release: prepare v1.2.32
This commit is contained in:
@@ -38,6 +38,8 @@ type App struct {
|
||||
telegramPairMu sync.Mutex
|
||||
telegramPairs map[string]telegramPairing
|
||||
telegramDeliveryMu sync.Mutex
|
||||
backupMu sync.Mutex
|
||||
backupJob *backupJob
|
||||
}
|
||||
|
||||
const (
|
||||
@@ -130,6 +132,7 @@ func New(cfg Config, logger *slog.Logger) (*App, error) {
|
||||
a.startWorker(func() { a.smtpEventsCleanupWorker(workerCtx) })
|
||||
a.startWorker(func() { a.statusWebhookWorker(workerCtx) })
|
||||
a.startWorker(func() { a.telegramMailWorker(workerCtx) })
|
||||
a.startWorker(func() { a.backupScheduleWorker(workerCtx) })
|
||||
return a, nil
|
||||
}
|
||||
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,173 @@
|
||||
package app
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"io"
|
||||
"mime"
|
||||
"mime/multipart"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestBackupEndpointsRejectMismatchedConfirmation(t *testing.T) {
|
||||
a := newTestApp(t)
|
||||
stopTestWorkers(a)
|
||||
server := httptest.NewServer(a.Router())
|
||||
defer server.Close()
|
||||
admin := &testClient{t: t, server: server}
|
||||
var response map[string]any
|
||||
if code := admin.do("POST", "/api/auth/login", map[string]string{"email": "admin@lanqin.local", "password": "ChangeMe123!"}, &response); code != http.StatusOK {
|
||||
t.Fatalf("login code=%d body=%v", code, response)
|
||||
}
|
||||
response = nil
|
||||
if code := admin.do("POST", "/api/admin/backups", map[string]any{"password": "BackupPassword123!", "confirmPassword": "DifferentPassword123!"}, &response); code != http.StatusBadRequest {
|
||||
t.Fatalf("manual backup mismatch code=%d body=%v", code, response)
|
||||
}
|
||||
response = nil
|
||||
if code := admin.do("POST", "/api/admin/backups/settings", map[string]any{"enabled": false, "days": 7, "password": "BackupPassword123!", "confirmPassword": "DifferentPassword123!"}, &response); code != http.StatusBadRequest {
|
||||
t.Fatalf("scheduled backup mismatch code=%d body=%v", code, response)
|
||||
}
|
||||
}
|
||||
|
||||
func TestDiscoverTelegramGroupsReturnsUniqueCandidates(t *testing.T) {
|
||||
telegramServer := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
_, _ = io.WriteString(w, `{"ok":true,"result":[`+
|
||||
`{"update_id":1,"message":{"text":"/newszxcn ABC123","chat":{"id":-1001,"type":"supergroup","title":"主备份"}}},`+
|
||||
`{"update_id":2,"message":{"text":"/newszxcn ABC123","chat":{"id":-1002,"type":"group","title":"异地备份"}}},`+
|
||||
`{"update_id":3,"message":{"text":"/newszxcn ABC123","chat":{"id":-1001,"type":"supergroup","title":"主备份"}}},`+
|
||||
`{"update_id":4,"message":{"text":"/newszxcn WRONG","chat":{"id":-1003,"type":"group","title":"无关群组"}}}]}`)
|
||||
}))
|
||||
defer telegramServer.Close()
|
||||
a := newTestApp(t)
|
||||
stopTestWorkers(a)
|
||||
a.telegramURL = telegramServer.URL
|
||||
groups, err := a.discoverTelegramGroups(context.Background(), "test-token", "ABC123")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(groups) != 2 || groups[0].ChatID != "-1001" || groups[1].ChatID != "-1002" {
|
||||
t.Fatalf("unexpected groups: %+v", groups)
|
||||
}
|
||||
}
|
||||
|
||||
