smoke-admin-functions.mjs 58 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582
  1. #!/usr/bin/env node
  2. import { randomBytes } from 'node:crypto';
  3. import { readFile } from 'node:fs/promises';
  4. const APP_ID = process.env.XIAOSHU_PARSE_APP_ID || '7pIbDBJmKx_main';
  5. const MASTER_KEY = process.env.XIAOSHU_MASTER_KEY || '';
  6. const PARSE_URL = (process.env.XIAOSHU_PARSE_URL || 'https://server.xiaoshu.pro/parse').replace(/\/$/, '');
  7. const FUNCTION_URL = (process.env.XIAOSHU_FUNCTION_URL || 'https://server.xiaoshu.pro/api/functions').replace(/\/$/, '');
  8. if (!MASTER_KEY) throw new Error('缺少 XIAOSHU_MASTER_KEY');
  9. async function jsonRequest(url, init = {}, master = false) {
  10. const response = await fetch(url, {
  11. ...init,
  12. headers: {
  13. 'X-Parse-Application-Id': APP_ID,
  14. ...(master ? { 'X-Parse-Master-Key': MASTER_KEY } : {}),
  15. 'Content-Type': 'application/json',
  16. ...(init.headers || {}),
  17. },
  18. });
  19. const payload = await response.json().catch(() => ({}));
  20. if (!response.ok) {
  21. const detail = payload.message || payload.error || payload;
  22. throw new Error(`${response.status}: ${typeof detail === 'string' ? detail : JSON.stringify(detail)}`);
  23. }
  24. return payload;
  25. }
  26. async function callFunction(path, token, params) {
  27. const payload = await jsonRequest(`${FUNCTION_URL}/${path}`, {
  28. method: 'POST',
  29. body: JSON.stringify({ token, params }),
  30. });
  31. if (!payload.success) throw new Error(payload.message || `${path} 返回失败`);
  32. return payload.data;
  33. }
  34. async function callFunctionError(path, token, params, expectedStatus) {
  35. const response = await fetch(`${FUNCTION_URL}/${path}`, {
  36. method: 'POST',
  37. headers: { 'X-Parse-Application-Id': APP_ID, 'Content-Type': 'application/json' },
  38. body: JSON.stringify({ token, params }),
  39. });
  40. const payload = await response.json().catch(() => ({}));
  41. if (response.status !== expectedStatus || payload.success !== false) throw new Error(`${path} 期望 ${expectedStatus} 失败,实际 ${response.status}: ${payload.message || payload.error || ''}`);
  42. return payload;
  43. }
  44. async function callLegacyFunction(token, params, expectedStatus = 200) {
  45. const response = await fetch(`${FUNCTION_URL}/xiaoshu/app/gateway`, {
  46. method: 'POST',
  47. headers: { 'X-Parse-Application-Id': APP_ID, 'Content-Type': 'application/json' },
  48. body: JSON.stringify({ ...(token ? { token } : {}), params }),
  49. });
  50. const payload = await response.json().catch(() => ({}));
  51. if (response.status !== expectedStatus) throw new Error(`app gateway ${params.action} 期望 ${expectedStatus},实际 ${response.status}: ${payload.retmsg || payload.error || ''}`);
  52. return payload;
  53. }
  54. async function sourceActions() {
  55. const source = await readFile(new URL('../src/app/core/source-parity.generated.ts', import.meta.url), 'utf8');
  56. const match = source.match(/export const SOURCE_API_ACTIONS = (\[[\s\S]*?\]) as const;/);
  57. if (!match) throw new Error('无法读取 SOURCE_API_ACTIONS');
  58. return JSON.parse(match[1]);
  59. }
  60. let userId = '';
  61. let adminCreatedUserId = '';
  62. let temporaryGroupObjectId = '';
  63. const temporaryNodeObjectIds = [];
  64. const temporarySpecialObjectIds = [];
  65. let temporaryModelObjectId = '';
  66. const temporaryModelFieldObjectIds = [];
  67. let registeredUserId = '';
  68. let memberId = '';
  69. let memberLegacyId = 0;
  70. let teamChildId = '';
  71. let coachId = '';
  72. let coachLegacyId = 0;
  73. let temporaryAppointmentId = '';
  74. let temporaryAppointmentObjectId = '';
  75. let temporaryGuestbookId = '';
  76. let contentHitObjectId = '';
  77. let contentHitOriginal = 0;
  78. const temporaryLessonIds = [];
  79. try {
  80. const sample = await jsonRequest(`${PARSE_URL}/classes/Company?limit=1&keys=objectId`, {}, true);
  81. const companyId = sample.results?.[0]?.objectId;
  82. if (!companyId) throw new Error('没有可用于帐套隔离测试的 Company');
  83. const company = { __type: 'Pointer', className: 'Company', objectId: companyId };
  84. const username = `codex_admin_smoke_${Date.now()}`;
  85. const password = randomBytes(24).toString('base64url');
  86. const created = await jsonRequest(`${PARSE_URL}/users`, {
  87. method: 'POST',
  88. body: JSON.stringify({ username, password, isAdmin: true, roles: ['admin'], company }),
  89. }, true);
  90. userId = created.objectId;
  91. const login = await jsonRequest(`${PARSE_URL}/login`, {
  92. method: 'POST',
  93. body: JSON.stringify({ username, password }),
  94. });
  95. if (!login.sessionToken) throw new Error('临时管理员登录未返回 sessionToken');
  96. const registeredUsername = `codex_register_smoke_${Date.now()}`;
  97. const registered = await callLegacyFunction('', { action: 'user_register', name: registeredUsername, passwd: 'Ab1234' });
  98. registeredUserId = String(registered.result?.objectId || '');
  99. const registeredLegacyId = Number(registered.result?.userId);
  100. if (!registeredUserId || !registeredLegacyId || !registered.result?.sessionToken || Number(registered.result?.groupId) !== 1 || Number(registered.addon?.parentUserId) !== 0) throw new Error(`新用户注册基础字段异常:${JSON.stringify(registered)}`);
  101. const registeredInfo = await callLegacyFunction(registered.result.sessionToken, { action: 'user_get', uid: registeredLegacyId });
  102. if (Number(registeredInfo.result?.userId) !== registeredLegacyId || Number(registeredInfo.result?.groupId) !== 1 || Number(registeredInfo.addon?.Purse) !== 0 || Number(registeredInfo.addon?.UserPoint) !== 0) throw new Error('新用户注册后自查异常');
  103. const registeredByName = await callLegacyFunction('', { action: 'user_info_name', uname: registeredUsername });
  104. if (registeredByName.result?.objectId !== registeredUserId) throw new Error('新用户用户名查重异常');
  105. await jsonRequest(`${PARSE_URL}/users/${registeredUserId}`, { method: 'DELETE' }, true);
  106. registeredUserId = '';
  107. const memberUsername = `codex_member_smoke_${Date.now()}`;
  108. const memberPassword = randomBytes(24).toString('base64url');
  109. memberLegacyId = 900000000 + Math.floor(Date.now() / 1000) % 90000000;
  110. const member = await jsonRequest(`${PARSE_URL}/users`, {
  111. method: 'POST',
  112. body: JSON.stringify({ username: memberUsername, password: memberPassword, legacyUserId: memberLegacyId, legacyGroupId: 1, legacyUserData: { UserID: memberLegacyId, UserName: memberUsername, HoneyName: '冒烟学员', GroupID: 1, ParentUserID: 0, VIP: 2, Purse: 2, SilverCoin: 2, UserExp: 2, UserPoint: 2 }, company }),
  113. }, true);
  114. memberId = member.objectId;
  115. const childLegacyId = memberLegacyId + 2;
  116. const child = await jsonRequest(`${PARSE_URL}/users`, {
  117. method: 'POST',
  118. body: JSON.stringify({ username: `codex_team_child_${Date.now()}`, password: randomBytes(24).toString('base64url'), legacyUserId: childLegacyId, legacyGroupId: 3, legacyUserData: { UserID: childLegacyId, UserName: `team_child_${childLegacyId}`, HoneyName: '冒烟团队成员', GroupID: 3, ParentUserID: memberLegacyId, VIP: 3, UserExp: 5, UserPwd: 'must-not-leak' }, company }),
