补 Rust 用例钉住发码 401/403 属系统变体
- map_auth_failure 对 AuthRoute::SendCode 的 401/403 仍归 UnexpectedRejection(不是权威失效、不是业务输入) - 依据:api-server 的 send_phone_code 只返回 400 与 5xx,401/403 出现即为契约异常,应带上文进上报池
This commit is contained in:
@@ -1350,6 +1350,28 @@ mod tests {
|
||||
assert_eq!(missing_reason.message(), "登录失败");
|
||||
}
|
||||
|
||||
/// 发码端点不带凭据:401/403 不是「用户可改的输入」,而是协议异常,属系统变体(带上文上报)。
|
||||
///
|
||||
/// api-server 的 `send_phone_code` 只会返回 400(手机号登录未启用)与 5xx;401/403 真出现时
|
||||
/// 说明契约破了,不该被当成业务提示吞掉。
|
||||
#[test]
|
||||
fn send_code_401_403_stay_system_rejections() {
|
||||
for status in [StatusCode::UNAUTHORIZED, StatusCode::FORBIDDEN] {
|
||||
let error = map_auth_failure(
|
||||
status,
|
||||
r#"{"error":{"message":"手机号登录暂未启用"}}"#,
|
||||
"发送验证码失败",
|
||||
AuthRoute::SendCode,
|
||||
);
|
||||
assert!(matches!(
|
||||
error,
|
||||
ClientAuthError::UnexpectedRejection(UnexpectedRejection { .. })
|
||||
));
|
||||
assert!(!error.is_authority_failure());
|
||||
assert_eq!(error.message(), "手机号登录暂未启用");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn input_rejections_and_throttling_keep_the_server_text() {
|
||||
let password_length = map_auth_failure(
|
||||
|
||||
Reference in New Issue
Block a user