Struktura podle zasad: rozdeleni souboru, lint, testy, prisny TypeScript
Projekt srovnan se zasadami v D:\GitHubRepository\CLAUDE.md bez zmeny chovani.
Struktura: scripts/ (skripty konektoru) -> connectors/, src/scripts ->
src/runtime/scripts; src/index.ts jen startuje, novy src/app.ts s createApp();
routes/dashboard.ts a routes/settings.ts rozdeleny do slozek; openapi.ts
rozdelen na openapi/{index,helpers,components} a paths/* (98 cest overeno
shodnych); ticketStore, automationStore a services jsou fasady nad slozkami
data/tickets, data/automations a data/services/catalog. process.env se cte
jen v config.ts. Web: hooky v hooks/, sdilena ui/Table a ui/ServiceIcon,
surove inputy nahrazeny komponentami, sedm velkych souboru rozdeleno.
Nastroje: eslint (typescript-eslint, react-hooks v7), prettier, editorconfig,
nvmrc, .env.example, vitest; skripty lint, format, test. Lint je cisty bez
jedineho eslint-disable (nove hooky useLatest a useSyncFromSource, odvozeny
stav misto setState v effectu). noUncheckedIndexedAccess v obou tsconfig,
84 mist zuzeno bez non-null operatoru; odhalilo zalohu backoffu fronty pri
nule pokusu a Retry-After NaN pri max 0. Cely kod naformatovan prettierem.
Testy: 8 souboru, 105 testu (prava, viditelnost, podminky a opakovani
v executoru, redaktor tajemstvi, sitove guardy, migrace resitelu, tickety,
health a prihlaseni pres supertest). Testy odhalily dve chyby ve vyhodnoceni
podminek, obe opravene: chybejici castka se porovnavala jako nula a podminka
nad vystupem druheho kroku cetla hodnotu prvniho se stejnym nazvem.
Pojmenovane konstanty misto magickych hodnot, ctx.util.base64 pro skripty
konektoru, README a dokumentace aktualizovany vcetne znamych odchylek.
This commit is contained in:
@@ -0,0 +1,114 @@
|
||||
/**
|
||||
* Zabrana proti volani dovnitr site a cteni tela s limitem (src/net/guard.ts).
|
||||
* `ALLOW_PRIVATE_TARGETS` je v testech vypnuty (tests/setup.ts).
|
||||
*/
|
||||
|
||||
import { describe, expect, test } from 'vitest';
|
||||
import {
|
||||
isPrivateHost,
|
||||
readBodyLimited,
|
||||
readJsonLimited,
|
||||
urlProblem,
|
||||
} from '../../src/net/guard.js';
|
||||
|
||||
describe('urlProblem', () => {
|
||||
test('verejna adresa pres http(s) projde', () => {
|
||||
expect(urlProblem(new URL('https://api.example.cz/v1'))).toBeNull();
|
||||
expect(urlProblem(new URL('http://example.cz:8080/'))).toBeNull();
|
||||
});
|
||||
|
||||
test('jiny protokol nez http(s) se odmitne', () => {
|
||||
expect(urlProblem(new URL('ftp://example.cz/'))).toContain('ftp:');
|
||||
expect(urlProblem(new URL('file:///etc/passwd'))).toContain('file:');
|
||||
});
|
||||
|
||||
test.each([
|
||||
'http://localhost:3000/',
|
||||
'http://127.0.0.1/',
|
||||
'http://10.1.2.3/',
|
||||
'http://192.168.1.10/',
|
||||
'http://172.16.0.1/',
|
||||
'http://172.31.255.1/',
|
||||
'http://169.254.169.254/latest/meta-data',
|
||||
'http://[::1]:8080/',
|
||||
'http://0.0.0.0/',
|
||||
])('adresa do vnitrni site se odmitne: %s', (address) => {
|
||||
const problem = urlProblem(new URL(address));
|
||||
expect(problem).not.toBeNull();
|
||||
expect(problem).toContain('vnitřní sítě');
|
||||
});
|
||||
|
||||
test('172.32.x a 11.x uz privatni nejsou', () => {
|
||||
expect(isPrivateHost('172.32.0.1')).toBe(false);
|
||||
expect(isPrivateHost('11.0.0.1')).toBe(false);
|
||||
expect(isPrivateHost('LOCALHOST')).toBe(true);
|
||||
});
|
||||
});
|
||||
|
||||
/** Odpoved, ktera prijde po kouscich. `chunks` jsou texty za sebou. */
|
||||
function streamed(chunks: string[], headers: Record<string, string> = {}): Response {
|
||||
const encoder = new TextEncoder();
|
||||
let index = 0;
|
||||
const body = new ReadableStream<Uint8Array>({
|
||||
pull(controller) {
|
||||
const chunk = chunks[index];
|
||||
if (chunk === undefined) {
|
||||
controller.close();
|
||||
return;
|
||||
}
|
||||
controller.enqueue(encoder.encode(chunk));
|
||||
index += 1;
|
||||
},
|
||||
});
|
||||
return new Response(body, { headers });
|
||||
}
|
||||
|
||||
describe('readBodyLimited', () => {
|
||||
test('telo v limitu se precte cele', async () => {
|
||||
const result = await readBodyLimited(streamed(['ab', 'cd', 'ef']), 100);
|
||||
expect(result).toEqual({ text: 'abcdef', tooLarge: false });
|
||||
});
|
||||
|
||||
test('cteni se zastavi na limitu a text je neuplny', async () => {
|
||||
const result = await readBodyLimited(streamed(['1234', '5678', '9012']), 6);
|
||||
expect(result.tooLarge).toBe(true);
|
||||
// Prvni kousek prosel, druhy uz limit prekrocil a nepripojil se.
|
||||
expect(result.text).toBe('1234');
|
||||
});
|
||||
|
||||
test('deklarovana delka nad limitem se ani nezacne cist', async () => {
|
||||
const result = await readBodyLimited(streamed(['abc'], { 'content-length': '5000' }), 10);
|
||||
expect(result).toEqual({ text: '', tooLarge: true });
|
||||
});
|
||||
|
||||
test('vicebajtove znaky rozdelene mezi kousky se slozi spravne', async () => {
|
||||
const bytes = new TextEncoder().encode('příliš');
|
||||
const body = new ReadableStream<Uint8Array>({
|
||||
start(controller) {
|
||||
controller.enqueue(bytes.slice(0, 3));
|
||||
controller.enqueue(bytes.slice(3));
|
||||
controller.close();
|
||||
},
|
||||
});
|
||||
const result = await readBodyLimited(new Response(body), 100);
|
||||
expect(result.text).toBe('příliš');
|
||||
});
|
||||
|
||||
test('odpoved bez tela je prazdna a v limitu', async () => {
|
||||
const result = await readBodyLimited(new Response(null), 10);
|
||||
expect(result).toEqual({ text: '', tooLarge: false });
|
||||
});
|
||||
});
|
||||
|
||||
describe('readJsonLimited', () => {
|
||||
test('platny JSON, prazdne telo, rozbity JSON a telo nad limitem', async () => {
|
||||
expect(await readJsonLimited(streamed(['{"a":', '1}']), 100)).toEqual({
|
||||
tooLarge: false,
|
||||
text: '{"a":1}',
|
||||
json: { a: 1 },
|
||||
});
|
||||
expect((await readJsonLimited(streamed([' ']), 100)).json).toBeNull();
|
||||
expect((await readJsonLimited(streamed(['{oops']), 100)).json).toBeUndefined();
|
||||
expect((await readJsonLimited(streamed(['{"a":1}']), 3)).tooLarge).toBe(true);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user