smoke-admin-functions.mjs 38 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428
  1. #!/usr/bin/env node
  2. import { randomBytes } from 'node:crypto';
  3. import { readFile } from 'node:fs/promises';
  4. const APP_ID = process.env.XIAOSHU_PARSE_APP_ID || '7pIbDBJmKx_main';
  5. const MASTER_KEY = process.env.XIAOSHU_MASTER_KEY || '';
  6. const PARSE_URL = (process.env.XIAOSHU_PARSE_URL || 'https://server.xiaoshu.pro/parse').replace(/\/$/, '');
  7. const FUNCTION_URL = (process.env.XIAOSHU_FUNCTION_URL || 'https://server.xiaoshu.pro/api/functions').replace(/\/$/, '');
  8. if (!MASTER_KEY) throw new Error('缺少 XIAOSHU_MASTER_KEY');
  9. async function jsonRequest(url, init = {}, master = false) {
  10. const response = await fetch(url, {
  11. ...init,
  12. headers: {
  13. 'X-Parse-Application-Id': APP_ID,
  14. ...(master ? { 'X-Parse-Master-Key': MASTER_KEY } : {}),
  15. 'Content-Type': 'application/json',
  16. ...(init.headers || {}),
  17. },
  18. });
  19. const payload = await response.json().catch(() => ({}));
  20. if (!response.ok) {
  21. const detail = payload.message || payload.error || payload;
  22. throw new Error(`${response.status}: ${typeof detail === 'string' ? detail : JSON.stringify(detail)}`);
  23. }
  24. return payload;
  25. }
  26. async function callFunction(path, token, params) {
  27. const payload = await jsonRequest(`${FUNCTION_URL}/${path}`, {
  28. method: 'POST',
  29. body: JSON.stringify({ token, params }),
  30. });
  31. if (!payload.success) throw new Error(payload.message || `${path} 返回失败`);
  32. return payload.data;
  33. }
  34. async function callLegacyFunction(token, params, expectedStatus = 200) {
  35. const response = await fetch(`${FUNCTION_URL}/xiaoshu/app/gateway`, {
  36. method: 'POST',
  37. headers: { 'X-Parse-Application-Id': APP_ID, 'Content-Type': 'application/json' },
  38. body: JSON.stringify({ ...(token ? { token } : {}), params }),
  39. });
  40. const payload = await response.json().catch(() => ({}));
  41. if (response.status !== expectedStatus) throw new Error(`app gateway ${params.action} 期望 ${expectedStatus},实际 ${response.status}: ${payload.retmsg || payload.error || ''}`);
  42. return payload;
  43. }
  44. async function sourceActions() {
  45. const source = await readFile(new URL('../src/app/core/source-parity.generated.ts', import.meta.url), 'utf8');
  46. const match = source.match(/export const SOURCE_API_ACTIONS = (\[[\s\S]*?\]) as const;/);
  47. if (!match) throw new Error('无法读取 SOURCE_API_ACTIONS');
  48. return JSON.parse(match[1]);
  49. }
  50. let userId = '';
  51. let registeredUserId = '';
  52. let memberId = '';
  53. let memberLegacyId = 0;
  54. let teamChildId = '';
  55. let coachId = '';
  56. let coachLegacyId = 0;
  57. let temporaryAppointmentId = '';
  58. let temporaryAppointmentObjectId = '';
  59. let temporaryGuestbookId = '';
  60. let contentHitObjectId = '';
  61. let contentHitOriginal = 0;
  62. const temporaryLessonIds = [];
  63. try {
  64. const sample = await jsonRequest(`${PARSE_URL}/classes/Company?limit=1&keys=objectId`, {}, true);
  65. const companyId = sample.results?.[0]?.objectId;
  66. if (!companyId) throw new Error('没有可用于帐套隔离测试的 Company');
  67. const company = { __type: 'Pointer', className: 'Company', objectId: companyId };
  68. const username = `codex_admin_smoke_${Date.now()}`;
  69. const password = randomBytes(24).toString('base64url');
  70. const created = await jsonRequest(`${PARSE_URL}/users`, {
  71. method: 'POST',
  72. body: JSON.stringify({ username, password, isAdmin: true, roles: ['admin'], company }),
  73. }, true);
  74. userId = created.objectId;
  75. const login = await jsonRequest(`${PARSE_URL}/login`, {
  76. method: 'POST',
  77. body: JSON.stringify({ username, password }),
  78. });
  79. if (!login.sessionToken) throw new Error('临时管理员登录未返回 sessionToken');
  80. const registeredUsername = `codex_register_smoke_${Date.now()}`;
  81. const registered = await callLegacyFunction('', { action: 'user_register', name: registeredUsername, passwd: 'Ab1234' });
  82. registeredUserId = String(registered.result?.objectId || '');
  83. const registeredLegacyId = Number(registered.result?.userId);
  84. if (!registeredUserId || !registeredLegacyId || !registered.result?.sessionToken || Number(registered.result?.groupId) !== 1 || Number(registered.addon?.parentUserId) !== 0) throw new Error(`新用户注册基础字段异常:${JSON.stringify(registered)}`);
  85. const registeredInfo = await callLegacyFunction(registered.result.sessionToken, { action: 'user_get', uid: registeredLegacyId });
  86. if (Number(registeredInfo.result?.userId) !== registeredLegacyId || Number(registeredInfo.result?.groupId) !== 1 || Number(registeredInfo.addon?.Purse) !== 0 || Number(registeredInfo.addon?.UserPoint) !== 0) throw new Error('新用户注册后自查异常');
