mirror of
https://github.com/DayuanJiang/next-ai-draw-io.git
synced 2026-09-03 01:50:23 +08:00
fix(admin): address Copilot review findings
- Reflect built-in defaults for boolean settings (ALLOW_PRIVATE_URLS defaults on) and allow clearing a saved boolean back to default, so the SSRF toggle matches actual runtime behavior. - Harden JSON loading: filter settings values to strings only, and schema-validate stored ADMIN_PROVIDERS entries, dropping malformed ones instead of letting them reach runtime code. - Set beforeunload returnValue so the unsaved-changes prompt shows in all browsers; reject non-finite numbers in settings validation. - Fix README/CN/JA docs that claimed the panel auto-generates AI_MODELS_CONFIG (providers are merged at read time, not written). - Add unit tests for corrupted-file value filtering and provider schema validation.
This commit is contained in:
@@ -39,6 +39,31 @@ describe("loadSettings", () => {
|
||||
)
|
||||
expect(loadSettings()).toEqual({ TEST_ADMIN_VAR: "abc" })
|
||||
})
|
||||
|
||||
it("drops non-string values from a corrupted file", () => {
|
||||
fs.writeFileSync(
|
||||
process.env.SETTINGS_FILE!,
|
||||
JSON.stringify({
|
||||
version: 1,
|
||||
values: {
|
||||
GOOD: "ok",
|
||||
NUM: 5,
|
||||
OBJ: { nested: true },
|
||||
ARR: [1, 2],
|
||||
NULL: null,
|
||||
},
|
||||
}),
|
||||
)
|
||||
expect(loadSettings()).toEqual({ GOOD: "ok" })
|
||||
})
|
||||
|
||||
it("returns empty object when values is null or an array", () => {
|
||||
fs.writeFileSync(
|
||||
process.env.SETTINGS_FILE!,
|
||||
JSON.stringify({ version: 1, values: null }),
|
||||
)
|
||||
expect(loadSettings()).toEqual({})
|
||||
})
|
||||
})
|
||||
|
||||
describe("applyToEnv / saveSettings", () => {
|
||||
|
||||
Reference in New Issue
Block a user