媒体验证 E2E 去掉对服务端存储前缀的硬编码断言
- 「公开投影只暴露服务端派生的媒体 objectKey」改为结构断言:非空去空白、含路径分隔符、不是客户端 part 文件名 - 不再断言 agc/project-snapshots/v1/game-distribution/media/ 这一内部布局常量 - 与服务端返回键的一致性仍由相邻的 owner/公开投影相等断言覆盖
This commit is contained in:
@@ -637,18 +637,25 @@ async function main() {
|
||||
publishedGame.screenshots[0] === created.data.screenshots[0],
|
||||
JSON.stringify(publishedGame?.screenshots ?? []),
|
||||
);
|
||||
// 只证明 objectKey 是服务端派生的对象路径、不是客户端直传的文件名;刻意不断言服务端内部
|
||||
// 的具体 bucket/前缀布局,避免把存储路径写死进 E2E。
|
||||
const clientPartNames = new Set([
|
||||
cover.fileName,
|
||||
shot1.fileName,
|
||||
shot2.fileName,
|
||||
]);
|
||||
const isServerDerivedMediaKey = (key) =>
|
||||
typeof key === 'string' &&
|
||||
key.length > 0 &&
|
||||
key.trim() === key &&
|
||||
key.includes('/') &&
|
||||
!/^(?:blob|https?):/iu.test(key) &&
|
||||
!clientPartNames.has(key);
|
||||
check(
|
||||
'公开投影只暴露服务端派生的媒体 objectKey',
|
||||
typeof publishedGame?.coverObjectKey === 'string' &&
|
||||
publishedGame.coverObjectKey.startsWith(
|
||||
'agc/project-snapshots/v1/game-distribution/media/',
|
||||
) &&
|
||||
isServerDerivedMediaKey(publishedGame?.coverObjectKey) &&
|
||||
Array.isArray(publishedGame?.screenshots) &&
|
||||
publishedGame.screenshots.every(
|
||||
(key) =>
|
||||
typeof key === 'string' &&
|
||||
key.startsWith('agc/project-snapshots/v1/game-distribution/media/'),
|
||||
),
|
||||
publishedGame.screenshots.every(isServerDerivedMediaKey),
|
||||
);
|
||||
|
||||
// 9. 匿名读授权:封面与截图都走新的游戏媒体读路由换签名地址
|
||||
|
||||
Reference in New Issue
Block a user