smoke-admin-functions.mjs 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281
  1. #!/usr/bin/env node
  2. import { randomBytes } from 'node:crypto';
  3. import { readFile } from 'node:fs/promises';
  4. const APP_ID = process.env.XIAOSHU_PARSE_APP_ID || '7pIbDBJmKx_main';
  5. const MASTER_KEY = process.env.XIAOSHU_MASTER_KEY || '';
  6. const PARSE_URL = (process.env.XIAOSHU_PARSE_URL || 'https://server.xiaoshu.pro/parse').replace(/\/$/, '');
  7. const FUNCTION_URL = (process.env.XIAOSHU_FUNCTION_URL || 'https://server.xiaoshu.pro/api/functions').replace(/\/$/, '');
  8. if (!MASTER_KEY) throw new Error('缺少 XIAOSHU_MASTER_KEY');
  9. async function jsonRequest(url, init = {}, master = false) {
  10. const response = await fetch(url, {
  11. ...init,
  12. headers: {
  13. 'X-Parse-Application-Id': APP_ID,
  14. ...(master ? { 'X-Parse-Master-Key': MASTER_KEY } : {}),
  15. 'Content-Type': 'application/json',
  16. ...(init.headers || {}),
  17. },
  18. });
  19. const payload = await response.json().catch(() => ({}));
  20. if (!response.ok) {
  21. const detail = payload.message || payload.error || payload;
  22. throw new Error(`${response.status}: ${typeof detail === 'string' ? detail : JSON.stringify(detail)}`);
  23. }
  24. return payload;
  25. }
  26. async function callFunction(path, token, params) {
  27. const payload = await jsonRequest(`${FUNCTION_URL}/${path}`, {
  28. method: 'POST',
  29. body: JSON.stringify({ token, params }),
  30. });
  31. if (!payload.success) throw new Error(payload.message || `${path} 返回失败`);
  32. return payload.data;
  33. }
  34. async function callLegacyFunction(token, params, expectedStatus = 200) {
  35. const response = await fetch(`${FUNCTION_URL}/xiaoshu/app/gateway`, {
  36. method: 'POST',
  37. headers: { 'X-Parse-Application-Id': APP_ID, 'Content-Type': 'application/json' },
  38. body: JSON.stringify({ ...(token ? { token } : {}), params }),
  39. });
  40. const payload = await response.json().catch(() => ({}));
  41. if (response.status !== expectedStatus) throw new Error(`app gateway ${params.action} 期望 ${expectedStatus},实际 ${response.status}: ${payload.retmsg || payload.error || ''}`);
  42. return payload;
  43. }
  44. async function sourceActions() {
  45. const source = await readFile(new URL('../src/app/core/source-parity.generated.ts', import.meta.url), 'utf8');
  46. const match = source.match(/export const SOURCE_API_ACTIONS = (\[[\s\S]*?\]) as const;/);
  47. if (!match) throw new Error('无法读取 SOURCE_API_ACTIONS');
  48. return JSON.parse(match[1]);
  49. }
  50. let userId = '';
  51. let memberId = '';
  52. let memberLegacyId = 0;
  53. let coachId = '';
  54. let coachLegacyId = 0;
  55. let temporaryAppointmentId = '';
  56. const temporaryLessonIds = [];
  57. try {
  58. const sample = await jsonRequest(`${PARSE_URL}/classes/Company?limit=1&keys=objectId`, {}, true);
  59. const companyId = sample.results?.[0]?.objectId;
  60. if (!companyId) throw new Error('没有可用于帐套隔离测试的 Company');
  61. const company = { __type: 'Pointer', className: 'Company', objectId: companyId };
  62. const username = `codex_admin_smoke_${Date.now()}`;
  63. const password = randomBytes(24).toString('base64url');
  64. const created = await jsonRequest(`${PARSE_URL}/users`, {
  65. method: 'POST',
  66. body: JSON.stringify({ username, password, isAdmin: true, roles: ['admin'], company }),
  67. }, true);
  68. userId = created.objectId;
  69. const login = await jsonRequest(`${PARSE_URL}/login`, {
  70. method: 'POST',
  71. body: JSON.stringify({ username, password }),
  72. });
  73. if (!login.sessionToken) throw new Error('临时管理员登录未返回 sessionToken');
  74. const memberUsername = `codex_member_smoke_${Date.now()}`;
  75. const memberPassword = randomBytes(24).toString('base64url');
  76. memberLegacyId = 900000000 + Math.floor(Date.now() / 1000) % 90000000;
  77. const member = await jsonRequest(`${PARSE_URL}/users`, {
  78. method: 'POST',
  79. body: JSON.stringify({ username: memberUsername, password: memberPassword, legacyUserId: memberLegacyId, legacyGroupId: 1, company }),
