From 5258ba951b9d420cebad50ca3abbbfd387bcea4e Mon Sep 17 00:00:00 2001 From: TIANYAO ZHANG <88520881+ZHANGTIANYAO1@users.noreply.github.com> Date: Sat, 3 Oct 2026 17:25:02 +0800 Subject: [PATCH] chore: prepare v1.15.0 release and exclude generated test copies --- README.md | 28 +++++++- .../2026-10-03-pr-integration-release.md | 71 +++++++++++-------- vitest.config.ts | 9 +++ 3 files changed, 76 insertions(+), 32 deletions(-) create mode 100644 vitest.config.ts diff --git a/README.md b/README.md index 2ff07f0..b600022 100644 --- a/README.md +++ b/README.md @@ -953,7 +953,33 @@ A:本项目内置 `/login` 限流(每 IP 每分钟 5 次),但生产部 > 完整历史请查看 [git log](https://github.com/ZHANGTIANYAO1/teamspeak-music-bot/commits/main) 或 [Releases](https://github.com/ZHANGTIANYAO1/teamspeak-music-bot/releases)。这里只列出重要变更和面向用户的破坏性改动。 -### 最新版本 — v1.14.0:歌单链接直接播放 / 每人绑定自己的网易云私人FM / B站分P +### 最新版本 — v1.15.0:歌手页面 / REST API / TS6 Profile 与 B站续播修复 + +**歌手搜索与页面([PR #175](https://github.com/ZHANGTIANYAO1/teamspeak-music-bot/pull/175),感谢 [@zzstar101](https://github.com/zzstar101))** + +- 网易云 / QQ 音乐支持搜索歌手、查看歌手介绍、热门歌曲和专辑,并播放或随机播放歌手曲目(最多 500 首)。搜索历史按音源保存在当前浏览器。 +- 歌手播放与单曲播放共用播放锁,避免同时点播时实际歌曲与队列不一致。QQ 曲目目录在上游查询失败时不缓存降级结果,不再因 50 张专辑的限制提前截断歌曲。 +- 歌手页面的迟到请求不会覆盖新页面;访客的随机播放按钮同时遵守歌手播放与模式切换权限。 + +**REST API([PR #173](https://github.com/ZHANGTIANYAO1/teamspeak-music-bot/pull/173),感谢 [@senlinjun](https://github.com/senlinjun))** + +- 在设置页创建、查看和撤销 API Key;脚本可用 Bearer 或 X-API-Key 调用已有 REST 端点,权限和可控机器人范围继承所属用户。完整说明见 [REST API 文档](docs/API.md)。 +- 修复管理员撤销他人 Key 时的审计对象。修改或重置密码会撤销该用户的全部 API Key,外部集成需要重新生成凭据。 + +**TS6 Profile([PR #174](https://github.com/ZHANGTIANYAO1/teamspeak-music-bot/pull/174),感谢 [@razaxq](https://github.com/razaxq))** + +- 昵称和 Away 状态通过真实音乐客户端更新,描述通过明确的客户端 ID 更新,避免修改 HTTP ServerQuery 客户端。 +- 频道描述写入和移动后的清理使用相同权限路径;重连后丢弃旧会话请求,权限不足时可靠降级。 + +**B站长视频续播([#161](https://github.com/ZHANGTIANYAO1/teamspeak-music-bot/issues/161),[PR #170](https://github.com/ZHANGTIANYAO1/teamspeak-music-bot/pull/170))** + +- 优先使用稳定 CDN 镜像;流提前结束时重新解析地址并从当前进度续播,连续无进展重试有次数限制。 +- 播放结束和恢复请求按播放会话校验,旧请求不会跳过新曲,也不会覆盖同一曲目的新一轮播放。 +- 恢复地址查询期间暂停会保留暂停状态;恢复播放不会重复发起查询,查询失败后仍可按重试上限继续恢复。 + +数据库自动新增 API Key 表,保留已有用户和设置。自动化测试只收集源码,排除旧的编译测试副本。 + +### v1.14.0:歌单链接直接播放 / 每人绑定自己的网易云私人FM / B站分P 处理了 5 个社区反馈的 issue。**没有配置变化,升级无需任何操作**;数据库会自动新增一张表(存放用户自己绑定的网易云账号),原有数据不受影响。 diff --git a/docs/superpowers/plans/2026-10-03-pr-integration-release.md b/docs/superpowers/plans/2026-10-03-pr-integration-release.md index 50af355..0a3800a 100644 --- a/docs/superpowers/plans/2026-10-03-pr-integration-release.md +++ b/docs/superpowers/plans/2026-10-03-pr-integration-release.md @@ -31,63 +31,72 @@ Files: src/bot/instance.test.ts (resolve #170 overlap by preserving both test suites). -- [ ] Verify open PR heads remain the audited SHAs. -- [ ] Create a release integration branch from origin/main. -- [ ] Merge #173, #174, #175 and #170 with merge commits; resolve the instance test conflict by retaining both independent additions. +- [x] Verify open PR heads remain the audited SHAs. +- [x] Create a release integration branch from origin/main. +- [x] Merge #173, #174, #175 and #170 with merge commits; resolve the instance test conflict by retaining both independent additions. ### Task 2: Correct artist playback and QQ catalogs Owner files: src/music/qq.ts, src/music/qq.test.ts, src/web/api/player.ts, src/web/api/play-artist.test.ts. -- [ ] Port the four review probes from ../.pr-review-20261003/175/review/review-artist-regressions.test.ts into repository tests. -- [ ] Run npm test -- src/music/qq.test.ts src/web/api/play-artist.test.ts and observe the known failures. -- [ ] Use bot.runExclusive for the stop/queue mutation/play sequence. Preserve permission middleware. -- [ ] Return a failure sentinel for failed singer lookup or malformed/nonzero album-search results; do not cache degradation. -- [ ] Scan albums until the 500-song ceiling or complete catalog; preserve hasMore/total correctness, avoid the silent 50-album limit. -- [ ] Re-run focused tests