fix(api): 服务器显示名称限 64 个可见字符,拒绝换行、控制符和不可见格式符
This commit is contained in:
19 files changed
+197
-20
No files matched your search
@@ -4,9 +4,11 @@ import (
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"felis.lolicon.best/internal/apis/felis/v1alpha1"
|
||||
"felis.lolicon.best/internal/naming"
|
||||
corev1 "k8s.io/api/core/v1"
|
||||
"k8s.io/apimachinery/pkg/api/resource"
|
||||
)
|
||||
@@ -43,6 +45,12 @@ const admittedImage = "registry.felis.svc:5000/mc:1"
|
||||
const validCreateBody = `{"name":"survival","subdomain":"survival",` +
|
||||
`"image":"registry.felis.svc:5000/mc:1","memory":"2Gi","storage":"10Gi"}`
|
||||
|
||||
// createBodyWithDisplayName is validCreateBody with a displayName, JSON-escaped.
|
||||
func createBodyWithDisplayName(name string) string {
|
||||
quoted, _ := json.Marshal(name)
|
||||
return strings.TrimSuffix(validCreateBody, "}") + `,"displayName":` + string(quoted) + "}"
|
||||
}
|
||||
|
||||
// TestCreateServerSuccess covers the happy path end-to-end: the form is
|
||||
// validated, the business rows are seeded, the CRD is created cold and unowned,
|
||||
// and the §22 memory ceiling is materialized on the created spec.
|
||||
@@ -195,6 +203,16 @@ func TestCreateServerRejections(t *testing.T) {
|
||||
body: `{"name":"survival","subdomain":"lobby","image":"registry.felis.svc:5000/mc:1","memory":"2Gi","storage":"10Gi"}`,
|
||||
wantCode: http.StatusBadRequest, wantErr: "bad_subdomain",
|
||||
},
|
||||
{
|
||||
name: "display name too long",
|
||||
body: createBodyWithDisplayName(strings.Repeat("生", naming.MaxDisplayName+1)),
|
||||
wantCode: http.StatusBadRequest, wantErr: "bad_display_name",
|
||||
},
|
||||
{
|
||||
name: "display name with a line break",
|
||||
body: createBodyWithDisplayName("Survival" + string(rune(0x0A)) + "Realm"),
|
||||
wantCode: http.StatusBadRequest, wantErr: "bad_display_name",
|
||||
},
|
||||
{
|
||||
name: "bad autostart policy",
|
||||
body: `{"name":"survival","subdomain":"survival","image":"registry.felis.svc:5000/mc:1","memory":"2Gi","storage":"10Gi","autostartPolicy":"sometimes"}`,
|
||||
@@ -330,3 +348,15 @@ func TestCreateServerWithoutBuilderIs503(t *testing.T) {
|
||||
t.Error("no CRD may be created without a Builder")
|
||||
}
|
||||
}
|
||||
|
||||
// The display name is trimmed before it is written, like a patch does.
