fix: nginx AppArmor 缺少 proxy temp 路径;test: 新增 POST body 代理测试(避免权限遗漏上线)
Some checks failed
Deploy Backend / deploy (push) Has been cancelled
Some checks failed
Deploy Backend / deploy (push) Has been cancelled
This commit is contained in:
22
lib/test.sh
22
lib/test.sh
@@ -452,6 +452,27 @@ test_payment_verify_detection() {
|
|||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# ---------- nginx 代理测试 ----------
|
||||||
|
|
||||||
|
test_nginx_proxy_temp() {
|
||||||
|
log_info "测试 nginx proxy temp(POST body 权限)..."
|
||||||
|
# 发送 POST 请求验证 nginx 能正确代理带 body 的请求(AppArmor proxy temp 权限检查)
|
||||||
|
local body; body=$(python3 -c "print('x'*50000)" 2>/dev/null || printf 'x%.0s' {1..50000})
|
||||||
|
local resp
|
||||||
|
resp=$(curl -sk --max-time 10 -X POST "${BASE_URL}" \
|
||||||
|
-H "Content-Type: application/json" \
|
||||||
|
-d "{\"test_body_size\":${#body}}" 2>&1) || true
|
||||||
|
|
||||||
|
# 只要能返回响应(包括错误),就说明 nginx 能正常处理 POST body
|
||||||
|
# 如果 proxy temp 无权限,nginx 会返回 502/403 或超时
|
||||||
|
if [ -n "$resp" ]; then
|
||||||
|
log_info " nginx POST body 代理正常 ✅"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
log_error "nginx POST body 代理失败(proxy temp 可能无权限)"
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
# ---------- 主测试入口 ----------
|
# ---------- 主测试入口 ----------
|
||||||
run_tests() {
|
run_tests() {
|
||||||
log_step "执行部署后测试..."
|
log_step "执行部署后测试..."
|
||||||
@@ -466,6 +487,7 @@ run_tests() {
|
|||||||
"test_invalid_token_401:无效 Token 401"
|
"test_invalid_token_401:无效 Token 401"
|
||||||
"test_response_content:响应内容验证"
|
"test_response_content:响应内容验证"
|
||||||
"test_mock_login:Mock 登录 + 通知接口"
|
"test_mock_login:Mock 登录 + 通知接口"
|
||||||
|
"test_nginx_proxy_temp:nginx proxy temp"
|
||||||
"test_payment_endpoints:支付端点"
|
"test_payment_endpoints:支付端点"
|
||||||
"test_payment_flow:支付链路"
|
"test_payment_flow:支付链路"
|
||||||
"test_migration_status:迁移状态"
|
"test_migration_status:迁移状态"
|
||||||
|
|||||||
Reference in New Issue
Block a user