  119. }, true);
  120. teamChildId = child.objectId;
  121. const coachUsername = `codex_coach_smoke_${Date.now()}`;
  122. const coachPassword = randomBytes(24).toString('base64url');
  123. coachLegacyId = memberLegacyId + 1;
  124. const coach = await jsonRequest(`${PARSE_URL}/users`, {
  125. method: 'POST',
  126. body: JSON.stringify({ username: coachUsername, password: coachPassword, legacyUserId: coachLegacyId, legacyGroupId: 3, company }),
  127. }, true);
  128. coachId = coach.objectId;
  129. for (const lessonType of [1, 2, 3]) {
  130. const lesson = await jsonRequest(`${PARSE_URL}/classes/LessonRecord`, {
  131. method: 'POST',
  132. body: JSON.stringify({ company, sourceKey: `cloud:smoke-lesson:${coachLegacyId}:${lessonType}`, jsmz: String(coachLegacyId), kclx: String(lessonType) }),
  133. }, true);
  134. temporaryLessonIds.push(lesson.objectId);
  135. }
  136. const memberLogin = await jsonRequest(`${PARSE_URL}/login`, {
  137. method: 'POST',
  138. body: JSON.stringify({ username: memberUsername, password: memberPassword }),
  139. });
  140. const coachLogin = await jsonRequest(`${PARSE_URL}/login`, {
  141. method: 'POST',
  142. body: JSON.stringify({ username: coachUsername, password: coachPassword }),
  143. });
  144. const feedbackModel = { UserID: memberLegacyId, Title: '冒烟学员 反馈的意见', TContent: '2026-08-19 请假一天', Cateid: 22 };
  145. const feedback = await callLegacyFunction(memberLogin.sessionToken, { action: 'guestbook_add', model: JSON.stringify(feedbackModel) });
  146. temporaryGuestbookId = String(feedback.result?.objectId || '');
  147. if (!temporaryGuestbookId || Number(feedback.result?.UserID) !== memberLegacyId || feedback.result?.Title !== feedbackModel.Title || feedback.result?.TContent !== feedbackModel.TContent || Number(feedback.result?.Cateid) !== 22) throw new Error(`旧版 model 留言写入异常:${JSON.stringify(feedback)}`);
  148. await callLegacyFunction(memberLogin.sessionToken, { action: 'guestbook_add', model: JSON.stringify({ ...feedbackModel, UserID: coachLegacyId }) }, 403);
  149. const profileModel = { honeyName: '冒烟资料更新', trueName: '测试学员', userFace: '/UploadFiles/smoke-avatar.png', sex: '女', birthday: '2000-01-02', mobile: '13800138000', Email: `${memberUsername}@example.test`, seturl: '/member/smoke', Position: '词汇小英雄' };
  150. const updatedProfile = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_update', uid: memberLegacyId, mu: JSON.stringify(profileModel), inviCode: '' });
  151. if (updatedProfile.result?.honeyName !== profileModel.honeyName || updatedProfile.result?.userFace !== profileModel.userFace || updatedProfile.result?.email !== profileModel.Email || updatedProfile.result?.seturl !== profileModel.seturl) throw new Error(`旧版 mu 用户资料更新异常:${JSON.stringify(updatedProfile)}`);
  152. await callLegacyFunction(memberLogin.sessionToken, { action: 'user_update', uid: coachLegacyId, mu: JSON.stringify({ honeyName: '越权' }) }, 403);
  153. await callLegacyFunction(memberLogin.sessionToken, { action: 'user_update_pwd', uid: memberLegacyId, vcode: '123456', newPass: 'Ab1234', reNewPass: 'Ab1234' }, 501);
  154. await callLegacyFunction(memberLogin.sessionToken, { action: 'user_update_pwdall', uid: memberLegacyId, login: 'Ab1234', pay: '123456' }, 501);
  155. const createdAppointment = await callLegacyFunction(login.sessionToken, { action: 'content_add', content: JSON.stringify({ ModelID: 54, nodeId: 29, inputer: coachUsername, status: 99, title: memberUsername }), addon: JSON.stringify({ szyh: memberLegacyId, kcid: 16, dslx: 1, dszt: 0, pl: coachLegacyId, fxpl: coachLegacyId, sdsd: '19:00' }) });
  156. temporaryAppointmentId = String(createdAppointment.result);
  157. const appointmentSourceKey = `cloud:content_add:${memberLegacyId}:${temporaryAppointmentId}`;
  158. const appointmentWhere = encodeURIComponent(JSON.stringify({ sourceKey: appointmentSourceKey }));
  159. const appointmentRows = await jsonRequest(`${PARSE_URL}/classes/CourseAppointment?where=${appointmentWhere}&limit=1`, {}, true);
  160. temporaryAppointmentObjectId = appointmentRows.results?.[0]?.objectId || '';
  161. if (!temporaryAppointmentObjectId) throw new Error('临时预约副表创建失败');
  162. const appointmentCommonRows = await jsonRequest(`${PARSE_URL}/classes/CommonModel?where=${appointmentWhere}&limit=1`, {}, true);
  163. const temporaryAppointmentCommonObjectId = String(appointmentCommonRows.results?.[0]?.objectId || '');
  164. if (!temporaryAppointmentCommonObjectId) throw new Error('临时预约主内容创建失败');
  165. const meta = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'meta' });
  166. if (meta.identity?.objectId !== userId || !meta.cloudFunctions) throw new Error('管理员 meta 校验失败');
  167. const dashboard = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'dashboard' });
  168. if (!Array.isArray(dashboard.metrics) || dashboard.metrics.length !== 8) throw new Error('dashboard 指标校验失败');
  169. const catalog = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'catalog' });
  170. if (!Array.isArray(catalog.resources) || catalog.resources.length < 90 || catalog.resources.some((item) => ['_Session', 'Function'].includes(item.className))) throw new Error('后台规范化类目录校验失败');
  171. const managedUsername = `codex_admin_created_${Date.now()}`;
  172. const managedPassword = randomBytes(24).toString('base64url');
  173. const managed = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'createUser', username: managedUsername, password: managedPassword, displayName: '后台开户冒烟', mobile: '13800138001', isAdmin: true, roles: ['admin'] });
  174. adminCreatedUserId = String(managed.objectId || '');
  175. if (!adminCreatedUserId || !Number(managed.userId) || Number(managed.groupId) !== 1 || managed.isAdmin === true || managed.roles?.includes?.('admin') || managed.sessionToken) throw new Error(`管理员开户响应异常:${JSON.stringify(managed)}`);
  176. const managedStored = await jsonRequest(`${PARSE_URL}/users/${adminCreatedUserId}`, {}, true);
  177. if (managedStored.username !== managedUsername || managedStored.isAdmin === true || managedStored.roles?.includes?.('admin') || Number(managedStored.legacyUserId) !== Number(managed.userId) || Number(managedStored.legacyGroupId) !== 1 || Number(managedStored.legacyUserData?.UserID) !== Number(managed.userId) || Number(managedStored.legacyUserData?.Purse) !== 0) throw new Error('管理员开户持久化约束校验失败');
  178. const managedLogin = await jsonRequest(`${PARSE_URL}/login`, { method: 'POST', body: JSON.stringify({ username: managedUsername, password: managedPassword }) });
  179. if (!managedLogin.sessionToken) throw new Error('后台开户用户登录失败');
  180. const locked = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'userBatch', className: '_User', action: 'lock', objectIds: [adminCreatedUserId], reason: '云函数冒烟' });
  181. if (locked.updated !== 1 || locked.results?.[0]?.isDisabled !== true || Number(locked.results?.[0]?.legacyUserData?.State) !== 0 || Number(locked.revokedSessions) < 1) throw new Error(`用户停用与会话撤销异常:${JSON.stringify(locked)}`);
