fix(api): 服务器显示名称限 64 个可见字符,拒绝换行、控制符和不可见格式符
This commit is contained in:
19 files changed
+197
-20
No files matched your search
@@ -92,6 +92,16 @@ describe("CreateServerDialog request body", () => {
|
||||
expect(screen.queryByRole("dialog")).toBeNull();
|
||||
});
|
||||
|
||||
it("stops the display name at the length the API takes", async () => {
|
||||
const user = await openDialog();
|
||||
|
||||
await fillValid(user);
|
||||
await user.type(screen.getByLabelText("Display name (optional)"), "x".repeat(70));
|
||||
await user.click(create());
|
||||
|
||||
expect(sent().displayName).toBe("x".repeat(64));
|
||||
});
|
||||
|
||||
it("leaves a blank display name out, and sends the default sizes and policy", async () => {
|
||||
const user = await openDialog();
|
||||
|
||||
|
||||
@@ -23,7 +23,7 @@ import { Label } from "@/components/ui/label";
|
||||
import { api, humanizeError } from "@/lib/api";
|
||||
import { useAsync } from "@/lib/hooks";
|
||||
import { hostFor, type RuntimeConfig } from "@/lib/config";
|
||||
import { serverNameIssue, type ServerNameIssue } from "@/lib/naming";
|
||||
import { DISPLAY_NAME_MAX, serverNameIssue, type ServerNameIssue } from "@/lib/naming";
|
||||
import type { AutostartPolicy, CreateServerRequest } from "@/lib/types";
|
||||
import { InlineError } from "@/components/MessageLine";
|
||||
|
||||
@@ -164,6 +164,7 @@ export function CreateServerDialog({ cfg, onCreated }: Props) {
|
||||
<Input
|
||||
id="cs-display"
|
||||
placeholder={t("create_server_display_name_placeholder")}
|
||||
maxLength={DISPLAY_NAME_MAX}
|
||||
value={form.displayName ?? ""}
|
||||
onChange={(e) => set("displayName", e.target.value)}
|
||||
/>
|
||||
|
||||
@@ -79,6 +79,15 @@ describe("EditServerDialog request body", () => {
|
||||
expect(calls.patchServer).toHaveBeenCalledWith("survival", { displayName: "" });
|
||||
});
|
||||
|
||||
it("stops the display name at the length the API takes", async () => {
|
||||
const user = await openDialog();
|
||||
await user.clear(screen.getByLabelText("Display name (optional)"));
|
||||
await user.type(screen.getByLabelText("Display name (optional)"), "x".repeat(70));
|
||||
await user.click(save());
|
||||
|
||||
expect(calls.patchServer).toHaveBeenCalledWith("survival", { displayName: "x".repeat(64) });
|
||||
});
|
||||
|
||||
it("lifts the CPU limit when the field is emptied", async () => {
|
||||
const user = await openDialog();
|
||||
await user.clear(cpuInput());
|
||||
|
||||
@@ -21,6 +21,7 @@ import { Input } from "@/components/ui/input";
|
||||
import { Label } from "@/components/ui/label";
|
||||
import { api, humanizeError } from "@/lib/api";
|
||||
import { splitImageRef } from "@/lib/format";
|
||||
import { DISPLAY_NAME_MAX } from "@/lib/naming";
|
||||
import { useAsync } from "@/lib/hooks";
|
||||
import type { AutostartPolicy } from "@/lib/types";
|
||||
import { InlineError } from "@/components/MessageLine";
|
||||
@@ -237,6 +238,7 @@ export function EditServerDialog({
|
||||
<Input
|
||||
id="es-display"
|
||||
placeholder={t("create_server_display_name_placeholder")}
|
||||
maxLength={DISPLAY_NAME_MAX}
|
||||
value={form.displayName}
|
||||
onChange={(e) => set("displayName", e.target.value)}
|
||||
/>
|
||||
|
||||
@@ -52,6 +52,7 @@
|
||||
"passkey_aborted": "Passkey registration was aborted.",
|
||||
"bad_name": "That server name is invalid — use 3–32 lowercase letters, digits or dashes, and avoid reserved names.",
|
||||
"bad_subdomain": "That subdomain is invalid — use 3–32 lowercase letters, digits or dashes, and avoid reserved names.",
|
||||
"bad_display_name": "That display name is invalid — use at most 64 characters, all visible ones or spaces, with no line breaks, tabs or invisible control characters.",