  87. const registeredByName = await callLegacyFunction('', { action: 'user_info_name', uname: registeredUsername });
  88. if (registeredByName.result?.objectId !== registeredUserId) throw new Error('新用户用户名查重异常');
  89. await jsonRequest(`${PARSE_URL}/users/${registeredUserId}`, { method: 'DELETE' }, true);
  90. registeredUserId = '';
  91. const memberUsername = `codex_member_smoke_${Date.now()}`;
  92. const memberPassword = randomBytes(24).toString('base64url');
  93. memberLegacyId = 900000000 + Math.floor(Date.now() / 1000) % 90000000;
  94. const member = await jsonRequest(`${PARSE_URL}/users`, {
  95. method: 'POST',
  96. body: JSON.stringify({ username: memberUsername, password: memberPassword, legacyUserId: memberLegacyId, legacyGroupId: 1, legacyUserData: { UserID: memberLegacyId, UserName: memberUsername, HoneyName: '冒烟学员', GroupID: 1, ParentUserID: 0, VIP: 2, Purse: 2, SilverCoin: 2, UserExp: 2, UserPoint: 2 }, company }),
  97. }, true);
  98. memberId = member.objectId;
  99. const childLegacyId = memberLegacyId + 2;
  100. const child = await jsonRequest(`${PARSE_URL}/users`, {
  101. method: 'POST',
  102. body: JSON.stringify({ username: `codex_team_child_${Date.now()}`, password: randomBytes(24).toString('base64url'), legacyUserId: childLegacyId, legacyGroupId: 3, legacyUserData: { UserID: childLegacyId, UserName: `team_child_${childLegacyId}`, HoneyName: '冒烟团队成员', GroupID: 3, ParentUserID: memberLegacyId, VIP: 3, UserExp: 5, UserPwd: 'must-not-leak' }, company }),
  103. }, true);
  104. teamChildId = child.objectId;
  105. const coachUsername = `codex_coach_smoke_${Date.now()}`;
  106. const coachPassword = randomBytes(24).toString('base64url');
  107. coachLegacyId = memberLegacyId + 1;
  108. const coach = await jsonRequest(`${PARSE_URL}/users`, {
  109. method: 'POST',
  110. body: JSON.stringify({ username: coachUsername, password: coachPassword, legacyUserId: coachLegacyId, legacyGroupId: 3, company }),
  111. }, true);
  112. coachId = coach.objectId;
  113. for (const lessonType of [1, 2, 3]) {
  114. const lesson = await jsonRequest(`${PARSE_URL}/classes/LessonRecord`, {
  115. method: 'POST',
  116. body: JSON.stringify({ company, sourceKey: `cloud:smoke-lesson:${coachLegacyId}:${lessonType}`, jsmz: String(coachLegacyId), kclx: String(lessonType) }),
  117. }, true);
  118. temporaryLessonIds.push(lesson.objectId);
  119. }
  120. const memberLogin = await jsonRequest(`${PARSE_URL}/login`, {
  121. method: 'POST',
  122. body: JSON.stringify({ username: memberUsername, password: memberPassword }),
  123. });
  124. const coachLogin = await jsonRequest(`${PARSE_URL}/login`, {
  125. method: 'POST',
  126. body: JSON.stringify({ username: coachUsername, password: coachPassword }),
  127. });
  128. const feedbackModel = { UserID: memberLegacyId, Title: '冒烟学员 反馈的意见', TContent: '2026-08-19 请假一天', Cateid: 22 };
  129. const feedback = await callLegacyFunction(memberLogin.sessionToken, { action: 'guestbook_add', model: JSON.stringify(feedbackModel) });
  130. temporaryGuestbookId = String(feedback.result?.objectId || '');
  131. if (!temporaryGuestbookId || Number(feedback.result?.UserID) !== memberLegacyId || feedback.result?.Title !== feedbackModel.Title || feedback.result?.TContent !== feedbackModel.TContent || Number(feedback.result?.Cateid) !== 22) throw new Error(`旧版 model 留言写入异常:${JSON.stringify(feedback)}`);
  132. await callLegacyFunction(memberLogin.sessionToken, { action: 'guestbook_add', model: JSON.stringify({ ...feedbackModel, UserID: coachLegacyId }) }, 403);
  133. const profileModel = { honeyName: '冒烟资料更新', trueName: '测试学员', userFace: '/UploadFiles/smoke-avatar.png', sex: '女', birthday: '2000-01-02', mobile: '13800138000', Email: `${memberUsername}@example.test`, seturl: '/member/smoke', Position: '词汇小英雄' };
  134. const updatedProfile = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_update', uid: memberLegacyId, mu: JSON.stringify(profileModel), inviCode: '' });
  135. if (updatedProfile.result?.honeyName !== profileModel.honeyName || updatedProfile.result?.userFace !== profileModel.userFace || updatedProfile.result?.email !== profileModel.Email || updatedProfile.result?.seturl !== profileModel.seturl) throw new Error(`旧版 mu 用户资料更新异常:${JSON.stringify(updatedProfile)}`);
  136. await callLegacyFunction(memberLogin.sessionToken, { action: 'user_update', uid: coachLegacyId, mu: JSON.stringify({ honeyName: '越权' }) }, 403);
  137. await callLegacyFunction(memberLogin.sessionToken, { action: 'user_update_pwd', uid: memberLegacyId, vcode: '123456', newPass: 'Ab1234', reNewPass: 'Ab1234' }, 501);
  138. await callLegacyFunction(memberLogin.sessionToken, { action: 'user_update_pwdall', uid: memberLegacyId, login: 'Ab1234', pay: '123456' }, 501);