  182. await callLegacyFunction('', { action: 'user_login_passwd', name: managedUsername, passwd: managedPassword }, 403);
  183. const unlocked = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'userBatch', className: '_User', action: 'unlock', objectIds: [adminCreatedUserId], reason: '恢复冒烟用户' });
  184. if (unlocked.updated !== 1 || unlocked.results?.[0]?.isDisabled !== false || Number(unlocked.results?.[0]?.legacyUserData?.State) !== 1) throw new Error(`用户解锁异常:${JSON.stringify(unlocked)}`);
  185. const temporaryGroup = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'saveGroup', className: 'Group', fields: { groupName: '云函数冒烟临时组', description: '验证帐套内原子组编号', parentGroupId: 0, regSelect: false } });
  186. temporaryGroupObjectId = String(temporaryGroup.objectId || '');
  187. const temporaryGroupNumber = Number(temporaryGroup.groupId);
  188. if (!temporaryGroupObjectId || !temporaryGroupNumber) throw new Error('临时用户组创建失败');
  189. const moved = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'userBatch', className: '_User', action: 'move', objectIds: [adminCreatedUserId], groupId: temporaryGroupNumber });
  190. if (moved.updated !== 1 || Number(moved.results?.[0]?.legacyGroupId) !== temporaryGroupNumber || Number(moved.results?.[0]?.legacyUserData?.GroupID) !== temporaryGroupNumber) throw new Error(`用户组同步异常:${JSON.stringify(moved)}`);
  191. const groupDeleteBlocked = await callFunctionError('xiaoshu/admin/gateway', login.sessionToken, { operation: 'delete', className: 'Group', objectId: temporaryGroupObjectId }, 409);
  192. if (!String(groupDeleteBlocked.message).includes('仍有用户')) throw new Error('用户组引用删除保护未返回明确原因');
  193. const managedAppLogin = await callLegacyFunction('', { action: 'user_login_passwd', name: managedUsername, passwd: managedPassword });
  194. if (!managedAppLogin.result?.sessionToken || Number(managedAppLogin.addon?.State) !== 1) throw new Error('解锁后旧版登录异常');
  195. await jsonRequest(`${PARSE_URL}/users/${adminCreatedUserId}`, { method: 'DELETE' }, true);
  196. adminCreatedUserId = '';
  197. const deletedGroup = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'delete', className: 'Group', objectId: temporaryGroupObjectId });
  198. if (deletedGroup.objectId !== temporaryGroupObjectId) throw new Error('无引用用户组删除失败');
  199. temporaryGroupObjectId = '';
  200. const schema = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'schema', className: 'CourseAppointment' });
  201. if (schema.className !== 'CourseAppointment' || !Array.isArray(schema.fields)) throw new Error('schema 校验失败');
  202. const contentSchema = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'schema', className: 'CommonModel' });
  203. const contentFieldMap = Object.fromEntries((contentSchema.fields || []).map((field) => [field.name, field]));
  204. if (contentSchema.creatable !== false || contentFieldMap.status?.writable !== false || contentFieldMap.modelId?.writable !== false || contentFieldMap.itemId?.writable !== false || contentFieldMap.nodeId?.writable !== false) throw new Error('内容结构字段未从通用创建/编辑中隔离');
  205. const nodeSchema = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'schema', className: 'Node' });
  206. const nodeFieldMap = Object.fromEntries((nodeSchema.fields || []).map((field) => [field.name, field]));
  207. if (nodeFieldMap.nodeId?.writable !== false || nodeFieldMap.parentId?.writable !== false || nodeFieldMap.depth?.writable !== false || nodeFieldMap.zstatus?.writable !== false || nodeFieldMap.sourceKey?.writable !== false) throw new Error('栏目结构字段未从通用编辑中隔离');
  208. await callFunctionError('xiaoshu/admin/gateway', login.sessionToken, { operation: 'save', className: 'Node', fields: { nodeName: '禁止通用新增' } }, 400);
  209. const nodeSuffix = Date.now().toString(36);
  210. const rootNode = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'saveNode', className: 'Node', parentId: 0, fields: { nodeName: `云函数冒烟栏目-${nodeSuffix}`, nodeDir: `smoke-${nodeSuffix}`, nodeType: 1, contentModel: '54' } });
  211. temporaryNodeObjectIds.push(String(rootNode.objectId || ''));
  212. const rootNodeId = Number(rootNode.nodeId);
  213. if (!temporaryNodeObjectIds[0] || !rootNodeId || Number(rootNode.parentId) !== 0 || Number(rootNode.depth) !== 1 || rootNode.sourceKey !== `[["NodeID",${rootNodeId}]]`) throw new Error(`栏目原子创建异常:${JSON.stringify(rootNode)}`);
  214. const childNode = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'saveNode', className: 'Node', parentId: rootNodeId, fields: { nodeName: `云函数冒烟子栏目-${nodeSuffix}`, nodeDir: `smoke-child-${nodeSuffix}`, nodeType: 1, contentModel: '54' } });
  215. temporaryNodeObjectIds.push(String(childNode.objectId || ''));
  216. const childNodeId = Number(childNode.nodeId);
  217. if (!temporaryNodeObjectIds[1] || !childNodeId || Number(childNode.parentId) !== rootNodeId || Number(childNode.depth) !== 2) throw new Error(`子栏目层级创建异常:${JSON.stringify(childNode)}`);
  218. const duplicateNode = await callFunctionError('xiaoshu/admin/gateway', login.sessionToken, { operation: 'saveNode', className: 'Node', parentId: 0, fields: { nodeName: `云函数冒烟栏目-${nodeSuffix}`, nodeDir: `another-${nodeSuffix}` } }, 409);
  219. if (!String(duplicateNode.message).includes('不能重复')) throw new Error('栏目同级重名保护未返回明确原因');
  220. const cycleNode = await callFunctionError('xiaoshu/admin/gateway', login.sessionToken, { operation: 'saveNode', className: 'Node', objectId: rootNode.objectId, parentId: childNodeId, fields: { ...rootNode, nodeName: rootNode.nodeName, nodeDir: rootNode.nodeDir } }, 409);
  221. if (!String(cycleNode.message).includes('自身或其下级')) throw new Error('栏目层级循环保护未返回明确原因');
  222. const movedNode = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'nodeBatch', className: 'Node', action: 'move', objectIds: [childNode.objectId], parentId: 0 });
  223. if (movedNode.updated !== 1 || Number(movedNode.results?.[0]?.parentId) !== 0) throw new Error('栏目批量迁移失败');
  224. const recycledNode = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'nodeBatch', className: 'Node', action: 'recycle', objectIds: [rootNode.objectId] });
  225. if (Number(recycledNode.results?.[0]?.zstatus) !== -2) throw new Error('栏目回收站状态更新失败');
  226. const recoveredNode = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'nodeBatch', className: 'Node', action: 'recover', objectIds: [rootNode.objectId] });
  227. if (Number(recoveredNode.results?.[0]?.zstatus) !== 99) throw new Error('栏目回收站恢复失败');
  228. await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'nodeBatch', className: 'Node', action: 'purge', objectIds: [childNode.objectId] });
  229. temporaryNodeObjectIds.pop();
  230. await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'nodeBatch', className: 'Node', action: 'purge', objectIds: [rootNode.objectId] });
  231. temporaryNodeObjectIds.pop();
  232. const specialSuffix = Date.now().toString(36);
  233. const rootSpecial = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'saveSpecial', className: 'Special', pid: 0, fields: { specName: `云函数冒烟专题-${specialSuffix}`, specDir: `special-${specialSuffix}`, specCate: 0, specDesc: '专题生命周期验证' } });
