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: otherSession.cookies, "x-csrf-token": otherSession.csrf }, payload: {} });
|
||||||
expect(otherChecked.statusCode).toBe(200);
|
expect(otherChecked.statusCode).toBe(200);
|
||||||
|
|
||||||
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
|
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.1", confirm: true } });
|
||||||
expect(applied.statusCode).toBe(202);
|
expect(applied.statusCode).toBe(202);
|
||||||
const jobId = applied.json().job.id as string;
|
const jobId = applied.json().job.id as string;
|
||||||
const request = JSON.parse(readFileSync(config.updateRequestPath, "utf8")) as { jobId: string; expectedSha256: string; currentLink: string };
|
const request = JSON.parse(readFileSync(config.updateRequestPath, "utf8")) as { jobId: string; expectedSha256: string; currentLink: string };
|
||||||
expect(request).toMatchObject({ jobId, version: "1.3.0", expectedSha256: "c".repeat(64), currentLink: config.currentLink });
|
expect(request).toMatchObject({ jobId, version: "1.3.1", expectedSha256: "c".repeat(64), currentLink: config.currentLink });
|
||||||
expect(statSync(config.updateRequestPath).mode & 0o777).toBe(0o600);
|
expect(statSync(config.updateRequestPath).mode & 0o777).toBe(0o600);
|
||||||
|
|
||||||
mockRelease();
|
mockRelease();
|
||||||
const duplicate = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
|
const duplicate = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.1", confirm: true } });
|
||||||
expect(duplicate.statusCode).toBe(409);
|
expect(duplicate.statusCode).toBe(409);
|
||||||
expect(duplicate.json().error.code).toBe("UPDATE_IN_PROGRESS");
|
expect(duplicate.json().error.code).toBe("UPDATE_IN_PROGRESS");
|
||||||
const status = await app.inject({ method: "GET", url: "/api/update/status", headers: { cookie: session.cookies } });
|
const status = await app.inject({ method: "GET", url: "/api/update/status", headers: { cookie: session.cookies } });
|
||||||
@@ -106,10 +106,10 @@ describe("更新 API", () => {
|
|||||||
mockRelease();
|
mockRelease();
|
||||||
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||||
expect(checked.statusCode).toBe(200);
|
expect(checked.statusCode).toBe(200);
|
||||||
const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
|
const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.1", confirm: true } });
|
||||||
expect(downloaded.statusCode).toBe(200);
|
expect(downloaded.statusCode).toBe(200);
|
||||||
const downloadJobId = downloaded.json().job.id as string;
|
const downloadJobId = downloaded.json().job.id as string;
|
||||||
expect(downloaded.json().job).toMatchObject({ operation: "download", status: expect.any(String), version: "1.3.0" });
|
expect(downloaded.json().job).toMatchObject({ operation: "download", status: expect.any(String), version: "1.3.1" });
|
||||||
await new Promise(resolve => setTimeout(resolve, 300)); // The download runs asynchronously in the web process; the request file
|
await new Promise(resolve => setTimeout(resolve, 300)); // The download runs asynchronously in the web process; the request file
|
||||||
// is only written after staging completes. Verify the job row exists.
|
// is only written after staging completes. Verify the job row exists.