  139. const createdAppointment = await callLegacyFunction(login.sessionToken, { action: 'content_add', content: JSON.stringify({ ModelID: 54, nodeId: 29, inputer: coachUsername, status: 99, title: memberUsername }), addon: JSON.stringify({ szyh: memberLegacyId, kcid: 16, dslx: 1, dszt: 0, pl: coachLegacyId, fxpl: coachLegacyId, sdsd: '19:00' }) });
  140. temporaryAppointmentId = String(createdAppointment.result);
  141. const appointmentSourceKey = `cloud:content_add:${memberLegacyId}:${temporaryAppointmentId}`;
  142. const appointmentWhere = encodeURIComponent(JSON.stringify({ sourceKey: appointmentSourceKey }));
  143. const appointmentRows = await jsonRequest(`${PARSE_URL}/classes/CourseAppointment?where=${appointmentWhere}&limit=1`, {}, true);
  144. temporaryAppointmentObjectId = appointmentRows.results?.[0]?.objectId || '';
  145. if (!temporaryAppointmentObjectId) throw new Error('临时预约副表创建失败');
  146. const meta = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'meta' });
  147. if (meta.identity?.objectId !== userId || !meta.cloudFunctions) throw new Error('管理员 meta 校验失败');
  148. const dashboard = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'dashboard' });
  149. if (!Array.isArray(dashboard.metrics) || dashboard.metrics.length !== 8) throw new Error('dashboard 指标校验失败');
  150. const schema = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'schema', className: 'CourseAppointment' });
  151. if (schema.className !== 'CourseAppointment' || !Array.isArray(schema.fields)) throw new Error('schema 校验失败');
  152. const page = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'list', className: 'CourseAppointment', page: 1, pageSize: 2 });
  153. if (!Array.isArray(page.results) || page.pageSize !== 2) throw new Error('资源分页校验失败');
  154. const normalized = await callFunction('xiaoshu/cms/content-normalizer', login.sessionToken, { content: '<p>中文&nbsp;<strong>内容</strong></p><script>alert(1)</script>' });
  155. if (normalized.content !== '中文 内容') throw new Error(`内容清理结果异常:${normalized.content}`);
  156. const exams = await callFunction('xiaoshu/cms/exams/classes', login.sessionToken, { page: 1, pageSize: 2 });
  157. if (!Array.isArray(exams.results)) throw new Error('考试班级投影校验失败');
  158. const guest = await callFunction('xiaoshu/cms/guest/bar', login.sessionToken, { page: 1, pageSize: 2 });
  159. if (!Array.isArray(guest.results)) throw new Error('互动社区投影校验失败');
  160. const migration = await callLegacyFunction('', { action: 'migration_status' });
  161. const sourceActionList = await sourceActions();
  162. const implementedActions = migration.result?.implemented || [];
  163. const blockedActions = Object.keys(migration.result?.blocked || {});
  164. const covered = new Set([...implementedActions, ...blockedActions]);
  165. const missing = sourceActionList.filter((action) => !covered.has(action));
  166. if (missing.length) throw new Error(`app gateway 迁移矩阵缺少:${missing.join(', ')}`);
  167. const sourceBlocked = blockedActions.filter((action) => sourceActionList.includes(action));
  168. const compatibilityActions = blockedActions.filter((action) => !sourceActionList.includes(action)).sort();
  169. const sourceImplemented = implementedActions.filter((action) => sourceActionList.includes(action));
  170. const compatibilityImplemented = implementedActions.filter((action) => !sourceActionList.includes(action)).sort();
  171. if (sourceImplemented.length !== 28 || sourceBlocked.length !== 63) throw new Error(`app gateway 源 action 计数异常:${sourceImplemented.length} 已映射 / ${sourceBlocked.length} 阻塞`);
  172. if (compatibilityImplemented.join(',') !== 'content_add_zt') throw new Error(`app gateway 已实现兼容 action 计数异常:${compatibilityImplemented.join(',')}`);
  173. if (compatibilityActions.join(',') !== 'product_add,product_upd') throw new Error(`app gateway 阻塞兼容 action 计数异常:${compatibilityActions.join(',')}`);
  174. const content = await callLegacyFunction('', { action: 'content_list', page: 1, pageSize: 2 });
  175. if (!Array.isArray(content.result) || content.result.length !== 2 || Number(content.page?.itemCount) < 89000) throw new Error('公开内容分页校验失败');
  176. const contentExact = await callLegacyFunction('', { action: 'content_list', page: 1, pageSize: 1, objectId: content.result[0].objectId });
  177. if (contentExact.result?.[0]?.objectId !== content.result[0].objectId || contentExact.page?.itemCount !== 1) throw new Error('内容 objectId 精确查询校验失败');
  178. const contentDetail = await callLegacyFunction('', { action: 'content_get', id: content.result[0].objectId });
  179. if (!Array.isArray(contentDetail.result) || contentDetail.result[0]?.objectId !== content.result[0].objectId) throw new Error('内容详情旧数组契约校验失败');