  234. temporarySpecialObjectIds.push(String(rootSpecial.objectId || ''));
  235. const rootSpecId = Number(rootSpecial.specId);
  236. if (!temporarySpecialObjectIds[0] || !rootSpecId || Number(rootSpecial.pid) !== 0 || rootSpecial.sourceKey !== `[["SpecID",${rootSpecId}]]`) throw new Error(`专题原子创建异常:${JSON.stringify(rootSpecial)}`);
  237. const childSpecial = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'saveSpecial', className: 'Special', pid: rootSpecId, fields: { specName: `云函数冒烟子专题-${specialSuffix}`, specDir: `special-child-${specialSuffix}` } });
  238. temporarySpecialObjectIds.push(String(childSpecial.objectId || ''));
  239. const childSpecId = Number(childSpecial.specId);
  240. if (!temporarySpecialObjectIds[1] || !childSpecId || Number(childSpecial.pid) !== rootSpecId) throw new Error(`子专题创建异常:${JSON.stringify(childSpecial)}`);
  241. await callFunctionError('xiaoshu/admin/gateway', login.sessionToken, { operation: 'saveSpecial', className: 'Special', pid: 0, fields: { specName: rootSpecial.specName, specDir: `special-other-${specialSuffix}` } }, 409);
  242. await callFunctionError('xiaoshu/admin/gateway', login.sessionToken, { operation: 'saveSpecial', className: 'Special', objectId: rootSpecial.objectId, pid: childSpecId, fields: { ...rootSpecial, specName: rootSpecial.specName, specDir: rootSpecial.specDir } }, 409);
  243. const specialDeleteBlocked = await callFunctionError('xiaoshu/admin/gateway', login.sessionToken, { operation: 'delete', className: 'Special', objectId: rootSpecial.objectId }, 409);
  244. if (!String(specialDeleteBlocked.message).includes('下级专题')) throw new Error('专题子级引用删除保护未返回明确原因');
  245. const movedSpecial = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'specialBatch', className: 'Special', action: 'move', objectIds: [childSpecial.objectId], pid: 0 });
  246. if (movedSpecial.updated !== 1 || Number(movedSpecial.results?.[0]?.pid) !== 0) throw new Error('专题批量迁移失败');
  247. const mergeBlocked = await callFunctionError('xiaoshu/admin/gateway', login.sessionToken, { operation: 'specialBatch', className: 'Special', action: 'merge', objectIds: [childSpecial.objectId], targetId: rootSpecId }, 501);
  248. if (!String(mergeBlocked.message).includes('specialId')) throw new Error('专题合并数据阻塞未返回明确原因');
  249. await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'delete', className: 'Special', objectId: childSpecial.objectId });
  250. temporarySpecialObjectIds.pop();
  251. await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'delete', className: 'Special', objectId: rootSpecial.objectId });
  252. temporarySpecialObjectIds.pop();
  253. const metadataSuffix = Date.now().toString(36);
  254. const temporaryModelId = 800000000 + Math.floor(Date.now() / 1000) % 100000000;
  255. const tempModel = await jsonRequest(`${PARSE_URL}/classes/Model`, { method: 'POST', body: JSON.stringify({ sourceKey: `cloud:smoke-model:${metadataSuffix}`, company, modelId: temporaryModelId, modelName: `冒烟模型-${metadataSuffix}`, tableName: `ZL_C_Smoke_${metadataSuffix}`, modelType: 1, itemName: '记录', itemUnit: '条', multiFlag: true }) }, true);
  256. temporaryModelObjectId = String(tempModel.objectId || '');
  257. const updatedModel = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'saveModelMetadata', className: 'Model', objectId: temporaryModelObjectId, fields: { modelName: `冒烟模型更新-${metadataSuffix}`, description: '仅元数据更新', tableName: 'malicious_table', modelId: 1 } });
  258. if (Number(updatedModel.modelId) !== temporaryModelId || updatedModel.tableName !== `ZL_C_Smoke_${metadataSuffix}` || updatedModel.description !== '仅元数据更新') throw new Error(`模型结构字段隔离异常:${JSON.stringify(updatedModel)}`);
  259. await callFunctionError('xiaoshu/admin/gateway', login.sessionToken, { operation: 'saveModelMetadata', className: 'Model', fields: { modelName: '禁止新增模型' } }, 501);
  260. for (let index = 0; index < 2; index++) {
  261. const field = await jsonRequest(`${PARSE_URL}/classes/ModelField`, { method: 'POST', body: JSON.stringify({ sourceKey: `cloud:smoke-model-field:${metadataSuffix}:${index}`, company, fieldId: temporaryModelId + index + 1, modelId: temporaryModelId, fieldName: `smokeField${index}`, fieldAlias: `冒烟字段${index}`, fieldType: 'TextType', orderId: index, isShow: true }) }, true);
  262. temporaryModelFieldObjectIds.push(String(field.objectId || ''));
  263. }
  264. const updatedField = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'saveModelFieldMetadata', className: 'ModelField', objectId: temporaryModelFieldObjectIds[0], fields: { fieldAlias: '更新后的字段别名', fieldTips: '仅展示元数据', fieldName: 'maliciousField', fieldType: 'SqlType', modelId: 1 } });
  265. if (updatedField.fieldAlias !== '更新后的字段别名' || updatedField.fieldName !== 'smokeField0' || updatedField.fieldType !== 'TextType' || Number(updatedField.modelId) !== temporaryModelId) throw new Error(`模型字段结构隔离异常:${JSON.stringify(updatedField)}`);
  266. const reorderedFields = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'modelFieldOrder', className: 'ModelField', items: [{ objectId: temporaryModelFieldObjectIds[0], orderId: 2 }, { objectId: temporaryModelFieldObjectIds[1], orderId: 1 }] });
  267. if (reorderedFields.updated !== 2 || Number(reorderedFields.modelId) !== temporaryModelId) throw new Error('模型字段排序失败');
  268. await callFunctionError('xiaoshu/admin/gateway', login.sessionToken, { operation: 'delete', className: 'ModelField', objectId: temporaryModelFieldObjectIds[0] }, 501);
  269. const contentPending = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'contentBatch', className: 'CommonModel', action: 'status', objectIds: [temporaryAppointmentCommonObjectId], status: 0 });
  270. if (contentPending.updated !== 1 || Number(contentPending.results?.[0]?.status) !== 0) throw new Error('内容待审核状态更新失败');
  271. const contentRecycled = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'contentBatch', className: 'CommonModel', action: 'recycle', objectIds: [temporaryAppointmentCommonObjectId] });
  272. if (Number(contentRecycled.results?.[0]?.status) !== -2) throw new Error('内容回收站状态更新失败');
  273. const contentRecovered = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'contentBatch', className: 'CommonModel', action: 'recover', objectIds: [temporaryAppointmentCommonObjectId] });
  274. if (Number(contentRecovered.results?.[0]?.status) !== 0) throw new Error('内容回收站恢复失败');
  275. const contentMoved = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'contentBatch', className: 'CommonModel', action: 'move', objectIds: [temporaryAppointmentCommonObjectId], nodeId: 29 });
  276. if (Number(contentMoved.results?.[0]?.nodeId) !== 29) throw new Error('内容节点移动失败');
  277. await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'contentBatch', className: 'CommonModel', action: 'status', objectIds: [temporaryAppointmentCommonObjectId], status: 99 });
  278. const page = await callFunction('xiaoshu/admin/gateway', login.sessionToken, { operation: 'list', className: 'CourseAppointment', page: 1, pageSize: 2 });
  279. if (!Array.isArray(page.results) || page.pageSize !== 2) throw new Error('资源分页校验失败');