|
||||||
expect(database.sqlite.prepare("SELECT id FROM update_jobs WHERE id=?").get(downloadJobId)).toBeDefined();
|
expect(database.sqlite.prepare("SELECT id FROM update_jobs WHERE id=?").get(downloadJobId)).toBeDefined();
|
||||||
@@ -118,21 +118,21 @@ describe("更新 API", () => {
|
|||||||
const stagedId = randomUUID();
|
const stagedId = randomUUID();
|
||||||
const now = Date.now();
|
const now = Date.now();
|
||||||
database.sqlite.prepare(`INSERT INTO update_jobs(id, admin_id, session_hash, request_id, requested_at, operation, status, version, platform, release_url, asset_name, asset_url, expected_sha256, actual_sha256, download_path, created_at, updated_at) VALUES (?, ?, ?, ?, ?, 'download', 'staged', ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)`)
|
database.sqlite.prepare(`INSERT INTO update_jobs(id, admin_id, session_hash, request_id, requested_at, operation, status, version, platform, release_url, asset_name, asset_url, expected_sha256, actual_sha256, download_path, created_at, updated_at) VALUES (?, ?, ?, ?, ?, 'download', 'staged', ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)`)
|
||||||
.run(stagedId, (await database.sqlite.prepare("SELECT id FROM admins WHERE username=?").get("update-staged") as { id: string }).id, "session", "staged-request", now, "1.3.0", detectPlatform().target, config.updateMetadataUrl, "release.tar.gz", "https://updates.example/release.tar.gz", "c".repeat(64), "c".repeat(64), path.join(config.dataDir, "staged-workspace"), now, now);
|
.run(stagedId, (await database.sqlite.prepare("SELECT id FROM admins WHERE username=?").get("update-staged") as { id: string }).id, "session", "staged-request", now, "1.3.1", detectPlatform().target, config.updateMetadataUrl, "release.tar.gz", "https://updates.example/release.tar.gz", "c".repeat(64), "c".repeat(64), path.join(config.dataDir, "staged-workspace"), now, now);
|
||||||
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { jobId: stagedId, version: "1.3.0", confirm: true } });
|
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { jobId: stagedId, version: "1.3.1", confirm: true } });
|
||||||
expect(applied.statusCode).toBe(202);
|
expect(applied.statusCode).toBe(202);
|
||||||
expect(applied.json().job).toMatchObject({ id: stagedId, operation: "apply", status: "staged" });
|
expect(applied.json().job).toMatchObject({ id: stagedId, operation: "apply", status: "staged" });
|
||||||
expect(database.sqlite.prepare("SELECT operation, status FROM update_jobs WHERE id=?").get(stagedId)).toEqual({ operation: "apply", status: "staged" });
|
expect(database.sqlite.prepare("SELECT operation, status FROM update_jobs WHERE id=?").get(stagedId)).toEqual({ operation: "apply", status: "staged" });
|
||||||
const applyRequest = JSON.parse(readFileSync(config.updateRequestPath, "utf8")) as { jobId: string; operation: string; assetUrl: string; expectedSha256: string };
|
const applyRequest = JSON.parse(readFileSync(config.updateRequestPath, "utf8")) as { jobId: string; operation: string; assetUrl: string; expectedSha256: string };
|
||||||
expect(applyRequest).toMatchObject({ jobId: stagedId, operation: "apply", assetUrl: "https://updates.example/release.tar.gz", expectedSha256: "c".repeat(64) });
|
expect(applyRequest).toMatchObject({ jobId: stagedId, operation: "apply", assetUrl: "https://updates.example/release.tar.gz", expectedSha256: "c".repeat(64) });
|
||||||
const duplicate = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { jobId: stagedId, version: "1.3.0", confirm: true } });
|
const duplicate = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { jobId: stagedId, version: "1.3.1", confirm: true } });
|
||||||
expect(duplicate.statusCode).toBe(409);
|
expect(duplicate.statusCode).toBe(409);
|
||||||
expect(duplicate.json().error.code).toBe("UPDATE_IN_PROGRESS");
|
expect(duplicate.json().error.code).toBe("UPDATE_IN_PROGRESS");
|
||||||
});
|
});
|
||||||
|
|
||||||
it("缺少确认或未启用 systemd 时不接受更新", async () => {
|
it("缺少确认或未启用 systemd 时不接受更新", async () => {
|
||||||
const session = await login();
|
const session = await login();
|
||||||
const invalid = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0" } });