  180. contentHitObjectId = String(content.result[0].objectId);
  181. contentHitOriginal = Number(content.result[0].hits ?? content.result[0].Hits ?? 0);
  182. const contentHit = await callLegacyFunction('', { action: 'content_uphis', id: contentHitObjectId, num: 999 });
  183. if (Number(contentHit.result?.hits) !== contentHitOriginal + 1) throw new Error(`公开内容浏览量未固定原子加一:${JSON.stringify(contentHit)}`);
  184. await jsonRequest(`${PARSE_URL}/classes/CommonModel/${contentHitObjectId}`, { method: 'PUT', body: JSON.stringify({ hits: contentHitOriginal }) }, true);
  185. contentHitObjectId = '';
  186. await callLegacyFunction('', { action: 'content_uphis', id: temporaryAppointmentId }, 401);
  187. const appUpdate = await callLegacyFunction('', { action: 'app_update' });
  188. if (Number(appUpdate.result?.ver) !== 113 || appUpdate.result?.nver !== '1.1.8' || !String(appUpdate.result?.path).startsWith('https://') || appUpdate.result?.size !== null || appUpdate.result?.sizeUnavailable !== true) throw new Error(`应用版本旧契约别名异常:${JSON.stringify(appUpdate)}`);
  189. const gameNode = await callLegacyFunction('', { action: 'node_get', id: 77 });
  190. if (gameNode.result?.NodeID === undefined || gameNode.result?.ConsumePoint === undefined || gameNode.result?.ConsumeDeposit === undefined) throw new Error(`栏目详情游戏消费字段别名异常:${JSON.stringify(gameNode.result)}`);
  191. const words = await callLegacyFunction('', { action: 'content_list', modelId: 52, page: 1, pageSize: 1 });
  192. if (Number(words.page?.itemCount) < 89000 || !words.result?.[0]?.GeneralID || words.result?.[0]?.sy === undefined) throw new Error('词库 addon 联表校验失败');
  193. const privateContent = await callLegacyFunction('', { action: 'content_list', modelId: 56, page: 1, pageSize: 1 }, 401);
  194. if (!String(privateContent.retmsg).includes('登录')) throw new Error('学习记录未阻止匿名访问');
  195. const learning = await callLegacyFunction(login.sessionToken, { action: 'content_list', modelId: 56, page: 1, pageSize: 1 });
  196. if (!learning.result?.[0]?.GeneralID || learning.result?.[0]?.xxqs === undefined) throw new Error('学习记录 addon 联表校验失败');
  197. const recordDetail = await callLegacyFunction(login.sessionToken, { action: 'e_record_detail', id: learning.result[0].GeneralID });
  198. if (!Array.isArray(recordDetail.result) || !recordDetail.result.length || !recordDetail.result[0]?.detail?.[0]?.Title) throw new Error('学习记录单词详情联查校验失败');
  199. const appointments = await callLegacyFunction(login.sessionToken, { action: 'content_list', modelId: 54, page: 1, pageSize: 1 });
  200. const appointment = await callLegacyFunction(login.sessionToken, { action: 'e_order_detail', id: appointments.result?.[0]?.GeneralID });
  201. if (!appointment.result?.[0]?.GeneralID || appointment.result[0].kcid === undefined) throw new Error('预约详情联查校验失败');
  202. const memberProfile = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_get', uid: memberLegacyId });
  203. if (memberProfile.result?.honeyName !== profileModel.honeyName || memberProfile.addon?.vip !== 2 || memberProfile.addon?.silverCoin !== 2 || JSON.stringify(memberProfile).includes('must-not-leak')) throw new Error('用户旧契约字段或敏感字段过滤异常');
  204. const teamMembers = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_list', puid: memberLegacyId, cpage: 1, psize: 10 });
  205. if (teamMembers.page?.itemCount !== 1 || Number(teamMembers.result?.[0]?.ParentUserID) !== memberLegacyId || Number(teamMembers.result?.[0]?.VIP) !== 3) throw new Error(`团队成员列表异常:${JSON.stringify(teamMembers)}`);
  206. const teamSummary = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_dept', uid: memberLegacyId });
  207. if (teamSummary.result?.childs !== 1 || teamSummary.result?.v3 !== 1) throw new Error(`团队会员统计异常:${JSON.stringify(teamSummary.result)}`);
  208. const childProfile = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_get', uid: childLegacyId });
  209. if (childProfile.result?.userId !== childLegacyId || childProfile.result?.puid !== memberLegacyId || JSON.stringify(childProfile).includes('must-not-leak')) throw new Error('团队成员详情或密码字段过滤异常');
  210. await callLegacyFunction(coachLogin.sessionToken, { action: 'user_get', uid: childLegacyId }, 403);
  211. const coachStudents = await callLegacyFunction(coachLogin.sessionToken, { action: 'e_user_list', cpage: 1, psize: 10 });
  212. if (coachStudents.page?.itemCount !== 1 || Number(coachStudents.result?.[0]?.szyh) !== memberLegacyId || coachStudents.result?.[0]?.honeyname !== profileModel.honeyName) throw new Error(`陪练学员分组列表异常:${JSON.stringify(coachStudents)}`);
  213. const newWords = await callLegacyFunction(login.sessionToken, { action: 'e_words_list', uid: 58, page: 1, pageSize: 2 });
  214. if (Number(newWords.page?.itemCount) < 1 || !newWords.result?.[0]?.detail?.[0]?.Title) throw new Error('用户生词联查校验失败');
