mirror of
https://github.com/DayuanJiang/next-ai-draw-io.git
synced 2026-10-04 16:57:48 +08:00
fix(api): require access codes and limit sizes on helper routes
- Shared checkAccessCode for validate-diagram, validate-model, parse-url, verify-access-code - parse-url: 5 MB streamed body limit; validate-diagram: 5 MB image limit - validate-model refuses redirects when private URLs are blocked - Admin settings state shared across module instances via globalThis - Server model ids: unique slugs (non-ASCII names encoded), duplicates rejected - Panel Bedrock credentials stored as ADMIN_AWS_* so the DynamoDB client keeps its own - Locale redirect keeps basePath and query; EdgeOne function drops open CORS and checks the access code - Providers payload reports whether .env sets a default model
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
import fs from "fs"
|
||||
import os from "os"
|
||||
import path from "path"
|
||||
import { afterEach, beforeEach, describe, expect, it } from "vitest"
|
||||
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest"
|
||||
import {
|
||||
_resetForTests,
|
||||
applyToEnv,
|
||||
@@ -100,6 +100,24 @@ describe("applyToEnv / saveSettings", () => {
|
||||
expect(process.env.TEST_ADMIN_VAR).toBeUndefined()
|
||||
})
|
||||
|
||||
it("a second module instance can remove a key the first one overlaid", async () => {
|
||||
// instrumentation.ts and API routes load separate copies in a build
|
||||
process.env.TEST_ADMIN_VAR = "from-env"
|
||||
fs.writeFileSync(
|
||||
process.env.SETTINGS_FILE!,
|
||||
JSON.stringify({ version: 1, values: { TEST_ADMIN_VAR: "abc" } }),
|
||||
)
|
||||
applyToEnv()
|
||||
expect(process.env.TEST_ADMIN_VAR).toBe("abc")
|
||||
|
||||
vi.resetModules()
|
||||
const second = await import("@/lib/admin/settings")
|
||||
expect(second.getValueSource("TEST_ADMIN_VAR")).toBe("file")
|
||||
second.saveSettings({ TEST_ADMIN_VAR: null })
|
||||
expect(process.env.TEST_ADMIN_VAR).toBe("from-env")
|
||||
expect(second.getEnvFallback("TEST_ADMIN_VAR")).toBe("from-env")
|
||||
})
|
||||
|
||||
it("persists across cache reset (file round-trip)", () => {
|
||||
saveSettings({ TEST_ADMIN_VAR: "persisted" })
|
||||
_resetForTests()
|
||||
|
||||
Reference in New Issue
Block a user