|
const invalid = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.1" } });
|
||||||
expect(invalid.statusCode).toBe(400);
|
expect(invalid.statusCode).toBe(400);
|
||||||
process.env.TALLYNOTE_UPDATE_STRATEGY = "disabled";
|
process.env.TALLYNOTE_UPDATE_STRATEGY = "disabled";
|
||||||
const disabledConfig = loadConfig();
|
const disabledConfig = loadConfig();
|
||||||
@@ -154,7 +154,7 @@ describe("更新 API", () => {
|
|||||||
mockRelease();
|
mockRelease();
|
||||||
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||||
expect(checked.statusCode).toBe(200);
|
expect(checked.statusCode).toBe(200);
|
||||||
expect(checked.json().latest).toMatchObject({ version: "1.3.0", isNewer: true });
|
expect(checked.json().latest).toMatchObject({ version: "1.3.1", isNewer: true });
|
||||||
});
|
});
|
||||||
|
|
||||||
it("不会应用已经等于当前版本的暂存更新", async () => {
|
it("不会应用已经等于当前版本的暂存更新", async () => {
|
||||||
@@ -210,7 +210,7 @@ describe("更新 API", () => {
|
|||||||
mockRelease();
|
mockRelease();
|
||||||
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: owner.cookies, "x-csrf-token": owner.csrf }, payload: {} });
|
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: owner.cookies, "x-csrf-token": owner.csrf }, payload: {} });
|
||||||
expect(checked.statusCode).toBe(200);
|
expect(checked.statusCode).toBe(200);
|
||||||
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: owner.cookies, "x-csrf-token": owner.csrf }, payload: { version: "1.3.0", confirm: true } });
|
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: owner.cookies, "x-csrf-token": owner.csrf }, payload: { version: "1.3.1", confirm: true } });
|
||||||
expect(applied.statusCode).toBe(202);
|
expect(applied.statusCode).toBe(202);
|
||||||
const jobId = applied.json().job.id as string;
|
const jobId = applied.json().job.id as string;
|
||||||
database.sqlite.prepare("UPDATE update_jobs SET error_message=? WHERE id=?").run("/var/lib/tallynote/secret-command-output", jobId);
|
database.sqlite.prepare("UPDATE update_jobs SET error_message=? WHERE id=?").run("/var/lib/tallynote/secret-command-output", jobId);
|
||||||
@@ -235,7 +235,7 @@ describe("更新 API", () => {
|
|||||||
const otherJobId = randomUUID();
|
const otherJobId = randomUUID();
|
||||||
const insert = database.sqlite.prepare(`
|
const insert = database.sqlite.prepare(`
|
||||||
INSERT INTO update_jobs(id, admin_id, operation, status, version, platform, asset_url, created_at, updated_at)
|
INSERT INTO update_jobs(id, admin_id, operation, status, version, platform, asset_url, created_at, updated_at)
|
||||||
VALUES (?, ?, 'download', 'queued', '1.3.0', ?, 'https://updates.example/update.tar.gz', ?, ?)
|
VALUES (?, ?, 'download', 'queued', '1.3.1', ?, 'https://updates.example/update.tar.gz', ?, ?)
|
||||||
`);
|
`);
|
||||||
insert.run(ownerJobId, ownerId, detectPlatform().target, now, now);
|
insert.run(ownerJobId, ownerId, detectPlatform().target, now, now);
|
||||||
insert.run(otherJobId, otherId, detectPlatform().target, now + 1, now + 1);
|
insert.run(otherJobId, otherId, detectPlatform().target, now + 1, now + 1);
|
||||||
@@ -264,7 +264,7 @@ describe("更新 API", () => {
|
|||||||
it("应用前重新校验失败时写入失败审计", async () => {
|
it("应用前重新校验失败时写入失败审计", async () => {
|
||||||
const session = await login("update-audit");
|
const session = await login("update-audit");
|
||||||
globalThis.fetch = (async () => new Response("upstream unavailable", { status: 503 })) as typeof fetch;
|
globalThis.fetch = (async () => new Response("upstream unavailable", { status: 503 })) as typeof fetch;
|
||||||
const response = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
|
const response = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.1", confirm: true } });
|
||||||
expect(response.statusCode).toBe(502);
|
expect(response.statusCode).toBe(502);
|
||||||
// A failed upstream check must not reserve the per-admin cooldown; an
|
// A failed upstream check must not reserve the per-admin cooldown; an
|
||||||
// operator can retry immediately after fixing the release endpoint.
|
// operator can retry immediately after fixing the release endpoint.
