mirror of
https://github.com/whyour/qinglong.git
synced 2026-09-28 09:02:12 +08:00
* feat(cli): add unified Commander CLI for QingLong 2.x * fix(cli): publish via npm and address security review feedback * ci(cli): package npm artifacts and remove evaluation collateral * test(cli): use a fixed shell fixture for log retention * refactor(cli): separate remote npm client from panel tools * feat(cli): cover active panel OpenAPI resources * docs(cli): unify authentication and skill guidance * refactor(cli): isolate internal commands and generate Commander help * refactor(cli): organize remote and internal modules by responsibility * ci(cli): publish verified npm archives from master * fix(cli): publish under the whyour npm scope * ci: use npm trusted publishing for both packages * docs: introduce the published CLI on the project homepage * fix(cli): preserve server log truncation and correct login hints * fix(cli): accept dashboard record request bodies * fix(cli): preserve stdin for local task execution * fix(cli): resolve task executables after changing directory * fix(cli): preserve shell function tasks and sanitize test failures * fix(cli): preserve shell hook state and resolve workdir after hooks * fix(cli): preserve cleanup across shared shell task timeouts * fix(cli): isolate shell control descriptors and reap timed-out descendants
35 lines
1.7 KiB
JavaScript
35 lines
1.7 KiB
JavaScript
const { test } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('node:fs');
|
|
const path = require('node:path');
|
|
const ts = require('typescript');
|
|
const { openOperations } = require('../../dist/remote/api/openOperations');
|
|
|
|
test('body-consuming backend routes expose a CLI request body or upload', () => {
|
|
const root = path.resolve(__dirname, '../../../back/api');
|
|
let checked = 0;
|
|
for (const filename of fs.readdirSync(root).filter(name => name.endsWith('.ts'))) {
|
|
const text = fs.readFileSync(path.join(root, filename), 'utf8');
|
|
const mount = text.match(/app\.use\(['"]([^'"]+)/)?.[1];
|
|
if (!mount) continue;
|
|
const source = ts.createSourceFile(filename, text, ts.ScriptTarget.Latest, true);
|
|
const visit = node => {
|
|
if (ts.isCallExpression(node) && ts.isPropertyAccessExpression(node.expression)
|
|
&& node.expression.expression.getText(source) === 'route'
|
|
&& ['post', 'put', 'delete'].includes(node.expression.name.text)
|
|
&& node.arguments[0] && ts.isStringLiteral(node.arguments[0])
|
|
&& /\breq\.body\b/.test(node.getText(source))) {
|
|
const endpoint = [mount, node.arguments[0].text].join('/').split('/').filter(Boolean).join('/');
|
|
const method = node.expression.name.text.toUpperCase();
|
|
const operation = openOperations.find(item => item.method === method && item.path === endpoint);
|
|
assert.ok(operation, `${method} ${endpoint} is missing`);
|
|
assert.ok(operation.body || operation.upload, `${operation.name} cannot provide req.body`);
|
|
checked++;
|
|
}
|
|
ts.forEachChild(node, visit);
|
|
};
|
|
visit(source);
|
|
}
|
|
assert.ok(checked > 0, 'No body-consuming routes were inspected');
|
|
});
|