test(ai-review): 補上安全與 Gitea 契約測試
This commit is contained in:
@@ -0,0 +1,74 @@
|
||||
'use strict';
|
||||
|
||||
const assert = require('node:assert/strict');
|
||||
const test = require('node:test');
|
||||
|
||||
const review = require('../src/lib/review');
|
||||
|
||||
test('agentFailureDetail 預設不輸出 stderr/stdout 片段', () => {
|
||||
const oldDebug = process.env.ACTIONS_STEP_DEBUG;
|
||||
delete process.env.ACTIONS_STEP_DEBUG;
|
||||
try {
|
||||
const detail = review.__test.agentFailureDetail({
|
||||
ok: false,
|
||||
error: Object.assign(new Error('boom'), { code: 1 }),
|
||||
stderr: 'token=super-secret-value',
|
||||
output: 'stdout with password=hidden',
|
||||
});
|
||||
assert.match(detail, /exit 1/);
|
||||
assert.doesNotMatch(detail, /super-secret-value|password|stdout|stderr/);
|
||||
} finally {
|
||||
if (oldDebug === undefined) delete process.env.ACTIONS_STEP_DEBUG;
|
||||
else process.env.ACTIONS_STEP_DEBUG = oldDebug;
|
||||
}
|
||||
});
|
||||
|
||||
test('agentFailureDetail 在 debug 模式輸出遮罩後片段', () => {
|
||||
const oldDebug = process.env.ACTIONS_STEP_DEBUG;
|
||||
process.env.ACTIONS_STEP_DEBUG = 'true';
|
||||
try {
|
||||
const detail = review.__test.agentFailureDetail({
|
||||
ok: false,
|
||||
error: Object.assign(new Error('boom'), { code: 2 }),
|
||||
stderr: 'Authorization: Bearer abcdefghijklmnopqrstuvwxyz1234567890',
|
||||
output: 'token=abcdefghijklmnopqrstuvwxyz1234567890TOKEN',
|
||||
});
|
||||
assert.match(detail, /exit 2/);
|
||||
assert.match(detail, /stderr:Authorization: \*\*\*/);
|
||||
assert.match(detail, /stdout:token=\*\*\*/);
|
||||
assert.doesNotMatch(detail, /abcdefghijklmnopqrstuvwxyz/);
|
||||
} finally {
|
||||
if (oldDebug === undefined) delete process.env.ACTIONS_STEP_DEBUG;
|
||||
else process.env.ACTIONS_STEP_DEBUG = oldDebug;
|
||||
}
|
||||
});
|
||||
|
||||
test('postOthersToIssue 批次送出 issue 留言', async () => {
|
||||
const calls = [];
|
||||
let active = 0;
|
||||
let maxActive = 0;
|
||||
const fakeGitea = {
|
||||
async createCommentOnIssue(ctx, issueNumber, body) {
|
||||
active += 1;
|
||||
maxActive = Math.max(maxActive, active);
|
||||
calls.push({ ctx, issueNumber, body });
|
||||
await new Promise((resolve) => setTimeout(resolve, 20));
|
||||
active -= 1;
|
||||
return { id: calls.length };
|
||||
},
|
||||
};
|
||||
|
||||
await review.postOthersToIssue({
|
||||
ctx: { token: 'hidden' },
|
||||
gitea: fakeGitea,
|
||||
issueNumber: 7,
|
||||
others: [
|
||||
{ severity: '警告', reviewer: 'Maya', file: 'a.js', startLine: 1, endLine: 1, problem: 'p1', suggestion: 's1' },
|
||||
{ severity: '建議', reviewer: 'Bard', file: 'b.js', startLine: 2, endLine: 2, problem: 'p2', suggestion: 's2' },
|
||||
],
|
||||
});
|
||||
|
||||
assert.equal(calls.length, 2);
|
||||
assert.equal(calls[0].issueNumber, 7);
|
||||
assert.ok(maxActive > 1);
|
||||
});
|
||||
Reference in New Issue
Block a user