mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
test: update pre-existing stale specs for 2.0 multimodal + validation behavior
Fixes a backlog of integration/unit specs that asserted pre-2.0 behavior and were failing CI (not caused by recent feature work): - modality-aware empty-input error is 'No file(s) provided', not /no image/i (rotate, border, crop, resize, smart-crop, edge-cases, adversarial-extended, api, tool-factory-route) - input validation rejects pre-enqueue with a clean 400 in 'error' (was a worker 422 in 'details'): create-zip, extract-zip, merge-csvs - resolveToolPool defaults unknown tools to the system pool (pool-routing) - /upload and fetch-urls accept non-image content, validated per-tool at process time (api, fetch-urls) - color-adjust legacy aliases were consolidated into adjust-colors: drop the removed-alias tests; retarget the format-preservation tests - xml-to-csv gracefully converts a single non-repeating record to a 1-row CSV - dropzone is multimodal; image-only filtering is opt-in via fileFilter - factory-multi-input: register the synthetic test tools in the catalog so they route correctly (file modality for concat; image for the validation-prefix test) Verified locally: unit 4546 passed, integration 8332 passed, typecheck + lint green.
This commit is contained in:
@@ -101,7 +101,7 @@ describe("extract-zip (pure JS, no skipIf)", () => {
|
||||
expect(dl.payload).toBe("hello world from extract-zip test");
|
||||
}, 30_000);
|
||||
|
||||
it("rejects a zip with path traversal (../evil.txt) with 422", async () => {
|
||||
it("rejects a zip with path traversal (../evil.txt) with 400", async () => {
|
||||
// Most zip libraries sanitize entry names, so we binary-patch
|
||||
// a placeholder to inject "../evil.txt" into the raw zip bytes.
|
||||
const zip = new AdmZip();
|
||||
@@ -118,11 +118,11 @@ describe("extract-zip (pure JS, no skipIf)", () => {
|
||||
}
|
||||
|
||||
const res = await runExtract("traversal.zip", zipBuf);
|
||||
expect(res.statusCode).toBe(422);
|
||||
expect(res.statusCode).toBe(400);
|
||||
const parsed = JSON.parse(res.body);
|
||||
// yauzl itself rejects "../" paths with "invalid relative path" (defense in depth);
|
||||
// our guard also catches them if yauzl's validation is bypassed
|
||||
expect(parsed.details).toMatch(/unsafe entry path|invalid relative path/i);
|
||||
// Path traversal is now rejected pre-enqueue with a clean 400 InputValidationError,
|
||||
// whose message is surfaced in `error` (the legacy worker path used `details`/422).
|
||||
expect(parsed.error).toMatch(/unsafe entry path|invalid relative path/i);
|
||||
}, 30_000);
|
||||
|
||||
it("rejects a high-ratio zip bomb with 422", async () => {
|
||||
|
||||
Reference in New Issue
Block a user