  80. }, true);
  81. memberId = member.objectId;
  82. const coachUsername = `codex_coach_smoke_${Date.now()}`;
  83. const coachPassword = randomBytes(24).toString('base64url');
  84. coachLegacyId = memberLegacyId + 1;
  85. const coach = await jsonRequest(`${PARSE_URL}/users`, {
  86. method: 'POST',
  87. body: JSON.stringify({ username: coachUsername, password: coachPassword, legacyUserId: coachLegacyId, legacyGroupId: 3, company }),
  88. }, true);
  89. coachId = coach.objectId;
  90. for (const lessonType of [1, 2, 3]) {
  91. const lesson = await jsonRequest(`${PARSE_URL}/classes/LessonRecord`, {
  92. method: 'POST',
  93. body: JSON.stringify({ company, sourceKey: `cloud:smoke-lesson:${coachLegacyId}:${lessonType}`, jsmz: String(coachLegacyId), kclx: String(lessonType) }),
  94. }, true);
  95. temporaryLessonIds.push(lesson.objectId);
  96. }
  97. const createdAppointment = await jsonRequest(`${PARSE_URL}/classes/CourseAppointment`, {
  98. method: 'POST',
  99. body: JSON.stringify({ company, sourceKey: `cloud:smoke-appointment:${memberLegacyId}`, szyh: String(memberLegacyId), kcid: '16', dslx: '1', dszt: '30', pl: String(coachLegacyId) }),
  100. }, true);
  101. temporaryAppointmentId = createdAppointment.objectId;
  102. const memberLogin = await jsonRequest(`${PARSE_URL}/login`, {
  103. method: 'POST',
  104. body: JSON.stringify({ username: memberUsername, password: memberPassword }),
  105. });
  106. const coachLogin = await jsonRequest(`${PARSE_URL}/login`, {
  107. method: 'POST',
  108. body: JSON.stringify({ username: coachUsername, password: coachPassword }),
  109. });
  110. const meta = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'meta' });
  111. if (meta.identity?.objectId !== userId || !meta.cloudFunctions) throw new Error('管理员 meta 校验失败');
  112. const dashboard = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'dashboard' });
  113. if (!Array.isArray(dashboard.metrics) || dashboard.metrics.length !== 8) throw new Error('dashboard 指标校验失败');
  114. const schema = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'schema', className: 'CourseAppointment' });
  115. if (schema.className !== 'CourseAppointment' || !Array.isArray(schema.fields)) throw new Error('schema 校验失败');
  116. const page = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'list', className: 'CourseAppointment', page: 1, pageSize: 2 });
  117. if (!Array.isArray(page.results) || page.pageSize !== 2) throw new Error('资源分页校验失败');
  118. const normalized = await callFunction('xiaoshu/cms/content-normalizer', login.sessionToken, { content: '<p>中文&nbsp;<strong>内容</strong></p><script>alert(1)</script>' });
  119. if (normalized.content !== '中文 内容') throw new Error(`内容清理结果异常:${normalized.content}`);
  120. const exams = await callFunction('xiaoshu/cms/exams/classes', login.sessionToken, { page: 1, pageSize: 2 });
  121. if (!Array.isArray(exams.results)) throw new Error('考试班级投影校验失败');
  122. const guest = await callFunction('xiaoshu/cms/guest/bar', login.sessionToken, { page: 1, pageSize: 2 });
  123. if (!Array.isArray(guest.results)) throw new Error('互动社区投影校验失败');
  124. const migration = await callLegacyFunction('', { action: 'migration_status' });
  125. const sourceActionList = await sourceActions();
  126. const implementedActions = migration.result?.implemented || [];
  127. const blockedActions = Object.keys(migration.result?.blocked || {});
  128. const covered = new Set([...implementedActions, ...blockedActions]);
  129. const missing = sourceActionList.filter((action) => !covered.has(action));
  130. if (missing.length) throw new Error(`app gateway 迁移矩阵缺少:${missing.join(', ')}`);
  131. const sourceBlocked = blockedActions.filter((action) => sourceActionList.includes(action));
  132. const compatibilityActions = blockedActions.filter((action) => !sourceActionList.includes(action)).sort();
  133. if (implementedActions.length !== 29 || sourceBlocked.length !== 62) throw new Error(`app gateway 源 action 计数异常:${implementedActions.length} 已映射 / ${sourceBlocked.length} 阻塞`);