  215. const courseWords = await callLegacyFunction(login.sessionToken, { action: 'e_ck_list', uid: 58, nids: 40, page: 1, pageSize: 1000 });
  216. const learnedWord = courseWords.result?.find((word) => Number(word.GeneralID) === 2505);
  217. if (Number(courseWords.page?.itemCount) < 1 || !courseWords.result?.[0]?.detail?.Title || Number(learnedWord?.w_learned) !== 7) throw new Error('课程词库学习进度联查校验失败');
  218. const memory = await callLegacyFunction(login.sessionToken, { action: 'e_get_21list', uid: 58, page: 1, pageSize: 2 });
  219. if (Number(memory.page?.itemCount) < 1 || !memory.result?.[0]?.GeneralID || memory.result[0].learned === undefined) throw new Error('21 天抗遗忘联查校验失败');
  220. const incomeBlocked = await callLegacyFunction(login.sessionToken, { action: 'e_get_21list_tj', uid: 58 }, 501);
  221. if (!String(incomeBlocked.retmsg).includes('计价规则')) throw new Error('复习收入缺失规则未显式阻塞');
  222. const ownEmpty = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_list', modelId: 56, myfield2: `UserId=${memberLegacyId}`, page: 1, pageSize: 1 });
  223. if (!Array.isArray(ownEmpty.result) || ownEmpty.page?.itemCount !== 0) throw new Error('普通用户本人记录权限校验失败');
  224. const ownCourseWords = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_ck_list', uid: memberLegacyId, nids: 40, page: 1, pageSize: 1 });
  225. if (!Array.isArray(ownCourseWords.result) || ownCourseWords.result[0]?.w_learned !== 0) throw new Error('普通用户本人课程词库权限校验失败');
  226. const learnedWrite = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_add_words', uid: memberLegacyId, wordsId: '2505', kcid: 16, save: 1 });
  227. if (learnedWrite.result?.created !== 1 || learnedWrite.result?.learnedIncremented !== 1) throw new Error('首次学习词进度写入校验失败');
  228. await callLegacyFunction('', { action: 'node_list', pid: 16, ifunit: 1, userId: memberLegacyId }, 401);
  229. const unitNodes = await callLegacyFunction(memberLogin.sessionToken, { action: 'node_list', pid: 16, ifunit: 1, userId: memberLegacyId, pageSize: 100 });
  230. const learnedUnit = unitNodes.result?.find((node) => Number(node.NodeID) === 40);
  231. if (!learnedUnit || Number(learnedUnit.total) < 1 || Number(learnedUnit.yx_word) !== 1 || Number(learnedUnit.process) !== Math.round(100 / Number(learnedUnit.total))) throw new Error(`单元已学进度异常:${JSON.stringify(learnedUnit)}`);
  232. const learnedRead = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_ck_list', uid: memberLegacyId, nids: 40, page: 1, pageSize: 1000 });
  233. if (Number(learnedRead.result?.find((word) => Number(word.GeneralID) === 2505)?.w_learned) !== 1) throw new Error('学习次数写后读校验失败');
  234. await callLegacyFunction(memberLogin.sessionToken, { action: 'e_add_words', uid: memberLegacyId, wordsId: '2505', kcid: 16, ifnew: 1 });
  235. const addedNewWord = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_words_list', uid: memberLegacyId, page: 1, pageSize: 10 });
  236. if (addedNewWord.page?.itemCount !== 1 || Number(addedNewWord.result?.[0]?.detail?.[0]?.GeneralID) !== 2505) throw new Error('加入生词写后读校验失败');
  237. await callLegacyFunction(memberLogin.sessionToken, { action: 'e_add_words', uid: memberLegacyId, wordsId: '2505', kcid: 16, ifnew: 0 });
  238. const removedNewWord = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_words_list', uid: memberLegacyId, page: 1, pageSize: 10 });
  239. if (removedNewWord.page?.itemCount !== 0) throw new Error('移出生词写后读校验失败');
  240. const scheduledStudy = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_add_zt', content: JSON.stringify({ ModelID: 56, nodeId: 291, inputer: memberUsername, status: 99, Hits: 1, title: memberUsername }), addon: JSON.stringify({ UserID: memberLegacyId, dqrq: '20991231', learned: 1, xxqs: JSON.stringify([{ GeneralID: 2505, Title: 'woman', check: 0 }]) }) });
  241. if (!/^\d{15}$/.test(String(scheduledStudy.result))) throw new Error('带复习计划的学习记录创建结果异常');
  242. const scheduledDetail = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_get', id: scheduledStudy.result });
  243. const reviewDates = String(scheduledDetail.result?.[0]?.fxrl || '').split(',').filter(Boolean);
  244. if (reviewDates.length !== 15 || !reviewDates.every((date) => /^\d{8}$/.test(date))) throw new Error('15 段抗遗忘复习日期生成失败');
  245. await callLegacyFunction(coachLogin.sessionToken, { action: 'content_update', content: JSON.stringify({ GeneralID: scheduledStudy.result }), addon: JSON.stringify({ con: '越权更新' }) }, 403);
  246. const scheduledUpdate = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_update', content: JSON.stringify({ GeneralID: scheduledStudy.result, Title: '已更新学习记录' }), addon: JSON.stringify({ con: '规范化内容更新', learned: 1 }) });
  247. if (String(scheduledUpdate.result) !== String(scheduledStudy.result)) throw new Error('规范化内容更新返回值异常');
