fix(api): 服务器显示名称限 64 个可见字符,拒绝换行、控制符和不可见格式符

This commit is contained in:
Lemon-miaow committed 2026-09-27 13:30:28 +08:00
1 parent b8da4e2318
commit 67a7e27f8d
19 files changed
+197 -20

No files matched your search

+30
View File
@@ -4,9 +4,11 @@ import (
"encoding/json"
"net/http"
"net/http/httptest"
"strings"
"testing"
"felis.lolicon.best/internal/apis/felis/v1alpha1"
"felis.lolicon.best/internal/naming"
corev1 "k8s.io/api/core/v1"
"k8s.io/apimachinery/pkg/api/resource"
)
@@ -43,6 +45,12 @@ const admittedImage = "registry.felis.svc:5000/mc:1"
const validCreateBody = `{"name":"survival","subdomain":"survival",` +
`"image":"registry.felis.svc:5000/mc:1","memory":"2Gi","storage":"10Gi"}`
// createBodyWithDisplayName is validCreateBody with a displayName, JSON-escaped.
func createBodyWithDisplayName(name string) string {
quoted, _ := json.Marshal(name)
return strings.TrimSuffix(validCreateBody, "}") + `,"displayName":` + string(quoted) + "}"
}
// TestCreateServerSuccess covers the happy path end-to-end: the form is
// validated, the business rows are seeded, the CRD is created cold and unowned,
// and the §22 memory ceiling is materialized on the created spec.
@@ -195,6 +203,16 @@ func TestCreateServerRejections(t *testing.T) {
body: `{"name":"survival","subdomain":"lobby","image":"registry.felis.svc:5000/mc:1","memory":"2Gi","storage":"10Gi"}`,
wantCode: http.StatusBadRequest, wantErr: "bad_subdomain",
},
{
name: "display name too long",
body: createBodyWithDisplayName(strings.Repeat("生", naming.MaxDisplayName+1)),
wantCode: http.StatusBadRequest, wantErr: "bad_display_name",
},
{
name: "display name with a line break",
body: createBodyWithDisplayName("Survival" + string(rune(0x0A)) + "Realm"),
wantCode: http.StatusBadRequest, wantErr: "bad_display_name",
},
{
name: "bad autostart policy",
body: `{"name":"survival","subdomain":"survival","image":"registry.felis.svc:5000/mc:1","memory":"2Gi","storage":"10Gi","autostartPolicy":"sometimes"}`,
@@ -330,3 +348,15 @@ func TestCreateServerWithoutBuilderIs503(t *testing.T) {
t.Error("no CRD may be created without a Builder")
}
}
// The display name is trimmed before it is written, like a patch does.
func TestCreateServerTrimsDisplayName(t *testing.T) {
api, _, cl, _ := newCreateAPI()
w := do(api.ExternalHandler(), "POST", "/api/v1/servers", createBodyWithDisplayName(" Survival Realm "), nil)
if w.Code != http.StatusCreated {
t.Fatalf("code = %d, want 201 (%s)", w.Code, w.Body.String())
}
if got := cl.created["survival"].DisplayName; got != "Survival Realm" {
t.Fatalf("created displayName = %q, want %q", got, "Survival Realm")
}
}
+10
View File
@@ -177,6 +177,16 @@ func TestPatchServerRejections(t *testing.T) {
body: `{"displayName":"x"}`,
wantCode: http.StatusBadRequest, wantErr: "bad_name",
},
{
name: "display name too long",
body: `{"displayName":"` + strings.Repeat("x", 65) + `"}`,
wantCode: http.StatusBadRequest, wantErr: "bad_display_name",
},
{
name: "display name with a right-to-left override",
body: `{"displayName":"abc` + string(rune(0x202E)) + `exe.txt"}`,
wantCode: http.StatusBadRequest, wantErr: "bad_display_name",
},
{
name: "empty autostart policy",
body: `{"autostartPolicy":""}`,
+11 -2
View File
@@ -455,6 +455,11 @@ func (a *API) handleCreateServer(w http.ResponseWriter, r *http.Request) {
writeError(w, r, newError(http.StatusBadRequest, "bad_subdomain", "invalid subdomain: %v", err))
return
}
displayName, err := naming.CleanDisplayName(body.DisplayName)
if err != nil {
writeError(w, r, newError(http.StatusBadRequest, "bad_display_name", "invalid display name: %v", err))
return
}
policy, err := parseAutostartPolicy(body.AutostartPolicy)
if err != nil {
@@ -569,7 +574,7 @@ func (a *API) handleCreateServer(w http.ResponseWriter, r *http.Request) {
in := CreateServerInput{
Name: body.Name,
Subdomain: body.Subdomain,
DisplayName: body.DisplayName,
DisplayName: displayName,
Image: image,
JavaMemory: javaMemory,
StorageSize: storage,
@@ -930,7 +935,11 @@ func (a *API) handlePatchServer(w http.ResponseWriter, r *http.Request) {
if body.DisplayName != nil {
// An empty name is allowed: the panel then shows the server's name.
displayName := strings.TrimSpace(*body.DisplayName)
displayName, err := naming.CleanDisplayName(*body.DisplayName)
if err != nil {
writeError(w, r, newError(http.StatusBadRequest, "bad_display_name", "invalid display name: %v", err))
return
}
patch.DisplayName = &displayName
changed = append(changed, "displayName")
}