|
||||||
@@ -289,7 +289,7 @@ describe("更新 API", () => {
|
|||||||
|
|
||||||
const archiveBytes = readFileSync(archivePath);
|
const archiveBytes = readFileSync(archivePath);
|
||||||
const digest = createHash("sha256").update(archiveBytes).digest("hex");
|
const digest = createHash("sha256").update(archiveBytes).digest("hex");
|
||||||
const assetName = `tallynote-1.3.0-${detectPlatform().target}-glibc.tar.gz`;
|
const assetName = `tallynote-1.3.1-${detectPlatform().target}-glibc.tar.gz`;
|
||||||
|
|
||||||
globalThis.fetch = (async (input: string | URL) => {
|
globalThis.fetch = (async (input: string | URL) => {
|
||||||
const url = input.toString();
|
const url = input.toString();
|
||||||
@@ -300,7 +300,7 @@ describe("更新 API", () => {
|
|||||||
return new Response(archiveBytes, { status: 200, headers: { "content-length": String(archiveBytes.length) } });
|
return new Response(archiveBytes, { status: 200, headers: { "content-length": String(archiveBytes.length) } });
|
||||||
}
|
}
|
||||||
return new Response(JSON.stringify({
|
return new Response(JSON.stringify({
|
||||||
tag_name: "v1.3.0",
|
tag_name: "v1.3.1",
|
||||||
assets: [
|
assets: [
|
||||||
{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" },
|
{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" },
|
||||||
{ name: assetName, browser_download_url: `https://updates.example/${assetName}` }
|
{ name: assetName, browser_download_url: `https://updates.example/${assetName}` }
|
||||||
@@ -312,7 +312,7 @@ describe("更新 API", () => {
|
|||||||
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||||
expect(checked.statusCode).toBe(200);
|
expect(checked.statusCode).toBe(200);
|
||||||
|
|
||||||
const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
|
const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.1", confirm: true } });
|
||||||
expect(downloaded.statusCode).toBe(200);
|
expect(downloaded.statusCode).toBe(200);
|
||||||
const downloadJobId = downloaded.json().job.id as string;
|
const downloadJobId = downloaded.json().job.id as string;
|
||||||
|
|
||||||
@@ -347,7 +347,7 @@ describe("更新 API", () => {
|
|||||||
|
|
||||||
const archiveBytes = readFileSync(archivePath);
|
const archiveBytes = readFileSync(archivePath);
|
||||||
const digest = createHash("sha256").update(archiveBytes).digest("hex");
|
const digest = createHash("sha256").update(archiveBytes).digest("hex");
|
||||||
const assetName = `tallynote-1.3.0-${detectPlatform().target}-glibc.tar.gz`;
|
const assetName = `tallynote-1.3.1-${detectPlatform().target}-glibc.tar.gz`;
|
||||||
|
|
||||||
// Mock a slow stream
|
// Mock a slow stream
|
||||||
let fetchAborted = false;
|
let fetchAborted = false;
|
||||||
@@ -374,7 +374,7 @@ describe("更新 API", () => {
|
|||||||
return new Response(stream, { status: 200, headers: { "content-length": String(archiveBytes.length) } });
|
return new Response(stream, { status: 200, headers: { "content-length": String(archiveBytes.length) } });
|
||||||
}
|
}
|
||||||
return new Response(JSON.stringify({
|
return new Response(JSON.stringify({
|
||||||
tag_name: "v1.3.0",
|
tag_name: "v1.3.1",
|
||||||
assets: [
|
assets: [
|
||||||
{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" },
|
{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" },
|
||||||
{ name: assetName, browser_download_url: `https://updates.example/${assetName}` }
|
{ name: assetName, browser_download_url: `https://updates.example/${assetName}` }
|
||||||
@@ -385,7 +385,7 @@ describe("更新 API", () => {
|
|||||||
const session = await login("update-cancel-inprocess");
|
const session = await login("update-cancel-inprocess");
|
||||||
await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||||
|
|
||||||
const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
|
const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.1", confirm: true } });
|
||||||
const downloadJobId = downloaded.json().job.id as string;
|
const downloadJobId = downloaded.json().job.id as string;
|
||||||
|
|
||||||
// Wait until status becomes downloading
|
// Wait until status becomes downloading
|
||||||
@@ -417,7 +417,7 @@ describe("更新 API", () => {
|
|||||||
const session = await login("update-cancel");
|
