本地 dev 不再把默认 CLI 配置里的远程 token 当作本地发布凭据
Project CI / AI game creator shell Rust smoke (pull_request) Successful in 1m15s
Project CI / AI game creator shell Rust crates (pull_request) Successful in 56s
Project CI / Backend tests (pull_request) Failing after 14s
Project CI / Frontend tests (pull_request) Successful in 1m57s
Project CI / Repository checks (pull_request) Failing after 16s
Project CI / AI game creator shell web tests (pull_request) Successful in 1m23s
Project CI / AI game creator shell Rust lane 2/2 (pull_request) Successful in 8m1s
Project CI / Native shell tests (pull_request) Successful in 5m45s
Project CI / AI game creator shell Rust lane 1/2 (pull_request) Successful in 8m37s
Project CI / AI game creator shell Rust smoke (pull_request) Successful in 1m15s
Project CI / AI game creator shell Rust crates (pull_request) Successful in 56s
Project CI / Backend tests (pull_request) Failing after 14s
Project CI / Frontend tests (pull_request) Successful in 1m57s
Project CI / Repository checks (pull_request) Failing after 16s
Project CI / AI game creator shell web tests (pull_request) Successful in 1m23s
Project CI / AI game creator shell Rust lane 2/2 (pull_request) Successful in 8m1s
Project CI / Native shell tests (pull_request) Successful in 5m45s
Project CI / AI game creator shell Rust lane 1/2 (pull_request) Successful in 8m37s
- shouldTrustExistingSpacetimeToken:本地(loopback)服务器额外要求 token 由本机签发(JWT iss 为 localhost/127.0.0.1/::1);默认 CLI 配置里的远程账号 token 形如有效但验签必然失败,会在 pre-publish check 抛 401 InvalidSignature - 显式 shell 覆盖 GENARRATIVE_SPACETIME_TOKEN 的语义保持不变,仍然优先 - 单测:远程签发 token 在本地服务器上不被信任、本机签发 token 被信任 - 验证:scripts/dev.test.ts 70 passed - 未覆盖(后续):本机签发但已失效的旧 token(数据目录重建后签名失效,iss 仍为 localhost)仍需手工清理 dev-cli/cli.toml 与 dev-api-identities/local-node.json;自动自愈需要把发布调用改成非致命,因为当前 runForeground 失败会直接结束进程,调用层 catch 拿不到
This commit is contained in:
+53
-9
@@ -30,6 +30,7 @@ import {
|
||||
createWatchConfigs,
|
||||
DevRunner,
|
||||
isDirectModuleExecution,
|
||||
isLocallyIssuedSpacetimeToken,
|
||||
isSpacetimePublishPermissionError,
|
||||
isStaleExternalGenerationWorkerProcess,
|
||||
normalizeCargoVersionRequirement,
|
||||
@@ -44,6 +45,16 @@ import {
|
||||
shouldTrustExistingSpacetimeToken,
|
||||
} from './dev.mjs';
|
||||
|
||||
/// 造一个带指定 iss 的假 JWT(只用于断言签发者判定)。
|
||||
const fakeJwt = (issuer: string): string =>
|
||||
[
|
||||
Buffer.from(JSON.stringify({ alg: 'none' })).toString('base64url'),
|
||||
Buffer.from(JSON.stringify({ iss: issuer, sub: 'fake' })).toString(
|
||||
'base64url',
|
||||
),
|
||||
'signature',
|
||||
].join('.');
|
||||
|
||||
const originalFetch = globalThis.fetch;
|
||||
|
||||
afterEach(() => {
|
||||
@@ -336,16 +347,13 @@ describe('dev scheduler argument routing', () => {
|
||||
}
|
||||
});
|
||||
|
||||
test('本地 SpacetimeDB 信任与当前 CLI 一致的 env token', () => {
|
||||
test('本地 SpacetimeDB 信任与当前 CLI 一致且由本机签发的 token', () => {
|
||||
const localToken = fakeJwt('localhost');
|
||||
expect(
|
||||
shouldTrustExistingSpacetimeToken(
|
||||
'owner-cli-token',
|
||||
'http://127.0.0.1:3101',
|
||||
{
|
||||
env: {},
|
||||
resolveCliToken: () => 'owner-cli-token',
|
||||
},
|
||||
),
|
||||
shouldTrustExistingSpacetimeToken(localToken, 'http://127.0.0.1:3101', {
|
||||
env: {},
|
||||
resolveCliToken: () => localToken,
|
||||
}),
|
||||
).toBe(true);
|
||||
});
|
||||
});
|
||||
@@ -1834,3 +1842,39 @@ spacetimedb tool version 2.8.3; spacetimedb-lib version 2.8.3;
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
describe('本地 token 信任判定', () => {
|
||||
it('拒绝远程账号签发的 token 用于本地服务器(曾经的 401 InvalidSignature)', () => {
|
||||
expect(
|
||||
isLocallyIssuedSpacetimeToken(fakeJwt('https://api.spacetimedb.com')),
|
||||
).toBe(false);
|
||||
expect(isLocallyIssuedSpacetimeToken('not-a-jwt')).toBe(false);
|
||||
expect(
|
||||
shouldTrustExistingSpacetimeToken(
|
||||
fakeJwt('https://api.spacetimedb.com'),
|
||||
'http://127.0.0.1:3101',
|
||||
{
|
||||
env: {},
|
||||
resolveCliToken: () => fakeJwt('https://api.spacetimedb.com'),
|
||||
},
|
||||
),
|
||||
).toBe(false);
|
||||
});
|
||||
|
||||
it('接受本机签发的 token', () => {
|
||||
expect(isLocallyIssuedSpacetimeToken(fakeJwt('localhost'))).toBe(true);
|
||||
expect(
|
||||
isLocallyIssuedSpacetimeToken(fakeJwt('http://127.0.0.1:3101')),
|
||||
).toBe(true);
|
||||
expect(
|
||||
shouldTrustExistingSpacetimeToken(
|
||||
fakeJwt('localhost'),
|
||||
'http://127.0.0.1:3101',
|
||||
{
|
||||
env: {},
|
||||
resolveCliToken: () => fakeJwt('localhost'),
|
||||
},
|
||||
),
|
||||
).toBe(true);
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user