  134. if (compatibilityActions.join(',') !== 'content_add_zt,product_add,product_upd') throw new Error(`app gateway 兼容 action 计数异常:${compatibilityActions.join(',')}`);
  135. const content = await callLegacyFunction('', { action: 'content_list', page: 1, pageSize: 2 });
  136. if (!Array.isArray(content.result) || content.result.length !== 2 || Number(content.page?.itemCount) < 89000) throw new Error('公开内容分页校验失败');
  137. const contentExact = await callLegacyFunction('', { action: 'content_list', page: 1, pageSize: 1, objectId: content.result[0].objectId });
  138. if (contentExact.result?.[0]?.objectId !== content.result[0].objectId || contentExact.page?.itemCount !== 1) throw new Error('内容 objectId 精确查询校验失败');
  139. const contentDetail = await callLegacyFunction('', { action: 'content_get', id: content.result[0].objectId });
  140. if (contentDetail.result?.objectId !== content.result[0].objectId) throw new Error('内容详情 ID 校验失败');
  141. const words = await callLegacyFunction('', { action: 'content_list', modelId: 52, page: 1, pageSize: 1 });
  142. if (Number(words.page?.itemCount) < 89000 || !words.result?.[0]?.GeneralID || words.result?.[0]?.sy === undefined) throw new Error('词库 addon 联表校验失败');
  143. const privateContent = await callLegacyFunction('', { action: 'content_list', modelId: 56, page: 1, pageSize: 1 }, 401);
  144. if (!String(privateContent.retmsg).includes('登录')) throw new Error('学习记录未阻止匿名访问');
  145. const learning = await callLegacyFunction(login.sessionToken, { action: 'content_list', modelId: 56, page: 1, pageSize: 1 });
  146. if (!learning.result?.[0]?.GeneralID || learning.result?.[0]?.xxqs === undefined) throw new Error('学习记录 addon 联表校验失败');
  147. const recordDetail = await callLegacyFunction(login.sessionToken, { action: 'e_record_detail', id: learning.result[0].GeneralID });
  148. if (!Array.isArray(recordDetail.result) || !recordDetail.result.length || !recordDetail.result[0]?.detail?.[0]?.Title) throw new Error('学习记录单词详情联查校验失败');
  149. const appointments = await callLegacyFunction(login.sessionToken, { action: 'content_list', modelId: 54, page: 1, pageSize: 1 });
  150. const appointment = await callLegacyFunction(login.sessionToken, { action: 'e_order_detail', id: appointments.result?.[0]?.GeneralID });
  151. if (!appointment.result?.[0]?.GeneralID || appointment.result[0].kcid === undefined) throw new Error('预约详情联查校验失败');
  152. const newWords = await callLegacyFunction(login.sessionToken, { action: 'e_words_list', uid: 58, page: 1, pageSize: 2 });
  153. if (Number(newWords.page?.itemCount) < 1 || !newWords.result?.[0]?.detail?.[0]?.Title) throw new Error('用户生词联查校验失败');
  154. const courseWords = await callLegacyFunction(login.sessionToken, { action: 'e_ck_list', uid: 58, nids: 40, page: 1, pageSize: 1000 });
  155. const learnedWord = courseWords.result?.find((word) => Number(word.GeneralID) === 2505);
  156. if (Number(courseWords.page?.itemCount) < 1 || !courseWords.result?.[0]?.detail?.Title || Number(learnedWord?.w_learned) !== 7) throw new Error('课程词库学习进度联查校验失败');
  157. const memory = await callLegacyFunction(login.sessionToken, { action: 'e_get_21list', uid: 58, page: 1, pageSize: 2 });
  158. if (Number(memory.page?.itemCount) < 1 || !memory.result?.[0]?.GeneralID || memory.result[0].learned === undefined) throw new Error('21 天抗遗忘联查校验失败');
  159. const incomeBlocked = await callLegacyFunction(login.sessionToken, { action: 'e_get_21list_tj', uid: 58 }, 501);
  160. if (!String(incomeBlocked.retmsg).includes('计价规则')) throw new Error('复习收入缺失规则未显式阻塞');
  161. const ownEmpty = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_list', modelId: 56, myfield2: `UserId=${memberLegacyId}`, page: 1, pageSize: 1 });
  162. if (!Array.isArray(ownEmpty.result) || ownEmpty.page?.itemCount !== 0) throw new Error('普通用户本人记录权限校验失败');
  163. const ownCourseWords = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_ck_list', uid: memberLegacyId, nids: 40, page: 1, pageSize: 1 });
  164. if (!Array.isArray(ownCourseWords.result) || ownCourseWords.result[0]?.w_learned !== 0) throw new Error('普通用户本人课程词库权限校验失败');