func TestGoogleDriveUploadRequestUsesMultipartRelated(t *testing.T) {
|
||||
dir := t.TempDir()
|
||||
path := filepath.Join(dir, "newszxcn-backup-test.tar.zst.enc")
|
||||
if err := os.WriteFile(path, []byte("encrypted backup"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
req, err := newGoogleDriveUploadRequest(context.Background(), path, "folder-123")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
mediaType, params, err := mime.ParseMediaType(req.Header.Get("Content-Type"))
|
||||
if err != nil || mediaType != "multipart/related" || params["boundary"] == "" {
|
||||
t.Fatalf("content type = %q, %v", req.Header.Get("Content-Type"), err)
|
||||
}
|
||||
reader := multipart.NewReader(req.Body, params["boundary"])
|
||||
metadataPart, err := reader.NextPart()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
var metadata struct {
|
||||
Name string `json:"name"`
|
||||
Parents []string `json:"parents"`
|
||||
}
|
||||
if err := json.NewDecoder(metadataPart).Decode(&metadata); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if metadata.Name != filepath.Base(path) || len(metadata.Parents) != 1 || metadata.Parents[0] != "folder-123" {
|
||||
t.Fatalf("metadata = %+v", metadata)
|
||||
}
|
||||
filePart, err := reader.NextPart()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
raw, err := io.ReadAll(filePart)
|
||||
if err != nil || string(raw) != "encrypted backup" {
|
||||
t.Fatalf("uploaded bytes = %q, %v", raw, err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestBackupEncryptionRequiresDeploymentSecret(t *testing.T) {
|
||||
dir := t.TempDir()
|
||||
a := newTestAppWithConfig(t, Config{
|
||||
Addr: ":0", DBPath: filepath.Join(dir, "data", "lanqin.db"), DataDir: filepath.Join(dir, "data"),
|
||||
CookieName: "lanqin_test", SessionTTLHours: 24, AdminEmail: "admin@example.com", AdminPassword: "ChangeMe123!", AllowInsecureHTTP: true,
|
||||
})
|
||||
if _, err := a.encryptBackupPassword("BackupPassword123!"); err == nil {
|
||||
t.Fatal("backup password encryption succeeded without a deployment secret")
|
||||
}
|
||||
}
|
||||
|
||||
func TestBackupPasswordValidation(t *testing.T) {
|
||||
for _, valid := range []string{"12345678", "Restore Password 123!"} {
|
||||
if !validBackupPassword(valid) {
|
||||
t.Errorf("valid password rejected: %q", valid)
|
||||
}
|
||||
}
|
||||
for _, invalid := range []string{"1234567", "password\nvalue", "password\x00value", strings.Repeat("x", 1025)} {
|
||||
if validBackupPassword(invalid) {
|
||||
t.Errorf("invalid password accepted: %q", invalid)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestBackupPasswordEncryptionAndTelegramReport(t *testing.T) {
|
||||
dir := t.TempDir()
|
||||
a := newTestAppWithConfig(t, Config{
|
||||
Addr: ":0", AppVersion: "v1.2.31", DBPath: filepath.Join(dir, "data", "lanqin.db"), DataDir: filepath.Join(dir, "data"),
|
||||
CookieName: "lanqin_test", SessionTTLHours: 24, AdminEmail: "admin@newszxcn.com", AdminPassword: "ChangeMe123!",
|
||||
PublicHostname: "mail.newszxcn.com", PublicBaseURL: "https://mail.newszxcn.com", AllowInsecureHTTP: true, UpdateServiceToken: "test-update-secret",
|
||||
})
|
||||
|
||||
ciphertext, err := a.encryptBackupPassword("BackupPassword123!")