and report changed files and result. +- [x] Port the four review probes from ../.pr-review-20261003/175/review/review-artist-regressions.test.ts into repository tests. +- [x] Run npm test -- src/music/qq.test.ts src/web/api/play-artist.test.ts and observe the known failures. +- [x] Use bot.runExclusive for the stop/queue mutation/play sequence. Preserve permission middleware. +- [x] Return a failure sentinel for failed singer lookup or malformed/nonzero album-search results; do not cache degradation. +- [x] Scan albums until the 500-song ceiling or complete catalog; preserve hasMore/total correctness, avoid the silent 50-album limit. +- [x] Re-run focused tests and report changed files and result. ### Task 3: Correct TS6 profile lifecycle Owner files: src/bot/profile.ts, src/bot/profile.test.ts, src/ts-protocol/http-query.ts, optionally src/ts-protocol/client.ts and a related focused protocol test if checked self updates need it. -- [ ] Port the three reviewer probes from ../.pr-review-20261003/174/src/bot/review-174.test.ts into profile tests. -- [ ] Confirm they fail before production changes. -- [ ] Clear old channel descriptions through checked HTTP channelEdit for TS6 and preserve TS3's working behavior. -- [ ] Fence client-list resolution and post-write remembered-channel state by generation/connection identity. -- [ ] Use a checked full-client self clientupdate that reports permission failures; never update HTTP ServerQuery self. -- [ ] Update old channel-description mocks to reflect checked TS3 writes without weakening assertions. -- [ ] Run profile/protocol tests and typecheck; report changes. +- [x] Port the three reviewer probes from ../.pr-review-20261003/174/src/bot/review-174.test.ts into profile tests. +- [x] Confirm they fail before production changes. +- [x] Clear old channel descriptions through checked HTTP channelEdit for TS6 and preserve TS3's working behavior. +- [x] Fence client-list resolution and post-write remembered-channel state by generation/connection identity. +- [x] Use a checked full-client self clientupdate that reports permission failures; never update HTTP ServerQuery self. +- [x] Update old channel-description mocks to reflect checked TS3 writes without weakening assertions. +- [x] Run profile/protocol tests and typecheck; report changes. ### Task 4: Correct API-key lifecycle and documentation Owner files: src/data/api-keys.ts, src/data/api-keys.test.ts, src/web/api/api-keys.ts, src/web/api/api-keys.test.ts, src/web/api/session.ts, src/web/api/session.test.ts, src/web/server.ts, docs/API.md. -- [ ] Test administrator revocation auditing the member owner and ordinary password changes invalidating old keys. -- [ ] Run the tests and observe the failures. -- [ ] Snapshot the key owner before deletion and use that owner in the audit target fields. -- [ ] Thread the API key store into the browser session router and revoke all keys after a successful self-service password change; preserve the active browser session convention. -- [ ] Keep documented administrator REST authority. Qualify the no-self-replication claim to direct /api/keys management; do not remove administrator /api/users functionality silently. -- [ ] Add Content-Type: application/octet-stream to the curl upload example. -- [ ] Run the focused auth/session/key suites; report changes. +- [x] Test administrator revocation auditing the member owner and ordinary password changes invalidating old keys. +- [x] Run the tests and observe the failures. +- [x] Snapshot the key owner before deletion and use that owner in the audit target fields. +- [x] Thread the API key store into the browser session router and revoke all keys after a successful self-service password change; preserve the active browser session convention. +- [x] Keep documented administrator REST authority. Qualify the no-self-replication claim to direct /api/keys management; do not remove administrator /api/users functionality silently. +- [x] Add Content-Type: application/octet-stream