fix: restore security hardening compatibility and validation

Restore authorized rule reveal, explicit full HTTP capture and retention, video task business fields, and valid payment URLs. Add opt-in credential preservation for trusted recovery, fix frontend type contracts and async races, and eliminate PostgreSQL test fixture resource leaks. Document audit coverage and successful fmt and CI-scoped Clippy checks.
This commit is contained in:
elky
2026-09-07 21:14:27 +08:00
parent a5c3699ae9
commit a90d564931
191 changed files with 6785 additions and 1643 deletions
@@ -14661,15 +14661,19 @@ mod tests {
assert_eq!(usage.status_code, Some(302));
assert_eq!(usage.error_category.as_deref(), Some("redirect"));
assert!(usage.error_message.is_none());
// HTTP capture is intentionally disabled at the persistence boundary. Keep the
// protocol facts above, but do not turn provider/client headers into an audit store.
assert!(usage.client_response_headers.is_none());
assert!(usage.response_headers.is_none());
assert_eq!(
usage.client_response_headers.as_ref().unwrap()["content-type"],
json!("application/json")
);
assert_eq!(
usage.response_headers.as_ref().unwrap()["content-type"],
json!("text/html")
);
assert!(
usage.response_body.is_none(),
"upstream redirect did not include a body"
);
assert!(usage.client_response_body.is_none());
assert_eq!(usage.client_response_body.as_ref(), Some(&body_json));
let candidates = request_candidate_repository
.list_by_request_id("req-remote-runtime-stream-redirect")
.await