  165. const learnedWrite = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_add_words', uid: memberLegacyId, wordsId: '2505', kcid: 16, save: 1 });
  166. if (learnedWrite.result?.created !== 1 || learnedWrite.result?.learnedIncremented !== 1) throw new Error('首次学习词进度写入校验失败');
  167. const learnedRead = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_ck_list', uid: memberLegacyId, nids: 40, page: 1, pageSize: 1000 });
  168. if (Number(learnedRead.result?.find((word) => Number(word.GeneralID) === 2505)?.w_learned) !== 1) throw new Error('学习次数写后读校验失败');
  169. await callLegacyFunction(memberLogin.sessionToken, { action: 'e_add_words', uid: memberLegacyId, wordsId: '2505', kcid: 16, ifnew: 1 });
  170. const addedNewWord = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_words_list', uid: memberLegacyId, page: 1, pageSize: 10 });
  171. if (addedNewWord.page?.itemCount !== 1 || Number(addedNewWord.result?.[0]?.detail?.[0]?.GeneralID) !== 2505) throw new Error('加入生词写后读校验失败');
  172. await callLegacyFunction(memberLogin.sessionToken, { action: 'e_add_words', uid: memberLegacyId, wordsId: '2505', kcid: 16, ifnew: 0 });
  173. const removedNewWord = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_words_list', uid: memberLegacyId, page: 1, pageSize: 10 });
  174. if (removedNewWord.page?.itemCount !== 0) throw new Error('移出生词写后读校验失败');
  175. const studyAddon = { con: '云函数学习记录冒烟测试', dqrq: '20260818', UserID: memberLegacyId, learned: 1, ygg: 0, djq: 0, xxqs: JSON.stringify([{ GeneralID: 2505, Title: 'woman', check: 0 }]) };
  176. const createdStudy = await callLegacyFunction(memberLogin.sessionToken, { action: 'stu_record_update_v2', orderId: temporaryAppointmentId, uid: memberLegacyId, inputer: memberUsername, addon: JSON.stringify(studyAddon) });
  177. if (!createdStudy.result?.created || !createdStudy.result?.GeneralID || !createdStudy.result?.recordObjectId) throw new Error('预约学习记录首次双表写入校验失败');
  178. const studyDetail = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_record_detail', id: createdStudy.result.GeneralID });
  179. if (studyDetail.result?.[0]?.detail?.[0]?.Title !== 'woman') throw new Error('预约学习记录写后详情校验失败');
  180. studyAddon.xxqs = JSON.stringify([{ GeneralID: 2505, Title: 'woman', check: 1 }]);
  181. const updatedStudy = await callLegacyFunction(memberLogin.sessionToken, { action: 'stu_record_update_v2', orderId: temporaryAppointmentId, uid: memberLegacyId, inputer: memberUsername, addon: JSON.stringify(studyAddon) });
  182. if (updatedStudy.result?.created || updatedStudy.result?.GeneralID !== createdStudy.result.GeneralID) throw new Error('预约学习记录幂等更新校验失败');
  183. const studyList = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_list', modelId: 56, myfield2: `UserId=${memberLegacyId}|dsid=${temporaryAppointmentId}`, page: 1, pageSize: 2 });
  184. if (studyList.page?.itemCount !== 1 || Number(studyList.result?.[0]?.ygg) !== 1 || Number(studyList.result?.[0]?.learned) !== 1) throw new Error('预约学习记录聚合字段写后读校验失败');
  185. const blockedOrderUpdate = await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_update_v2', uid: coachLegacyId, status: 10, content: JSON.stringify({ GeneralID: temporaryAppointmentId }) }, 501);
  186. if (!String(blockedOrderUpdate.retmsg).includes('课时')) throw new Error('预约状态写入未显式阻塞隐藏副作用');
  187. const coachStats = await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_tongji', uid: coachLegacyId });
  188. if (coachStats.result?.t30 !== '1' || coachStats.result?.t60 !== '1' || coachStats.result?.t_tiyan !== '1' || coachStats.result?.t_total !== '3' || coachStats.result?.t_shichang !== '2.5' || coachStats.result?.t_yongji !== '100') throw new Error('陪练预约统计公式校验失败');
  189. const memberStats = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_order_tongji', uid: memberLegacyId });
  190. if (memberStats.result?.t30 !== '1' || memberStats.result?.t60 !== '0' || memberStats.result?.t_tiyan !== '0' || memberStats.result?.t_total !== '1' || memberStats.result?.t_shichang !== '0.5' || memberStats.result?.t_yongji !== '0') throw new Error(`学员预约与生词统计公式校验失败:${JSON.stringify(memberStats.result)}`);
