|
|
|
@@ -59,10 +59,10 @@ describe("更新 API", () => {
|
|
|
|
|
|
|
|
|
|
function mockRelease() {
|
|
|
|
|
const digest = "c".repeat(64);
|
|
|
|
|
const asset = `tallynote-1.1.8-${detectPlatform().target}-glibc.tar.gz`;
|
|
|
|
|
const asset = `tallynote-1.1.9-${detectPlatform().target}-glibc.tar.gz`;
|
|
|
|
|
globalThis.fetch = (async (input: string | URL) => input.toString().endsWith("SHA256SUMS")
|
|
|
|
|
? new Response(`${digest} ${asset}\n`, { status: 200 })
|
|
|
|
|
: new Response(JSON.stringify({ tag_name: "v1.1.8", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: asset, browser_download_url: `https://updates.example/${asset}` }] }), { status: 200 })) as typeof fetch;
|
|
|
|
|
: new Response(JSON.stringify({ tag_name: "v1.1.9", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: asset, browser_download_url: `https://updates.example/${asset}` }] }), { status: 200 })) as typeof fetch;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
it("检查 release、创建受保护请求文件并拒绝重复任务", async () => {
|
|
|
|
@@ -70,21 +70,21 @@ describe("更新 API", () => {
|
|
|
|
|
mockRelease();
|
|
|
|
|
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
|
|
|
|
expect(checked.statusCode).toBe(200);
|
|
|
|
|
expect(checked.json().latest).toMatchObject({ version: "1.1.8", compatible: true, integrityReady: true, isNewer: true });
|
|
|
|
|
expect(checked.json().latest).toMatchObject({ version: "1.1.9", compatible: true, integrityReady: true, isNewer: true });
|
|
|
|
|
expect(checked.headers["cache-control"]).toBe("no-store");
|
|
|
|
|
const tooSoon = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
|
|
|
|
expect(tooSoon.statusCode).toBe(429);
|
|
|
|
|
expect(tooSoon.headers["retry-after"]).toBeDefined();
|
|
|
|
|
|
|
|
|
|
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.1.8", confirm: true } });
|
|
|
|
|
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.1.9", confirm: true } });
|
|
|
|
|
expect(applied.statusCode).toBe(202);
|
|
|
|
|
const jobId = applied.json().job.id as string;
|
|
|
|
|
const request = JSON.parse(readFileSync(config.updateRequestPath, "utf8")) as { jobId: string; expectedSha256: string; currentLink: string };
|
|
|
|
|
expect(request).toMatchObject({ jobId, version: "1.1.8", expectedSha256: "c".repeat(64), currentLink: config.currentLink });
|
|
|
|
|
expect(request).toMatchObject({ jobId, version: "1.1.9", expectedSha256: "c".repeat(64), currentLink: config.currentLink });
|
|
|
|
|
expect(statSync(config.updateRequestPath).mode & 0o777).toBe(0o600);
|
|
|
|
|
|
|
|
|
|
mockRelease();
|
|
|
|
|
const duplicate = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.1.8", confirm: true } });
|
|
|
|
|
const duplicate = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.1.9", confirm: true } });
|
|
|
|
|
expect(duplicate.statusCode).toBe(409);
|
|
|
|
|
expect(duplicate.json().error.code).toBe("UPDATE_IN_PROGRESS");
|
|
|
|
|
const status = await app.inject({ method: "GET", url: "/api/update/status", headers: { cookie: session.cookies } });
|
|
|
|
@@ -98,10 +98,10 @@ describe("更新 API", () => {
|
|
|
|
|
mockRelease();
|
|
|
|
|
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
|
|
|
|
expect(checked.statusCode).toBe(200);
|
|
|
|
|
const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.1.8", confirm: true } });
|
|
|
|
|
const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.1.9", confirm: true } });
|
|
|
|
|
expect(downloaded.statusCode).toBe(202);
|
|
|
|
|
const downloadJobId = downloaded.json().job.id as string;
|
|
|
|
|
expect(downloaded.json().job).toMatchObject({ operation: "download", status: "queued", version: "1.1.8" });
|
|
|
|
|
expect(downloaded.json().job).toMatchObject({ operation: "download", status: "queued", version: "1.1.9" });
|
|
|
|
|
const downloadRequest = JSON.parse(readFileSync(config.updateRequestPath, "utf8")) as { jobId: string; operation: string };
|
|
|
|
|
expect(downloadRequest).toMatchObject({ jobId: downloadJobId, operation: "download" });
|
|
|
|
|
expect(database.sqlite.prepare("SELECT operation, status FROM update_jobs WHERE id=?").get(downloadJobId)).toEqual({ operation: "download", status: "queued" });
|
|
|
|
@@ -110,21 +110,21 @@ describe("更新 API", () => {
|
|
|
|
|
const stagedId = randomUUID();
|
|
|
|
|
const now = Date.now();
|
|
|
|
|
