diff --git a/scripts/check-game-distribution-media-e2e.mjs b/scripts/check-game-distribution-media-e2e.mjs index 545e1aa6c..7d1fbd0fa 100644 --- a/scripts/check-game-distribution-media-e2e.mjs +++ b/scripts/check-game-distribution-media-e2e.mjs @@ -637,18 +637,25 @@ async function main() { publishedGame.screenshots[0] === created.data.screenshots[0], JSON.stringify(publishedGame?.screenshots ?? []), ); + // 只证明 objectKey 是服务端派生的对象路径、不是客户端直传的文件名;刻意不断言服务端内部 + // 的具体 bucket/前缀布局,避免把存储路径写死进 E2E。 + const clientPartNames = new Set([ + cover.fileName, + shot1.fileName, + shot2.fileName, + ]); + const isServerDerivedMediaKey = (key) => + typeof key === 'string' && + key.length > 0 && + key.trim() === key && + key.includes('/') && + !/^(?:blob|https?):/iu.test(key) && + !clientPartNames.has(key); check( '公开投影只暴露服务端派生的媒体 objectKey', - typeof publishedGame?.coverObjectKey === 'string' && - publishedGame.coverObjectKey.startsWith( - 'agc/project-snapshots/v1/game-distribution/media/', - ) && + isServerDerivedMediaKey(publishedGame?.coverObjectKey) && Array.isArray(publishedGame?.screenshots) && - publishedGame.screenshots.every( - (key) => - typeof key === 'string' && - key.startsWith('agc/project-snapshots/v1/game-distribution/media/'), - ), + publishedGame.screenshots.every(isServerDerivedMediaKey), ); // 9. 匿名读授权:封面与截图都走新的游戏媒体读路由换签名地址