This commit is contained in:
toom1996
2026-09-25 11:31:52 +08:00
parent 4f4c11d508
commit 42f6316125
51 changed files with 4489 additions and 998 deletions

View File

@ -0,0 +1,66 @@
//go:build integration
// 集成测试:公开只读视图(public_brand_runways / public_street_snaps)不得暴露审核/溯源列
// (job_id / reviewer / reject_reason)。设计规格 I2:视图列集已显式枚举,刻意排除这些列,
// 使基表加列时敏感列不会无意泄露到公开读路径。
//
// 运行:go test -tags integration ./internal/repository/ -run TestPublicViewsExcludeSensitiveColumns -v
package repository
import (
"testing"
)
// TestPublicViewsExcludeSensitiveColumns 断言两个主表公开视图不含敏感列。
func TestPublicViewsExcludeSensitiveColumns(t *testing.T) {
db := testDB(t)
applyMigration(t, db, "2026-09-22-01-single-table-publish.sql")
type v struct {
view, col string
}
cases := []v{}
for _, view := range []string{"public_brand_runways", "public_street_snaps"} {
for _, col := range []string{"job_id", "reviewer", "reject_reason"} {
cases = append(cases, v{view, col})
}
}
for _, c := range cases {
var cnt int64
if err := db.Raw(
`SELECT count(*) FROM information_schema.columns WHERE table_name = ? AND column_name = ?`,
c.view, c.col,
).Scan(&cnt).Error; err != nil {
t.Fatalf("查 information_schema 失败: %v", err)
}
if cnt != 0 {
t.Errorf("公开视图 %s 不应暴露敏感列 %s", c.view, c.col)
}
}
}
// TestPublicViewsKeepNeededColumns 断言公开视图仍含对外必需的列(回归保护,避免收窄时误删)。
func TestPublicViewsKeepNeededColumns(t *testing.T) {
db := testDB(t)
applyMigration(t, db, "2026-09-22-01-single-table-publish.sql")
keep := map[string][]string{
"public_brand_runways": {"id", "brand_id", "title_en", "cover", "image_count", "year", "season_code", "status"},
"public_street_snaps": {"id", "title", "title_cn", "city", "cover", "image_count", "year", "status"},
}
for view, cols := range keep {
for _, col := range cols {
var cnt int64
if err := db.Raw(
`SELECT count(*) FROM information_schema.columns WHERE table_name = ? AND column_name = ?`,
view, col,
).Scan(&cnt).Error; err != nil {
t.Fatalf("查 information_schema 失败: %v", err)
}
if cnt != 1 {
t.Errorf("公开视图 %s 必须含列 %s(收窄时误删)", view, col)
}
}
}
}