const session = await login("update-cancel");
|
||||||
mockRelease();
|
mockRelease();
|
||||||
await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||||
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
|
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.1", confirm: true } });
|
||||||
expect(applied.statusCode).toBe(202);
|
expect(applied.statusCode).toBe(202);
|
||||||
expect(existsSync(config.updateRequestPath)).toBe(true);
|
expect(existsSync(config.updateRequestPath)).toBe(true);
|
||||||
|
|
||||||
|
|||||||
+23
-23
@@ -40,23 +40,23 @@ describe("更新安全工具", () => {
|
|||||||
expect(isNewerVersion("1.0.0", "1.0.0-beta.1")).toBe(false);
|
expect(isNewerVersion("1.0.0", "1.0.0-beta.1")).toBe(false);
|
||||||
expect(detectPlatform("linux", "x86_64").target).toBe("linux-x64");
|
expect(detectPlatform("linux", "x86_64").target).toBe("linux-x64");
|
||||||
const release = {
|
const release = {
|
||||||
version: "1.3.0",
|
version: "1.3.1",
|
||||||
assets: [
|
assets: [
|
||||||
{ name: "tallynote-1.3.0-linux-arm64-glibc.tar.gz", url: "https://updates.example/arm" },
|
{ name: "tallynote-1.3.1-linux-arm64-glibc.tar.gz", url: "https://updates.example/arm" },
|
||||||
{ name: "tallynote-1.3.0-linux-x64-glibc.tar.gz", url: "https://updates.example/x64" },
|
{ name: "tallynote-1.3.1-linux-x64-glibc.tar.gz", url: "https://updates.example/x64" },
|
||||||
],
|
],
|
||||||
};
|
};
|
||||||
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"))?.name).toContain("linux-x64");
|
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"))?.name).toContain("linux-x64");
|
||||||
expect(selectReleaseAsset({ version: "1.3.0", assets: [{ name: "tallynote-1.3.0-linux-arm64-glibc.tar.gz", url: "https://updates.example/arm" }] }, detectPlatform("linux", "x86_64"))).toBeUndefined();
|
expect(selectReleaseAsset({ version: "1.3.1", assets: [{ name: "tallynote-1.3.1-linux-arm64-glibc.tar.gz", url: "https://updates.example/arm" }] }, detectPlatform("linux", "x86_64"))).toBeUndefined();
|
||||||
expect(() => validateHttpsUrl("http://updates.example/x64", { allowedHosts: ["updates.example"] })).toThrow();
|
expect(() => validateHttpsUrl("http://updates.example/x64", { allowedHosts: ["updates.example"] })).toThrow();
|
||||||
expect(() => sanitizeAssetName("../release.tar.gz")).toThrow();
|
expect(() => sanitizeAssetName("../release.tar.gz")).toThrow();
|
||||||
});
|
});
|
||||||
|
|
||||||
it("优先选择运行时匹配的轻量更新包,并对旧客户端保留完整包回退", () => {
|
it("优先选择运行时匹配的轻量更新包,并对旧客户端保留完整包回退", () => {
|
||||||
const runtimeHash = runtimeHashFromLockfile("lockfile-v1\n");
|
const runtimeHash = runtimeHashFromLockfile("lockfile-v1\n");
|
||||||
const full = { name: "tallynote-1.3.0-linux-x64-glibc.tar.gz", url: "https://updates.example/full" };
|
const full = { name: "tallynote-1.3.1-linux-x64-glibc.tar.gz", url: "https://updates.example/full" };
|
||||||
const app = { name: `tallynote-1.3.0-linux-x64-glibc.update-${runtimeHash}.tar.gz`, url: "https://updates.example/app" };
|
const app = { name: `tallynote-1.3.1-linux-x64-glibc.update-${runtimeHash}.tar.gz`, url: "https://updates.example/app" };
|
||||||
const release = { version: "1.3.0", assets: [full, app] };
|
const release = { version: "1.3.1", assets: [full, app] };
|
||||||
expect(applicationUpdateRuntimeHash(app.name)).toBe(runtimeHash);
|
expect(applicationUpdateRuntimeHash(app.name)).toBe(runtimeHash);
|
||||||
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"), runtimeHash)).toEqual(app);
|
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"), runtimeHash)).toEqual(app);
|
||||||
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"))).toEqual(full);
|
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"))).toEqual(full);
|
||||||
@@ -102,12 +102,12 @@ describe("更新安全工具", () => {
|
|||||||
globalThis.fetch = (async (input: string | URL) => {
|
globalThis.fetch = (async (input: string | URL) => {
|
||||||
const url = input.toString();
|
const url = input.toString();
|
||||||
if (url.endsWith("/latest")) {
|
if (url.endsWith("/latest")) {
|
||||||
return new Response(JSON.stringify({ tag_name: "v1.3.0", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: "app-linux-x64.tar.gz", browser_download_url: "https://updates.example/app-linux-x64.tar.gz" }] }), { status: 200, headers: { "content-type": "application/json" } });