  248. const updatedScheduledDetail = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_get', id: scheduledStudy.result });
  249. if (updatedScheduledDetail.result?.[0]?.con !== '规范化内容更新' || updatedScheduledDetail.result?.[0]?.Title !== '已更新学习记录') throw new Error('规范化内容双表更新写后读失败');
  250. const assessment = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_add', content: JSON.stringify({ ModelID: 61, nodeId: 389, inputer: memberUsername, status: 99, Hits: 1, title: memberUsername }), addon: JSON.stringify({ UserID: memberLegacyId, askid: 1, prev_score: 0, totalScore: 10, wrong: 2, dontKnow: 1, answerid: 7, df: 7 }) });
  251. if (!/^\d{15}$/.test(String(assessment.result))) throw new Error('规范化测评内容新增结果异常');
  252. const assessmentDetail = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_get', id: assessment.result });
  253. if (String(assessmentDetail.result?.[0]?.df) !== '7' || String(assessmentDetail.result?.[0]?.prevScore) !== '0' || Number(assessmentDetail.result?.[0]?.UserID ?? assessmentDetail.result?.[0]?.userId) !== memberLegacyId) throw new Error('规范化测评内容新增写后读失败');
  254. const missingSchemaCreate = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_add', content: JSON.stringify({ ModelID: 55, nodeId: 255 }), addon: JSON.stringify({ UserID: memberLegacyId, scnr: '[]' }) }, 501);
  255. if (!String(missingSchemaCreate.retmsg).includes('未迁移内容模型 55')) throw new Error('缺 Schema 内容新增未明确拒绝');
  256. const studyAddon = { con: '云函数学习记录冒烟测试', dqrq: '20260818', fxrl: '20260819,20260820', UserID: memberLegacyId, learned: 1, ygg: 0, djq: 0, xxqs: JSON.stringify([{ GeneralID: 2505, Title: 'woman', check: 0 }]) };
  257. const createdStudy = await callLegacyFunction(memberLogin.sessionToken, { action: 'stu_record_update_v2', orderId: temporaryAppointmentId, uid: memberLegacyId, inputer: memberUsername, addon: JSON.stringify(studyAddon) });
  258. if (!createdStudy.result?.created || !createdStudy.result?.GeneralID || !createdStudy.result?.recordObjectId) throw new Error('预约学习记录首次双表写入校验失败');
  259. const studyDetail = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_record_detail', id: createdStudy.result.GeneralID });
  260. if (studyDetail.result?.[0]?.detail?.[0]?.Title !== 'woman') throw new Error('预约学习记录写后详情校验失败');
  261. studyAddon.xxqs = JSON.stringify([{ GeneralID: 2505, Title: 'woman', check: 1 }]);
  262. const updatedStudy = await callLegacyFunction(memberLogin.sessionToken, { action: 'stu_record_update_v2', orderId: temporaryAppointmentId, uid: memberLegacyId, inputer: memberUsername, addon: JSON.stringify(studyAddon) });
  263. if (updatedStudy.result?.created || updatedStudy.result?.GeneralID !== createdStudy.result.GeneralID) throw new Error('预约学习记录幂等更新校验失败');
  264. const studyList = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_list', modelId: 56, myfield2: `UserId=${memberLegacyId}|dsid=${temporaryAppointmentId}`, page: 1, pageSize: 2 });
  265. if (studyList.page?.itemCount !== 1 || Number(studyList.result?.[0]?.ygg) !== 1 || Number(studyList.result?.[0]?.learned) !== 1) throw new Error('预约学习记录聚合字段写后读校验失败');
  266. const orderContent = JSON.stringify({ GeneralID: temporaryAppointmentId, UpDateTime: '2026-08-18 13:30' });
  267. await callLegacyFunction(memberLogin.sessionToken, { action: 'e_order_update_v2', uid: memberLegacyId, status: 10, content: orderContent }, 403);
  268. const startedOrder = await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_update_v2', uid: coachLegacyId, status: 10, content: orderContent });
  269. if (startedOrder.result?.previousStatus !== 0 || startedOrder.result?.status !== 10) throw new Error('预约开始状态迁移失败');
  270. const endedOrder = await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_update_v2', uid: coachLegacyId, status: 11, content: orderContent });
  271. if (endedOrder.result?.reviewCount !== 2 || !endedOrder.result?.periodDeducted) throw new Error('预约结束课时与抗遗忘副作用失败');
  272. const repeatedEnd = await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_update_v2', uid: coachLegacyId, status: 11, content: orderContent });
  273. if (!repeatedEnd.result?.unchanged) throw new Error('预约结束状态未保持幂等');
  274. const updatedMember = await jsonRequest(`${PARSE_URL}/users/${memberId}`, {}, true);
  275. if (Number(updatedMember.legacyUserData?.Purse) !== 1 || Number(updatedMember.legacyUserData?.UserPoint) !== 1.5) throw new Error(`预约结束课时扣减异常:${JSON.stringify(updatedMember.legacyUserData)}`);
  276. const sideEffectWhere = encodeURIComponent(JSON.stringify({ sourceKey: { $regex: `^cloud:e_order_update:${temporaryAppointmentId}:` } }));
  277. const [periodLogs, pointLogs, memoryRows, memoryCommonRows] = await Promise.all([
  278. jsonRequest(`${PARSE_URL}/classes/UserExpDomP?where=${sideEffectWhere}&count=1&limit=0`, {}, true),
