mirror of
https://github.com/whyour/qinglong.git
synced 2026-10-01 05:13:50 +08:00
feat(cli): cover OpenAPI with a remote npm CLI and internal panel tools (#3074)
* feat(cli): add unified Commander CLI for QingLong 2.x * fix(cli): publish via npm and address security review feedback * ci(cli): package npm artifacts and remove evaluation collateral * test(cli): use a fixed shell fixture for log retention * refactor(cli): separate remote npm client from panel tools * feat(cli): cover active panel OpenAPI resources * docs(cli): unify authentication and skill guidance * refactor(cli): isolate internal commands and generate Commander help * refactor(cli): organize remote and internal modules by responsibility * ci(cli): publish verified npm archives from master * fix(cli): publish under the whyour npm scope * ci: use npm trusted publishing for both packages * docs: introduce the published CLI on the project homepage * fix(cli): preserve server log truncation and correct login hints * fix(cli): accept dashboard record request bodies * fix(cli): preserve stdin for local task execution * fix(cli): resolve task executables after changing directory * fix(cli): preserve shell function tasks and sanitize test failures * fix(cli): preserve shell hook state and resolve workdir after hooks * fix(cli): preserve cleanup across shared shell task timeouts * fix(cli): isolate shell control descriptors and reap timed-out descendants
This commit is contained in:
@@ -0,0 +1,56 @@
|
||||
const assert = require('node:assert/strict');
|
||||
const path = require('node:path');
|
||||
const os = require('node:os');
|
||||
const { randomUUID } = require('node:crypto');
|
||||
const { spawnSync } = require('node:child_process');
|
||||
|
||||
exports.verifyAccountMaintenance = async function verifyAccountMaintenance(
|
||||
api,
|
||||
) {
|
||||
const credentials = {
|
||||
username: `renamed-${randomUUID()}`,
|
||||
password: `--${randomUUID()}`,
|
||||
};
|
||||
const local = (action, value) => {
|
||||
const result = spawnSync(
|
||||
path.join(os.homedir(), 'bin/ql'),
|
||||
[action, ...(value ? ['--', value] : [])],
|
||||
{
|
||||
env: { ...process.env, QL_DIR: '/ql' },
|
||||
encoding: 'utf8',
|
||||
timeout: 15000,
|
||||
},
|
||||
);
|
||||
assert.equal(result.status, 0, `${action} failed: ${result.stderr}`);
|
||||
assert.equal(JSON.parse(result.stdout).data.completed, true);
|
||||
};
|
||||
const login = async () => {
|
||||
const response = await fetch('http://127.0.0.1:5700/api/user/login', {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify(credentials),
|
||||
signal: AbortSignal.timeout(5000),
|
||||
});
|
||||
return response.json();
|
||||
};
|
||||
local('resetname', credentials.username);
|
||||
local('resetpwd', credentials.password);
|
||||
assert.equal((await login()).code, 200, 'New credentials were not saved');
|
||||
await api('system/auth/reset', 'PUT', { retries: 4 });
|
||||
assert.notEqual(
|
||||
(await login()).code,
|
||||
200,
|
||||
'Fixture failed to activate login limit',
|
||||
);
|
||||
local('resetlet');
|
||||
assert.equal((await login()).code, 200, 'Login limit was not cleared');
|
||||
await api('system/auth/reset', 'PUT', { twoFactorActivated: true });
|
||||
assert.notEqual(
|
||||
(await login()).code,
|
||||
200,
|
||||
'Fixture failed to activate second factor',
|
||||
);
|
||||
local('resettfa');
|
||||
assert.equal((await login()).code, 200, 'Second factor was not cleared');
|
||||
return true;
|
||||
};
|
||||
Reference in New Issue
Block a user