|
||||
if err != nil || ciphertext == "BackupPassword123!" {
|
||||
t.Fatalf("password encryption failed: %q %v", ciphertext, err)
|
||||
}
|
||||
plain, err := a.decryptBackupPassword(ciphertext)
|
||||
if err != nil || plain != "BackupPassword123!" {
|
||||
t.Fatalf("password decryption = %q, %v", plain, err)
|
||||
}
|
||||
if !validTelegramPrivateChatID("-1001234567890") {
|
||||
t.Fatal("private Telegram group chat ID was rejected")
|
||||
}
|
||||
|
||||
now := a.now().UTC().Format("2006-01-02T15:04:05Z")
|
||||
if _, err := a.db.Exec(`INSERT INTO domains(id,name,status,dkim_selector,dkim_public_key,dkim_private_key,dns_status,created_at,updated_at) VALUES('domain_xyes','xyes.me','active','mail','','','unchecked',?,?)`, now, now); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := a.db.Exec(`INSERT INTO users(id,login_name,email,display_name,role,password_hash,created_at,updated_at) VALUES('user_xyes','user@xyes.me','user@xyes.me','User','user','hash',?,?)`, now, now); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
path := filepath.Join(dir, "newszxcn-backup-20260811-120000-1.2.31.tar.zst.enc")
|
||||
if err := os.WriteFile(path, []byte("encrypted backup"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
info, err := os.Stat(path)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
report, err := a.backupTelegramReport(context.Background(), path, info)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
for _, expected := range []string{"备份成功", "mail.newszxcn.com", "已有域名", "newszxcn.com", "xyes.me", "管理员账号", "admin@newszxcn.com", "普通用户账号", "user@xyes.me", "请不要解压", "本地上传", "1Password"} {
|
||||
if !strings.Contains(report, expected) {
|
||||
t.Errorf("report missing %q: %s", expected, report)
|
||||
}
|
||||
}
|
||||
if strings.Contains(report, "newszxcn.com(管理员)") {
|
||||
t.Fatal("domain list incorrectly contains account role")
|
||||
}
|
||||
if strings.Contains(report, "BackupPassword123!") || strings.Contains(report, "ChangeMe123!") {
|
||||
t.Fatal("report leaked a password")
|
||||
}
|
||||
}
|
||||
@@ -67,6 +67,8 @@ type Config struct {
|
||||
ReleaseAPIURL string
|
||||
UpdateServiceURL string
|
||||
UpdateServiceToken string
|
||||
BackupSourceDir string
|
||||
BackupDir string
|
||||
}
|
||||
|
||||
func LoadConfig() Config {
|
||||
@@ -131,6 +133,8 @@ func LoadConfig() Config {
|
||||
ReleaseAPIURL: getenv("LANQIN_RELEASE_API_URL", "https://api.github.com/repos/zxyszx/NewSzxcn-Email/releases/latest"),
|
||||
UpdateServiceURL: getenv("LANQIN_UPDATE_SERVICE_URL", ""),
|
||||
UpdateServiceToken: getenv("LANQIN_UPDATE_SERVICE_TOKEN", ""),
|
||||
BackupSourceDir: getenv("LANQIN_BACKUP_SOURCE_DIR", ""),
|
||||
BackupDir: getenv("LANQIN_BACKUP_DIR", filepath.Join(dataDir, "disaster-backups")),
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -139,6 +139,19 @@ func (a *App) Router() http.Handler {
|
||||
r.Use(a.requireAdminAccess)
|
||||
r.Get("/admin/system/version", a.handleSystemVersion)
|
||||
r.Post("/admin/system/update", a.handleSystemUpdate)
|
||||
r.Get("/admin/backups", a.handleListBackups)
|
||||
r.Post("/admin/backups/settings", a.handleUpdateBackupSettings)
|
||||
r.Post("/admin/backups/telegram/test", a.handleTestBackupTelegram)
|
||||
r.Post("/admin/backups/telegram/discover-group", a.handleDiscoverBackupTelegramGroup)
|
||||
r.Post("/admin/backups/google-drive/connect", a.handleGoogleDriveConnect)
|
||||
r.Get("/admin/backups/google-drive/callback", a.handleGoogleDriveCallback)
|
||||