  279. jsonRequest(`${PARSE_URL}/classes/UserUserPoint?where=${sideEffectWhere}&count=1&limit=0`, {}, true),
  280. jsonRequest(`${PARSE_URL}/classes/MemoryPracticeRecord?where=${sideEffectWhere}&count=1&limit=0`, {}, true),
  281. jsonRequest(`${PARSE_URL}/classes/CommonModel?where=${sideEffectWhere}&count=1&limit=0`, {}, true),
  282. ]);
  283. if (periodLogs.count !== 1 || pointLogs.count !== 1 || memoryRows.count !== 2 || memoryCommonRows.count !== 2) throw new Error(`预约结束账本/抗遗忘数量异常:${periodLogs.count}/${pointLogs.count}/${memoryRows.count}/${memoryCommonRows.count}`);
  284. const purseHistory = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_point_list', uid: memberLegacyId, stype: 1, cpage: 1, psize: 10 });
  285. if (purseHistory.page?.itemCount !== 1 || Number(purseHistory.result?.[0]?.score) !== -1 || !purseHistory.result?.[0]?.ExpHisID || purseHistory.result?.[0]?.Detail === undefined || purseHistory.addon?.purseFeeRuleUnavailable !== true) throw new Error(`余额账本读取异常:${JSON.stringify(purseHistory)}`);
  286. const couponHistory = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_point_list', uid: memberLegacyId, stype: 4, cpage: 1, psize: 10 });
  287. if (couponHistory.page?.itemCount !== 1 || Number(couponHistory.result?.[0]?.score) !== -0.5 || !couponHistory.result?.[0]?.HisTime) throw new Error(`点券账本读取异常:${JSON.stringify(couponHistory)}`);
  288. await callLegacyFunction(memberLogin.sessionToken, { action: 'user_point_list', uid: memberLegacyId, stype: 7 }, 400);
  289. await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_update_v2', uid: coachLegacyId, status: 20, content: orderContent }, 403);
  290. await callLegacyFunction(memberLogin.sessionToken, { action: 'e_order_update_v2', uid: memberLegacyId, status: 20, content: orderContent });
  291. await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_update_v2', uid: coachLegacyId, status: 30, content: orderContent });
  292. const completedOrder = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_order_detail', id: temporaryAppointmentId });
  293. if (Number(completedOrder.result?.[0]?.dszt) !== 30) throw new Error('预约状态机写后读失败');
  294. const coachStats = await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_tongji', uid: coachLegacyId });
  295. if (coachStats.result?.t30 !== '1' || coachStats.result?.t60 !== '1' || coachStats.result?.t_tiyan !== '1' || coachStats.result?.t_total !== '3' || coachStats.result?.t_shichang !== '2.5' || coachStats.result?.t_yongji !== '100') throw new Error('陪练预约统计公式校验失败');
  296. const memberStats = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_order_tongji', uid: memberLegacyId });
  297. if (memberStats.result?.t30 !== '1' || memberStats.result?.t60 !== '0' || memberStats.result?.t_tiyan !== '0' || memberStats.result?.t_total !== '1' || memberStats.result?.t_shichang !== '0.5' || memberStats.result?.t_yongji !== '0') throw new Error(`学员预约与生词统计公式校验失败:${JSON.stringify(memberStats.result)}`);
  298. const deniedCourseWords = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_ck_list', uid: 58, nids: 40, page: 1, pageSize: 1 }, 403);
  299. if (!String(deniedCourseWords.retmsg).includes('无权')) throw new Error('普通用户跨用户课程词库未被拒绝');
  300. const denied = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_list', modelId: 56, myfield2: 'UserId=3', page: 1, pageSize: 1 }, 403);
  301. if (!String(denied.retmsg).includes('无权')) throw new Error('普通用户跨用户记录未被拒绝');
  302. const profile = await callLegacyFunction(login.sessionToken, { action: 'user_get' });
  303. if (profile.retcode !== 0 || profile.result?.objectId !== userId) throw new Error('app gateway 用户会话校验失败');
  304. const blocked = await callLegacyFunction('', { action: 'cart_list' }, 501);
  305. if (!String(blocked.retmsg).startsWith('migration_blocked:')) throw new Error('阻塞接口未返回 migration_blocked');
  306. const productBlocked = await callLegacyFunction('', { action: 'product_list' }, 501);
  307. if (!String(productBlocked.retmsg).includes('ZL_Commodities')) throw new Error('缺商品主表的读取接口未明确阻塞');
  308. console.log('Cloud smoke passed: admin auth/tenant/CRUD reads, CMS projections, normalized learning joins, app action coverage, public content, session scope, explicit blocked APIs.');
  309. } finally {
  310. if (contentHitObjectId) await jsonRequest(`${PARSE_URL}/classes/CommonModel/${contentHitObjectId}`, { method: 'PUT', body: JSON.stringify({ hits: contentHitOriginal }) }, true).catch((error) => {
  311. console.error(`公开内容浏览量恢复失败:${error.message}`);
  312. process.exitCode = 1;
  313. });
  314. if (registeredUserId) await jsonRequest(`${PARSE_URL}/users/${registeredUserId}`, { method: 'DELETE' }, true).catch((error) => {
  315. console.error(`临时注册用户清理失败:${error.message}`);
