Files
go-admin/app/admin/service/dto/sys_role_data_scope_test.go
T
zhangwenjian bd5e83d464 fix🐛: validate data scope on the role DTOs
Nothing checked what went into sys_role.data_scope, so creating a role without
a dataScope stored an empty string - the value that used to be indistinguishable
from "see everything".

All three DTOs that write the column are validated, not just the insert path:
they target the same column, and guarding one entrance while leaving two open
would not be a guard.

Claude-Session: https://claude.ai/code/session_01HPTAw8b8tAdFNFn8rKdPYx
2026-09-04 17:24:41 +08:00

65 lines
2.1 KiB
Go

package dto
import (
"testing"
vd "github.com/bytedance/go-tagexpr/v2/validator"
)
// api.Bind calls vd.Validate unconditionally on every request, regardless of
// which binding stage ran, so a vd tag on DataScope is enough to reject
// anything actions.Permission's fail-closed default would otherwise have to
// deal with. PRD 006 F14/H2 named this the real trigger for the default
// branch: SysRoleInsertReq.DataScope had no validation at all, so leaving
// dataScope out of a create-role request wrote an empty string straight to
// sys_role.
func TestDataScopeRejectsWhatPermissionCannotRecognize(t *testing.T) {
invalid := []string{"", "0", "6", "all", " 1", "1 "}
valid := []string{"1", "2", "3", "4", "5"}
t.Run("SysRoleInsertReq", func(t *testing.T) {
for _, s := range invalid {
req := SysRoleInsertReq{RoleName: "r", RoleKey: "r", DataScope: s}
if err := vd.Validate(&req); err == nil {
t.Errorf("DataScope %q was accepted, want rejected", s)
}
}
for _, s := range valid {
req := SysRoleInsertReq{RoleName: "r", RoleKey: "r", DataScope: s}
if err := vd.Validate(&req); err != nil {
t.Errorf("DataScope %q was rejected: %v", s, err)
}
}
})
t.Run("SysRoleUpdateReq", func(t *testing.T) {
for _, s := range invalid {
req := SysRoleUpdateReq{RoleName: "r", RoleKey: "r", DataScope: s}
if err := vd.Validate(&req); err == nil {
t.Errorf("DataScope %q was accepted, want rejected", s)
}
}
for _, s := range valid {
req := SysRoleUpdateReq{RoleName: "r", RoleKey: "r", DataScope: s}
if err := vd.Validate(&req); err != nil {
t.Errorf("DataScope %q was rejected: %v", s, err)
}
}
})
t.Run("RoleDataScopeReq", func(t *testing.T) {
for _, s := range invalid {
req := RoleDataScopeReq{RoleId: 1, DataScope: s}
if err := vd.Validate(&req); err == nil {
t.Errorf("DataScope %q was accepted, want rejected", s)
}
}
for _, s := range valid {
req := RoleDataScopeReq{RoleId: 1, DataScope: s}
if err := vd.Validate(&req); err != nil {
t.Errorf("DataScope %q was rejected: %v", s, err)
}
}
})
}