mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-09-28 20:56:42 +08:00
12d51d7195
Most tests opened a throwaway panel DB with database.InitDB, which runs the full AutoMigrate + seed on an empty file every time: ~230ms, and ~850ms under -race because GORM's reflection-heavy migration is what the detector slows most. internal/web/service does this in ~550 of its 830 tests, so the CI race job spent ~10 of its ~14.6 minutes re-migrating empty databases. internal/database/dbtest.InitDB migrates once per test process, then hands each test its own copy of that file (~130ms under -race) and registers the CloseDB cleanup. The copy then goes through InitDB like a panel restart, so every test still starts from the state a fresh install has. Tests that reopen an existing file, migrate a hand-built legacy DB or target Postgres keep calling database.InitDB. Locally under -race: internal/web/service 626s (last CI run) -> 114s, internal/sub 246s -> 35s.
92 lines
3.1 KiB
Go
92 lines
3.1 KiB
Go
package controller
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"net/url"
|
|
"path/filepath"
|
|
"strconv"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/gin-gonic/gin"
|
|
|
|
"github.com/mhsanaei/3x-ui/v3/internal/database"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/database/dbtest"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/database/model"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/util/crypto"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/web/runtime"
|
|
)
|
|
|
|
// A sub-node stores whatever the master pushes. A master row whose certificate
|
|
// predates the TLS guard must still land, or the node silently falls out of sync.
|
|
func TestNodeSyncPushSkipsOperatorTLSGuard(t *testing.T) {
|
|
gin.SetMode(gin.TestMode)
|
|
dbDir := t.TempDir()
|
|
t.Setenv("XUI_DB_FOLDER", dbDir)
|
|
dbtest.InitDB(t, filepath.Join(dbDir, "x-ui.db"))
|
|
prev := runtime.GetManager()
|
|
runtime.SetManager(runtime.NewManager(runtime.LocalDeps{APIPort: func() int { return 0 }, SetNeedRestart: func() {}}))
|
|
t.Cleanup(func() { runtime.SetManager(prev) })
|
|
|
|
for name, scope := range map[string]string{"node-sync": model.ApiScopeNodeSync, "admin": model.ApiScopeAdmin} {
|
|
row := &model.ApiToken{Name: name, Token: crypto.HashTokenSHA256(name + "-token"), Enabled: true, Scope: scope}
|
|
if err := database.GetDB().Create(row).Error; err != nil {
|
|
t.Fatalf("seed %s token: %v", name, err)
|
|
}
|
|
}
|
|
|
|
engine := gin.New()
|
|
a := &APIController{}
|
|
api := engine.Group("/panel/api")
|
|
api.Use(a.checkAPIAuth, a.enforceTokenScope)
|
|
NewInboundController(api.Group("/inbounds"))
|
|
|
|
const legacyStream = `{"network":"tcp","security":"tls","tlsSettings":{"certificates":[{"certificateFile":"","keyFile":"","certificate":[],"key":[]}]}}`
|
|
add := func(t *testing.T, token string, port int) string {
|
|
t.Helper()
|
|
form := url.Values{
|
|
"protocol": {"vless"},
|
|
"port": {strconv.Itoa(port)},
|
|
"tag": {"tls-legacy-" + strconv.Itoa(port)},
|
|
"enable": {"true"},
|
|
"settings": {`{"clients":[]}`},
|
|
"streamSettings": {legacyStream},
|
|
}
|
|
req := httptest.NewRequest(http.MethodPost, "/panel/api/inbounds/add", strings.NewReader(form.Encode()))
|
|
req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
|
|
req.Header.Set("Authorization", "Bearer "+token)
|
|
w := httptest.NewRecorder()
|
|
engine.ServeHTTP(w, req)
|
|
return w.Body.String()
|
|
}
|
|
rows := func(t *testing.T, tag string) int64 {
|
|
t.Helper()
|
|
var n int64
|
|
if err := database.GetDB().Model(&model.Inbound{}).Where("tag = ?", tag).Count(&n).Error; err != nil {
|
|
t.Fatalf("count %s: %v", tag, err)
|
|
}
|
|
return n
|
|
}
|
|
|
|
t.Run("a master push lands on the node", func(t *testing.T) {
|
|
body := add(t, "node-sync-token", 45001)
|
|
if !strings.Contains(body, `"success":true`) {
|
|
t.Fatalf("node-sync add rejected: %s", body)
|
|
}
|
|
if got := rows(t, "tls-legacy-45001"); got != 1 {
|
|
t.Fatalf("stored rows = %d, want 1", got)
|
|
}
|
|
})
|
|
|
|
t.Run("an operator token is still held to the guard", func(t *testing.T) {
|
|
body := add(t, "admin-token", 45002)
|
|
if !strings.Contains(body, `"success":false`) || !strings.Contains(body, "TLS") {
|
|
t.Fatalf("admin add should fail on TLS, got: %s", body)
|
|
}
|
|
if got := rows(t, "tls-legacy-45002"); got != 0 {
|
|
t.Fatalf("stored rows = %d, want 0", got)
|
|
}
|
|
})
|
|
}
|