mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-08-10 05:10:58 +00:00
f4b7b08e08
FetchVlessFlags returns (empty map, nil) whenever the bind succeeds but the search yields nothing usable — a renamed OU, a service account that lost read on the user attribute, a filter that stopped matching. The only guard on the destructive half of the sync was `err != nil`, so that answer was read as "every user is gone" and the job detached every client from the configured inbounds, once a minute, for as long as the directory stayed broken. Gate auto-delete behind autoDeleteSafeForFetch: refuse an empty fetch, and refuse one that collapsed below half of the last successful sync, which is a misconfigured directory far more often than real churn. Also stop splitCsv from defaulting an empty string to DefaultTruthyValues. That default belongs to the truthy-value setting, but splitCsv is also what parses ldapInboundTags, so an unconfigured tag list silently resolved to ["true","1","yes","on"]. It only ever bounded the blast radius by accident.
35 lines
1.1 KiB
Go
35 lines
1.1 KiB
Go
package job
|
|
|
|
import "testing"
|
|
|
|
// A bind that succeeds with an unusable search returns (empty, nil); the only
|
|
// guard was `err != nil`, so that answer detached the entire inbound.
|
|
func TestAutoDeleteAllowed(t *testing.T) {
|
|
cases := []struct {
|
|
name string
|
|
previous int64
|
|
fetched int
|
|
want bool
|
|
}{
|
|
{"empty fetch on a fresh job is refused", 0, 0, false},
|
|
{"empty fetch after a healthy sync is refused", 500, 0, false},
|
|
{"full fetch on a fresh job is allowed", 0, 500, true},
|
|
{"steady fetch is allowed", 500, 500, true},
|
|
{"growth is allowed", 500, 900, true},
|
|
{"shrink above the retention floor is allowed", 500, 250, true},
|
|
{"shrink below the retention floor is refused", 500, 249, false},
|
|
{"collapse to a single user is refused", 500, 1, false},
|
|
{"single user with no history is allowed", 0, 1, true},
|
|
}
|
|
for _, c := range cases {
|
|
t.Run(c.name, func(t *testing.T) {
|
|
j := NewLdapSyncJob()
|
|
j.lastFlagCount.Store(c.previous)
|
|
if got := j.autoDeleteSafeForFetch(c.fetched); got != c.want {
|
|
t.Fatalf("autoDeleteSafeForFetch(previous=%d, fetched=%d) = %v, want %v",
|
|
c.previous, c.fetched, got, c.want)
|
|
}
|
|
})
|
|
}
|
|
}
|