fix(api): require access codes and limit sizes on helper routes

- Shared checkAccessCode for validate-diagram, validate-model, parse-url, verify-access-code
- parse-url: 5 MB streamed body limit; validate-diagram: 5 MB image limit
- validate-model refuses redirects when private URLs are blocked
- Admin settings state shared across module instances via globalThis
- Server model ids: unique slugs (non-ASCII names encoded), duplicates rejected
- Panel Bedrock credentials stored as ADMIN_AWS_* so the DynamoDB client keeps its own
- Locale redirect keeps basePath and query; EdgeOne function drops open CORS and checks the access code
- Providers payload reports whether .env sets a default model
This commit is contained in:
dayuan.jiang
2026-10-03 17:45:41 +09:00
parent 366480426d
commit 528b6e54c8
16 changed files with 622 additions and 93 deletions
+48
View File
@@ -4,6 +4,7 @@ import {
loadFlattenedServerModels,
type ServerModelsConfig,
ServerModelsConfigSchema,
slugify,
} from "@/lib/server-model-config"
const ORIGINAL_ENV = { ...process.env }
@@ -233,3 +234,50 @@ describe("loadFlattenedServerModels", () => {
expect(models[0].apiKeyEnv).toEqual(["OPENAI_KEY_1", "OPENAI_KEY_2"])
})
})
describe("slugify", () => {
it("keeps ASCII names readable", () => {
expect(slugify("OpenAI Production")).toBe("openai-production")
})
it("gives distinct ASCII slugs to distinct CJK names", () => {
const slugs = ["主力", "备用", "DeepSeek 官方", "DeepSeek 备用"].map(
slugify,
)
expect(new Set(slugs).size).toBe(4)
for (const slug of slugs) expect(slug).toMatch(/^[a-z0-9-]+$/)
})
})
describe("loadFlattenedServerModels id collisions", () => {
it("drops a model whose id repeats an earlier provider's", async () => {
const config: ServerModelsConfig = {
providers: [
{ name: "OpenAI", provider: "openai", models: ["gpt-4o"] },
{
name: "openai",
provider: "openai",
models: ["gpt-4o"],
apiKeyEnv: "OTHER_KEY",
},
{
name: "主力",
provider: "deepseek",
models: ["deepseek-chat"],
},
{
name: "备用",
provider: "deepseek",
models: ["deepseek-chat"],
},
],
}
process.env.AI_MODELS_CONFIG = JSON.stringify(config)
const models = await loadFlattenedServerModels()
const ids = models.map((m) => m.id)
expect(new Set(ids).size).toBe(ids.length)
expect(ids).toHaveLength(3)
expect(models[0].apiKeyEnv).toBeUndefined()
})
})