fix: restore security hardening compatibility and validation

Restore authorized rule reveal, explicit full HTTP capture and retention, video task business fields, and valid payment URLs. Add opt-in credential preservation for trusted recovery, fix frontend type contracts and async races, and eliminate PostgreSQL test fixture resource leaks. Document audit coverage and successful fmt and CI-scoped Clippy checks.
This commit is contained in:
elky
2026-09-07 21:14:27 +08:00
parent a5c3699ae9
commit a90d564931
191 changed files with 6785 additions and 1643 deletions
@@ -1,6 +1,7 @@
import { beforeEach, describe, expect, it } from 'vitest'
import {
POOL_MANAGEMENT_VIEW_STORAGE_KEY,
buildPoolManagementQueryPatch,
readPoolManagementViewState,
resolvePoolManagementPageAfterLoad,
@@ -71,8 +72,9 @@ describe('poolManagementState', () => {
})
it('falls back to storage when query is missing', () => {
writePoolManagementViewState(
{
storage.setItem(
POOL_MANAGEMENT_VIEW_STORAGE_KEY,
JSON.stringify({
providerId: 'provider-c',
search: 'stored only',
status: 'active',
@@ -81,8 +83,7 @@ describe('poolManagementState', () => {
sortBy: 'last_used_at',
sortOrder: 'asc',
statsMode: 'account_total',
},
storage,
}),
)
const state = readPoolManagementViewState({}, storage)
@@ -23,7 +23,8 @@ export function mergePoolKeyQuotaSnapshots(
...(quotaSnapshot ? {
quota_updated_at: quotaSnapshot.updated_at ?? quotaSnapshot.observed_at ?? key.quota_updated_at ?? null,
status_snapshot: {
...(key.status_snapshot ?? {}),
oauth: key.status_snapshot?.oauth ?? { code: 'none' },
account: key.status_snapshot?.account ?? { code: 'unknown', blocked: false },
quota: quotaSnapshot,
},
} : {}),