解决登录和oss问题
This commit is contained in:
1 parent
30c2e44dc0
commit
cd007e2f6a
15 files changed
+154
-12
No files matched your search
@@ -5,6 +5,7 @@ def test_oss_settings_are_loaded_from_prefixed_environment(monkeypatch):
|
||||
monkeypatch.setenv("OSS_ACCESS_KEY_ID", "example-access-key-id")
|
||||
monkeypatch.setenv("OSS_ACCESS_KEY_SECRET", "example-access-key-secret")
|
||||
monkeypatch.setenv("OSS_ENDPOINT", "oss-cn-example.aliyuncs.com")
|
||||
monkeypatch.setenv("OSS_PUBLIC_BASE_URL", "https://example-bucket.oss-cn-example.aliyuncs.com")
|
||||
monkeypatch.setenv("OSS_BUCKET_NAME", "example-bucket")
|
||||
|
||||
settings = Settings(_env_file=None)
|
||||
@@ -12,6 +13,7 @@ def test_oss_settings_are_loaded_from_prefixed_environment(monkeypatch):
|
||||
assert settings.oss_access_key_id == "example-access-key-id"
|
||||
assert settings.oss_access_key_secret == "example-access-key-secret"
|
||||
assert settings.oss_endpoint == "oss-cn-example.aliyuncs.com"
|
||||
assert settings.oss_public_base_url == "https://example-bucket.oss-cn-example.aliyuncs.com"
|
||||
assert settings.oss_bucket_name == "example-bucket"
|
||||
|
||||
|
||||
|
||||
@@ -9,3 +9,9 @@ def test_api_compose_forwards_wechat_miniapp_settings_from_host_environment():
|
||||
|
||||
assert "WECHAT_MINIAPP_APPID: ${WECHAT_MINIAPP_APPID:-}" in compose
|
||||
assert "WECHAT_MINIAPP_SECRET: ${WECHAT_MINIAPP_SECRET:-}" in compose
|
||||
|
||||
|
||||
def test_api_compose_forwards_oss_public_base_url_from_host_environment():
|
||||
compose = COMPOSE_PATH.read_text(encoding="utf-8")
|
||||
|
||||
assert "OSS_PUBLIC_BASE_URL: ${OSS_PUBLIC_BASE_URL:-}" in compose
|
||||
@@ -40,6 +40,7 @@ def test_resolve_media_url_only_signs_the_configured_oss_host(monkeypatch):
|
||||
oss_access_key_id="test-access-key",
|
||||
oss_access_key_secret="test-access-secret",
|
||||
oss_endpoint="oss-cn-guangzhou.aliyuncs.com",
|
||||
oss_public_base_url="https://one-feel-ota-data.oss-cn-guangzhou.aliyuncs.com",
|
||||
oss_bucket_name="one-feel-ota-data",
|
||||
),
|
||||
)
|
||||
@@ -55,6 +56,29 @@ def test_resolve_media_url_only_signs_the_configured_oss_host(monkeypatch):
|
||||
assert media_urls.resolve_media_url(external_url) == external_url
|
||||
|
||||
|
||||
def test_resolve_media_url_rewrites_legacy_internal_oss_host_before_signing(monkeypatch):
|
||||
monkeypatch.setattr(
|
||||
media_urls,
|
||||
"get_settings",
|
||||
lambda: SimpleNamespace(
|
||||
oss_access_key_id="test-access-key",
|
||||
oss_access_key_secret="test-access-secret",
|
||||
oss_endpoint="oss-cn-guangzhou-internal.aliyuncs.com",
|
||||
oss_public_base_url="https://one-feel-ota-data.oss-cn-guangzhou.aliyuncs.com",
|
||||
oss_bucket_name="one-feel-ota-data",
|
||||
),
|
||||
)
|
||||
monkeypatch.setattr(media_urls, "time", lambda: 1_800_000_000)
|
||||
legacy_url = "https://one-feel-ota-data.oss-cn-guangzhou-internal.aliyuncs.com/admin/image.webp"
|
||||
|
||||
signed = media_urls.resolve_media_url(legacy_url)
