mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-07 01:47:47 +08:00
fix: restore security hardening compatibility and validation
Restore authorized rule reveal, explicit full HTTP capture and retention, video task business fields, and valid payment URLs. Add opt-in credential preservation for trusted recovery, fix frontend type contracts and async races, and eliminate PostgreSQL test fixture resource leaks. Document audit coverage and successful fmt and CI-scoped Clippy checks.
This commit is contained in:
@@ -426,11 +426,8 @@ mod tests {
|
||||
assert!(candidate.finished_at_unix_ms.is_some());
|
||||
}
|
||||
|
||||
/// The guard holds no request body, and the persistence boundary intentionally
|
||||
/// rejects request/response capture material. A dropped-attempt settlement
|
||||
/// must not re-introduce an inline body or a caller-controlled body reference.
|
||||
#[tokio::test]
|
||||
async fn settling_a_dropped_attempt_does_not_reintroduce_request_body_capture() {
|
||||
async fn settling_a_dropped_attempt_respects_disabled_request_body_capture() {
|
||||
let usage_repository = Arc::new(InMemoryUsageReadRepository::default());
|
||||
let request_candidate_repository = Arc::new(InMemoryRequestCandidateRepository::default());
|
||||
let state = test_state(&usage_repository, &request_candidate_repository);
|
||||
@@ -444,8 +441,6 @@ mod tests {
|
||||
candidate_started_unix_ms,
|
||||
)
|
||||
.await;
|
||||
// This deliberately supplies capture material to prove that the usage
|
||||
// persistence boundary strips it before either lifecycle write stores it.
|
||||
let captured_body = json!({"stream": true, "service_tier": "priority"});
|
||||
let mut capture = build_pending_usage_record(
|
||||
&plan,
|
||||
@@ -481,7 +476,10 @@ mod tests {
|
||||
.expect("cancelled usage should be recorded");
|
||||
assert_eq!(usage.provider_request_body, None);
|
||||
assert_eq!(usage.provider_request_body_ref, None);
|
||||
assert_eq!(usage.provider_request_body_state, None);
|
||||
assert_eq!(
|
||||
usage.provider_request_body_state,
|
||||
Some(UsageBodyCaptureState::Disabled)
|
||||
);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
|
||||
@@ -14661,15 +14661,19 @@ mod tests {
|
||||
assert_eq!(usage.status_code, Some(302));
|
||||
assert_eq!(usage.error_category.as_deref(), Some("redirect"));
|
||||
assert!(usage.error_message.is_none());
|
||||
// HTTP capture is intentionally disabled at the persistence boundary. Keep the
|
||||
// protocol facts above, but do not turn provider/client headers into an audit store.
|
||||
assert!(usage.client_response_headers.is_none());
|
||||
assert!(usage.response_headers.is_none());
|
||||
assert_eq!(
|
||||
usage.client_response_headers.as_ref().unwrap()["content-type"],
|
||||
json!("application/json")
|
||||
);
|
||||
assert_eq!(
|
||||
usage.response_headers.as_ref().unwrap()["content-type"],
|
||||
json!("text/html")
|
||||
);
|
||||
assert!(
|
||||
usage.response_body.is_none(),
|
||||
"upstream redirect did not include a body"
|
||||
);
|
||||
assert!(usage.client_response_body.is_none());
|
||||
assert_eq!(usage.client_response_body.as_ref(), Some(&body_json));
|
||||
let candidates = request_candidate_repository
|
||||
.list_by_request_id("req-remote-runtime-stream-redirect")
|
||||
.await
|
||||
|
||||
Reference in New Issue
Block a user