  280. const normalized = await callFunction('xiaoshu/cms/content-normalizer', login.sessionToken, { content: '<p>中文&nbsp;<strong>内容</strong></p><script>alert(1)</script>' });
  281. if (normalized.content !== '中文 内容') throw new Error(`内容清理结果异常:${normalized.content}`);
  282. const exams = await callFunction('xiaoshu/cms/exams/classes', login.sessionToken, { page: 1, pageSize: 2 });
  283. if (!Array.isArray(exams.results)) throw new Error('考试班级投影校验失败');
  284. const guest = await callFunction('xiaoshu/cms/guest/bar', login.sessionToken, { page: 1, pageSize: 2 });
  285. if (!Array.isArray(guest.results)) throw new Error('互动社区投影校验失败');
  286. const migration = await callLegacyFunction('', { action: 'migration_status' });
  287. const sourceActionList = await sourceActions();
  288. const implementedActions = migration.result?.implemented || [];
  289. const blockedActions = Object.keys(migration.result?.blocked || {});
  290. const covered = new Set([...implementedActions, ...blockedActions]);
  291. const missing = sourceActionList.filter((action) => !covered.has(action));
  292. if (missing.length) throw new Error(`app gateway 迁移矩阵缺少:${missing.join(', ')}`);
  293. const sourceBlocked = blockedActions.filter((action) => sourceActionList.includes(action));
  294. const compatibilityActions = blockedActions.filter((action) => !sourceActionList.includes(action)).sort();
  295. const sourceImplemented = implementedActions.filter((action) => sourceActionList.includes(action));
  296. const compatibilityImplemented = implementedActions.filter((action) => !sourceActionList.includes(action)).sort();
  297. if (sourceImplemented.length !== 28 || sourceBlocked.length !== 63) throw new Error(`app gateway 源 action 计数异常:${sourceImplemented.length} 已映射 / ${sourceBlocked.length} 阻塞`);
  298. if (compatibilityImplemented.join(',') !== 'content_add_zt') throw new Error(`app gateway 已实现兼容 action 计数异常:${compatibilityImplemented.join(',')}`);
  299. if (compatibilityActions.join(',') !== 'product_add,product_upd') throw new Error(`app gateway 阻塞兼容 action 计数异常:${compatibilityActions.join(',')}`);
  300. const content = await callLegacyFunction('', { action: 'content_list', page: 1, pageSize: 2 });
  301. if (!Array.isArray(content.result) || content.result.length !== 2 || Number(content.page?.itemCount) < 89000) throw new Error('公开内容分页校验失败');
  302. const contentExact = await callLegacyFunction('', { action: 'content_list', page: 1, pageSize: 1, objectId: content.result[0].objectId });
  303. if (contentExact.result?.[0]?.objectId !== content.result[0].objectId || contentExact.page?.itemCount !== 1) throw new Error('内容 objectId 精确查询校验失败');
  304. const contentDetail = await callLegacyFunction('', { action: 'content_get', id: content.result[0].objectId });
  305. if (!Array.isArray(contentDetail.result) || contentDetail.result[0]?.objectId !== content.result[0].objectId) throw new Error('内容详情旧数组契约校验失败');
  306. contentHitObjectId = String(content.result[0].objectId);
  307. contentHitOriginal = Number(content.result[0].hits ?? content.result[0].Hits ?? 0);
  308. const contentHit = await callLegacyFunction('', { action: 'content_uphis', id: contentHitObjectId, num: 999 });
  309. if (Number(contentHit.result?.hits) !== contentHitOriginal + 1) throw new Error(`公开内容浏览量未固定原子加一:${JSON.stringify(contentHit)}`);
  310. await jsonRequest(`${PARSE_URL}/classes/CommonModel/${contentHitObjectId}`, { method: 'PUT', body: JSON.stringify({ hits: contentHitOriginal }) }, true);
  311. contentHitObjectId = '';
  312. await callLegacyFunction('', { action: 'content_uphis', id: temporaryAppointmentId }, 401);
  313. const appUpdate = await callLegacyFunction('', { action: 'app_update' });
  314. if (Number(appUpdate.result?.ver) !== 113 || appUpdate.result?.nver !== '1.1.8' || !String(appUpdate.result?.path).startsWith('https://') || appUpdate.result?.size !== null || appUpdate.result?.sizeUnavailable !== true) throw new Error(`应用版本旧契约别名异常:${JSON.stringify(appUpdate)}`);
  315. const gameNode = await callLegacyFunction('', { action: 'node_get', id: 77 });
  316. if (gameNode.result?.NodeID === undefined || gameNode.result?.ConsumePoint === undefined || gameNode.result?.ConsumeDeposit === undefined) throw new Error(`栏目详情游戏消费字段别名异常:${JSON.stringify(gameNode.result)}`);
  317. const words = await callLegacyFunction('', { action: 'content_list', modelId: 52, page: 1, pageSize: 1 });
  318. if (Number(words.page?.itemCount) < 89000 || !words.result?.[0]?.GeneralID || words.result?.[0]?.sy === undefined) throw new Error('词库 addon 联表校验失败');
  319. const privateContent = await callLegacyFunction('', { action: 'content_list', modelId: 56, page: 1, pageSize: 1 }, 401);
  320. if (!String(privateContent.retmsg).includes('登录')) throw new Error('学习记录未阻止匿名访问');
  321. const learning = await callLegacyFunction(login.sessionToken, { action: 'content_list', modelId: 56, page: 1, pageSize: 1 });
  322. if (!learning.result?.[0]?.GeneralID || learning.result?.[0]?.xxqs === undefined) throw new Error('学习记录 addon 联表校验失败');
  323. const recordDetail = await callLegacyFunction(login.sessionToken, { action: 'e_record_detail', id: learning.result[0].GeneralID });
  324. if (!Array.isArray(recordDetail.result) || !recordDetail.result.length || !recordDetail.result[0]?.detail?.[0]?.Title) throw new Error('学习记录单词详情联查校验失败');
  325. const appointments = await callLegacyFunction(login.sessionToken, { action: 'content_list', modelId: 54, page: 1, pageSize: 1 });
  326. const appointment = await callLegacyFunction(login.sessionToken, { action: 'e_order_detail', id: appointments.result?.[0]?.GeneralID });
  327. if (!appointment.result?.[0]?.GeneralID || appointment.result[0].kcid === undefined) throw new Error('预约详情联查校验失败');
  328. const memberProfile = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_get', uid: memberLegacyId });
  329. if (memberProfile.result?.honeyName !== profileModel.honeyName || memberProfile.addon?.vip !== 2 || memberProfile.addon?.silverCoin !== 2 || JSON.stringify(memberProfile).includes('must-not-leak')) throw new Error('用户旧契约字段或敏感字段过滤异常');
  330. const teamMembers = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_list', puid: memberLegacyId, cpage: 1, psize: 10 });
  331. if (teamMembers.page?.itemCount !== 1 || Number(teamMembers.result?.[0]?.ParentUserID) !== memberLegacyId || Number(teamMembers.result?.[0]?.VIP) !== 3) throw new Error(`团队成员列表异常:${JSON.stringify(teamMembers)}`);
  332. const teamSummary = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_dept', uid: memberLegacyId });
  333. if (teamSummary.result?.childs !== 1 || teamSummary.result?.v3 !== 1) throw new Error(`团队会员统计异常:${JSON.stringify(teamSummary.result)}`);
  334. const childProfile = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_get', uid: childLegacyId });
  335. if (childProfile.result?.userId !== childLegacyId || childProfile.result?.puid !== memberLegacyId || JSON.stringify(childProfile).includes('must-not-leak')) throw new Error('团队成员详情或密码字段过滤异常');
  336. await callLegacyFunction(coachLogin.sessionToken, { action: 'user_get', uid: childLegacyId }, 403);
