This commit is contained in:
@@ -176,6 +176,42 @@ describe("更新 API", () => {
|
||||
expect(ownDetail.json().job.errorMessage).toBe("更新失败,请查看服务器日志或重试");
|
||||
});
|
||||
|
||||
it("取消任务按管理员隔离,并只删除匹配任务的请求文件", async () => {
|
||||
const owner = await login("cancel-owner");
|
||||
const other = await login("cancel-other");
|
||||
const ownerId = (database.sqlite.prepare("SELECT id FROM admins WHERE username=?").get("cancel-owner") as { id: string }).id;
|
||||
const otherId = (database.sqlite.prepare("SELECT id FROM admins WHERE username=?").get("cancel-other") as { id: string }).id;
|
||||
const now = Date.now();
|
||||
const ownerJobId = randomUUID();
|
||||
const otherJobId = randomUUID();
|
||||
const insert = database.sqlite.prepare(`
|
||||
INSERT INTO update_jobs(id, admin_id, operation, status, version, platform, asset_url, created_at, updated_at)
|
||||
VALUES (?, ?, 'download', 'queued', '1.3.0', ?, 'https://updates.example/update.tar.gz', ?, ?)
|
||||
`);
|
||||
insert.run(ownerJobId, ownerId, detectPlatform().target, now, now);
|
||||
insert.run(otherJobId, otherId, detectPlatform().target, now + 1, now + 1);
|
||||
await import("node:fs/promises").then(({ writeFile }) => writeFile(config.updateRequestPath, JSON.stringify({ jobId: otherJobId }), { encoding: "utf8", mode: 0o600 }));
|
||||
|
||||
const ownerCancel = await app.inject({
|
||||
method: "POST", url: "/api/update/cancel",
|
||||
headers: { origin: config.publicOrigin, cookie: owner.cookies, "x-csrf-token": owner.csrf },
|
||||
payload: { jobId: ownerJobId },
|
||||
});
|
||||
expect(ownerCancel.statusCode).toBe(200);
|
||||
expect((database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(ownerJobId) as { status: string }).status).toBe("cancelled");
|
||||
expect((database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(otherJobId) as { status: string }).status).toBe("queued");
|
||||
expect(existsSync(config.updateRequestPath)).toBe(true);
|
||||
|
||||
const otherCancel = await app.inject({
|
||||
method: "POST", url: "/api/update/cancel",
|
||||
headers: { origin: config.publicOrigin, cookie: other.cookies, "x-csrf-token": other.csrf },
|
||||
payload: {},
|
||||
});
|
||||
expect(otherCancel.statusCode).toBe(200);
|
||||
expect((database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(otherJobId) as { status: string }).status).toBe("cancelled");
|
||||
expect(existsSync(config.updateRequestPath)).toBe(false);
|
||||
});
|
||||
|
||||
it("应用前重新校验失败时写入失败审计", async () => {
|
||||
const session = await login("update-audit");
|
||||
globalThis.fetch = (async () => new Response("upstream unavailable", { status: 503 })) as typeof fetch;
|
||||
|
||||
+28
-7
@@ -286,8 +286,27 @@ describe("更新安全工具", () => {
|
||||
expect(await readFile(path.join(config.currentLink, "dist", "marker"), "utf8")).toBe("new");
|
||||
const row = database.sqlite.prepare("SELECT operation, status FROM update_jobs WHERE id=?").get(jobId);
|
||||
expect(row).toEqual({ operation: "apply", status: "applying" });
|
||||
finalizeUpdateJob(database.sqlite, jobId, "failed");
|
||||
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "failed" });
|
||||
finalizeUpdateJob(database.sqlite, jobId, "failed", "健康检查失败(自定义)");
|
||||
expect(database.sqlite.prepare("SELECT status, error_message AS errorMessage FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "failed", errorMessage: "健康检查失败(自定义)" });
|
||||
finalizeUpdateJob(database.sqlite, jobId, "failed", "第二次 finalize 不应覆盖原消息");
|
||||
expect(database.sqlite.prepare("SELECT status, error_message AS errorMessage FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "failed", errorMessage: "健康检查失败(自定义)" });
|
||||
expect(database.sqlite.prepare("SELECT COUNT(*) AS count FROM audit_events WHERE action='update.failed' AND target_id=?").get(jobId)).toEqual({ count: 1 });
|
||||
const defaultJobId = randomUUID();
|
||||
database.sqlite.prepare(`
|
||||
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
||||
VALUES (?, 'apply', 'applying', '1.3.0', ?, ?, ?, ?)
|
||||
`).run(defaultJobId, detectPlatform().target, "https://updates.example/" + assetName, now, now);
|
||||
finalizeUpdateJob(database.sqlite, defaultJobId, "failed", "");
|
||||
expect(database.sqlite.prepare("SELECT error_message AS errorMessage FROM update_jobs WHERE id=?").get(defaultJobId)).toEqual({ errorMessage: "新版本健康检查失败,已恢复上一版本" });
|
||||
const completedJobId = randomUUID();
|
||||
database.sqlite.prepare(`
|
||||
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
||||
VALUES (?, 'apply', 'completed', '1.3.0', ?, ?, ?, ?)
|
||||
`).run(completedJobId, detectPlatform().target, "https://updates.example/" + assetName, now, now);
|
||||
finalizeUpdateJob(database.sqlite, completedJobId, "completed");
|
||||
expect(database.sqlite.prepare("SELECT COUNT(*) AS count FROM audit_events WHERE action='update.completed' AND target_id=?").get(completedJobId)).toEqual({ count: 0 });
|
||||
expect(() => finalizeUpdateJob(database.sqlite, completedJobId, "failed", "不能降级已完成任务")).toThrow("更新任务状态不允许完成");
|
||||
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(completedJobId)).toEqual({ status: "completed" });
|
||||
} finally {
|
||||
globalThis.fetch = previousFetch;
|
||||
if (database) database.sqlite.close();
|
||||
@@ -385,7 +404,7 @@ describe("更新安全工具", () => {
|
||||
}
|
||||
});
|
||||
|
||||
it("队列任务有新请求标记时可被重新检查,标记过期后才回收", async () => {
|
||||
it("队列任务有匹配请求标记时保留到租约过期,过期后才回收", async () => {
|
||||
const root = await mkdtemp(path.join(tmpdir(), "tallynote-update-queued-marker-"));
|
||||
let database: ReturnType<typeof openDatabase> | undefined;
|
||||
try {
|
||||
@@ -412,12 +431,14 @@ describe("更新安全工具", () => {
|
||||
const now = Date.now();
|
||||
await utimes(config.updateRequestPath, new Date(now), new Date(now));
|
||||
|
||||
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, now)).toBe(1);
|
||||
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "failed" });
|
||||
await expect(stat(config.updateRequestPath)).rejects.toThrow();
|
||||
// The DB row is old, but the request marker is fresh and names this
|
||||
// exact job. Keep it queued while systemd has a chance to consume it.
|
||||
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, now)).toBe(0);
|
||||
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "queued" });
|
||||
await expect(stat(config.updateRequestPath)).resolves.toBeTruthy();
|
||||
|
||||
const expiredNow = now + ORPHANED_UPDATE_TIMEOUT_MS + 1;
|
||||
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, expiredNow)).toBe(0);
|
||||
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, expiredNow)).toBe(1);
|
||||
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "failed" });
|
||||
await expect(stat(config.updateRequestPath)).rejects.toThrow();
|
||||
} finally {
|
||||
|
||||
Reference in New Issue
Block a user