fix(02): stop short ids rewriting pagination and IPv4 (CR-01)

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Jakub Zych
2026-09-17 14:39:45 +02:00
parent d27897c7e0
commit 5994e671b3
2 changed files with 59 additions and 21 deletions

View File

@@ -375,7 +375,7 @@ func TestScrubShortNumericIDsDoNotCorruptPaths(t *testing.T) {
ID: "genres",
Request: Request{
Method: http.MethodGet,
Path: "/_fonoteka/api/v1/genres",
Path: "/_fonoteka/api/v1/genres/1",
Headers: map[string]string{"Authorization": "Bearer x"},
},
Response: Response{
@@ -386,21 +386,41 @@ func TestScrubShortNumericIDsDoNotCorruptPaths(t *testing.T) {
if err := ScrubStep(store, &step); err != nil {
t.Fatal(err)
}
if step.Request.Path != "/_fonoteka/api/v1/genres" {
t.Fatalf("path corrupted: %s", step.Request.Path)
if step.Request.Path != "/_fonoteka/api/v1/genres/{{id:alice}}" {
t.Fatalf("path id not scrubbed: %s", step.Request.Path)
}
body := string(step.Response.Body)
if !strings.Contains(body, `"id":{{id:alice}}`) {
t.Fatalf("id 1 not isolated: %s", body)
if body != `{"data":[{"id":1,"name":"Rock","album_count":0},{"id":15,"name":"Latin"},{"id":4,"name":"Jazz","album_count":1}]}` {
t.Fatalf("JSON body short ids must stay literal: %s", body)
}
if !strings.Contains(body, `"id":15`) {
t.Fatalf("id 15 must stay intact: %s", body)
if strings.Contains(string(step.Request.Path), "v{{id:alice}}") {
t.Fatalf("substring replace leaked: %s", step.Request.Path)
}
if !strings.Contains(body, `"id":{{id:genre}}`) {
t.Fatalf("id 4 not isolated: %s", body)
}
func TestScrubShortIDsLeavePaginationAndIPv4Literal(t *testing.T) {
store, err := OpenStore("")
if err != nil {
t.Fatal(err)
}
if strings.Contains(body, "{{id:alice}}5") || strings.Contains(body, "v{{id:alice}}") {
t.Fatalf("substring replace leaked: %s", body)
store.Set("id:album", "1")
step := Step{
ID: "page",
Request: Request{Method: http.MethodGet, Path: "/albums/1"},
Response: Response{
Status: 200,
Body: Body(`{"id":1,"total":1,"host":"127.0.0.1"}`),
},
}
if err := ScrubStep(store, &step); err != nil {
t.Fatal(err)
}
if step.Request.Path != "/albums/{{id:album}}" {
t.Fatalf("path id not scrubbed: %s", step.Request.Path)
}
body := string(step.Response.Body)
if body != `{"id":1,"total":1,"host":"127.0.0.1"}` {
t.Fatalf("pagination/IPv4 rewritten: %s", body)
}
}