test: update pre-existing stale specs for 2.0 multimodal + validation behavior

Fixes a backlog of integration/unit specs that asserted pre-2.0 behavior and
were failing CI (not caused by recent feature work):
- modality-aware empty-input error is 'No file(s) provided', not /no image/i
  (rotate, border, crop, resize, smart-crop, edge-cases, adversarial-extended,
  api, tool-factory-route)
- input validation rejects pre-enqueue with a clean 400 in 'error' (was a worker
  422 in 'details'): create-zip, extract-zip, merge-csvs
- resolveToolPool defaults unknown tools to the system pool (pool-routing)
- /upload and fetch-urls accept non-image content, validated per-tool at process
  time (api, fetch-urls)
- color-adjust legacy aliases were consolidated into adjust-colors: drop the
  removed-alias tests; retarget the format-preservation tests
- xml-to-csv gracefully converts a single non-repeating record to a 1-row CSV
- dropzone is multimodal; image-only filtering is opt-in via fileFilter
- factory-multi-input: register the synthetic test tools in the catalog so they
  route correctly (file modality for concat; image for the validation-prefix test)

Verified locally: unit 4546 passed, integration 8332 passed, typecheck + lint green.
This commit is contained in:
SnapOtter
2026-06-17 15:54:48 +08:00
parent 3726335063
commit de8bd79b04
18 changed files with 117 additions and 82 deletions
+5 -5
View File
@@ -101,7 +101,7 @@ describe("extract-zip (pure JS, no skipIf)", () => {
expect(dl.payload).toBe("hello world from extract-zip test");
}, 30_000);
it("rejects a zip with path traversal (../evil.txt) with 422", async () => {
it("rejects a zip with path traversal (../evil.txt) with 400", async () => {
// Most zip libraries sanitize entry names, so we binary-patch
// a placeholder to inject "../evil.txt" into the raw zip bytes.
const zip = new AdmZip();
@@ -118,11 +118,11 @@ describe("extract-zip (pure JS, no skipIf)", () => {
}
const res = await runExtract("traversal.zip", zipBuf);
expect(res.statusCode).toBe(422);
expect(res.statusCode).toBe(400);
const parsed = JSON.parse(res.body);
// yauzl itself rejects "../" paths with "invalid relative path" (defense in depth);
// our guard also catches them if yauzl's validation is bypassed
expect(parsed.details).toMatch(/unsafe entry path|invalid relative path/i);
// Path traversal is now rejected pre-enqueue with a clean 400 InputValidationError,
// whose message is surfaced in `error` (the legacy worker path used `details`/422).
expect(parsed.error).toMatch(/unsafe entry path|invalid relative path/i);
}, 30_000);
it("rejects a high-ratio zip bomb with 422", async () => {