增加日志与退出时404问题处理
This commit is contained in:
1 parent
2a2f78c81e
commit
648b274c55
7 files changed
+226
-2
No files matched your search
@@ -4,7 +4,10 @@ import (
|
||||
"bytes"
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"io"
|
||||
"log"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
@@ -93,3 +96,61 @@ func TestOSSRejectsUnsafeKeysAndIncompleteConfiguration(t *testing.T) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestOSSOperationDiagnosticIncludesStageAndSafeServiceError(t *testing.T) {
|
||||
diagnostic := diagnoseOSSOperation("set_acl", &OSSError{
|
||||
Status: 403,
|
||||
Code: "AccessDenied",
|
||||
Err: errors.New("private-key private-object secret response"),
|
||||
})
|
||||
if diagnostic.Operation != "set_acl" || diagnostic.Status != 403 || diagnostic.Code != "AccessDenied" || diagnostic.ErrorClass != "service" {
|
||||
t.Fatalf("diagnostic = %#v", diagnostic)
|
||||
}
|
||||
serialized := fmt.Sprintf("%+v", diagnostic)
|
||||
for _, secret := range []string{"private-key", "private-object", "secret response"} {
|
||||
if strings.Contains(serialized, secret) {
|
||||
t.Fatalf("diagnostic leaks %q: %s", secret, serialized)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestOSSPutFailureLogsStageWithoutSensitiveDetails(t *testing.T) {
|
||||
var output bytes.Buffer
|
||||
previousOutput, previousFlags := log.Writer(), log.Flags()
|
||||
log.SetOutput(&output)
|
||||
log.SetFlags(0)
|
||||
t.Cleanup(func() {
|
||||
log.SetOutput(previousOutput)
|
||||
log.SetFlags(previousFlags)
|
||||
})
|
||||
|
||||
client := &ossClientStub{errorToReturn: &OSSError{
|
||||
Status: 403,
|
||||
Code: "AccessDenied",
|
||||
Err: errors.New("access-key private-object secret response"),
|
||||
}}
|
||||
store, err := NewOSS(OSSConfig{
|
||||
Endpoint: "https://oss-cn-guangzhou.aliyuncs.com",
|
||||
Bucket: "private-bucket",
|
||||
PublicBaseURL: "https://private-bucket.oss-cn-guangzhou.aliyuncs.com",
|
||||
PublicRead: true,
|
||||
}, client)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err = store.Put(context.Background(), "uploads/private-file.png", bytes.NewReader([]byte("png")), 3, "image/png"); err == nil {
|
||||
t.Fatal("Put error = nil")
|
||||
}
|
||||
|
||||
got := output.String()
|
||||
for _, expected := range []string{"operation=put", "status=403", `code="AccessDenied"`, "errorClass=service"} {
|
||||
if !strings.Contains(got, expected) {
|
||||
t.Fatalf("log %q does not contain %q", got, expected)
|
||||
}
|
||||
}
|
||||
for _, secret := range []string{"access-key", "private-object", "secret response", "private-bucket", "private-file"} {
|
||||
if strings.Contains(got, secret) {
|
||||
t.Fatalf("log leaks %q: %s", secret, got)
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user