to the curl upload example. +- [x] Run the focused auth/session/key suites; report changes. ### Task 5: Correct EOF/recovery ordering Owner files: src/bot/instance.ts, src/bot/instance.test.ts. Do not change the artist route owned by Task 2. -- [ ] Turn the independent actual-handler probe into repository tests using the existing setupPlayerEvents fixture; avoid runtime source transpilation. -- [ ] Confirm normal NetEase/Bilibili EOF can currently advance a pending replacement. -- [ ] Fence every delayed fallback by the ending song and playback session, including failed recovery; preserve immediate ordinary EOF ordering where practical. -- [ ] Verify stop, skip, restart of the same queue song, pause, null URL and failed lookup do not clobber a newer playback session. -- [ ] Run instance/player/Bilibili tests and report results. +- [x] Turn the independent actual-handler probe into repository tests using the existing setupPlayerEvents fixture; avoid runtime source transpilation. +- [x] Confirm normal NetEase/Bilibili EOF can currently advance a pending replacement. +- [x] Fence every delayed fallback by the ending song and playback session, including failed recovery; preserve immediate ordinary EOF ordering where practical. +- [x] Verify stop, skip, restart of the same queue song, pause, null URL and failed lookup do not clobber a newer playback session. +- [x] Run instance/player/Bilibili tests and report results. ### Task 6: Review, verify and release Owner files: README.md changelog; release notes kept outside the repository for gh --notes-file. -- [ ] Independently review every correction and the integrated changes; resolve substantive findings. -- [ ] Run npm test -- --exclude 'dist/**' --exclude 'web/dist/**' and npm run build sequentially. -- [ ] Update the README changelog and prepare release notes with contributor credits, changes, migration notes and verified test results. +- [x] Independently review every correction and the integrated changes; resolve substantive findings, including paused recovery, malformed QQ rows, and artist UI permissions/response ordering. +- [x] Run npm test (generated outputs excluded by vitest.config.ts) and npm run build sequentially; repeat affected verification after final review fixes. +- [x] Update the README changelog and prepare release notes with contributor credits, changes, migration notes and verified test results. - [ ] Confirm main has not moved, integrate the tested branch and push main without force. - [ ] Verify all four GitHub PRs show merged and point at the integrated history. - [ ] Create and push v1.15.0 (or the user's chosen version), create the GitHub release, and inspect the Docker publish workflow to completion. - [ ] Report the release URL, test totals and Docker publishing result. State that live TeamSpeak/music-provider integration was not exercised. + +## Final local evidence (2026-10-03) + +- All four audited PR heads were unchanged on GitHub before publishing. +- Every correction passed independent review; no malicious behavior was found. +- After the final artist UI corrections, `npm test` passed 79 source test files and all 1283 tests. +- `npm run build` passed backend TypeScript, Vue type checking and production bundling. +- `npm run check:native` passed. Compiled Vue component probes verified artist permission combinations and late-response ordering. +- Live TeamSpeak servers and music-provider playback were not exercised. Publishing evidence is recorded in the GitHub release and its Docker workflow. diff --git a/vitest.config.ts b/vitest.config.ts new file mode 100644 index 0000000..dd57c86 --- /dev/null +++ b/vitest.config.ts @@ -0,0 +1,9 @@ +import { configDefaults, defineConfig } from "vitest/config"; + +export default defineConfig({ + test: { + // TypeScript compiles test files into dist. Test the source once, even + // when an older build is present, rather than collecting stale copies. + exclude: [...configDefaults.exclude, "dist/**", "web/dist/**"], + }, +});