feat: custom domain management, config and notification fixes, and VPS auto-renewal rollover

This commit is contained in:
Bot
2026-09-01 23:45:21 +08:00
parent 00f5777112
commit 3d2b27f4ec
30 changed files with 610 additions and 359 deletions
@@ -46,32 +46,6 @@ func setAuthUser(c *gin.Context, userID uint64, role model.Role) {
})
}
func TestTerminalStreamRejectsForeignMember(t *testing.T) {
gin.SetMode(gin.TestMode)
ensureLocalizerForStreamTests(t)
rpc.NezhaHandlerSingleton = rpc.NewNezhaHandler()
rpc.NezhaHandlerSingleton.CreateStream("alice-terminal", 100, 1)
r := gin.New()
r.Use(func(c *gin.Context) {
setAuthUser(c, 200, model.RoleMember) // bob
c.Next()
})
r.GET("/ws/terminal/:id", commonHandler(terminalStream))
w := httptest.NewRecorder()
req := httptest.NewRequest(http.MethodGet, "/ws/terminal/alice-terminal", nil)
r.ServeHTTP(w, req)
success, errMsg := decodeCommonResponseError(t, w.Body.Bytes())
assert.False(t, success, "foreign member must not be authorized to attach to alice's terminal")
assert.Contains(t, errMsg, "permission denied")
// And the existing stream must NOT have been torn down by the failed attempt.
_, stillExists := rpc.NezhaHandlerSingleton.StreamOwnership("alice-terminal")
assert.True(t, stillExists, "rejected attempt must not destroy the legitimate session")
}
func TestFMStreamRejectsForeignMember(t *testing.T) {
gin.SetMode(gin.TestMode)
ensureLocalizerForStreamTests(t)
@@ -97,26 +71,6 @@ func TestFMStreamRejectsForeignMember(t *testing.T) {
assert.True(t, stillExists, "rejected attempt must not destroy the legitimate FM session")
}
func TestTerminalStreamRejectsUnknownStreamID(t *testing.T) {
gin.SetMode(gin.TestMode)
ensureLocalizerForStreamTests(t)
rpc.NezhaHandlerSingleton = rpc.NewNezhaHandler()
r := gin.New()
r.Use(func(c *gin.Context) {
setAuthUser(c, 100, model.RoleMember)
c.Next()
})
r.GET("/ws/terminal/:id", commonHandler(terminalStream))
w := httptest.NewRecorder()
req := httptest.NewRequest(http.MethodGet, "/ws/terminal/nonexistent", nil)
r.ServeHTTP(w, req)
success, _ := decodeCommonResponseError(t, w.Body.Bytes())
assert.False(t, success, "unknown stream id must produce an error response")
}
// JWT cookie security: SigningAlgorithm must be pinned to HS256 (defense
// against future algorithm-confusion regressions in the library) and the
// JWT cookie must use SameSite=Lax so cross-site GET navigations don't