fix: restore security hardening compatibility and validation

Restore authorized rule reveal, explicit full HTTP capture and retention, video task business fields, and valid payment URLs. Add opt-in credential preservation for trusted recovery, fix frontend type contracts and async races, and eliminate PostgreSQL test fixture resource leaks. Document audit coverage and successful fmt and CI-scoped Clippy checks.
This commit is contained in:
elky
2026-09-07 21:14:27 +08:00
parent a5c3699ae9
commit a90d564931
191 changed files with 6785 additions and 1643 deletions
@@ -115,9 +115,6 @@ pub(super) fn usage_cleanup_window(
usage_cleanup_window_with_override(now_utc, settings, None)
}
/// Clamp is non-aggressive: each tier's cutoff becomes `max(policy_cutoff, now - override)`.
/// A later cutoff = fewer records deleted, so the override can only make cleanup more
/// conservative than the configured retention, never more destructive.
pub(super) fn usage_cleanup_window_with_override(
now_utc: DateTime<Utc>,
settings: UsageCleanupSettings,
@@ -135,9 +132,9 @@ pub(super) fn usage_cleanup_window_with_override(
};
let manual_cutoff = now_utc - override_duration;
UsageCleanupWindow {
detail_cutoff: policy.detail_cutoff.max(manual_cutoff),
compressed_cutoff: policy.compressed_cutoff.max(manual_cutoff),
header_cutoff: policy.header_cutoff.max(manual_cutoff),
log_cutoff: policy.log_cutoff.max(manual_cutoff),
detail_cutoff: policy.detail_cutoff.min(manual_cutoff),
compressed_cutoff: policy.compressed_cutoff.min(manual_cutoff),
header_cutoff: policy.header_cutoff.min(manual_cutoff),
log_cutoff: policy.log_cutoff.min(manual_cutoff),
}
}
@@ -1140,19 +1140,40 @@ fn usage_cleanup_window_with_override_is_always_non_aggressive() {
let override_duration = chrono::Duration::days(180);
let clamped = usage_cleanup_window_with_override(now_utc, settings, Some(override_duration));
assert_eq!(clamped.detail_cutoff, policy.detail_cutoff);
assert_eq!(clamped.compressed_cutoff, policy.compressed_cutoff);
assert_eq!(clamped.header_cutoff, policy.header_cutoff);
assert_eq!(clamped.log_cutoff, now_utc - override_duration);
assert!(clamped.log_cutoff > policy.log_cutoff);
assert_eq!(clamped.detail_cutoff, now_utc - override_duration);
assert_eq!(clamped.compressed_cutoff, now_utc - override_duration);
assert_eq!(clamped.header_cutoff, now_utc - override_duration);
assert_eq!(clamped.log_cutoff, policy.log_cutoff);
assert!(clamped.log_cutoff <= policy.log_cutoff);
let far_override = chrono::Duration::days(5);
let far = usage_cleanup_window_with_override(now_utc, settings, Some(far_override));
assert_eq!(far.detail_cutoff, now_utc - far_override);
assert_eq!(far.compressed_cutoff, now_utc - far_override);
assert_eq!(far.header_cutoff, now_utc - far_override);
assert_eq!(far.log_cutoff, now_utc - far_override);
assert!(far.log_cutoff > policy.log_cutoff);
assert_eq!(far, policy);
for days in [0, 5, 30, 180, 400] {
let cutoff = now_utc - chrono::Duration::days(days);
let window = usage_cleanup_window_with_override(
now_utc,
settings,
Some(chrono::Duration::days(days)),
);
for (actual, configured) in [
(window.detail_cutoff, policy.detail_cutoff),
(window.compressed_cutoff, policy.compressed_cutoff),
(window.header_cutoff, policy.header_cutoff),
(window.log_cutoff, policy.log_cutoff),
] {
assert!(actual <= configured);
assert!(actual <= cutoff);
for age in [1, 7, 15, 30, 90, 180, 365, 401] {
let created_at = now_utc - chrono::Duration::days(age);
if created_at < actual {
assert!(created_at < configured);
assert!(created_at < cutoff);
}
}
}
}
let passthrough = usage_cleanup_window_with_override(now_utc, settings, None);
assert_eq!(passthrough, policy);