|
||||
func TestCreateServerTrimsDisplayName(t *testing.T) {
|
||||
api, _, cl, _ := newCreateAPI()
|
||||
w := do(api.ExternalHandler(), "POST", "/api/v1/servers", createBodyWithDisplayName(" Survival Realm "), nil)
|
||||
if w.Code != http.StatusCreated {
|
||||
t.Fatalf("code = %d, want 201 (%s)", w.Code, w.Body.String())
|
||||
}
|
||||
if got := cl.created["survival"].DisplayName; got != "Survival Realm" {
|
||||
t.Fatalf("created displayName = %q, want %q", got, "Survival Realm")
|
||||
}
|
||||
}
|
||||
@@ -177,6 +177,16 @@ func TestPatchServerRejections(t *testing.T) {
|
||||
body: `{"displayName":"x"}`,
|
||||
wantCode: http.StatusBadRequest, wantErr: "bad_name",
|
||||
},
|
||||
{
|
||||
name: "display name too long",
|
||||
body: `{"displayName":"` + strings.Repeat("x", 65) + `"}`,
|
||||
wantCode: http.StatusBadRequest, wantErr: "bad_display_name",
|
||||
},
|
||||
{
|
||||
name: "display name with a right-to-left override",
|
||||
body: `{"displayName":"abc` + string(rune(0x202E)) + `exe.txt"}`,
|
||||
wantCode: http.StatusBadRequest, wantErr: "bad_display_name",
|
||||
},
|
||||
{
|
||||
name: "empty autostart policy",
|
||||
body: `{"autostartPolicy":""}`,
|
||||
|
||||
@@ -455,6 +455,11 @@ func (a *API) handleCreateServer(w http.ResponseWriter, r *http.Request) {
|
||||
writeError(w, r, newError(http.StatusBadRequest, "bad_subdomain", "invalid subdomain: %v", err))
|
||||
return
|
||||
}
|
||||
displayName, err := naming.CleanDisplayName(body.DisplayName)
|
||||
if err != nil {
|
||||
writeError(w, r, newError(http.StatusBadRequest, "bad_display_name", "invalid display name: %v", err))
|
||||
return
|
||||
}
|
||||
|
||||
policy, err := parseAutostartPolicy(body.AutostartPolicy)
|
||||
if err != nil {
|
||||
@@ -569,7 +574,7 @@ func (a *API) handleCreateServer(w http.ResponseWriter, r *http.Request) {
|
||||
in := CreateServerInput{
|
||||
Name: body.Name,
|
||||
Subdomain: body.Subdomain,
|
||||
DisplayName: body.DisplayName,
|
||||
DisplayName: displayName,
|
||||
Image: image,
|
||||
JavaMemory: javaMemory,
|
||||
StorageSize: storage,
|
||||
@@ -930,7 +935,11 @@ func (a *API) handlePatchServer(w http.ResponseWriter, r *http.Request) {
|
||||
|
||||
if body.DisplayName != nil {
|
||||
// An empty name is allowed: the panel then shows the server's name.
|
||||
displayName := strings.TrimSpace(*body.DisplayName)
|
||||
displayName, err := naming.CleanDisplayName(*body.DisplayName)
|
||||
if err != nil {
|
||||
writeError(w, r, newError(http.StatusBadRequest, "bad_display_name", "invalid display name: %v", err))
|
||||
return
|
||||
}
|
||||
patch.DisplayName = &displayName
|
||||
changed = append(changed, "displayName")
|
||||
}
|
||||
|
||||
@@ -9,6 +9,8 @@ import (
|
||||
"fmt"
|
||||
"regexp"
|
||||
"strings"
|
||||
"unicode"
|
||||
"unicode/utf8"
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -145,6 +147,33 @@ func ValidateSystemServerName(name string) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// zeroWidthJoiner (U+200D) glues emoji such as the rainbow flag into one picture.
|
||||
const zeroWidthJoiner = 0x200D
|
||||
|
||||
// MaxDisplayName is the most characters a server's display name may have. The
|
||||
// panel shows it on one line in the fleet grid and the server header.
|
||||
const MaxDisplayName = 64
|
||||
|
||||
// CleanDisplayName trims a server's display name and checks what is left: at most
|
||||
// MaxDisplayName characters, every one a visible character or a space. Control
|
||||
// characters, line breaks and the invisible format characters (bidi overrides,
|
||||
// zero-width spaces) are refused, since they would break the line the panel puts
|
||||
// the name on or make it read as something else; the zero-width joiner stays,
|
||||
// because emoji such as the rainbow flag are built with it. An empty result is
|
||||
// valid: the server then goes by its name.
