mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-09-30 21:56:41 +08:00
12d51d7195
Most tests opened a throwaway panel DB with database.InitDB, which runs the full AutoMigrate + seed on an empty file every time: ~230ms, and ~850ms under -race because GORM's reflection-heavy migration is what the detector slows most. internal/web/service does this in ~550 of its 830 tests, so the CI race job spent ~10 of its ~14.6 minutes re-migrating empty databases. internal/database/dbtest.InitDB migrates once per test process, then hands each test its own copy of that file (~130ms under -race) and registers the CloseDB cleanup. The copy then goes through InitDB like a panel restart, so every test still starts from the state a fresh install has. Tests that reopen an existing file, migrate a hand-built legacy DB or target Postgres keep calling database.InitDB. Locally under -race: internal/web/service 626s (last CI run) -> 114s, internal/sub 246s -> 35s.
240 lines
7.8 KiB
Go
240 lines
7.8 KiB
Go
package controller
|
|
|
|
import (
|
|
"encoding/json"
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"path/filepath"
|
|
"strconv"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/gin-gonic/gin"
|
|
|
|
"github.com/mhsanaei/3x-ui/v3/internal/database"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/database/dbtest"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/database/model"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/util/crypto"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/web/locale"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/web/service"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/web/service/discord"
|
|
)
|
|
|
|
func TestValidateRegex(t *testing.T) {
|
|
gin.SetMode(gin.TestMode)
|
|
router := gin.New()
|
|
NewSettingController(router.Group("/panel/api"))
|
|
|
|
tests := []struct {
|
|
name string
|
|
body string
|
|
success bool
|
|
}{
|
|
{name: "Go RE2 inline flag", body: `{"regex":"(?m)^general-purpose$"}`, success: true},
|
|
{name: "invalid expression", body: `{"regex":"["}`, success: false},
|
|
}
|
|
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
req := httptest.NewRequest(http.MethodPost, "/panel/api/setting/validateRegex", strings.NewReader(tt.body))
|
|
req.Header.Set("Content-Type", "application/json")
|
|
resp := httptest.NewRecorder()
|
|
|
|
router.ServeHTTP(resp, req)
|
|
|
|
if resp.Code != http.StatusOK {
|
|
t.Fatalf("status = %d, want 200; body=%s", resp.Code, resp.Body.String())
|
|
}
|
|
needle := `"success":true`
|
|
if !tt.success {
|
|
needle = `"success":false`
|
|
}
|
|
if !strings.Contains(resp.Body.String(), needle) {
|
|
t.Fatalf("body = %s, want %s", resp.Body.String(), needle)
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
func TestAPITokenMutationRoutesEnforceExpectedScope(t *testing.T) {
|
|
t.Setenv("XUI_DB_FOLDER", t.TempDir())
|
|
dbtest.InitDB(t, filepath.Join(t.TempDir(), "x-ui.db"))
|
|
row := &model.ApiToken{Name: "route-scope", Token: crypto.HashTokenSHA256("token"), Enabled: true, Scope: model.ApiScopeNodeSync}
|
|
if err := database.GetDB().Create(row).Error; err != nil {
|
|
t.Fatalf("seed token: %v", err)
|
|
}
|
|
|
|
gin.SetMode(gin.TestMode)
|
|
router := gin.New()
|
|
NewSettingController(router.Group("/panel/api"))
|
|
for _, path := range []string{
|
|
"/panel/api/setting/apiTokens/delete/" + strconv.Itoa(row.Id),
|
|
"/panel/api/setting/apiTokens/setEnabled/" + strconv.Itoa(row.Id),
|
|
} {
|
|
body := `{"expectedScope":"admin","enabled":false}`
|
|
req := httptest.NewRequest(http.MethodPost, path, strings.NewReader(body))
|
|
req.Header.Set("Content-Type", "application/json")
|
|
resp := httptest.NewRecorder()
|
|
router.ServeHTTP(resp, req)
|
|
if !strings.Contains(resp.Body.String(), `"success":false`) {
|
|
t.Fatalf("%s accepted wrong expected scope: %s", path, resp.Body.String())
|
|
}
|
|
}
|
|
var stored model.ApiToken
|
|
if err := database.GetDB().First(&stored, row.Id).Error; err != nil {
|
|
t.Fatalf("token was deleted by wrong scope: %v", err)
|
|
}
|
|
if !stored.Enabled {
|
|
t.Fatal("token was disabled by wrong scope")
|
|
}
|
|
}
|
|
|
|
// GHSA-xqqw-jqqv-99h6: a save that keeps 2FA enabled must not be able to
|
|
// rebind the authenticator without presenting a current code.
