fix(news): enforce shared comment publication and moderation rules
This commit is contained in:
1 parent
8aefb415b6
commit
fe34d4ac93
7 files changed
+554
-126
No files matched your search
@@ -42,6 +42,8 @@ vi.mock("next/navigation", () => ({
|
||||
},
|
||||
}));
|
||||
vi.mock("@/lib/services/webhook", () => ({ notify: boundaries.notify }));
|
||||
vi.mock("@/lib/auth", () => ({ auth: async () => ({ user: { id: "7" } }) }));
|
||||
vi.mock("@/lib/api-auth", () => ({ bearerUserId: async () => 7 }));
|
||||
|
||||
const exec = promisify(execFile);
|
||||
const NEWS_REVISION_KEY = "cms:news:revision";
|
||||
@@ -63,6 +65,10 @@ let operations: typeof import("@/features/operations/server");
|
||||
let cache: typeof import("@/lib/cache");
|
||||
let articles: typeof import("@/actions/admin-articles");
|
||||
let publicNews: typeof import("@/lib/services/news-detail");
|
||||
let commentSubmission: typeof import("@/lib/services/article-comment-submission");
|
||||
let commentModeration: typeof import("@/lib/services/moderation");
|
||||
let commentAction: typeof import("@/actions/article-comments");
|
||||
let commentApi: typeof import("@/app/api/articles/[slug]/comment/route");
|
||||
let scheduler: typeof import("@/lib/services/news-scheduler");
|
||||
let worker: typeof import("@/features/operations/worker");
|
||||
let migrationRoot: string | undefined;
|
||||
@@ -143,6 +149,7 @@ beforeAll(async () => {
|
||||
process.env.DATABASE_URL = databaseUrl;
|
||||
process.env.REDIS_URL = `redis://:${redisPassword}@${redisContainer.getHost()}:${redisContainer.getMappedPort(6379)}/0`;
|
||||
delete process.env.SKIP_ENV_VALIDATION;
|
||||
delete process.env.OPENAI_API_KEY;
|
||||
Object.assign(process.env, { NODE_ENV: "test" });
|
||||
process.env.HOTEL_NAME = "Integration";
|
||||
|
||||
@@ -158,6 +165,12 @@ beforeAll(async () => {
|
||||
await connection.query(
|
||||
"CREATE TABLE website_articles (id BIGINT UNSIGNED AUTO_INCREMENT PRIMARY KEY, slug VARCHAR(255) NOT NULL UNIQUE, title VARCHAR(255) NOT NULL, short_story VARCHAR(255) NOT NULL, full_story LONGTEXT NOT NULL, user_id INT NULL, image VARCHAR(255) NOT NULL, created_at TIMESTAMP NULL DEFAULT NULL, updated_at TIMESTAMP NULL DEFAULT NULL) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4",
|
||||
);
|
||||
await connection.query(
|
||||
"CREATE TABLE website_article_comments (id BIGINT UNSIGNED AUTO_INCREMENT PRIMARY KEY, article_id BIGINT UNSIGNED NOT NULL, user_id INT NOT NULL, comment VARCHAR(255) NOT NULL, created_at TIMESTAMP NULL, updated_at TIMESTAMP NULL) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4",
|
||||
);
|
||||
await connection.query(
|
||||
"CREATE TABLE website_wordfilter (id BIGINT UNSIGNED AUTO_INCREMENT PRIMARY KEY, word VARCHAR(255) NOT NULL UNIQUE, created_at TIMESTAMP NULL, updated_at TIMESTAMP NULL) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4",
|
||||
);
|
||||
// The emulator owns core tables. Exercise the real CMS migration CLI over this baseline.
|
||||
migrationRoot = await mkdtemp(join(resolve("integration"), ".migration-"));
|
||||
await mkdir(join(migrationRoot, "scripts"));
|
||||
@@ -188,6 +201,10 @@ beforeAll(async () => {
|
||||
operations = await import("@/features/operations/server");
|
||||
articles = await import("@/actions/admin-articles");
|
||||
publicNews = await import("@/lib/services/news-detail");
|
||||
commentSubmission = await import("@/lib/services/article-comment-submission");
|
||||
commentModeration = await import("@/lib/services/moderation");
|
||||
commentAction = await import("@/actions/article-comments");
|
||||
commentApi = await import("@/app/api/articles/[slug]/comment/route");
|
||||
scheduler = await import("@/lib/services/news-scheduler");
|
||||
worker = await import("@/features/operations/worker");
|
||||
});
|
||||
@@ -226,6 +243,14 @@ beforeEach(async () => {
|
||||
);
|
||||
await connection.query("DELETE FROM website_article_revisions");
|
||||
await connection.query("DELETE FROM website_article_drafts");
|
||||
await connection.query("DELETE FROM website_article_comments");
|
||||
await connection.query("DELETE FROM website_wordfilter");
|
||||
commentModeration.reloadWordFilter();
|
||||
await appRedis?.del(
|
||||
"ratelimit:comment:7",
|
||||
"ratelimit:comment:8",
|
||||
"ratelimit:comment:9",
|
||||
);
|
||||
await connection.query("DELETE FROM website_articles");
|
||||
await connection.query("DELETE FROM cms_outbox");
|
||||
await connection.query("DELETE FROM cms_operations");
