package app import ( "encoding/json" "fmt" "net/http" "net/http/httptest" "strings" "testing" "time" "lingniu/vehicle-data-platform/apps/api/internal/config" ) func TestWithRequestTimeoutAddsContextDeadline(t *testing.T) { handler := withRequestTimeout(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { deadline, ok := r.Context().Deadline() if !ok { t.Fatal("request context should have deadline") } if time.Until(deadline) > 250*time.Millisecond { t.Fatalf("deadline too far away: %s", time.Until(deadline)) } w.WriteHeader(http.StatusNoContent) }), 200*time.Millisecond) rec := httptest.NewRecorder() req := httptest.NewRequest(http.MethodGet, "/api/ops/health", nil) handler.ServeHTTP(rec, req) if rec.Code != http.StatusNoContent { t.Fatalf("status = %d", rec.Code) } } func TestProductionDataModeFailsClosedWithoutMySQL(t *testing.T) { handler := NewServer(config.Config{DataMode: "production", RequestTimeout: time.Second}) rec := httptest.NewRecorder() handler.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/api/ops/health", nil)) if rec.Code != http.StatusServiceUnavailable || !strings.Contains(rec.Body.String(), "DATA_STORE_UNAVAILABLE") { t.Fatalf("status=%d body=%s", rec.Code, rec.Body.String()) } } func TestWithRequestTimeoutReturnsEnvelopeWithTraceID(t *testing.T) { handler := withRequestTimeout(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { <-r.Context().Done() }), time.Millisecond) rec := httptest.NewRecorder() req := httptest.NewRequest(http.MethodGet, "/api/ops/health", nil) req.Header.Set("X-Trace-Id", "trace-from-test") handler.ServeHTTP(rec, req) if rec.Code != http.StatusServiceUnavailable { t.Fatalf("status = %d body=%s", rec.Code, rec.Body.String()) } var body struct { Error struct { Code string `json:"code"` Message string `json:"message"` } `json:"error"` TraceID string `json:"traceId"` } if err := json.Unmarshal(rec.Body.Bytes(), &body); err != nil { t.Fatalf("timeout response should be JSON: %v body=%s", err, rec.Body.String()) } if body.Error.Code != "REQUEST_TIMEOUT" || body.Error.Message != "请求处理超时" || body.TraceID != "trace-from-test" { t.Fatalf("unexpected timeout envelope: %+v body=%s", body, rec.Body.String()) } } func TestAppConfigScriptIsRuntimeRendered(t *testing.T) { handler := withAppConfig(http.NotFoundHandler(), config.Config{ AMapWebJSKey: "web-key", AMapAPIKey: "server-api-key", AMapSecurityCode: "security-code", AMapServiceHost: "/_AMapService", }) rec := httptest.NewRecorder() req := httptest.NewRequest(http.MethodGet, "/app-config.js", nil) handler.ServeHTTP(rec, req) if rec.Code != http.StatusOK { t.Fatalf("status = %d body=%s", rec.Code, rec.Body.String()) } if got := rec.Header().Get("Cache-Control"); got != "no-store" { t.Fatalf("Cache-Control = %q, want no-store", got) } body := rec.Body.String() for _, want := range []string{"window.__LINGNIU_APP_CONFIG__=", `"amapWebJsKey":"web-key"`, `"amapSecurityServiceHost":"/_AMapService"`} { if !strings.Contains(body, want) { t.Fatalf("app config script missing %q: %s", want, body) } } if strings.Contains(body, "security-code") || strings.Contains(body, "server-api-key") || strings.Contains(body, "amapSecurityJsCode") || strings.Contains(body, "amapApiKey") { t.Fatalf("app config script should not expose server-side AMap secrets: %s", body) } } func TestAMapSecurityProxyAppendsServerSideJscode(t *testing.T) { var gotPath string var gotJscode string upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { gotPath = r.URL.Path gotJscode = r.URL.Query().Get("jscode") w.Header().Set("X-AMap-Test", "ok") _, _ = w.Write([]byte("proxied")) })) defer upstream.Close() handler := withAMapSecurityProxy(http.NotFoundHandler(), config.Config{ AMapSecurityCode: "security-code", AMapServiceHost: "/_AMapService", }, amapProxyUpstreams{RestAPI: upstream.URL}, http.DefaultClient) rec := httptest.NewRecorder() req := httptest.NewRequest(http.MethodGet, "/_AMapService/v3/weather/weatherInfo?city=440100", nil) handler.ServeHTTP(rec, req) if rec.Code != http.StatusOK { t.Fatalf("status = %d body=%s", rec.Code, rec.Body.String()) } if gotPath != "/v3/weather/weatherInfo" || gotJscode != "security-code" { t.Fatalf("upstream path=%q jscode=%q", gotPath, gotJscode) } if rec.Body.String() != "proxied" || rec.Header().Get("X-AMap-Test") != "ok" { t.Fatalf("proxy response not copied: headers=%v body=%s", rec.Header(), rec.Body.String()) } } func TestAMapSecurityProxyRoutesKnownMapResources(t *testing.T) { seen := map[string]string{} newUpstream := func(name string) *httptest.Server { return httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { seen[name] = r.URL.Path _, _ = w.Write([]byte(name)) })) } rest := newUpstream("rest") webapi := newUpstream("webapi") fmap := newUpstream("fmap") defer rest.Close() defer webapi.Close() defer fmap.Close() handler := withAMapSecurityProxy(http.NotFoundHandler(), config.Config{ AMapSecurityCode: "security-code", AMapServiceHost: "/_AMapService", }, amapProxyUpstreams{RestAPI: rest.URL, WebAPI: webapi.URL, FMap: fmap.URL}, http.DefaultClient) for _, path := range []string{ "/_AMapService/v4/map/styles", "/_AMapService/v3/vectormap", "/_AMapService/v3/weather/weatherInfo", } { rec := httptest.NewRecorder() req := httptest.NewRequest(http.MethodGet, path, nil) handler.ServeHTTP(rec, req) if rec.Code != http.StatusOK { t.Fatalf("%s status = %d body=%s", path, rec.Code, rec.Body.String()) } } if seen["webapi"] != "/v4/map/styles" || seen["fmap"] != "/v3/vectormap" || seen["rest"] != "/v3/weather/weatherInfo" { t.Fatalf("unexpected proxy routing: %+v", seen) } } func TestAMapReverseGeocodeAPIUsesServerSideKey(t *testing.T) { var gotKey string var gotLocation string upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { gotKey = r.URL.Query().Get("key") gotLocation = r.URL.Query().Get("location") if r.URL.Path != "/v3/geocode/regeo" { t.Fatalf("path = %q", r.URL.Path) } _, _ = w.Write([]byte(`{ "status":"1", "info":"OK", "regeocode":{ "formatted_address":"广东省广州市天河区测试路", "addressComponent":{ "province":"广东省", "city":"广州市", "district":"天河区", "township":"五山街道", "adcode":"440106" } } }`)) })) defer upstream.Close() handler := withAMapReverseGeocodeAPI(http.NotFoundHandler(), config.Config{AMapAPIKey: "server-api-key"}, upstream.URL, http.DefaultClient) rec := httptest.NewRecorder() req := httptest.NewRequest(http.MethodGet, "/api/map/reverse-geocode?longitude=113.1234567&latitude=23.7654321", nil) req.Header.Set("X-Trace-Id", "trace-map") handler.ServeHTTP(rec, req) if rec.Code != http.StatusOK { t.Fatalf("status = %d body=%s", rec.Code, rec.Body.String()) } mapLongitude, mapLatitude := wgs84ToGCJ02(113.1234567, 23.7654321) if gotKey != "server-api-key" || gotLocation != fmt.Sprintf("%.6f,%.6f", mapLongitude, mapLatitude) { t.Fatalf("key=%q location=%q", gotKey, gotLocation) } var body struct { Data struct { Provider string `json:"provider"` Longitude float64 `json:"longitude"` Latitude float64 `json:"latitude"` FormattedAddress string `json:"formattedAddress"` Province string `json:"province"` City string `json:"city"` District string `json:"district"` Township string `json:"township"` Adcode string `json:"adcode"` } `json:"data"` TraceID string `json:"traceId"` } if err := json.Unmarshal(rec.Body.Bytes(), &body); err != nil { t.Fatalf("response should be JSON: %v body=%s", err, rec.Body.String()) } if body.TraceID != "trace-map" || body.Data.Provider != "AMap" || body.Data.FormattedAddress != "广东省广州市天河区测试路" || body.Data.Adcode != "440106" { t.Fatalf("unexpected reverse geocode body: %+v", body) } } func TestAMapReverseGeocodeAPIRequiresServerSideKey(t *testing.T) { handler := withAMapReverseGeocodeAPI(http.NotFoundHandler(), config.Config{}, "https://example.com", http.DefaultClient) rec := httptest.NewRecorder() req := httptest.NewRequest(http.MethodGet, "/api/map/reverse-geocode?longitude=113.1&latitude=23.1", nil) handler.ServeHTTP(rec, req) if rec.Code != http.StatusServiceUnavailable { t.Fatalf("status = %d body=%s", rec.Code, rec.Body.String()) } if !strings.Contains(rec.Body.String(), "AMAP_API_UNCONFIGURED") { t.Fatalf("body should mention missing AMap API config: %s", rec.Body.String()) } } func TestAMapReverseGeocodeAPIRejectsBadCoordinate(t *testing.T) { handler := withAMapReverseGeocodeAPI(http.NotFoundHandler(), config.Config{AMapAPIKey: "server-api-key"}, "https://example.com", http.DefaultClient) rec := httptest.NewRecorder() req := httptest.NewRequest(http.MethodGet, "/api/map/reverse-geocode?longitude=0&latitude=0", nil) handler.ServeHTTP(rec, req) if rec.Code != http.StatusBadRequest { t.Fatalf("status = %d body=%s", rec.Code, rec.Body.String()) } if !strings.Contains(rec.Body.String(), "BAD_COORDINATE") { t.Fatalf("body should mention bad coordinate: %s", rec.Body.String()) } } func TestServerRequiresAuthenticationForAMapReverseGeocode(t *testing.T) { handler := NewServer(config.Config{ AuthMode: "enforce", AuthTokensJSON: `[{"token":"0123456789abcdef","name":"test-viewer","role":"viewer"}]`, DataMode: "mock", AMapAPIKey: "server-api-key", RequestTimeout: time.Second, }) recorder := httptest.NewRecorder() request := httptest.NewRequest(http.MethodGet, "/api/map/reverse-geocode?longitude=121.47&latitude=31.23", nil) handler.ServeHTTP(recorder, request) if recorder.Code != http.StatusUnauthorized { t.Fatalf("anonymous reverse geocode status=%d body=%s", recorder.Code, recorder.Body.String()) } }