|
|
func TestUpdateSettingRequiresCodeToReplaceTwoFactorToken(t *testing.T) {
|
|
t.Setenv("XUI_DB_FOLDER", t.TempDir())
|
|
dbtest.InitDB(t, filepath.Join(t.TempDir(), "x-ui.db"))
|
|
|
|
settingService := service.SettingService{}
|
|
if err := settingService.SetTwoFactorToken("ORIGINALSECRET234567"); err != nil {
|
|
t.Fatalf("seed token: %v", err)
|
|
}
|
|
if err := settingService.SetTwoFactorEnable(true); err != nil {
|
|
t.Fatalf("seed enable: %v", err)
|
|
}
|
|
|
|
post := func(t *testing.T, mutate func(map[string]any)) string {
|
|
t.Helper()
|
|
base, err := settingService.GetAllSetting()
|
|
if err != nil {
|
|
t.Fatalf("GetAllSetting: %v", err)
|
|
}
|
|
raw, err := json.Marshal(base)
|
|
if err != nil {
|
|
t.Fatalf("marshal: %v", err)
|
|
}
|
|
body := map[string]any{}
|
|
if err := json.Unmarshal(raw, &body); err != nil {
|
|
t.Fatalf("unmarshal: %v", err)
|
|
}
|
|
mutate(body)
|
|
payload, err := json.Marshal(body)
|
|
if err != nil {
|
|
t.Fatalf("marshal payload: %v", err)
|
|
}
|
|
|
|
gin.SetMode(gin.TestMode)
|
|
router := gin.New()
|
|
NewSettingController(router.Group("/panel/api"))
|
|
req := httptest.NewRequest(http.MethodPost, "/panel/api/setting/update", strings.NewReader(string(payload)))
|
|
req.Header.Set("Content-Type", "application/json")
|
|
resp := httptest.NewRecorder()
|
|
router.ServeHTTP(resp, req)
|
|
return resp.Body.String()
|
|
}
|
|
|
|
t.Run("rebind without code is rejected", func(t *testing.T) {
|
|
got := post(t, func(body map[string]any) {
|
|
body["twoFactorEnable"] = true
|
|
body["twoFactorToken"] = "ATTACKERSECRET567890"
|
|
})
|
|
if !strings.Contains(got, `"success":false`) {
|
|
t.Fatalf("rebind without a 2FA code was accepted: %s", got)
|
|
}
|
|
stored, err := settingService.GetTwoFactorToken()
|
|
if err != nil {
|
|
t.Fatalf("GetTwoFactorToken: %v", err)
|
|
}
|
|
if stored != "ORIGINALSECRET234567" {
|
|
t.Fatalf("stored 2FA secret = %q, want it unchanged", stored)
|
|
}
|
|
})
|
|
|
|
t.Run("ordinary save with redacted token still succeeds", func(t *testing.T) {
|
|
got := post(t, func(body map[string]any) {
|
|
body["twoFactorEnable"] = true
|
|
body["twoFactorToken"] = ""
|
|
})
|
|
if !strings.Contains(got, `"success":true`) {
|
|
t.Fatalf("normal settings save was rejected: %s", got)
|
|
}
|
|
stored, err := settingService.GetTwoFactorToken()
|
|
if err != nil {
|
|
t.Fatalf("GetTwoFactorToken: %v", err)
|
|
}
|
|
if stored != "ORIGINALSECRET234567" {
|
|
t.Fatalf("stored 2FA secret = %q, want it preserved", stored)
|
|
}
|
|
})
|
|
}
|
|
|
|
func TestTestDiscordEndpoint(t *testing.T) {
|
|
gin.SetMode(gin.TestMode)
|
|
|
|
// 1. Service not initialized
|
