Files
SaveAny-Bot/storage/alist/alist_test.go
T
Krau c2f8ab3c01 refactor: quality overhaul (#234)
* fix: prevent queue deadlock after cancelling tasks

Get no longer recurses while holding the mutex.
Cancelled queued tasks leave the map, making their IDs reusable.
Closed empty queues return ErrQueueClosed.

* fix: init task queue lazily and close on shutdown

AddTask is safe before Run by initializing the queue once.
Close unblocks workers waiting in Get.

* fix: make resource fingerprints deterministic

Sort map keys before hashing so Resource.ID is stable.

* fix: harden per-item processing tracking in tasks

Use the resource fingerprint as the dedup key on insert and delete.
Check and set processing entries atomically instead of TOCTOU.
Count only successful downloads.

* fix: honor IgnoreErrors in batch tasks

Element failures no longer cancel sibling elements or stop later groups.

* fix: report streamed upload bytes in batch tasks

Stream downloads report their byte count as the upload total.

* fix: validate i18n key parity across locales

geni18n fails when a language file misses any key.
Align the syncpeers completion key between en and zh-Hans.
Translate three untranslated parse keys in zh-Hans.

* refactor: share progress throttling helpers

Move size-tiered and count-based throttling into progressutil.
Localize hardcoded Chinese progress strings.
Drop five duplicated implementations and dead local copies.

* refactor: share unique filename logic

Storage backends use fsutil.UniquePath instead of local loops.

* fix: sanitize local storage paths

Reject absolute paths and dot-dot escapes in Save.
Check close errors and wrap creation failures.

* fix: preserve webdav error causes

Wrap mkdir and write failures with %w and drop dead error values.

* fix: kill rclone subprocess on reader close

Prevent cat processes from hanging after the pipe is closed.

* fix: fail alist init instead of exiting

Replace log.Fatalf with wrapped errors so a bad alist cannot kill the bot.
Cancel token refresh with the init context and re-login on 401.

* fix: enforce telegram album limits and track saved paths

Use tglimit.MaxAlbumItems for album batching and video splitting.
Exists now reports previously saved paths instead of always false.

* fix: guard storage registry maps

Protect Storages and UserStorages with mutexes and expose read accessors.

* fix: harden JS parser plugin runtime

Validate semver instead of panicking and require canHandle.
Recover plugin worker panics and time out CanHandle calls.
Return a copy from the registry and sanitize install filenames.

* fix: guard kemono parser against nil fields

Skip sparse preview and attachment entries instead of panicking.

* refactor: remove commented-out dead code

Drop unused kemono legacy types and commented response structs.

* test: cover invalid plugin version rejection

* fix: show all queued tasks in /task list

Render up to ten tasks and append the truncation note once.

* fix: guard callback data parsing

Reject malformed callback payloads before indexing split parts.

* fix: isolate media groups per user

Key pending groups by chat, user and group id.

* fix: require permission for callback handlers

* fix: initialize userbot context once

Replace the racy lazy init with sync.OnceValue.

* fix: avoid leaking raw errors in /dir reply

* fix: notify users on invalid update version

* fix: fail fast when API listen fails

Bind synchronously and surface errors instead of logging them.

* fix: add timeouts and backoff to webhook delivery

* refactor: remove dead code from api and bot

Drop the empty ProgressTracker shim, unused token context key and a redundant SetBotCommands call.

* fix: load remote config without local lookup

Skip the local file search after reading a config URL and add a timeout.

* refactor: drop unused hook config

* docs: document parser plugin config

* ci: fix BuildTime formatting and align checkout

Actions format does not format dates; pass the raw timestamp.

* chore: ignore cache directory

* fix: make cache init idempotent

* fix: upload only downloaded batch elements

Failed elements keep partial cache files and never reach the backend.
Successfully downloaded siblings still upload when one element fails.

* fix: record telegram saved paths only after upload

Skip-large returns a sentinel so skipped files are not marked as saved.

* fix: deduplicate alist token refreshes

Guard token access with a mutex and merge concurrent logins.
Reuse a recent refresh to avoid login storms.

* test: cover concurrent alist 401 retry

Ten parallel uploads share a single re-login under -race.

* fix: count parsed resources in progress text

* fix: localize storage lookup errors in /dir

Use the shared i18n key and escape the dynamic error.

* fix: deduplicate concurrent storage initialization

singleflight merges first-time inits so side effects are not duplicated.

* fix: guard nil progress trackers in api-created tasks

Batch, telegraph and transfer tasks run without a Telegram tracker
when created through the API; their callbacks must not panic.

* fix: keep album order when filtering failed batch items

Download results are stored by original index so surviving
elements keep their source order.

* test: cover nil-tracker task execution

* fix: report partial failure in batch done message

IgnoreErrors runs with failed elements show success and failed
counts instead of claiming every file completed.

* fix: skip login refresh for token-only alist storage

401 responses surface the auth error instead of sending a
credential-less login; the refresh window never exceeds TokenExp.

* test: cover alist refresh semantics

Concurrent refresh uses username/password; token-only storage
never attempts a login on 401.

* fix: call tracker from notifyProgress instead of recursing

The helper called itself, overflowing the stack on any batch
task with a progress tracker.

* fix: propagate cancellation past IgnoreErrors

Cancelled tasks must not be reported as successful: only
ordinary element failures are ignored.

* test: cover notifyProgress tracker call

* test: cover cancellation with IgnoreErrors

* fix: refresh alist token after startup 401s

The init login no longer satisfies the dedup window, so an
early 401 triggers a real refresh; later 401s reuse it.
Clarify that streaming uploads cannot replay their body.