database.sqlite.prepare(`INSERT INTO update_jobs(id, admin_id, session_hash, request_id, requested_at, operation, status, version, platform, release_url, asset_name, asset_url, expected_sha256, actual_sha256, download_path, created_at, updated_at) VALUES (?, ?, ?, ?, ?, 'download', 'staged', ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)`)
|
|
|
|
|
.run(stagedId, (await database.sqlite.prepare("SELECT id FROM admins WHERE username=?").get("update-staged") as { id: string }).id, "session", "staged-request", now, "1.1.8", detectPlatform().target, config.updateMetadataUrl, "release.tar.gz", "https://updates.example/release.tar.gz", "c".repeat(64), "c".repeat(64), path.join(config.dataDir, "staged-workspace"), now, now);
|
|
|
|
|
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { jobId: stagedId, version: "1.1.8", confirm: true } });
|
|
|
|
|
.run(stagedId, (await database.sqlite.prepare("SELECT id FROM admins WHERE username=?").get("update-staged") as { id: string }).id, "session", "staged-request", now, "1.1.9", detectPlatform().target, config.updateMetadataUrl, "release.tar.gz", "https://updates.example/release.tar.gz", "c".repeat(64), "c".repeat(64), path.join(config.dataDir, "staged-workspace"), now, now);
|
|
|
|
|
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { jobId: stagedId, version: "1.1.9", confirm: true } });
|
|
|
|
|
expect(applied.statusCode).toBe(202);
|
|
|
|
|
expect(applied.json().job).toMatchObject({ id: stagedId, operation: "apply", status: "staged" });
|
|
|
|
|
expect(database.sqlite.prepare("SELECT operation, status FROM update_jobs WHERE id=?").get(stagedId)).toEqual({ operation: "apply", status: "staged" });
|
|
|
|
|
const applyRequest = JSON.parse(readFileSync(config.updateRequestPath, "utf8")) as { jobId: string; operation: string; assetUrl: string; expectedSha256: string };
|
|
|
|
|
expect(applyRequest).toMatchObject({ jobId: stagedId, operation: "apply", assetUrl: "https://updates.example/release.tar.gz", expectedSha256: "c".repeat(64) });
|
|
|
|
|
const duplicate = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { jobId: stagedId, version: "1.1.8", confirm: true } });
|
|
|
|
|
const duplicate = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { jobId: stagedId, version: "1.1.9", confirm: true } });
|
|
|
|
|
expect(duplicate.statusCode).toBe(409);
|
|
|
|
|
expect(duplicate.json().error.code).toBe("UPDATE_IN_PROGRESS");
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("缺少确认或未启用 systemd 时不接受更新", async () => {
|
|
|
|
|
const session = await login();
|
|
|
|
|
const invalid = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.1.8" } });
|
|
|
|
|
const invalid = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.1.9" } });
|
|
|
|
|
expect(invalid.statusCode).toBe(400);
|
|
|
|
|
process.env.TALLYNOTE_UPDATE_STRATEGY = "disabled";
|
|
|
|
|
const disabledConfig = loadConfig();
|
|
|
|
@@ -137,7 +137,7 @@ describe("更新 API", () => {
|
|
|
|
|
mockRelease();
|
|
|
|
|
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: owner.cookies, "x-csrf-token": owner.csrf }, payload: {} });
|
|
|
|
|
expect(checked.statusCode).toBe(200);
|
|
|
|
|
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: owner.cookies, "x-csrf-token": owner.csrf }, payload: { version: "1.1.8", confirm: true } });
|
|
|
|
|
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: owner.cookies, "x-csrf-token": owner.csrf }, payload: { version: "1.1.9", confirm: true } });
|
|
|
|
|
expect(applied.statusCode).toBe(202);
|
|
|
|
|
const jobId = applied.json().job.id as string;
|
|
|
|
|
database.sqlite.prepare("UPDATE update_jobs SET error_message=? WHERE id=?").run("/var/lib/tallynote/secret-command-output", jobId);
|
|
|
|
@@ -155,7 +155,7 @@ describe("更新 API", () => {
|
|
|
|
|
it("应用前重新校验失败时写入失败审计", async () => {
|
|
|
|
|
const session = await login("update-audit");
|
|
|
|
|
globalThis.fetch = (async () => new Response("upstream unavailable", { status: 503 })) as typeof fetch;
|
|
|
|
|
const response = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.1.8", confirm: true } });
|
|
|
|
|
const response = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.1.9", confirm: true } });
|
|
|
|
|
expect(response.statusCode).toBe(502);
|
|
|
|
|
const audit = database.sqlite.prepare("SELECT outcome FROM audit_events WHERE action='update.apply_requested' ORDER BY id DESC LIMIT 1").get() as { outcome: string } | undefined;
|
|
|
|
|
expect(audit?.outcome).toBe("failure");
|
|
|
|
|