  316. process.exitCode = 1;
  317. });
  318. if (temporaryGuestbookId) await jsonRequest(`${PARSE_URL}/classes/Guestbook/${temporaryGuestbookId}`, { method: 'DELETE' }, true).catch((error) => {
  319. console.error(`临时留言清理失败:${error.message}`);
  320. process.exitCode = 1;
  321. });
  322. for (const lessonId of temporaryLessonIds) await jsonRequest(`${PARSE_URL}/classes/LessonRecord/${lessonId}`, { method: 'DELETE' }, true).catch((error) => {
  323. console.error(`临时陪练课次清理失败:${error.message}`);
  324. process.exitCode = 1;
  325. });
  326. if (memberLegacyId) {
  327. const commonWhere = encodeURIComponent(JSON.stringify({ sourceKey: { $regex: `^cloud:(stu_record|content_add_zt|content_add):${memberLegacyId}:` } }));
  328. const commonRows = await jsonRequest(`${PARSE_URL}/classes/CommonModel?where=${commonWhere}&limit=1000`, {}, true).catch(() => ({ results: [] }));
  329. for (const row of commonRows.results || []) await jsonRequest(`${PARSE_URL}/classes/CommonModel/${row.objectId}`, { method: 'DELETE' }, true).catch((error) => {
  330. console.error(`临时学习主记录清理失败:${error.message}`);
  331. process.exitCode = 1;
  332. });
  333. const studyWhere = encodeURIComponent(JSON.stringify({ userId: memberLegacyId }));
  334. const studyRows = await jsonRequest(`${PARSE_URL}/classes/DailyStudyRecord?where=${studyWhere}&limit=1000`, {}, true).catch(() => ({ results: [] }));
  335. for (const row of studyRows.results || []) await jsonRequest(`${PARSE_URL}/classes/DailyStudyRecord/${row.objectId}`, { method: 'DELETE' }, true).catch((error) => {
  336. console.error(`临时学习 addon 清理失败:${error.message}`);
  337. process.exitCode = 1;
  338. });
  339. }
  340. if (temporaryAppointmentObjectId) await jsonRequest(`${PARSE_URL}/classes/CourseAppointment/${temporaryAppointmentObjectId}`, { method: 'DELETE' }, true).catch((error) => {
  341. console.error(`临时预约清理失败:${error.message}`);
  342. process.exitCode = 1;
  343. });
  344. if (temporaryAppointmentId) {
  345. const sideEffectWhere = encodeURIComponent(JSON.stringify({ sourceKey: { $regex: `^cloud:e_order_update:${temporaryAppointmentId}:` } }));
  346. for (const className of ['CommonModel', 'MemoryPracticeRecord', 'UserExpDomP', 'UserUserPoint']) {
  347. const rows = await jsonRequest(`${PARSE_URL}/classes/${className}?where=${sideEffectWhere}&limit=1000`, {}, true).catch(() => ({ results: [] }));
  348. for (const row of rows.results || []) await jsonRequest(`${PARSE_URL}/classes/${className}/${row.objectId}`, { method: 'DELETE' }, true).catch((error) => {
  349. console.error(`临时预约副作用清理失败(${className}):${error.message}`);
  350. process.exitCode = 1;
  351. });
  352. }
  353. }
  354. if (memberLegacyId) {
  355. const assessmentWhere = encodeURIComponent(JSON.stringify({ sourceKey: { $regex: `^cloud:content_add:${memberLegacyId}:` } }));
  356. const assessments = await jsonRequest(`${PARSE_URL}/classes/AssessmentProfile?where=${assessmentWhere}&limit=1000`, {}, true).catch(() => ({ results: [] }));
  357. for (const assessment of assessments.results || []) await jsonRequest(`${PARSE_URL}/classes/AssessmentProfile/${assessment.objectId}`, { method: 'DELETE' }, true).catch((error) => {
  358. console.error(`临时测评记录清理失败:${error.message}`);
  359. process.exitCode = 1;
  360. });
  361. }
  362. if (memberLegacyId) {
  363. const where = encodeURIComponent(JSON.stringify({ yhid: String(memberLegacyId) }));
  364. const practices = await jsonRequest(`${PARSE_URL}/classes/PracticeRecord?where=${where}&limit=1000`, {}, true).catch(() => ({ results: [] }));
  365. for (const practice of practices.results || []) await jsonRequest(`${PARSE_URL}/classes/PracticeRecord/${practice.objectId}`, { method: 'DELETE' }, true).catch((error) => {
  366. console.error(`临时学习进度清理失败:${error.message}`);
  367. process.exitCode = 1;
  368. });
  369. }
  370. if (teamChildId) {
  371. await jsonRequest(`${PARSE_URL}/users/${teamChildId}`, { method: 'DELETE' }, true).catch((error) => {
  372. console.error(`临时团队成员清理失败:${error.message}`);
  373. process.exitCode = 1;
  374. });
  375. }
  376. if (memberId) {
  377. await jsonRequest(`${PARSE_URL}/users/${memberId}`, { method: 'DELETE' }, true).catch((error) => {
  378. console.error(`临时普通用户清理失败:${error.message}`);
  379. process.exitCode = 1;
  380. });
  381. }
  382. if (coachId) {
  383. await jsonRequest(`${PARSE_URL}/users/${coachId}`, { method: 'DELETE' }, true).catch((error) => {
  384. console.error(`临时陪练用户清理失败:${error.message}`);
  385. process.exitCode = 1;
  386. });
  387. }
  388. if (userId) {
  389. await jsonRequest(`${PARSE_URL}/users/${userId}`, { method: 'DELETE' }, true).catch((error) => {
  390. console.error(`临时管理员清理失败:${error.message}`);
  391. process.exitCode = 1;
  392. });
  393. }
  394. }