  337. const coachStudents = await callLegacyFunction(coachLogin.sessionToken, { action: 'e_user_list', cpage: 1, psize: 10 });
  338. if (coachStudents.page?.itemCount !== 1 || Number(coachStudents.result?.[0]?.szyh) !== memberLegacyId || coachStudents.result?.[0]?.honeyname !== profileModel.honeyName) throw new Error(`陪练学员分组列表异常:${JSON.stringify(coachStudents)}`);
  339. const newWords = await callLegacyFunction(login.sessionToken, { action: 'e_words_list', uid: 58, page: 1, pageSize: 2 });
  340. if (Number(newWords.page?.itemCount) < 1 || !newWords.result?.[0]?.detail?.[0]?.Title) throw new Error('用户生词联查校验失败');
  341. const courseWords = await callLegacyFunction(login.sessionToken, { action: 'e_ck_list', uid: 58, nids: 40, page: 1, pageSize: 1000 });
  342. const learnedWord = courseWords.result?.find((word) => Number(word.GeneralID) === 2505);
  343. if (Number(courseWords.page?.itemCount) < 1 || !courseWords.result?.[0]?.detail?.Title || Number(learnedWord?.w_learned) !== 7) throw new Error('课程词库学习进度联查校验失败');
  344. const memory = await callLegacyFunction(login.sessionToken, { action: 'e_get_21list', uid: 58, page: 1, pageSize: 2 });
  345. if (Number(memory.page?.itemCount) < 1 || !memory.result?.[0]?.GeneralID || memory.result[0].learned === undefined) throw new Error('21 天抗遗忘联查校验失败');
  346. const incomeBlocked = await callLegacyFunction(login.sessionToken, { action: 'e_get_21list_tj', uid: 58 }, 501);
  347. if (!String(incomeBlocked.retmsg).includes('计价规则')) throw new Error('复习收入缺失规则未显式阻塞');
  348. const ownEmpty = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_list', modelId: 56, myfield2: `UserId=${memberLegacyId}`, page: 1, pageSize: 1 });
  349. if (!Array.isArray(ownEmpty.result) || ownEmpty.page?.itemCount !== 0) throw new Error('普通用户本人记录权限校验失败');
  350. const ownCourseWords = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_ck_list', uid: memberLegacyId, nids: 40, page: 1, pageSize: 1 });
  351. if (!Array.isArray(ownCourseWords.result) || ownCourseWords.result[0]?.w_learned !== 0) throw new Error('普通用户本人课程词库权限校验失败');
  352. const learnedWrite = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_add_words', uid: memberLegacyId, wordsId: '2505', kcid: 16, save: 1 });
  353. if (learnedWrite.result?.created !== 1 || learnedWrite.result?.learnedIncremented !== 1) throw new Error('首次学习词进度写入校验失败');
  354. await callLegacyFunction('', { action: 'node_list', pid: 16, ifunit: 1, userId: memberLegacyId }, 401);
  355. const unitNodes = await callLegacyFunction(memberLogin.sessionToken, { action: 'node_list', pid: 16, ifunit: 1, userId: memberLegacyId, pageSize: 100 });
  356. const learnedUnit = unitNodes.result?.find((node) => Number(node.NodeID) === 40);
  357. if (!learnedUnit || Number(learnedUnit.total) < 1 || Number(learnedUnit.yx_word) !== 1 || Number(learnedUnit.process) !== Math.round(100 / Number(learnedUnit.total))) throw new Error(`单元已学进度异常:${JSON.stringify(learnedUnit)}`);
  358. const learnedRead = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_ck_list', uid: memberLegacyId, nids: 40, page: 1, pageSize: 1000 });
  359. if (Number(learnedRead.result?.find((word) => Number(word.GeneralID) === 2505)?.w_learned) !== 1) throw new Error('学习次数写后读校验失败');
  360. await callLegacyFunction(memberLogin.sessionToken, { action: 'e_add_words', uid: memberLegacyId, wordsId: '2505', kcid: 16, ifnew: 1 });
  361. const addedNewWord = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_words_list', uid: memberLegacyId, page: 1, pageSize: 10 });
  362. if (addedNewWord.page?.itemCount !== 1 || Number(addedNewWord.result?.[0]?.detail?.[0]?.GeneralID) !== 2505) throw new Error('加入生词写后读校验失败');
  363. await callLegacyFunction(memberLogin.sessionToken, { action: 'e_add_words', uid: memberLegacyId, wordsId: '2505', kcid: 16, ifnew: 0 });
  364. const removedNewWord = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_words_list', uid: memberLegacyId, page: 1, pageSize: 10 });
  365. if (removedNewWord.page?.itemCount !== 0) throw new Error('移出生词写后读校验失败');
  366. const scheduledStudy = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_add_zt', content: JSON.stringify({ ModelID: 56, nodeId: 291, inputer: memberUsername, status: 99, Hits: 1, title: memberUsername }), addon: JSON.stringify({ UserID: memberLegacyId, dqrq: '20991231', learned: 1, xxqs: JSON.stringify([{ GeneralID: 2505, Title: 'woman', check: 0 }]) }) });
  367. if (!/^\d{15}$/.test(String(scheduledStudy.result))) throw new Error('带复习计划的学习记录创建结果异常');
  368. const scheduledDetail = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_get', id: scheduledStudy.result });
  369. const reviewDates = String(scheduledDetail.result?.[0]?.fxrl || '').split(',').filter(Boolean);
  370. if (reviewDates.length !== 15 || !reviewDates.every((date) => /^\d{8}$/.test(date))) throw new Error('15 段抗遗忘复习日期生成失败');
  371. await callLegacyFunction(coachLogin.sessionToken, { action: 'content_update', content: JSON.stringify({ GeneralID: scheduledStudy.result }), addon: JSON.stringify({ con: '越权更新' }) }, 403);
  372. const scheduledUpdate = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_update', content: JSON.stringify({ GeneralID: scheduledStudy.result, Title: '已更新学习记录' }), addon: JSON.stringify({ con: '规范化内容更新', learned: 1 }) });
  373. if (String(scheduledUpdate.result) !== String(scheduledStudy.result)) throw new Error('规范化内容更新返回值异常');
  374. const updatedScheduledDetail = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_get', id: scheduledStudy.result });
  375. if (updatedScheduledDetail.result?.[0]?.con !== '规范化内容更新' || updatedScheduledDetail.result?.[0]?.Title !== '已更新学习记录') throw new Error('规范化内容双表更新写后读失败');
  376. const assessment = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_add', content: JSON.stringify({ ModelID: 61, nodeId: 389, inputer: memberUsername, status: 99, Hits: 1, title: memberUsername }), addon: JSON.stringify({ UserID: memberLegacyId, askid: 1, prev_score: 0, totalScore: 10, wrong: 2, dontKnow: 1, answerid: 7, df: 7 }) });
  377. if (!/^\d{15}$/.test(String(assessment.result))) throw new Error('规范化测评内容新增结果异常');
  378. const assessmentDetail = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_get', id: assessment.result });
  379. if (String(assessmentDetail.result?.[0]?.df) !== '7' || String(assessmentDetail.result?.[0]?.prevScore) !== '0' || Number(assessmentDetail.result?.[0]?.UserID ?? assessmentDetail.result?.[0]?.userId) !== memberLegacyId) throw new Error('规范化测评内容新增写后读失败');
  380. const missingSchemaCreate = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_add', content: JSON.stringify({ ModelID: 55, nodeId: 255 }), addon: JSON.stringify({ UserID: memberLegacyId, scnr: '[]' }) }, 501);
  381. if (!String(missingSchemaCreate.retmsg).includes('未迁移内容模型 55')) throw new Error('缺 Schema 内容新增未明确拒绝');
  382. const studyAddon = { con: '云函数学习记录冒烟测试', dqrq: '20260818', fxrl: '20260819,20260820', UserID: memberLegacyId, learned: 1, ygg: 0, djq: 0, xxqs: JSON.stringify([{ GeneralID: 2505, Title: 'woman', check: 0 }]) };
