fix: stabilize fetch-urls tests for CI and extend format-matrix timeout

Replace mock HTTP server + vi.mock approach with vi.stubGlobal('fetch')
using a public IP (1.2.3.4) that passes real SSRF validation. This
eliminates both the fragile vi.mock (broken under V8 coverage) and the
localhost network dependency (unreliable in CI).

Revert the SSRF_ALLOW_PRIVATE env var that broke ssrf unit tests.

Extend timeout for exotic format error resilience tests to 120s to
accommodate slow JXL + Image enhancement combination in CI.
This commit is contained in:
SnapOtter
2026-05-12 03:58:42 +08:00
parent c9c09a96bc
commit 706f78b309
4 changed files with 112 additions and 202 deletions
-4
View File
@@ -33,10 +33,6 @@ function isPrivateIPv6(ip: string): boolean {
}
async function resolveAndCheck(hostname: string): Promise<void> {
// Allow tests to bypass private-IP checks so a local mock HTTP server can be
// used without fragile vi.mock() overrides that break under V8 coverage.
if (process.env.SSRF_ALLOW_PRIVATE === "1") return;
const bare = hostname.replace(/^\[|]$/g, "");
if (isIP(bare)) {
if (isPrivateIPv4(bare) || isPrivateIPv6(bare)) {