|
||||
func CleanDisplayName(s string) (string, error) {
|
||||
s = strings.TrimSpace(s)
|
||||
if n := utf8.RuneCountInString(s); n > MaxDisplayName {
|
||||
return "", fmt.Errorf("naming: display name has %d characters, at most %d are allowed", n, MaxDisplayName)
|
||||
}
|
||||
for _, r := range s {
|
||||
if r == utf8.RuneError || !unicode.IsGraphic(r) && r != zeroWidthJoiner {
|
||||
return "", fmt.Errorf("naming: display name contains %U, which is not a visible character", r)
|
||||
}
|
||||
}
|
||||
return s, nil
|
||||
}
|
||||
|
||||
// worldVolumeName mirrors operator.dataVolumeName: the per-server StatefulSet's
|
||||
// volumeClaimTemplate is named "world", so a single-replica server's world PVC
|
||||
// is "world-<name>-0". This is the one naming convention shared by the operator
|
||||
|
||||
@@ -149,3 +149,41 @@ func TestValidateHostname(t *testing.T) {
|
||||
t.Error("ValidateHostname should reject an empty root domain")
|
||||
}
|
||||
}
|
||||
|
||||
func TestCleanDisplayName(t *testing.T) {
|
||||
str := func(rs ...rune) string { return string(rs) }
|
||||
rainbow := str(0x1F3F3, 0xFE0F, 0x200D, 0x1F308)
|
||||
cjk := func(n int) string {
|
||||
s := ""
|
||||
for range n {
|
||||
s += "生"
|
||||
}
|
||||
return s
|
||||
}
|
||||
for _, c := range []struct {
|
||||
name, in, want string
|
||||
ok bool
|
||||
}{
|
||||
{"trimmed", " Survival World ", "Survival World", true},
|
||||
{"empty", "", "", true},
|
||||
{"only spaces", " ", "", true},
|
||||
{"cjk and punctuation", "生存服 · 第二季!", "生存服 · 第二季!", true},
|
||||
{"emoji joined by zwj", "Pride " + rainbow, "Pride " + rainbow, true},
|
||||
{"ideographic space inside", "生存" + str(0x3000) + "服", "生存" + str(0x3000) + "服", true},
|
||||
{"64 characters of 3 bytes each", cjk(64), cjk(64), true},
|
||||
{"65 characters", cjk(65), "", false},
|
||||
{"tab", "a" + str(0x09) + "b", "", false},
|
||||
{"newline", "a" + str(0x0A) + "b", "", false},
|
||||
{"nul", "a" + str(0x00), "", false},
|
||||
{"right-to-left override", "abc" + str(0x202E) + "exe.txt", "", false},
|
||||
{"zero-width space", "ad" + str(0x200B) + "min", "", false},
|
||||
{"line separator", "a" + str(0x2028) + "b", "", false},
|
||||
{"private use", "a" + str(0xE000), "", false},
|
||||
{"invalid utf-8", string([]byte{'a', 0xff}), "", false},
|
||||
} {
|
||||
got, err := naming.CleanDisplayName(c.in)
|
||||
if (err == nil) != c.ok || got != c.want {
|
||||
t.Errorf("%s: CleanDisplayName(%q) = %q, %v; want %q, ok=%v", c.name, c.in, got, err, c.want, c.ok)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,6 +1,7 @@
|
||||
package naming
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
"regexp"
|
||||
"slices"
|
||||
@@ -11,7 +12,8 @@ import (
|
||||
// The panel's create form checks names as they are typed with its own copy of
|
||||
// this rule (panel/src/lib/naming.ts). A name reserved or a length changed here
|
||||
// without the panel would let the form send what the API refuses, or refuse what
|
||||
// it takes, so the copy is compared to the source.
|
||||
// it takes, so the copy is compared to the source. The copy also holds the display-name
|
||||
// length the create and edit forms stop at.
|
||||
func TestPanelMirrorsServerNameRule(t *testing.T) {
|
||||
raw, err := os.ReadFile("../../panel/src/lib/naming.ts")
|
||||
if err != nil {
|
||||
@@ -40,4 +42,7 @@ func TestPanelMirrorsServerNameRule(t *testing.T) {
|
||||
if want := "const SERVER_NAME_RE = /" + serverNameRE.String() + "/;"; !strings.Contains(src, want) {
|
||||
t.Errorf("panel/src/lib/naming.ts lacks %q", want)
|
||||
}
|
||||
if want := fmt.Sprintf("export const DISPLAY_NAME_MAX = %d;", MaxDisplayName); !strings.Contains(src, want) {
|
||||
t.Errorf("panel/src/lib/naming.ts lacks %q", want)
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user