Files
wxianfeng 93d6fdb17e feat: edition layer for Wukong overlay; promote shared code to pkg/
Introduce a build-time edition hook so downstream overlays (e.g. Wukong)
can customize auth UX, config dir, static server list, visible products,
and extra root commands while keeping the default open-source behavior.

- Add pkg/edition (defaults) and pkg/editiontest contract tests; Makefile
  target edition-test; CI job edition-tests.
- Root: optional RegisterExtraCommands with tool caller adapter; inject
  static servers to skip market discovery when configured; deduplicate
  top-level commands so overlay wins; extend hideNonDirectRuntimeCommands
  with edition VisibleProducts and static commands (recovery/schema/mcp).
- Auth/config: gate login subcommand and auth login hints for embedded
  editions; optional token auto-purge; edition ConfigDir override.
- version: human-readable multi-line output plus JSON with edition,
  architecture, build, commit.
- Relocate internal/{config,convert,validate} to pkg/; add pkg/cli and
  pkg/cmdutil (flags/time helpers).
- CI: optional notify-downstream job (GitLab trigger via secrets) on main
  push; open_source_policy_test adjusted for new layout.

Secrets (repo settings): WUKONG_TRIGGER_TOKEN, WUKONG_TRIGGER_URL — optional;
if unset, downstream step is skipped.

Made-with: Cursor
2026-03-31 15:29:21 +08:00

84 lines
2.5 KiB
Go

// Copyright 2026 Alibaba Group
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package validate
import (
"strings"
"testing"
)
func TestResourceName(t *testing.T) {
t.Parallel()
tests := []struct {
name string
value string
wantErr bool
errContain string
}{
{"valid simple ID", "user123", false, ""},
{"valid UUID", "550e8400-e29b-41d4-a716-446655440000", false, ""},
{"valid with slash", "org/team/member", false, ""},
{"empty", "", true, "must not be empty"},
{"path traversal", "../admin", true, "path traversal"},
{"path traversal mid", "a/../b", true, "path traversal"},
{"query injection", "user?admin=true", true, "invalid characters"},
{"fragment injection", "user#section", true, "invalid characters"},
{"percent encoding bypass", "user%2e%2e", true, "invalid characters"},
{"null byte", "user\x00id", true, "invalid characters"},
{"control char", "user\x1fid", true, "invalid characters"},
{"zero-width space", "user\u200Bid", true, "dangerous Unicode"},
{"Bidi override", "user\u202Eid", true, "dangerous Unicode"},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
t.Parallel()
err := ResourceName(tt.value, "--id")
if (err != nil) != tt.wantErr {
t.Errorf("ResourceName(%q) error = %v, wantErr %v", tt.value, err, tt.wantErr)
}
if err != nil && tt.errContain != "" && !strings.Contains(err.Error(), tt.errContain) {
t.Errorf("ResourceName(%q) error = %q, want containing %q", tt.value, err.Error(), tt.errContain)
}
})
}
}
func TestEncodePathSegment(t *testing.T) {
t.Parallel()
tests := []struct {
input string
want string
}{
{"simple", "simple"},
{"with/slash", "with%2Fslash"},
{"with?query", "with%3Fquery"},
{"with#frag", "with%23frag"},
{"with space", "with%20space"},
{"../traversal", "..%2Ftraversal"},
}
for _, tt := range tests {
t.Run(tt.input, func(t *testing.T) {
t.Parallel()
got := EncodePathSegment(tt.input)
if got != tt.want {
t.Errorf("EncodePathSegment(%q) = %q, want %q", tt.input, got, tt.want)
}
})
}
}