|
||||
"at_capacity": "The cluster is at its running-server cap — try again once a server stops.",
|
||||
"storage_immutable": "Storage size can't be changed online.",
|
||||
"bad_idle_stop": "Idle stop must be between 1 minute and 24 hours, or Never.",
|
||||
|
||||
@@ -52,6 +52,7 @@
|
||||
"passkey_aborted": "Passkey 注册已被取消。",
|
||||
"bad_name": "服务器名称不合法:需为 3–32 位小写字母、数字或连字符,且不能使用保留名。",
|
||||
"bad_subdomain": "子域名不合法:需为 3–32 位小写字母、数字或连字符,且不能使用保留名。",
|
||||
"bad_display_name": "显示名称最多 64 个字符,只能包含可见字符和空格,不能含换行、制表符或不可见的控制字符。",
|
||||
"at_capacity": "集群的在线服务器已达上限——等一台服务器停止后再试。",
|
||||
"storage_immutable": "存储容量不支持在线调整。",
|
||||
"bad_idle_stop": "空闲停服时长须在 1 分钟到 24 小时之间,或选择“从不”。",
|
||||
|
||||
@@ -444,6 +444,12 @@ describe("api access-control wire shapes", () => {
|
||||
);
|
||||
});
|
||||
|
||||
it("says what a display name may hold when the server refuses one", () => {
|
||||
expect(humanizeError({ status: 400, code: "bad_display_name" })).toBe(
|
||||
"That display name is invalid — use at most 64 characters, all visible ones or spaces, with no line breaks, tabs or invisible control characters.",
|
||||
);
|
||||
});
|
||||
|
||||
it("says email codes are off when the install has no mail relay", async () => {
|
||||
const { humanizeError } = await import("./api");
|
||||
expect(humanizeError({ status: 503, code: "mail_unavailable" })).toBe(
|
||||
|
||||
@@ -1119,6 +1119,8 @@ export function humanizeError(e: unknown): string {
|
||||
return t("bad_name");
|
||||
case "bad_subdomain":
|
||||
return t("bad_subdomain");
|
||||
case "bad_display_name":
|
||||
return t("bad_display_name");
|
||||
case "at_capacity":
|
||||
return t("at_capacity");
|
||||
case "storage_immutable":
|
||||
|
||||
@@ -21,6 +21,10 @@ export const RESERVED_SERVER_NAMES: readonly string[] = [
|
||||
|
||||
const SERVER_NAME_RE = /^[a-z0-9-]{3,32}$/;
|
||||
|
||||
// DISPLAY_NAME_MAX mirrors naming.MaxDisplayName. The input counts UTF-16 units, so an
|
||||
// emoji takes two of them there: the box may stop a little early, never late.
|
||||
export const DISPLAY_NAME_MAX = 64;
|
||||
|
||||
export type ServerNameIssue = "shape" | "reserved";
|
||||
|
||||
/** serverNameIssue says why the API would refuse this name, or null if it takes it. */
|
||||
|
||||
@@ -3143,16 +3143,17 @@ export interface operations {
|
||||
"application/json": {
|
||||
name: string;
|
||||
subdomain: string;
|
||||
display_name?: string;
|
||||
/** @description Trimmed; at most 64 characters, all visible ones or spaces (400 bad_display_name otherwise). */
|
||||
displayName?: string;
|
||||
image?: string;
|
||||
memory?: string;
|
||||
storage?: string;
|
||||
autostart_policy?: string;
|
||||
autostartPolicy?: string;
|
||||
resources?: {
|
||||
cpu?: string;
|
||||
cpu_request?: string;
|
||||
cpuRequest?: string;
|
||||
memory?: string;
|
||||
memory_request?: string;
|
||||
memoryRequest?: string;
|
||||
};
|
||||
};
|
||||
};
|
||||
@@ -8022,7 +8023,7 @@ export interface operations {
|
||||
requestBody: {
|
||||
content: {
|
||||
"application/json": {
|
||||
/** @description Trimmed. An empty name clears it, and the server goes by its name again. */
|
||||
/** @description Trimmed. An empty name clears it, and the server goes by its name again. At most 64 characters, all visible ones or spaces (400 bad_display_name otherwise). */
|
||||
displayName?: string;
|
||||
autostartPolicy?: string;
|
||||
/** @description Re-admitted against the whitelist (a pinned name:tag@sha256:… ref is admitted by its name:tag) and pinned like create does. A pin equal to the current image is no change; any other needs confirmImageChange. */
|
||||
|
||||
Reference in new issue
Block a user