  383. const createdStudy = await callLegacyFunction(memberLogin.sessionToken, { action: 'stu_record_update_v2', orderId: temporaryAppointmentId, uid: memberLegacyId, inputer: memberUsername, addon: JSON.stringify(studyAddon) });
  384. if (!createdStudy.result?.created || !createdStudy.result?.GeneralID || !createdStudy.result?.recordObjectId) throw new Error('预约学习记录首次双表写入校验失败');
  385. const studyDetail = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_record_detail', id: createdStudy.result.GeneralID });
  386. if (studyDetail.result?.[0]?.detail?.[0]?.Title !== 'woman') throw new Error('预约学习记录写后详情校验失败');
  387. studyAddon.xxqs = JSON.stringify([{ GeneralID: 2505, Title: 'woman', check: 1 }]);
  388. const updatedStudy = await callLegacyFunction(memberLogin.sessionToken, { action: 'stu_record_update_v2', orderId: temporaryAppointmentId, uid: memberLegacyId, inputer: memberUsername, addon: JSON.stringify(studyAddon) });
  389. if (updatedStudy.result?.created || updatedStudy.result?.GeneralID !== createdStudy.result.GeneralID) throw new Error('预约学习记录幂等更新校验失败');
  390. const studyList = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_list', modelId: 56, myfield2: `UserId=${memberLegacyId}|dsid=${temporaryAppointmentId}`, page: 1, pageSize: 2 });
  391. if (studyList.page?.itemCount !== 1 || Number(studyList.result?.[0]?.ygg) !== 1 || Number(studyList.result?.[0]?.learned) !== 1) throw new Error('预约学习记录聚合字段写后读校验失败');
  392. const orderContent = JSON.stringify({ GeneralID: temporaryAppointmentId, UpDateTime: '2026-08-18 13:30' });
  393. await callLegacyFunction(memberLogin.sessionToken, { action: 'e_order_update_v2', uid: memberLegacyId, status: 10, content: orderContent }, 403);
  394. const startedOrder = await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_update_v2', uid: coachLegacyId, status: 10, content: orderContent });
  395. if (startedOrder.result?.previousStatus !== 0 || startedOrder.result?.status !== 10) throw new Error('预约开始状态迁移失败');
  396. const endedOrder = await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_update_v2', uid: coachLegacyId, status: 11, content: orderContent });
  397. if (endedOrder.result?.reviewCount !== 2 || !endedOrder.result?.periodDeducted) throw new Error('预约结束课时与抗遗忘副作用失败');
  398. const repeatedEnd = await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_update_v2', uid: coachLegacyId, status: 11, content: orderContent });
  399. if (!repeatedEnd.result?.unchanged) throw new Error('预约结束状态未保持幂等');
  400. const updatedMember = await jsonRequest(`${PARSE_URL}/users/${memberId}`, {}, true);
  401. if (Number(updatedMember.legacyUserData?.Purse) !== 1 || Number(updatedMember.legacyUserData?.UserPoint) !== 1.5) throw new Error(`预约结束课时扣减异常:${JSON.stringify(updatedMember.legacyUserData)}`);
  402. const sideEffectWhere = encodeURIComponent(JSON.stringify({ sourceKey: { $regex: `^cloud:e_order_update:${temporaryAppointmentId}:` } }));
  403. const [periodLogs, pointLogs, memoryRows, memoryCommonRows] = await Promise.all([
  404. jsonRequest(`${PARSE_URL}/classes/UserExpDomP?where=${sideEffectWhere}&count=1&limit=0`, {}, true),
  405. jsonRequest(`${PARSE_URL}/classes/UserUserPoint?where=${sideEffectWhere}&count=1&limit=0`, {}, true),
  406. jsonRequest(`${PARSE_URL}/classes/MemoryPracticeRecord?where=${sideEffectWhere}&count=1&limit=0`, {}, true),
  407. jsonRequest(`${PARSE_URL}/classes/CommonModel?where=${sideEffectWhere}&count=1&limit=0`, {}, true),
  408. ]);
  409. if (periodLogs.count !== 1 || pointLogs.count !== 1 || memoryRows.count !== 2 || memoryCommonRows.count !== 2) throw new Error(`预约结束账本/抗遗忘数量异常:${periodLogs.count}/${pointLogs.count}/${memoryRows.count}/${memoryCommonRows.count}`);
  410. const purseHistory = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_point_list', uid: memberLegacyId, stype: 1, cpage: 1, psize: 10 });
  411. if (purseHistory.page?.itemCount !== 1 || Number(purseHistory.result?.[0]?.score) !== -1 || !purseHistory.result?.[0]?.ExpHisID || purseHistory.result?.[0]?.Detail === undefined || purseHistory.addon?.purseFeeRuleUnavailable !== true) throw new Error(`余额账本读取异常:${JSON.stringify(purseHistory)}`);
  412. const couponHistory = await callLegacyFunction(memberLogin.sessionToken, { action: 'user_point_list', uid: memberLegacyId, stype: 4, cpage: 1, psize: 10 });
  413. if (couponHistory.page?.itemCount !== 1 || Number(couponHistory.result?.[0]?.score) !== -0.5 || !couponHistory.result?.[0]?.HisTime) throw new Error(`点券账本读取异常:${JSON.stringify(couponHistory)}`);
  414. await callLegacyFunction(memberLogin.sessionToken, { action: 'user_point_list', uid: memberLegacyId, stype: 7 }, 400);
  415. await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_update_v2', uid: coachLegacyId, status: 20, content: orderContent }, 403);
  416. await callLegacyFunction(memberLogin.sessionToken, { action: 'e_order_update_v2', uid: memberLegacyId, status: 20, content: orderContent });
  417. await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_update_v2', uid: coachLegacyId, status: 30, content: orderContent });
  418. const completedOrder = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_order_detail', id: temporaryAppointmentId });
  419. if (Number(completedOrder.result?.[0]?.dszt) !== 30) throw new Error('预约状态机写后读失败');
  420. const coachStats = await callLegacyFunction(coachLogin.sessionToken, { action: 'e_order_tongji', uid: coachLegacyId });
  421. if (coachStats.result?.t30 !== '1' || coachStats.result?.t60 !== '1' || coachStats.result?.t_tiyan !== '1' || coachStats.result?.t_total !== '3' || coachStats.result?.t_shichang !== '2.5' || coachStats.result?.t_yongji !== '100') throw new Error('陪练预约统计公式校验失败');
  422. const memberStats = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_order_tongji', uid: memberLegacyId });
  423. if (memberStats.result?.t30 !== '1' || memberStats.result?.t60 !== '0' || memberStats.result?.t_tiyan !== '0' || memberStats.result?.t_total !== '1' || memberStats.result?.t_shichang !== '0.5' || memberStats.result?.t_yongji !== '0') throw new Error(`学员预约与生词统计公式校验失败:${JSON.stringify(memberStats.result)}`);
  424. const deniedCourseWords = await callLegacyFunction(memberLogin.sessionToken, { action: 'e_ck_list', uid: 58, nids: 40, page: 1, pageSize: 1 }, 403);
  425. if (!String(deniedCourseWords.retmsg).includes('无权')) throw new Error('普通用户跨用户课程词库未被拒绝');
  426. const denied = await callLegacyFunction(memberLogin.sessionToken, { action: 'content_list', modelId: 56, myfield2: 'UserId=3', page: 1, pageSize: 1 }, 403);
  427. if (!String(denied.retmsg).includes('无权')) throw new Error('普通用户跨用户记录未被拒绝');
  428. const profile = await callLegacyFunction(login.sessionToken, { action: 'user_get' });
  429. if (profile.retcode !== 0 || profile.result?.objectId !== userId) throw new Error('app gateway 用户会话校验失败');
  430. const blocked = await callLegacyFunction('', { action: 'cart_list' }, 501);
  431. if (!String(blocked.retmsg).startsWith('migration_blocked:')) throw new Error('阻塞接口未返回 migration_blocked');
  432. const productBlocked = await callLegacyFunction('', { action: 'product_list' }, 501);
  433. if (!String(productBlocked.retmsg).includes('ZL_Commodities')) throw new Error('缺商品主表的读取接口未明确阻塞');
