mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-01 20:42:50 +08:00
feat(bot): lock settings reads from guests + persist guestMode
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
d763043305
commit
e0acbf5457
2 files changed
+79
-2
No files matched your search
@@ -159,3 +159,58 @@ describe("bot router /settings", () => {
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
describe("bot router /settings guest-mode gating + persistence", () => {
|
||||
let tmpDir: string;
|
||||
let configPath: string;
|
||||
let config: BotConfig;
|
||||
let botDb: BotDatabase;
|
||||
|
||||
beforeEach(() => {
|
||||
botDb = createDatabase(":memory:");
|
||||
tmpDir = mkdtempSync(join(tmpdir(), "botsettings-gm-"));
|
||||
configPath = join(tmpDir, "config.json");
|
||||
config = getDefaultConfig();
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
botDb.close();
|
||||
rmSync(tmpDir, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
/** Mounts createBotRouter with an injected req.user (no session/cookie). */
|
||||
function mountBot(injectUser: () => unknown): express.Express {
|
||||
const fakeManager = { getAllBots: () => [] } as unknown as BotManager;
|
||||
const avatarStore = createAvatarStore(tmpDir);
|
||||
const app = express();
|
||||
app.use(express.json());
|
||||
app.use((req, _res, next) => { (req as { user?: unknown }).user = injectUser(); next(); });
|
||||
app.use(
|
||||
"/api/bot",
|
||||
createBotRouter(fakeManager, config, configPath, pino({ level: "silent" }), botDb, avatarStore),
|
||||
);
|
||||
return app;
|
||||
}
|
||||
|
||||
it("GET /settings is 403 for guests and includes guestMode for admins", async () => {
|
||||
const guestApp = mountBot(() => ({ role: "guest", guest: {} }));
|
||||
expect((await request(guestApp).get("/api/bot/settings")).status).toBe(403);
|
||||
const adminApp = mountBot(() => ({ role: "admin" }));
|
||||
const res = await request(adminApp).get("/api/bot/settings");
|
||||
expect(res.status).toBe(200);
|
||||
expect(res.body.guestMode).toBeDefined();
|
||||
expect(res.body.guestMode.enabled).toBe(false);
|
||||
});
|
||||
|
||||
it("POST /settings persists a guestMode block", async () => {
|
||||
const adminApp = mountBot(() => ({ role: "admin" }));
|
||||
const res = await request(adminApp).post("/api/bot/settings").send({
|
||||
guestMode: { enabled: true, bots: ["bot1"], permissions: { playNext: true } },
|
||||
});
|
||||
expect(res.status).toBe(200);
|
||||
expect(res.body.guestMode.enabled).toBe(true);
|
||||
expect(res.body.guestMode.bots).toEqual(["bot1"]);
|
||||
expect(res.body.guestMode.permissions.playNext).toBe(true);
|
||||
expect(res.body.guestMode.permissions.addToQueue).toBe(true); // untouched default
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user