|
||||
parsed = urlsplit(signed)
|
||||
|
||||
assert parsed.netloc == "one-feel-ota-data.oss-cn-guangzhou.aliyuncs.com"
|
||||
assert parsed.path == "/admin/image.webp"
|
||||
assert parse_qs(parsed.query)["OSSAccessKeyId"] == ["test-access-key"]
|
||||
|
||||
|
||||
def test_resolve_media_fields_signs_common_image_fields(monkeypatch):
|
||||
monkeypatch.setattr(
|
||||
"app.serializers.resolve_media_url",
|
||||
|
||||
@@ -0,0 +1,58 @@
|
||||
from io import BytesIO
|
||||
from types import SimpleNamespace
|
||||
|
||||
from app.routers import admin as admin_router
|
||||
|
||||
|
||||
class FakeOssResponse:
|
||||
status = 200
|
||||
|
||||
def read(self, _size: int) -> bytes:
|
||||
return b""
|
||||
|
||||
|
||||
class FakeOssConnection:
|
||||
instances: list["FakeOssConnection"] = []
|
||||
|
||||
def __init__(self, host: str, timeout: int):
|
||||
self.host = host
|
||||
self.timeout = timeout
|
||||
self.request_path: str | None = None
|
||||
self.__class__.instances.append(self)
|
||||
|
||||
def request(self, _method, path, **_kwargs) -> None:
|
||||
self.request_path = path
|
||||
|
||||
def getresponse(self) -> FakeOssResponse:
|
||||
return FakeOssResponse()
|
||||
|
||||
def close(self) -> None:
|
||||
pass
|
||||
|
||||
|
||||
def test_upload_uses_internal_endpoint_but_returns_public_url(monkeypatch):
|
||||
FakeOssConnection.instances.clear()
|
||||
monkeypatch.setattr(
|
||||
admin_router,
|
||||
"oss_settings",
|
||||
lambda: SimpleNamespace(
|
||||
oss_access_key_id="test-access-key",
|
||||
oss_access_key_secret="test-access-secret",
|
||||
oss_endpoint="oss-cn-guangzhou-internal.aliyuncs.com",
|
||||
oss_public_base_url="https://one-feel-ota-data.oss-cn-guangzhou.aliyuncs.com",
|
||||
oss_bucket_name="one-feel-ota-data",
|
||||
),
|
||||
)
|
||||
monkeypatch.setattr(admin_router.http.client, "HTTPSConnection", FakeOssConnection)
|
||||
|
||||
url = admin_router.upload_image_to_oss(
|
||||
BytesIO(b"image"),
|
||||
"admin/general/image.webp",
|
||||
"image/webp",
|
||||
5,
|
||||
)
|
||||
|
||||
connection = FakeOssConnection.instances[0]
|
||||
assert connection.host == "one-feel-ota-data.oss-cn-guangzhou-internal.aliyuncs.com"
|
||||
assert connection.request_path == "/admin/general/image.webp"
|
||||
assert url == "https://one-feel-ota-data.oss-cn-guangzhou.aliyuncs.com/admin/general/image.webp"
|
||||
@@ -0,0 +1,14 @@
|
||||
from redis.cluster import key_slot
|
||||
|
||||
from app.redis_session import RedisAdminSessionStore, hash_refresh_token
|
||||
|
||||
|
||||
def test_redis_session_rotation_keys_share_cluster_slot():
|
||||
store = RedisAdminSessionStore.__new__(RedisAdminSessionStore)
|
||||
keys = [
|
||||
store._session_key("session-1"),
|
||||
store._refresh_key(hash_refresh_token("refresh-1")),
|
||||
store._refresh_key(hash_refresh_token("refresh-2")),
|
||||
]
|
||||
|
||||
assert len({key_slot(key.encode("utf-8")) for key in keys}) == 1
|
||||
Reference in new issue
Block a user