Fix shared upload permissions for capability-restricted LTX backend
This commit is contained in:
+5
-1
@@ -1,7 +1,7 @@
|
||||
import { test } from 'node:test'
|
||||
import assert from 'node:assert/strict'
|
||||
import http from 'node:http'
|
||||
import { mkdtemp, mkdir, writeFile, readFile, symlink, rm } from 'node:fs/promises'
|
||||
import { mkdtemp, mkdir, writeFile, readFile, symlink, rm, stat, chmod } from 'node:fs/promises'
|
||||
import os from 'node:os'
|
||||
import path from 'node:path'
|
||||
import { createApp } from './app.mjs'
|
||||
@@ -54,6 +54,7 @@ test('upload, backend path, range playback and existence check',async t=>{
|
||||
const {call,dir}=await fixture(t)
|
||||
const upload=await call('/web/upload?name=clip.mp4',{method:'POST',body:'0123456789'})
|
||||
assert.equal(upload.status,201);const result=await upload.json();assert.ok(result.path.startsWith('/ltx/inputs/'))
|
||||
assert.equal((await stat(path.join(dir,'input',path.basename(result.path)))).mode & 0o777,0o640)
|
||||
assert.equal(await readFile(path.join(dir,'input',path.basename(result.path)),'utf8'),'0123456789')
|
||||
const media=await call('/web/media?path='+encodeURIComponent(result.path),{headers:{Range:'bytes=2-5'}})
|
||||
assert.equal(media.status,206);assert.equal(media.headers.get('content-range'),'bytes 2-5/10');assert.equal(await media.text(),'2345')
|
||||
@@ -76,13 +77,16 @@ test('shared media can be inspected, copied and thumbnailed without an inference
|
||||
const {call,dir}=await fixture(t)
|
||||
// Deliberately tiny synthetic PPM pixels; ffprobe detects content, not extension.
|
||||
await writeFile(path.join(dir,'output','test.png'),Buffer.concat([Buffer.from('P6\n2 2\n255\n'),Buffer.from([0,0,255,0,0,255,0,0,255,0,0,255])]))
|
||||
await chmod(path.join(dir,'output','test.png'),0o600)
|
||||
const invoke=async action=>{
|
||||
const response=await call('/web/files',{method:'POST',body:JSON.stringify({action,path:'/ltx/outputs/test.png'})})
|
||||
assert.equal(response.status,200);return response.json()
|
||||
}
|
||||
const metadata=await invoke('metadata');assert.equal(metadata.width,2);assert.equal(metadata.height,2)
|
||||
const copy=await invoke('copy');assert.ok(copy.path.startsWith('/ltx/inputs/'))
|
||||
assert.equal((await stat(path.join(dir,'input',path.basename(copy.path)))).mode & 0o777,0o640)
|
||||
const thumbnail=await invoke('thumbnail');assert.ok(thumbnail.path.endsWith('.jpg'))
|
||||
assert.equal((await stat(path.join(dir,'input',path.basename(thumbnail.path)))).mode & 0o777,0o640)
|
||||
const response=await call('/web/media?path='+encodeURIComponent(thumbnail.path));assert.equal(response.status,200)
|
||||
assert.equal(response.headers.get('content-type'),'image/jpeg');assert.ok((await response.arrayBuffer()).byteLength>100)
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user