|
return new Response(JSON.stringify({ tag_name: "v1.3.1", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: "app-linux-x64.tar.gz", browser_download_url: "https://updates.example/app-linux-x64.tar.gz" }] }), { status: 200, headers: { "content-type": "application/json" } });
|
||||||
}
|
}
|
||||||
return new Response(`${digest} app-linux-x64.tar.gz\n`, { status: 200 });
|
return new Response(`${digest} app-linux-x64.tar.gz\n`, { status: 200 });
|
||||||
}) as typeof fetch;
|
}) as typeof fetch;
|
||||||
const metadata = await fetchReleaseMetadata("https://updates.example/latest", { allowedHosts: ["updates.example"] });
|
const metadata = await fetchReleaseMetadata("https://updates.example/latest", { allowedHosts: ["updates.example"] });
|
||||||
expect(metadata.version).toBe("1.3.0");
|
expect(metadata.version).toBe("1.3.1");
|
||||||
expect((await fetchReleaseText("https://updates.example/SHA256SUMS", { allowedHosts: ["updates.example"] })).trim()).toContain(digest);
|
expect((await fetchReleaseText("https://updates.example/SHA256SUMS", { allowedHosts: ["updates.example"] })).trim()).toContain(digest);
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -253,22 +253,22 @@ describe("更新安全工具", () => {
|
|||||||
const jobId = randomUUID();
|
const jobId = randomUUID();
|
||||||
database = openDatabase(config);
|
database = openDatabase(config);
|
||||||
const now = Date.now();
|
const now = Date.now();
|
||||||
const assetName = `tallynote-1.3.0-${detectPlatform().target}.tar.gz`;
|
const assetName = `tallynote-1.3.1-${detectPlatform().target}.tar.gz`;
|
||||||
database.sqlite.prepare(`
|
database.sqlite.prepare(`
|
||||||
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url,
|
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url,
|
||||||
expected_sha256, created_at, updated_at, requested_at)
|
expected_sha256, created_at, updated_at, requested_at)
|
||||||
VALUES (?, 'apply', 'queued', '1.3.0', ?, ?, ?, ?, ?, ?)
|
VALUES (?, 'apply', 'queued', '1.3.1', ?, ?, ?, ?, ?, ?)
|
||||||
`).run(jobId, detectPlatform().target, "https://updates.example/" + assetName, digest, now, now, now);
|
`).run(jobId, detectPlatform().target, "https://updates.example/" + assetName, digest, now, now, now);
|
||||||
globalThis.fetch = (async (input: string | URL) => {
|
globalThis.fetch = (async (input: string | URL) => {
|
||||||
const url = input.toString();
|
const url = input.toString();
|
||||||
if (url.endsWith("/latest")) return new Response(JSON.stringify({ tag_name: "v1.3.0", assets: [{ name: assetName, browser_download_url: `https://updates.example/${assetName}` }, { name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }] }));
|
if (url.endsWith("/latest")) return new Response(JSON.stringify({ tag_name: "v1.3.1", assets: [{ name: assetName, browser_download_url: `https://updates.example/${assetName}` }, { name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }] }));
|
||||||
if (url.endsWith("SHA256SUMS")) return new Response(`${digest} ${assetName}\n`);
|
if (url.endsWith("SHA256SUMS")) return new Response(`${digest} ${assetName}\n`);
|
||||||
return new Response(bytes, { headers: { "content-length": String(bytes.length) } });
|
return new Response(bytes, { headers: { "content-length": String(bytes.length) } });
|
||||||
}) as typeof fetch;
|
}) as typeof fetch;
|
||||||
|
|
||||||
await runUpdate({
|
await runUpdate({
|
||||||
metadataUrl: config.updateMetadataUrl,
|
metadataUrl: config.updateMetadataUrl,
|
||||||
version: "1.3.0",
|
version: "1.3.1",
|
||||||
currentVersion: config.appVersion,
|
currentVersion: config.appVersion,
|
||||||
currentDir: config.currentLink,
|
currentDir: config.currentLink,
|
||||||
stagingDir: path.join(root, "staging"),
|
stagingDir: path.join(root, "staging"),
|
||||||
@@ -294,14 +294,14 @@ describe("更新安全工具", () => {
|
|||||||
const defaultJobId = randomUUID();
|
const defaultJobId = randomUUID();
|
||||||
database.sqlite.prepare(`
|
database.sqlite.prepare(`
|
||||||
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
||||||
VALUES (?, 'apply', 'applying', '1.3.0', ?, ?, ?, ?)
|
VALUES (?, 'apply', 'applying', '1.3.1', ?, ?, ?, ?)
