diff --git a/scripts/check-game-distribution-media-e2e.mjs b/scripts/check-game-distribution-media-e2e.mjs index 89f95f49a..85c4486d2 100644 --- a/scripts/check-game-distribution-media-e2e.mjs +++ b/scripts/check-game-distribution-media-e2e.mjs @@ -606,6 +606,39 @@ async function main() { `status=${readBefore.status}`, ); + // 6b. owner 作用域:作者本人在待审期间就能预览自己作品的封面 + const ownerRead = await api( + `/api/game-distribution/my-games/${gameId}/media/read-url?objectKey=${encodeURIComponent(created.data.coverObjectKey)}`, + { token: author }, + ); + check( + '作者本人可经 owner 路由预览未公开作品封面', + ownerRead.status === 200 && + Boolean(ownerRead.data?.read?.signedUrl ?? ownerRead.data?.signedUrl), + `status=${ownerRead.status} ${ownerRead.text.slice(0, 200)}`, + ); + + // 6c. owner 路由必须带令牌:匿名走 owner 路由被拒,不会退化成公开读 + const ownerReadAnonymous = await api( + `/api/game-distribution/my-games/${gameId}/media/read-url?objectKey=${encodeURIComponent(created.data.coverObjectKey)}`, + ); + check( + 'owner 路由不带令牌被拒', + ownerReadAnonymous.status === 401, + `status=${ownerReadAnonymous.status}`, + ); + + // 6d. owner 路由只认自己作品当前行的媒体:同作者拿别人的 objectKey 换不出来 + const ownerReadForeignKey = await api( + `/api/game-distribution/my-games/${gameId}/media/read-url?objectKey=${encodeURIComponent('agc/project-snapshots/v1/game-distribution/media/other/cover-other.png')}`, + { token: author }, + ); + check( + 'owner 路由拒绝非本作品媒体的 objectKey', + ownerReadForeignKey.status === 404, + `status=${ownerReadForeignKey.status}`, + ); + // 7. 管理员审核通过(发行入口由服务端按部署模板与 gameId 派生;管理员 token 在步骤 1.1 已取得) const approved = await api( `/admin/api/game-distribution/versions/${versionId}/review`,