chore: initialize standalone business plugin repository
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
import { chromium } from 'playwright'
|
||||
import fs from 'node:fs/promises'
|
||||
import path from 'node:path'
|
||||
|
||||
const origin = process.env.PLUGIN_BROWSER_ORIGIN || 'http://127.0.0.1:18090'
|
||||
const entry = `${origin}/admin/`
|
||||
const outputDir = path.resolve(process.env.PLUGIN_SCREENSHOT_DIR || '.playwright-cli/plugin-admin')
|
||||
const email = process.env.PLUGIN_TEST_EMAIL || 'admin@example.com'
|
||||
const password = process.env.PLUGIN_TEST_PASSWORD || 'password'
|
||||
|
||||
await fs.mkdir(outputDir, { recursive: true })
|
||||
const browser = await chromium.launch({ headless: true })
|
||||
try {
|
||||
for (const width of [425, 900, 1440]) {
|
||||
const page = await browser.newPage({ viewport: { width, height: 900 }, deviceScaleFactor: 1 })
|
||||
const responseLeaks = []
|
||||
page.on('response', async (response) => {
|
||||
if (!response.headers()['content-type']?.includes('application/json')) return
|
||||
try {
|
||||
const body = await response.text()
|
||||
if (/access_token|refresh_token|admin[_-]?api[_-]?key|password|client_secret/i.test(body)) responseLeaks.push(response.url())
|
||||
} catch (_) {}
|
||||
})
|
||||
await page.goto(entry, { waitUntil: 'networkidle' })
|
||||
await page.getByLabel('邮箱').fill(email)
|
||||
await page.getByLabel('密码').fill(password)
|
||||
await page.getByRole('button', { name: '登录' }).click()
|
||||
await page.getByRole('heading', { name: '已登记插件' }).waitFor()
|
||||
const overflow = await page.evaluate(() => document.documentElement.scrollWidth > window.innerWidth)
|
||||
if (overflow) throw new Error(`horizontal overflow at ${width}px`)
|
||||
const buttons = await page.locator('button, .file-button').evaluateAll((items) => items.filter((item) => item.getClientRects().length > 0 && getComputedStyle(item).visibility !== 'hidden').every((item) => item.getBoundingClientRect().height >= 28 && item.getBoundingClientRect().width >= 28))
|
||||
if (!buttons) throw new Error(`control collapsed at ${width}px`)
|
||||
await page.waitForTimeout(50)
|
||||
if (responseLeaks.length) throw new Error(`sensitive response field exposed at ${width}px: ${responseLeaks.join(', ')}`)
|
||||
await page.screenshot({ path: path.join(outputDir, `plugin-admin-${width}.png`), fullPage: true })
|
||||
await page.close()
|
||||
}
|
||||
} finally {
|
||||
await browser.close()
|
||||
}
|
||||
+7
@@ -0,0 +1,7 @@
|
||||
#!/usr/bin/env sh
|
||||
set -eu
|
||||
|
||||
ROOT=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd)
|
||||
PLUGIN_BROWSER_ORIGIN=${PLUGIN_BROWSER_ORIGIN:-http://127.0.0.1:18090} \
|
||||
PLUGIN_SCREENSHOT_DIR=${PLUGIN_SCREENSHOT_DIR:-$ROOT/.screenshots/plugin-admin} \
|
||||
node "$ROOT/test/browser-check.mjs"
|
||||
Reference in New Issue
Block a user