  191. const deniedCourseWords = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_ck_list', uid: 58, nids: 40, page: 1, pageSize: 1 }, 403);
  192. if (!String(deniedCourseWords.retmsg).includes('无权')) throw new Error('普通用户跨用户课程词库未被拒绝');
  193. const denied = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_list', modelId: 56, myfield2: 'UserId=3', page: 1, pageSize: 1 }, 403);
  194. if (!String(denied.retmsg).includes('无权')) throw new Error('普通用户跨用户记录未被拒绝');
  195. const profile = await callLegacyFunction(login.sessionToken, { action: 'user_get' });
  196. if (profile.retcode !== 0 || profile.result?.objectId !== userId) throw new Error('app gateway 用户会话校验失败');
  197. const blocked = await callLegacyFunction('', { action: 'cart_list' }, 501);
  198. if (!String(blocked.retmsg).startsWith('migration_blocked:')) throw new Error('阻塞接口未返回 migration_blocked');
  199. console.log('Cloud smoke passed: admin auth/tenant/CRUD reads, CMS projections, normalized learning joins, app action coverage, public content, session scope, explicit blocked APIs.');
  200. } finally {
  201. for (const lessonId of temporaryLessonIds) await jsonRequest(`${PARSE_URL}/classes/LessonRecord/${lessonId}`, { method: 'DELETE' }, true).catch((error) => {
  202. console.error(`临时陪练课次清理失败:${error.message}`);
  203. process.exitCode = 1;
  204. });
  205. if (memberLegacyId) {
  206. const commonWhere = encodeURIComponent(JSON.stringify({ sourceKey: { $regex: `^cloud:stu_record:${memberLegacyId}:` } }));
  207. const commonRows = await jsonRequest(`${PARSE_URL}/classes/CommonModel?where=${commonWhere}&limit=1000`, {}, true).catch(() => ({ results: [] }));
  208. for (const row of commonRows.results || []) await jsonRequest(`${PARSE_URL}/classes/CommonModel/${row.objectId}`, { method: 'DELETE' }, true).catch((error) => {
  209. console.error(`临时学习主记录清理失败:${error.message}`);
  210. process.exitCode = 1;
  211. });
  212. const studyWhere = encodeURIComponent(JSON.stringify({ userId: memberLegacyId }));
  213. const studyRows = await jsonRequest(`${PARSE_URL}/classes/DailyStudyRecord?where=${studyWhere}&limit=1000`, {}, true).catch(() => ({ results: [] }));
  214. for (const row of studyRows.results || []) await jsonRequest(`${PARSE_URL}/classes/DailyStudyRecord/${row.objectId}`, { method: 'DELETE' }, true).catch((error) => {
  215. console.error(`临时学习 addon 清理失败:${error.message}`);
  216. process.exitCode = 1;
  217. });
  218. }
  219. if (temporaryAppointmentId) await jsonRequest(`${PARSE_URL}/classes/CourseAppointment/${temporaryAppointmentId}`, { method: 'DELETE' }, true).catch((error) => {
  220. console.error(`临时预约清理失败:${error.message}`);
  221. process.exitCode = 1;
  222. });
  223. if (memberLegacyId) {
  224. const where = encodeURIComponent(JSON.stringify({ yhid: String(memberLegacyId) }));
  225. const practices = await jsonRequest(`${PARSE_URL}/classes/PracticeRecord?where=${where}&limit=1000`, {}, true).catch(() => ({ results: [] }));
  226. for (const practice of practices.results || []) await jsonRequest(`${PARSE_URL}/classes/PracticeRecord/${practice.objectId}`, { method: 'DELETE' }, true).catch((error) => {
  227. console.error(`临时学习进度清理失败:${error.message}`);
  228. process.exitCode = 1;
  229. });
  230. }
  231. if (memberId) {
  232. await jsonRequest(`${PARSE_URL}/users/${memberId}`, { method: 'DELETE' }, true).catch((error) => {
  233. console.error(`临时普通用户清理失败:${error.message}`);
  234. process.exitCode = 1;
  235. });
  236. }
  237. if (coachId) {
  238. await jsonRequest(`${PARSE_URL}/users/${coachId}`, { method: 'DELETE' }, true).catch((error) => {
  239. console.error(`临时陪练用户清理失败:${error.message}`);
  240. process.exitCode = 1;
  241. });
  242. }
  243. if (userId) {
  244. await jsonRequest(`${PARSE_URL}/users/${userId}`, { method: 'DELETE' }, true).catch((error) => {
  245. console.error(`临时管理员清理失败:${error.message}`);
  246. process.exitCode = 1;
  247. });
  248. }
  249. }