Files
MeBox/internal/service/image_proxy_test.go
T
soldosluka857 7cc59f095c fix(auth/images): long-lived Emby token, unthrottle refresh, serve library posters
Three regressions reported on third-party clients and the web UI:

- Third-party clients (Emby/Jellyfin) dropped login / could not play /
  could not refresh the library, roughly hourly. The Emby
  AuthenticateByName response returned the 60-minute access token, but
  Emby clients have no refresh mechanism and reuse the AccessToken until
  logout. Issue a long-lived (30d) token for the Emby compat layer via
  AuthService.IssueEmbyToken so device sessions persist.

- Web could be thrown back to login under load: /auth/refresh was inside
  the IP rate-limited /auth group, so multiple users/tabs behind one
  reverse-proxy/NAT IP exhausted the budget and refresh failed -> logout.
  Only login/register are rate-limited now (raised to 30/min for shared
  IPs); refresh is excluded (already protected by a one-time refresh token).

- Posters/images stopped displaying on the web home and other pages
  (refresh did not help). The SSRF/path hardening (a) blocked the image
  proxy whenever a hostname *resolved* to a private IP, which happens
  under GFW DNS poisoning of public CDNs like image.tmdb.org, and (b)
  restricted local image reads to data/cache/movies/tv/anime dirs only,
  dropping sidecar posters stored under arbitrary per-library roots to a
  placeholder. isPrivateHost now only blocks literal private/loopback IPs
  (real SSRF vectors) and ImageProxy also allows reads under configured
  library roots.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-30 15:16:04 +08:00

97 lines
3.4 KiB
Go

package service
import (
"net/http"
"net/http/httptest"
"os"
"path/filepath"
"testing"
"go.uber.org/zap"
"github.com/ShukeBta/MediaStationGo/internal/config"
)
func TestImageProxyServesLocalImagePath(t *testing.T) {
dir := t.TempDir()
imagePath := filepath.Join(dir, "episode-thumb.png")
if err := os.WriteFile(imagePath, transparent1x1PNG, 0o644); err != nil {
t.Fatal(err)
}
proxy := NewImageProxy(&config.Config{Cache: config.CacheConfig{CacheDir: filepath.Join(dir, "cache")}}, zap.NewNop())
req := httptest.NewRequest(http.MethodGet, "/api/img", nil)
rec := httptest.NewRecorder()
if err := proxy.Serve(t.Context(), rec, req, imagePath); err != nil {
t.Fatal(err)
}
if rec.Code != http.StatusOK {
t.Fatalf("status = %d, want 200", rec.Code)
}
if got := rec.Header().Get("Content-Type"); got == "" {
t.Fatal("missing content-type")
}
if rec.Body.Len() != len(transparent1x1PNG) {
t.Fatalf("body length = %d, want %d", rec.Body.Len(), len(transparent1x1PNG))
}
}
// TestImageProxyServesPosterUnderLibraryRoot verifies that sidecar posters
// stored under an arbitrary media library root (not the configured
// data/cache/movies dirs) are served rather than dropped to the placeholder.
// This is the regression that made web/Emby posters disappear.
func TestImageProxyServesPosterUnderLibraryRoot(t *testing.T) {
libDir := t.TempDir()
posterPath := filepath.Join(libDir, "Inception (2010)", "poster.png")
if err := os.MkdirAll(filepath.Dir(posterPath), 0o755); err != nil {
t.Fatal(err)
}
realPoster := []byte("THIS-IS-A-REAL-POSTER-NOT-THE-PLACEHOLDER")
if err := os.WriteFile(posterPath, realPoster, 0o644); err != nil {
t.Fatal(err)
}
proxy := NewImageProxy(&config.Config{Cache: config.CacheConfig{CacheDir: filepath.Join(t.TempDir(), "cache")}}, zap.NewNop())
// Without a library-roots provider the poster lives outside every allowed
// root, so it must fall back to the transparent placeholder.
rec := httptest.NewRecorder()
if err := proxy.Serve(t.Context(), rec, httptest.NewRequest(http.MethodGet, "/api/img", nil), posterPath); err != nil {
t.Fatal(err)
}
if rec.Body.Len() != len(transparent1x1PNG) {
t.Fatalf("expected placeholder before provider set, got %d bytes", rec.Body.Len())
}
// Once the library root is known, the real poster bytes are served.
proxy.SetLibraryRootsProvider(func() []string { return []string{libDir} })
rec = httptest.NewRecorder()
if err := proxy.Serve(t.Context(), rec, httptest.NewRequest(http.MethodGet, "/api/img", nil), posterPath); err != nil {
t.Fatal(err)
}
if rec.Code != http.StatusOK {
t.Fatalf("status = %d, want 200", rec.Code)
}
if got := rec.Body.Bytes(); string(got) != string(realPoster) {
t.Fatalf("served %q, want real poster bytes", string(got))
}
}
func TestIsPrivateHost(t *testing.T) {
blocked := []string{"127.0.0.1", "10.0.0.5", "192.168.1.10", "169.254.169.254", "0.0.0.0", "::1", ""}
for _, h := range blocked {
if !isPrivateHost(h) {
t.Errorf("isPrivateHost(%q) = false, want true (literal private/loopback IP)", h)
}
}
// Hostnames must NOT be blocked even though GFW DNS poisoning may resolve
// them to private/loopback IPs — blocking them broke legitimate posters.
allowed := []string{"image.tmdb.org", "lain.bgm.tv", "example.com", "8.8.8.8"}
for _, h := range allowed {
if isPrivateHost(h) {
t.Errorf("isPrivateHost(%q) = true, want false", h)
}
}
}