|
SetDiscordService(nil)
|
|
router := gin.New()
|
|
router.Use(func(c *gin.Context) {
|
|
c.Set("I18n", func(_ locale.I18nType, key string, _ ...string) string { return key })
|
|
c.Next()
|
|
})
|
|
NewSettingController(router.Group("/panel/api"))
|
|
|
|
req := httptest.NewRequest(http.MethodPost, "/panel/api/setting/testDiscord", nil)
|
|
resp := httptest.NewRecorder()
|
|
router.ServeHTTP(resp, req)
|
|
|
|
if !strings.Contains(resp.Body.String(), `"success":false`) || !strings.Contains(resp.Body.String(), "pages.settings.discordNotInitialized") {
|
|
t.Fatalf("expected uninitialized error, got %s", resp.Body.String())
|
|
}
|
|
|
|
// Setup DB
|
|
t.Setenv("XUI_DB_FOLDER", t.TempDir())
|
|
dbtest.InitDB(t, filepath.Join(t.TempDir(), "x-ui.db"))
|
|
t.Cleanup(func() { SetDiscordService(nil) })
|
|
|
|
settingService := service.SettingService{}
|
|
svc := discord.NewDiscordService(settingService)
|
|
SetDiscordService(svc)
|
|
|
|
// 2. Discord bot disabled
|
|
_ = settingService.SetDiscordBotEnable(false)
|
|
req = httptest.NewRequest(http.MethodPost, "/panel/api/setting/testDiscord", nil)
|
|
resp = httptest.NewRecorder()
|
|
router.ServeHTTP(resp, req)
|
|
|
|
if !strings.Contains(resp.Body.String(), `"success":false`) || !strings.Contains(resp.Body.String(), "pages.settings.discordBotNotEnabled") {
|
|
t.Fatalf("expected disabled error, got %s", resp.Body.String())
|
|
}
|
|
|
|
// 3. Discord bot enabled but missing config
|
|
_ = settingService.SetDiscordBotEnable(true)
|
|
req = httptest.NewRequest(http.MethodPost, "/panel/api/setting/testDiscord", nil)
|
|
resp = httptest.NewRecorder()
|
|
router.ServeHTTP(resp, req)
|
|
|
|
if !strings.Contains(resp.Body.String(), `"success":false`) || !strings.Contains(resp.Body.String(), "pages.settings.discordTestFailed") {
|
|
t.Fatalf("expected send failure error, got %s", resp.Body.String())
|
|
}
|
|
|
|
// 4. Discord bot enabled with working server
|
|
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
w.WriteHeader(http.StatusOK)
|
|
_, _ = w.Write([]byte(`{"id": "msg-1"}`))
|
|
}))
|
|
defer server.Close()
|
|
|
|
_ = settingService.SetDiscordBotToken("test-bot-token")
|
|
_ = settingService.SetDiscordChannelId("123456789")
|
|
svc.SetBaseURL(server.URL)
|
|
svc.SetHTTPClient(server.Client())
|
|
|
|
req = httptest.NewRequest(http.MethodPost, "/panel/api/setting/testDiscord", nil)
|
|
resp = httptest.NewRecorder()
|
|
router.ServeHTTP(resp, req)
|
|
|
|
if !strings.Contains(resp.Body.String(), `"success":true`) || !strings.Contains(resp.Body.String(), "pages.settings.discordTestSuccess") {
|
|
t.Fatalf("expected success, got %s", resp.Body.String())
|
|
}
|
|
}
|