  434. console.log('Cloud smoke passed: admin auth/tenant/account lifecycle/group sync/node/special/model metadata lifecycle/content workflow/CRUD reads, CMS projections, normalized learning joins, app action coverage, public content, session scope, explicit blocked APIs.');
  435. } finally {
  436. if (contentHitObjectId) await jsonRequest(`${PARSE_URL}/classes/CommonModel/${contentHitObjectId}`, { method: 'PUT', body: JSON.stringify({ hits: contentHitOriginal }) }, true).catch((error) => {
  437. console.error(`公开内容浏览量恢复失败:${error.message}`);
  438. process.exitCode = 1;
  439. });
  440. if (registeredUserId) await jsonRequest(`${PARSE_URL}/users/${registeredUserId}`, { method: 'DELETE' }, true).catch((error) => {
  441. console.error(`临时注册用户清理失败:${error.message}`);
  442. process.exitCode = 1;
  443. });
  444. if (adminCreatedUserId) await jsonRequest(`${PARSE_URL}/users/${adminCreatedUserId}`, { method: 'DELETE' }, true).catch((error) => {
  445. console.error(`管理员开户临时用户清理失败:${error.message}`);
  446. process.exitCode = 1;
  447. });
  448. if (temporaryGroupObjectId) await jsonRequest(`${PARSE_URL}/classes/Group/${temporaryGroupObjectId}`, { method: 'DELETE' }, true).catch((error) => {
  449. console.error(`临时用户组清理失败:${error.message}`);
  450. process.exitCode = 1;
  451. });
  452. for (const nodeId of temporaryNodeObjectIds) if (nodeId) await jsonRequest(`${PARSE_URL}/classes/Node/${nodeId}`, { method: 'DELETE' }, true).catch((error) => {
  453. console.error(`临时栏目清理失败:${error.message}`);
  454. process.exitCode = 1;
  455. });
  456. for (const specialId of temporarySpecialObjectIds) if (specialId) await jsonRequest(`${PARSE_URL}/classes/Special/${specialId}`, { method: 'DELETE' }, true).catch((error) => {
  457. console.error(`临时专题清理失败:${error.message}`);
  458. process.exitCode = 1;
  459. });
  460. for (const fieldId of temporaryModelFieldObjectIds) if (fieldId) await jsonRequest(`${PARSE_URL}/classes/ModelField/${fieldId}`, { method: 'DELETE' }, true).catch((error) => {
  461. console.error(`临时模型字段清理失败:${error.message}`);
  462. process.exitCode = 1;
  463. });
  464. if (temporaryModelObjectId) await jsonRequest(`${PARSE_URL}/classes/Model/${temporaryModelObjectId}`, { method: 'DELETE' }, true).catch((error) => {
  465. console.error(`临时模型清理失败:${error.message}`);
  466. process.exitCode = 1;
  467. });
  468. if (temporaryGuestbookId) await jsonRequest(`${PARSE_URL}/classes/Guestbook/${temporaryGuestbookId}`, { method: 'DELETE' }, true).catch((error) => {
  469. console.error(`临时留言清理失败:${error.message}`);
  470. process.exitCode = 1;
  471. });
  472. for (const lessonId of temporaryLessonIds) await jsonRequest(`${PARSE_URL}/classes/LessonRecord/${lessonId}`, { method: 'DELETE' }, true).catch((error) => {
  473. console.error(`临时陪练课次清理失败:${error.message}`);
  474. process.exitCode = 1;
  475. });
  476. if (memberLegacyId) {
  477. const commonWhere = encodeURIComponent(JSON.stringify({ sourceKey: { $regex: `^cloud:(stu_record|content_add_zt|content_add):${memberLegacyId}:` } }));
  478. const commonRows = await jsonRequest(`${PARSE_URL}/classes/CommonModel?where=${commonWhere}&limit=1000`, {}, true).catch(() => ({ results: [] }));
  479. for (const row of commonRows.results || []) await jsonRequest(`${PARSE_URL}/classes/CommonModel/${row.objectId}`, { method: 'DELETE' }, true).catch((error) => {
  480. console.error(`临时学习主记录清理失败:${error.message}`);
  481. process.exitCode = 1;
  482. });
  483. const studyWhere = encodeURIComponent(JSON.stringify({ userId: memberLegacyId }));
  484. const studyRows = await jsonRequest(`${PARSE_URL}/classes/DailyStudyRecord?where=${studyWhere}&limit=1000`, {}, true).catch(() => ({ results: [] }));
  485. for (const row of studyRows.results || []) await jsonRequest(`${PARSE_URL}/classes/DailyStudyRecord/${row.objectId}`, { method: 'DELETE' }, true).catch((error) => {
  486. console.error(`临时学习 addon 清理失败:${error.message}`);
  487. process.exitCode = 1;
  488. });
  489. }
  490. if (temporaryAppointmentObjectId) await jsonRequest(`${PARSE_URL}/classes/CourseAppointment/${temporaryAppointmentObjectId}`, { method: 'DELETE' }, true).catch((error) => {
  491. console.error(`临时预约清理失败:${error.message}`);
  492. process.exitCode = 1;
  493. });
  494. if (temporaryAppointmentId) {
  495. const sideEffectWhere = encodeURIComponent(JSON.stringify({ sourceKey: { $regex: `^cloud:e_order_update:${temporaryAppointmentId}:` } }));
  496. for (const className of ['CommonModel', 'MemoryPracticeRecord', 'UserExpDomP', 'UserUserPoint']) {
  497. const rows = await jsonRequest(`${PARSE_URL}/classes/${className}?where=${sideEffectWhere}&limit=1000`, {}, true).catch(() => ({ results: [] }));
  498. for (const row of rows.results || []) await jsonRequest(`${PARSE_URL}/classes/${className}/${row.objectId}`, { method: 'DELETE' }, true).catch((error) => {
  499. console.error(`临时预约副作用清理失败(${className}):${error.message}`);
  500. process.exitCode = 1;
  501. });
  502. }
  503. }
  504. if (memberLegacyId) {
  505. const assessmentWhere = encodeURIComponent(JSON.stringify({ sourceKey: { $regex: `^cloud:content_add:${memberLegacyId}:` } }));
  506. const assessments = await jsonRequest(`${PARSE_URL}/classes/AssessmentProfile?where=${assessmentWhere}&limit=1000`, {}, true).catch(() => ({ results: [] }));
  507. for (const assessment of assessments.results || []) await jsonRequest(`${PARSE_URL}/classes/AssessmentProfile/${assessment.objectId}`, { method: 'DELETE' }, true).catch((error) => {
  508. console.error(`临时测评记录清理失败:${error.message}`);
  509. process.exitCode = 1;
  510. });
  511. }
  512. if (memberLegacyId) {
  513. const where = encodeURIComponent(JSON.stringify({ yhid: String(memberLegacyId) }));
  514. const practices = await jsonRequest(`${PARSE_URL}/classes/PracticeRecord?where=${where}&limit=1000`, {}, true).catch(() => ({ results: [] }));
  515. for (const practice of practices.results || []) await jsonRequest(`${PARSE_URL}/classes/PracticeRecord/${practice.objectId}`, { method: 'DELETE' }, true).catch((error) => {
  516. console.error(`临时学习进度清理失败:${error.message}`);
  517. process.exitCode = 1;
  518. });
  519. }
  520. if (teamChildId) {
  521. await jsonRequest(`${PARSE_URL}/users/${teamChildId}`, { method: 'DELETE' }, true).catch((error) => {
  522. console.error(`临时团队成员清理失败:${error.message}`);
  523. process.exitCode = 1;
  524. });
  525. }
  526. if (memberId) {
  527. await jsonRequest(`${PARSE_URL}/users/${memberId}`, { method: 'DELETE' }, true).catch((error) => {
  528. console.error(`临时普通用户清理失败:${error.message}`);
  529. process.exitCode = 1;
  530. });
  531. }
  532. if (coachId) {
  533. await jsonRequest(`${PARSE_URL}/users/${coachId}`, { method: 'DELETE' }, true).catch((error) => {
  534. console.error(`临时陪练用户清理失败:${error.message}`);
  535. process.exitCode = 1;
  536. });
  537. }
  538. if (userId) {
  539. await jsonRequest(`${PARSE_URL}/users/${userId}`, { method: 'DELETE' }, true).catch((error) => {
  540. console.error(`临时管理员清理失败:${error.message}`);
  541. process.exitCode = 1;
  542. });
  543. }
  544. }