* test: exercise the alist 401 refresh path

Concurrent uploads now reject the init token, share one
refresh and retry with the new token; token-only stays inert.

* style: trim verbose comments

Drop process-style explanations; keep one-line behavior notes.

* style: gofmt test files

* fix: drop unbounded saved-path cache in telegram storage

Telegram cannot reliably query remote file existence, so the
cache answered a question it could not answer and grew without
bound. Exists returns false again, as before.

* style: format codes
2026-08-17 19:10:03 +08:00

153 lines
4.4 KiB
Go

package alist_test
import (
"bytes"
"encoding/json"
"fmt"
"net/http"
"net/http/httptest"
"strings"
"sync"
"testing"
storconfig "github.com/krau/SaveAny-Bot/config/storage"
"github.com/krau/SaveAny-Bot/storage/alist"
)
// newAlistServer starts a fake alist whose login endpoint issues sequential
// tokens and whose PUT endpoint rejects the given token (simulating an expired
// credential) while accepting refreshed ones.
func newAlistServer(t *testing.T, rejectedToken string) (*httptest.Server, *sync.Mutex, *int, *[]putRecord) {
t.Helper()
var mu sync.Mutex
loginCount := 0
tokenSeq := 0
var puts []putRecord
mux := http.NewServeMux()
mux.HandleFunc("/api/auth/login", func(w http.ResponseWriter, r *http.Request) {
mu.Lock()
loginCount++
tokenSeq++
token := fmt.Sprintf("token-%d", tokenSeq)
mu.Unlock()
w.Header().Set("Content-Type", "application/json")
json.NewEncoder(w).Encode(map[string]any{"code": 200, "message": "ok", "data": map[string]any{"token": token}})
})
mux.HandleFunc("/api/me", func(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
json.NewEncoder(w).Encode(map[string]any{"code": 200, "message": "ok", "data": map[string]any{"username": "probe"}})
})
mux.HandleFunc("/api/fs/put", func(w http.ResponseWriter, r *http.Request) {
mu.Lock()
rejected := r.Header.Get("Authorization") == rejectedToken
puts = append(puts, putRecord{auth: r.Header.Get("Authorization"), rejected: rejected})
mu.Unlock()
w.Header().Set("Content-Type", "application/json")
if rejected {
w.WriteHeader(http.StatusUnauthorized)
json.NewEncoder(w).Encode(map[string]any{"code": 401, "message": "unauthorized"})
return
}
json.NewEncoder(w).Encode(map[string]any{"code": 200, "message": "ok"})
})
srv := httptest.NewServer(mux)
t.Cleanup(srv.Close)
return srv, &mu, &loginCount, &puts
}
type putRecord struct {
auth string
rejected bool
}
// Regression: concurrent uploads hitting 401 must share a single re-login
// (singleflight) and retry with the refreshed token. Init performs login #1
// (token-1); the server rejects it, so the concurrent uploads must trigger a
// second, merged login (token-2).
func TestConcurrent401RetrySingleLogin(t *testing.T) {
srv, mu, loginCount, putAuths := newAlistServer(t, "token-1")
cfg := &storconfig.AlistStorageConfig{}
cfg.Name = "probe"
cfg.URL = srv.URL
cfg.Username = "user"
cfg.Password = "pass"
cfg.BasePath = "/probe"
stor := &alist.Alist{}
if err := stor.Init(t.Context(), cfg); err != nil {
t.Fatalf("Init failed: %v", err)
}
const workers = 10
var wg sync.WaitGroup
errs := make(chan error, workers)
for range workers {
wg.Go(func() {
errs <- stor.Save(t.Context(), bytes.NewReader([]byte("data")), "dir/file.txt")
})
}
wg.Wait()
close(errs)
for err := range errs {
if err != nil {
t.Fatalf("Save failed: %v", err)
}
}
mu.Lock()
defer mu.Unlock()
// One login for init, one merged login for the 401 storm.
if *loginCount != 2 {
t.Fatalf("expected 2 logins (init + merged retry), got %d", *loginCount)
}
accepted := 0
for _, put := range *putAuths {
if put.rejected {
if put.auth != "token-1" {
t.Fatalf("expected rejected uploads to use the expired token-1, got %q", put.auth)
}
continue
}
accepted++
if put.auth != "token-2" {
t.Fatalf("expected accepted uploads to use the refreshed token-2, got %q", put.auth)
}
}
if accepted != workers {
t.Fatalf("expected %d accepted uploads, got %d", workers, accepted)
}
}
// A token-only storage receives 401 and must return the auth error without
// attempting a login (it has no credentials to refresh with).
func TestTokenOnlyNoLoginOn401(t *testing.T) {
srv, mu, loginCount, _ := newAlistServer(t, "token-0")
cfg := &storconfig.AlistStorageConfig{}
cfg.Name = "probe"
cfg.URL = srv.URL
cfg.Token = "token-0"
cfg.BasePath = "/probe"
stor := &alist.Alist{}
if err := stor.Init(t.Context(), cfg); err != nil {
t.Fatalf("Init failed: %v", err)
}
err := stor.Save(t.Context(), bytes.NewReader([]byte("data")), "dir/file.txt")
if err == nil {
t.Fatal("expected auth error from token-only storage, got nil")
}
if !strings.Contains(err.Error(), "401") {
t.Fatalf("expected 401 auth error, got: %v", err)
}
mu.Lock()
defer mu.Unlock()
if *loginCount != 0 {
t.Fatalf("expected no login attempts for token-only storage, got %d", *loginCount)
}
}