|
||||||
`).run(defaultJobId, detectPlatform().target, "https://updates.example/" + assetName, now, now);
|
`).run(defaultJobId, detectPlatform().target, "https://updates.example/" + assetName, now, now);
|
||||||
finalizeUpdateJob(database.sqlite, defaultJobId, "failed", "");
|
finalizeUpdateJob(database.sqlite, defaultJobId, "failed", "");
|
||||||
expect(database.sqlite.prepare("SELECT error_message AS errorMessage FROM update_jobs WHERE id=?").get(defaultJobId)).toEqual({ errorMessage: "新版本健康检查失败,已恢复上一版本" });
|
expect(database.sqlite.prepare("SELECT error_message AS errorMessage FROM update_jobs WHERE id=?").get(defaultJobId)).toEqual({ errorMessage: "新版本健康检查失败,已恢复上一版本" });
|
||||||
const completedJobId = randomUUID();
|
const completedJobId = randomUUID();
|
||||||
database.sqlite.prepare(`
|
database.sqlite.prepare(`
|
||||||
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
||||||
VALUES (?, 'apply', 'completed', '1.3.0', ?, ?, ?, ?)
|
VALUES (?, 'apply', 'completed', '1.3.1', ?, ?, ?, ?)
|
||||||
`).run(completedJobId, detectPlatform().target, "https://updates.example/" + assetName, now, now);
|
`).run(completedJobId, detectPlatform().target, "https://updates.example/" + assetName, now, now);
|
||||||
finalizeUpdateJob(database.sqlite, completedJobId, "completed");
|
finalizeUpdateJob(database.sqlite, completedJobId, "completed");
|
||||||
expect(database.sqlite.prepare("SELECT COUNT(*) AS count FROM audit_events WHERE action='update.completed' AND target_id=?").get(completedJobId)).toEqual({ count: 0 });
|
expect(database.sqlite.prepare("SELECT COUNT(*) AS count FROM audit_events WHERE action='update.completed' AND target_id=?").get(completedJobId)).toEqual({ count: 0 });
|
||||||
@@ -342,10 +342,10 @@ describe("更新安全工具", () => {
|
|||||||
const applyingId = randomUUID();
|
const applyingId = randomUUID();
|
||||||
const stagedId = randomUUID();
|
const stagedId = randomUUID();
|
||||||
const stagedApplyId = randomUUID();
|
const stagedApplyId = randomUUID();
|
||||||
insert.run(queuedId, "apply", "queued", "1.3.0", "linux-x64", "https://updates.example/queued.tar.gz", staleAt, staleAt);
|
insert.run(queuedId, "apply", "queued", "1.3.1", "linux-x64", "https://updates.example/queued.tar.gz", staleAt, staleAt);
|
||||||
insert.run(applyingId, "apply", "applying", config.appVersion, "linux-x64", "https://updates.example/applying.tar.gz", staleAt, staleAt);
|
insert.run(applyingId, "apply", "applying", config.appVersion, "linux-x64", "https://updates.example/applying.tar.gz", staleAt, staleAt);
|
||||||
insert.run(stagedId, "download", "staged", "1.3.0", "linux-x64", "https://updates.example/staged.tar.gz", staleAt, staleAt);
|
insert.run(stagedId, "download", "staged", "1.3.1", "linux-x64", "https://updates.example/staged.tar.gz", staleAt, staleAt);
|
||||||
insert.run(stagedApplyId, "apply", "staged", "1.3.0", "linux-x64", "https://updates.example/staged-apply.tar.gz", staleAt, staleAt);
|
insert.run(stagedApplyId, "apply", "staged", "1.3.1", "linux-x64", "https://updates.example/staged-apply.tar.gz", staleAt, staleAt);
|
||||||
const now = Date.now();
|
const now = Date.now();
|
||||||
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, now)).toBe(3);
|
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, now)).toBe(3);
|
||||||
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(queuedId)).toEqual({ status: "failed" });
|
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(queuedId)).toEqual({ status: "failed" });
|
||||||
@@ -381,7 +381,7 @@ describe("更新安全工具", () => {
|
|||||||
const jobId = randomUUID();
|
const jobId = randomUUID();
|
||||||
database.sqlite.prepare(`
|
database.sqlite.prepare(`
|
||||||
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
||||||
VALUES (?, 'download', 'downloading', '1.3.0', 'linux-x64', ?, ?, ?)
|
VALUES (?, 'download', 'downloading', '1.3.1', 'linux-x64', ?, ?, ?)