|
||||
@@ -862,3 +887,106 @@ describe("real news publication, scheduling and cache delivery", () => {
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
async function seedCommentArticles() {
|
||||
if (!connection) throw Error("Integration database is not connected");
|
||||
await connection.query(
|
||||
"INSERT INTO website_articles (id,slug,title,short_story,full_story,image,status,publish_at) VALUES (101,'comment-public','Public','','','','published',NULL),(102,'comment-draft','Draft','','','','draft',NULL),(103,'comment-future','Future','','','','published',DATE_ADD(UTC_TIMESTAMP(), INTERVAL 1 DAY)),(104,'comment-due','Due','','','','published',DATE_SUB(UTC_TIMESTAMP(), INTERVAL 1 DAY))",
|
||||
);
|
||||
}
|
||||
|
||||
describe("real comment publication, moderation and shared quota", () => {
|
||||
it("checks both target forms with MariaDB and rejects blocked text through the real word filter", async () => {
|
||||
await seedCommentArticles();
|
||||
for (const userId of [8, 9]) {
|
||||
for (const [id, slug, eligible] of [
|
||||
[101, "comment-public", true],
|
||||
[102, "comment-draft", false],
|
||||
[103, "comment-future", false],
|
||||
[104, "comment-due", true],
|
||||
] as const) {
|
||||
const result = await commentSubmission.submitArticleComment({
|
||||
userId,
|
||||
target: userId === 8 ? { id: String(id) } : { slug },
|
||||
comment: "Database verified",
|
||||
});
|
||||
expect(result).toEqual(
|
||||
eligible ? { ok: true, slug } : { ok: false, reason: "not_found" },
|
||||
);
|
||||
}
|
||||
}
|
||||
expect(
|
||||
await rows(
|
||||
"SELECT article_id,user_id,comment FROM website_article_comments ORDER BY id",
|
||||
),
|
||||
).toEqual([
|
||||
{ article_id: "101", user_id: 8, comment: "Database verified" },
|
||||
{ article_id: "104", user_id: 8, comment: "Database verified" },
|
||||
{ article_id: "101", user_id: 9, comment: "Database verified" },
|
||||
{ article_id: "104", user_id: 9, comment: "Database verified" },
|
||||
]);
|
||||
await connection?.query(
|
||||
"INSERT INTO website_wordfilter (word) VALUES ('blocked-content')",
|
||||
);
|
||||
commentModeration.reloadWordFilter();
|
||||
expect(
|
||||
await commentSubmission.submitArticleComment({
|
||||
userId: 8,
|
||||
target: { slug: "comment-public" },
|
||||
comment: "BLOCKED-CONTENT",
|
||||
}),
|
||||
).toEqual({ ok: false, reason: "moderated" });
|
||||
expect(await rows("SELECT id FROM website_article_comments")).toHaveLength(
|
||||
4,
|
||||
);
|
||||
});
|
||||
|
||||
it("shares the Redis bucket when alternating the real form and API handlers", async () => {
|
||||
if (!appRedis) throw Error("Redis must be enabled in integration tests");
|
||||
await seedCommentArticles();
|
||||
const form = new FormData();
|
||||
form.set("articleId", "101");
|
||||
form.set("slug", "comment-public");
|
||||
form.set("comment", "Shared quota");
|
||||
form.set("userId", "999");
|
||||
const api = () =>
|
||||
commentApi.POST(
|
||||
new Request("https://hotel.test/api/articles/comment-public/comment", {
|
||||
method: "POST",
|
||||
headers: { "content-type": "application/json" },
|
||||
body: JSON.stringify({ comment: "Shared quota", userId: 999 }),
|
||||
}),
|
||||
{ params: Promise.resolve({ slug: "comment-public" }) },
|
||||
);
|
||||
for (let attempt = 0; attempt < 5; attempt++) {
|
||||
if (attempt % 2 === 0) {
|
||||
await expect(commentAction.postComment(form)).rejects.toThrow(
|
||||
"/news/comment-public?comment=posted",
|
||||
);
|
||||
} else {
|
||||
const response = await api();
|
||||
expect(response.status).toBe(200);
|
||||
expect(await response.json()).toEqual({ ok: true });
|
||||
}
|
||||
}
|
||||
const limited = await api();
|
||||
expect(limited.status).toBe(429);
|
||||
expect(Number(limited.headers.get("Retry-After"))).toBeGreaterThan(0);
|
||||
await expect(commentAction.postComment(form)).rejects.toThrow(
|
||||
"/news/comment-public?error=ratelimit",
|
||||
);
|
||||
expect(await appRedis.get("ratelimit:comment:7")).toBe("7");
|
||||
expect(await appRedis.pttl("ratelimit:comment:7")).toBeGreaterThan(0);
|
||||
expect(await appRedis.pttl("ratelimit:comment:7")).toBeLessThanOrEqual(
|
||||
30_000,
|
||||
);
|
||||
expect(
|
||||
await rows("SELECT user_id,comment FROM website_article_comments"),
|
||||
).toEqual(
|
||||
Array.from({ length: 5 }, () => ({
|
||||
user_id: 7,
|
||||
comment: "Shared quota",
|
||||
})),
|
||||
);
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user