mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-02 13:02:49 +08:00
fix(guest): normalize guestMode config on load + strict-boolean authorize gate
loadConfig now sanitizes guestMode the same way the write path does: bots is coerced to "all" | string[] (numbers/objects/missing fall back to the default "all"), and permissions are rebuilt from defaults with each known flag strict-coerced to a boolean so a hand-edited/legacy/corrupt config.json can no longer crash the gate or leak garbage index keys. The authorize guest gate now uses === true instead of a truthy check. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
952f1fbad3
commit
66230e6b43
4 files changed
+84
-9
No files matched your search
@@ -30,4 +30,8 @@ describe("authorize", () => {
|
||||
it("guest is denied on routes with no guestFlag (e.g. play-song)", () => {
|
||||
expect(run({ role: "guest", guest: { addToQueue: true } }, { capability: "player.control" }).res.statusCode).toBe(403);
|
||||
});
|
||||
it("guest with a non-boolean truthy flag value (1) is denied (strict-boolean gate)", () => {
|
||||
expect(run({ role: "guest", guest: { playNext: 1 } as any }, { guestFlag: "playNext" }).res.statusCode).toBe(403);
|
||||
expect(run({ role: "guest", guest: { playNext: true } }, { guestFlag: "playNext" }).next).toHaveBeenCalled();
|
||||
});
|
||||
});
|
||||
@@ -19,7 +19,7 @@ export function authorize<P = Record<string, string>>(opts: {
|
||||
if (!user) { res.status(401).json({ error: "unauthenticated" }); return; }
|
||||
if (user.role === "admin") { next(); return; }
|
||||
if (user.role === "guest") {
|
||||
if (opts.guestFlag && user.guest?.[opts.guestFlag]) { next(); return; }
|
||||
if (opts.guestFlag && user.guest?.[opts.guestFlag] === true) { next(); return; }
|
||||
res.status(403).json({ error: "forbidden" });
|
||||
return;
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user