|
||||||
`).run(jobId, "https://updates.example/download.tar.gz", staleAt, staleAt);
|
`).run(jobId, "https://updates.example/download.tar.gz", staleAt, staleAt);
|
||||||
await writeFile(config.updateRequestPath, JSON.stringify({ jobId, operation: "download" }));
|
await writeFile(config.updateRequestPath, JSON.stringify({ jobId, operation: "download" }));
|
||||||
const statePath = path.join(config.installPrefix, ".update-state");
|
const statePath = path.join(config.installPrefix, ".update-state");
|
||||||
@@ -425,7 +425,7 @@ describe("更新安全工具", () => {
|
|||||||
const jobId = randomUUID();
|
const jobId = randomUUID();
|
||||||
database.sqlite.prepare(`
|
database.sqlite.prepare(`
|
||||||
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
||||||
VALUES (?, 'apply', 'queued', '1.3.0', 'linux-x64', ?, ?, ?)
|
VALUES (?, 'apply', 'queued', '1.3.1', 'linux-x64', ?, ?, ?)
|
||||||
`).run(jobId, "https://updates.example/queued.tar.gz", staleAt, staleAt);
|
`).run(jobId, "https://updates.example/queued.tar.gz", staleAt, staleAt);
|
||||||
await writeFile(config.updateRequestPath, JSON.stringify({ jobId, operation: "apply" }));
|
await writeFile(config.updateRequestPath, JSON.stringify({ jobId, operation: "apply" }));
|
||||||
const now = Date.now();
|
const now = Date.now();
|
||||||
@@ -513,17 +513,17 @@ describe("更新元数据缓存", () => {
|
|||||||
prepareDataDirectories(config);
|
prepareDataDirectories(config);
|
||||||
const database = openDatabase(config);
|
const database = openDatabase(config);
|
||||||
const digest = "b".repeat(64);
|
const digest = "b".repeat(64);
|
||||||
const platformAsset = `tallynote-1.3.0-${detectPlatform().target}-glibc.tar.gz`;
|
const platformAsset = `tallynote-1.3.1-${detectPlatform().target}-glibc.tar.gz`;
|
||||||
const sums = `${digest} ${platformAsset}\n`;
|
const sums = `${digest} ${platformAsset}\n`;
|
||||||
const signature = sign(null, Buffer.from(sums), privateKey);
|
const signature = sign(null, Buffer.from(sums), privateKey);
|
||||||
globalThis.fetch = (async (input: string | URL) => input.toString().endsWith("SHA256SUMS.sig")
|
globalThis.fetch = (async (input: string | URL) => input.toString().endsWith("SHA256SUMS.sig")
|
||||||
? new Response(signature)
|
? new Response(signature)
|
||||||
: input.toString().endsWith("SHA256SUMS")
|
: input.toString().endsWith("SHA256SUMS")
|
||||||
? new Response(sums)
|
? new Response(sums)
|
||||||
: new Response(JSON.stringify({ tag_name: "v1.3.0", published_at: "2026-08-28T00:00:00Z", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: "SHA256SUMS.sig", browser_download_url: "https://updates.example/SHA256SUMS.sig" }, { name: platformAsset, browser_download_url: `https://updates.example/${platformAsset}` }] }), { status: 200 })) as typeof fetch;
|
: new Response(JSON.stringify({ tag_name: "v1.3.1", published_at: "2026-08-28T00:00:00Z", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: "SHA256SUMS.sig", browser_download_url: "https://updates.example/SHA256SUMS.sig" }, { name: platformAsset, browser_download_url: `https://updates.example/${platformAsset}` }] }), { status: 200 })) as typeof fetch;
|
||||||
try {
|
try {
|
||||||
const result = await checkForUpdate(database.sqlite, config);
|
const result = await checkForUpdate(database.sqlite, config);
|
||||||
expect(result.latest).toMatchObject({ version: "1.3.0", compatible: true, integrityReady: true, signatureReady: true, isNewer: true });
|
expect(result.latest).toMatchObject({ version: "1.3.1", compatible: true, integrityReady: true, signatureReady: true, isNewer: true });
|
||||||
const cached = database.sqlite.prepare("SELECT value FROM system_settings WHERE key='update.release.v1'").get() as { value: string };
|
const cached = database.sqlite.prepare("SELECT value FROM system_settings WHERE key='update.release.v1'").get() as { value: string };
|
||||||
expect(JSON.parse(cached.value).asset.sha256).toBe(digest);
|
expect(JSON.parse(cached.value).asset.sha256).toBe(digest);
|
||||||
} finally {
|
} finally {
|
||||||
|
|||||||
Reference in New Issue
Block a user