mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-02 21:12:49 +08:00
fix(guest): deny favorites + auth-status reads to guests; UI polish
Consolidated fix wave from the final whole-branch review of guest mode. - FIX 1 (critical): gate /api/favorites mount with requireNotGuest — the router keys off req.user.id (shared __guest__ principal), so guests could read/write a shared favorites bucket. Added focused guest-deny tests. - FIX 2: gate GET /api/auth/status and /api/auth/qrcode/status with requireNotGuest so config reads no longer leak to guests. - FIX 3: requireAuthInline in createSessionRouter now rejects guest sessions with 401 once guest mode is disabled (mirrors createRequireAuth), so /me stops returning guest data after an admin disables the feature. - FIX 4: Login guest button now sits BELOW the card (auth-page flex-direction column + guest-btn width 360px) instead of beside it. - FIX 5: mobile mini-player transport buttons in App.vue are now per-button gated for guests (prev/play/next/mode/volume), mirroring Player.vue. - FIX 6: refreshed stale "gated on player.control" seek comments in Player.vue and relabeled the now-stale quality-GET test. npm test: 354/354 pass. npm run build: tsc + vue-tsc + vite all green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
e47fc76529
commit
f142c514cd
8 files changed
+113
-12
No files matched your search
@@ -236,4 +236,37 @@ describe("session router — guest mode", () => {
|
||||
const res = await request(app).get("/api/session/needs-setup");
|
||||
expect(res.body.guestAllowed).toBe(true);
|
||||
});
|
||||
|
||||
it("GET /me returns 401 for a guest session once guest mode is disabled", async () => {
|
||||
// Build an app whose guest config can be toggled at runtime, mirroring an
|
||||
// admin flipping the setting mid-session (requireAuthInline must reject).
|
||||
botDb = createDatabase(":memory:");
|
||||
const users = createUserStore(botDb.db);
|
||||
const sessions = createSessionStore(botDb.db);
|
||||
const audit = createAuditStore(botDb.db);
|
||||
const permissions = createPermissionStore(botDb.db);
|
||||
const guestCfg: GuestModeConfig = {
|
||||
enabled: true,
|
||||
bots: getDefaultConfig().guestMode.bots,
|
||||
permissions: getDefaultConfig().guestMode.permissions,
|
||||
};
|
||||
const app = express();
|
||||
app.use(express.json());
|
||||
app.use(cookieParser());
|
||||
app.use(
|
||||
"/api/session",
|
||||
createSessionRouter(users, sessions, audit, pino({ level: "silent" }), permissions, () => guestCfg)
|
||||
);
|
||||
|
||||
const login = await request(app).post("/api/session/guest");
|
||||
expect(login.status).toBe(200);
|
||||
const cookie = login.headers["set-cookie"];
|
||||
|
||||
// While enabled, /me works for the guest.
|
||||
expect((await request(app).get("/api/session/me").set("Cookie", cookie)).status).toBe(200);
|
||||
|
||||
// Admin disables guest mode → the in-flight guest session is now invalid.
|
||||
guestCfg.enabled = false;
|
||||
expect((await request(app).get("/api/session/me").set("Cookie", cookie)).status).toBe(401);
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user