fix: audit remediation — SSE user scoping, FK transactional safety, UI error handling

- H4: scoped SSE import progress to exact userId match; non-HTTP events excluded from all subscribers
- H2: moved PRAGMA foreign_key_check inside SQLite transaction before COMMIT; violations rollback preserving old tables
- M1: removed dead axios-style error branch from extractErrorMessage (interceptor already unwraps)
- M2: split handleSave try/catch — save errors vs reload errors shown distinctly
- M3: added provider field validation before AI config test request
- Added SSE scoping regression tests (import service + controller)
- Added FK check failure rollback test (database-migrations.spec)
- Updated controller spec expectations for userId parameter

Co-authored-by: Code Review <branch-review>
This commit is contained in:
2026-07-12 22:59:03 +08:00
parent b6fca99390
commit cc4f4dae4e
69 changed files with 6262 additions and 1980 deletions

View File

@@ -0,0 +1,53 @@
import { DingTalkService } from './dingtalk.service';
describe('DingTalkService attendance group deletion', () => {
const originalAppKey = process.env.DINGTALK_APP_KEY;
const originalAppSecret = process.env.DINGTALK_APP_SECRET;
let service: DingTalkService;
beforeEach(() => {
process.env.DINGTALK_APP_KEY = 'test-app-key';
process.env.DINGTALK_APP_SECRET = 'test-app-secret';
service = new DingTalkService({} as never, {} as never);
Object.assign(service, {
accessToken: 'test-token',
tokenExpiresAt: Date.now() + 3_600_000,
});
});
afterEach(() => {
jest.restoreAllMocks();
global.fetch = undefined as unknown as typeof fetch;
});
afterAll(() => {
if (originalAppKey === undefined) delete process.env.DINGTALK_APP_KEY;
else process.env.DINGTALK_APP_KEY = originalAppKey;
if (originalAppSecret === undefined) delete process.env.DINGTALK_APP_SECRET;
else process.env.DINGTALK_APP_SECRET = originalAppSecret;
});
it('converts groupId to groupKey before deleting the group', async () => {
global.fetch = jest
.fn()
.mockResolvedValueOnce({
json: jest.fn().mockResolvedValue({ errcode: 0, errmsg: 'ok', result: 'group-key-1' }),
})
.mockResolvedValueOnce({
json: jest.fn().mockResolvedValue({ errcode: 0, errmsg: 'ok', success: true }),
}) as jest.MockedFunction<typeof fetch>;
await service.deleteAttendanceGroup(123, 'manager');
expect(global.fetch).toHaveBeenNthCalledWith(
1,
expect.stringContaining('/topapi/attendance/groups/idtokey'),
expect.objectContaining({ body: JSON.stringify({ op_user_id: 'manager', group_id: 123 }) }),
);
expect(global.fetch).toHaveBeenNthCalledWith(
2,
expect.stringContaining('/topapi/attendance/group/delete'),
expect.objectContaining({ body: JSON.stringify({ op_userid: 'manager', group_key: 'group-key-1' }) }),
);
});
});