r.Delete("/admin/backups/google-drive", a.handleGoogleDriveDisconnect)
|
||||
r.Post("/admin/backups", a.handleCreateBackup)
|
||||
r.Get("/admin/backups/{name}/download", a.handleDownloadBackup)
|
||||
r.Post("/admin/backups/{name}/verify", a.handleVerifyBackup)
|
||||
r.Post("/admin/backups/{name}/telegram", a.handleSendBackupTelegram)
|
||||
r.Post("/admin/backups/{name}/google-drive", a.handleSendBackupGoogleDrive)
|
||||
r.Delete("/admin/backups/{name}", a.handleDeleteBackup)
|
||||
r.With(a.requirePermission(PermissionAdminOverview)).Get("/admin/overview", a.handleAdminOverview)
|
||||
r.With(a.requireAnyPermission(PermissionUsersView, PermissionMailboxesView)).Get("/admin/users", a.handleListUsers)
|
||||
r.With(a.requirePermission(PermissionUsersCreate)).Post("/admin/users", a.handleCreateUser)
|
||||
|
||||
@@ -71,6 +71,7 @@ type telegramUpdate struct {
|
||||
Chat struct {
|
||||
ID int64 `json:"id"`
|
||||
Type string `json:"type"`
|
||||
Title string `json:"title"`
|
||||
FirstName string `json:"first_name"`
|
||||
LastName string `json:"last_name"`
|
||||
Username string `json:"username"`
|
||||
@@ -112,7 +113,7 @@ func normalizeTelegramBodyMode(value string) string {
|
||||
|
||||
func validTelegramPrivateChatID(value string) bool {
|
||||
id, err := strconv.ParseInt(strings.TrimSpace(value), 10, 64)
|
||||
return err == nil && id > 0
|
||||
return err == nil && id != 0
|
||||
}
|
||||
|
||||
func (a *App) handleCreateTelegramPairing(w http.ResponseWriter, r *http.Request) {
|
||||
@@ -259,6 +260,50 @@ func (a *App) discoverTelegramPrivateChat(ctx context.Context, token, pairingCod
|
||||
return "", "", errors.New("未找到匹配的私聊,请打开机器人发送绑定码后重试")
|
||||
}
|
||||
|
||||
type telegramDiscoveredChat struct {
|
||||
ChatID string `json:"chatId"`
|
||||
DisplayName string `json:"displayName"`
|
||||
}
|
||||
|
||||
func (a *App) discoverTelegramGroups(ctx context.Context, token, pairingCode string) ([]telegramDiscoveredChat, error) {
|
||||
var updates []telegramUpdate
|
||||
if err := a.callTelegram(ctx, token, "getUpdates", map[string]any{
|
||||
"limit": 100, "timeout": 0, "allowed_updates": []string{"message"},
|
||||
}, &updates); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
found := make([]telegramDiscoveredChat, 0)
|
||||
seen := make(map[int64]bool)
|
||||
for i := len(updates) - 1; i >= 0; i-- {
|
||||
message := updates[i].Message
|
||||
if message == nil || (message.Chat.Type != "group" && message.Chat.Type != "supergroup") || message.Chat.ID >= 0 {
|
||||
continue
|
||||
}
|
||||
text := strings.TrimSpace(message.Text)
|
||||
fields := strings.Fields(text)
|
||||
matches := strings.EqualFold(text, pairingCode)
|
||||
if len(fields) == 2 && strings.HasPrefix(strings.ToLower(fields[0]), "/newszxcn") {
|
||||
matches = strings.EqualFold(fields[1], pairingCode)
|
||||
}
|
||||
if !matches {
|
||||
continue
|
||||
}
|
||||
if seen[message.Chat.ID] {
|
||||
continue
|
||||
}
|
||||
seen[message.Chat.ID] = true
|
||||
name := strings.TrimSpace(message.Chat.Title)
|
||||
if name == "" {
|
||||
name = "Telegram 群组"
|
||||
}
|
||||
found = append(found, telegramDiscoveredChat{ChatID: strconv.FormatInt(message.Chat.ID, 10), DisplayName: name})
|
||||
}
|
||||
if len(found) == 0 {
|
||||
return nil, errors.New("未找到匹配的群组,请确认机器人已加入群组,并在群里发送查询命令")
|
||||
}
|
||||
return found, nil
|
||||
}
|
||||
|
||||
func newTelegramPairingCode() (string, error) {
|
||||
raw := make([]byte, 6)
|
||||
if _, err := rand.Read(raw); err != nil {
|
||||
|
||||
Reference in New Issue
Block a user