You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
54 lines
2.0 KiB
54 lines
2.0 KiB
package console
|
|
|
|
import "testing"
|
|
|
|
// 分发桶是公共读、直接挂在 dl.ymaikj.com 上的,key 拼错就等于把它变成公开网盘,
|
|
// 所以每条边界都钉在测试里。
|
|
func TestBuildDistObjectKey(t *testing.T) {
|
|
ok := map[string][3]string{
|
|
"正常": {"EAIMAR", "android", "eaimar-release-1.0.2-20260923.apk"},
|
|
"目录带斜杠": {"EAIMAR", "/android/", "a.apk"},
|
|
"文件名夹带目录": {"EAIMAR", "android", "../../etc/passwd"},
|
|
"另一个应用": {"deepGlass", "android", "a.apk"},
|
|
"应用名带斜杠": {"a/../b", "android", "a.apk"},
|
|
}
|
|
want := map[string]string{
|
|
"正常": "android/EAIMAR/eaimar-release-1.0.2-20260923.apk",
|
|
"目录带斜杠": "android/EAIMAR/a.apk",
|
|
"文件名夹带目录": "android/EAIMAR/passwd",
|
|
"另一个应用": "android/deepGlass/a.apk",
|
|
"应用名带斜杠": "android/a____b/a.apk",
|
|
}
|
|
for name, in := range ok {
|
|
got, err := buildDistObjectKey(in[0], in[1], in[2])
|
|
if err != nil {
|
|
t.Errorf("%s: 本该通过,却报错 %v", name, err)
|
|
continue
|
|
}
|
|
if got != want[name] {
|
|
t.Errorf("%s: 期望 %q,得到 %q", name, want[name], got)
|
|
}
|
|
}
|
|
|
|
bad := map[string][3]string{
|
|
"没选应用": {"", "android", "a.apk"},
|
|
"应用名全是非法字符": {"//", "android", "a.apk"},
|
|
"目录为空": {"EAIMAR", "", "a.apk"},
|
|
"目录不在白名单": {"EAIMAR", "anything", "a.apk"},
|
|
"用 .. 跳出去": {"EAIMAR", "android/../secret", "a.apk"},
|
|
"绝对路径跳根": {"EAIMAR", "/../../", "a.apk"},
|
|
"文件名为空": {"EAIMAR", "android", " "},
|
|
}
|
|
for name, in := range bad {
|
|
if got, err := buildDistObjectKey(in[0], in[1], in[2]); err == nil {
|
|
t.Errorf("%s: 本该被拒,却得到 %q", name, got)
|
|
}
|
|
}
|
|
}
|
|
|
|
// apk 的 Content-Type 必须由服务端强制:它计入预签名,签错了要等真机装包才发现。
|
|
func TestDistContentTypeForced(t *testing.T) {
|
|
if distContentTypes[".apk"] != "application/vnd.android.package-archive" {
|
|
t.Fatalf("apk 的 Content-Type 不对: %q", distContentTypes[".apk"])
|
|
}
|
|
}
|
|
|