fix(protocol): reject invalid request contract values

This commit is contained in:
2026-09-05 02:16:47 +08:00
parent 0a7951ba32
commit fdc6fc2264
5 changed files with 113 additions and 38 deletions
@@ -97,12 +97,15 @@ test('buildLoginRequest 只在显式复用模式且缓存 ID 有效时加入 pla
});
assert.equal(enabled.data.playerid, 430511);
for (const cachedPlayerId of [-1, 1.5, '430511', null]) {
const invalid = buildLoginRequest(runtimeConfig, account, {
...device,
loginPlayerId: { enabled: true, cachedPlayerId },
});
assert.equal(owns(invalid.data, 'playerid'), false);
for (const cachedPlayerId of [-1, 0, 1.5, Number.NaN, Infinity, '430511', null, undefined]) {
const type = cachedPlayerId === null ? 'null' : typeof cachedPlayerId;
assert.throws(
() => buildLoginRequest(runtimeConfig, account, {
...device,
loginPlayerId: { enabled: true, cachedPlayerId },
}),
new RegExp(`\\$\\.device\\.loginPlayerId\\.cachedPlayerId.*${type}`),
);
}
});
@@ -235,6 +238,20 @@ test('房间请求 builder 使用唯一 route,并仅发协议定义字段', ()
});
});
test('房间请求拒绝 agentid/gameid 的非有限数值并报告来源路径', () => {
for (const field of ['agentid', 'gameid'] as const) {
for (const value of [Number.NaN, Infinity, -Infinity]) {
assert.throws(
() => buildPrepareRequest(
{ identity: { ...runtimeConfig.identity, [field]: value } },
{ playerid: 430511, roomcode: '100001' },
),
new RegExp(`\\$\\.runtimeConfig\\.identity\\.${field}.*number`),
);
}
}
});
test('buildJoinRoomRequest 不凭空补 vipMatch 或 match_id', () => {
const request = buildJoinRoomRequest(
runtimeConfig,
@@ -245,6 +262,40 @@ test('buildJoinRoomRequest 不凭空补 vipMatch 或 match_id', () => {
assert.equal(owns(request.data, 'match_id'), false);
});
test('buildJoinRoomRequest 拒绝非法或 undefined vipMatch', () => {
for (const vipMatch of [undefined, 0, 2, '1', Number.NaN, Infinity]) {
const type = typeof vipMatch;
assert.throws(
() => buildJoinRoomRequest(
runtimeConfig,
{ playerid: 430511, roomcode: '100001' },
{ location: null, ip: '127.0.0.1', vipMatch } as never,
),
new RegExp(`\\$\\.environment\\.vipMatch.*${type}`),
);
}
});
test('buildJoinRoomRequest 拒绝非法、undefined 或非有限 match_id', () => {
for (const match_id of [undefined, null, false, {}, Number.NaN, Infinity]) {
const type = match_id === null ? 'null' : Array.isArray(match_id) ? 'array' : typeof match_id;
assert.throws(
() => buildJoinRoomRequest(
runtimeConfig,
{ playerid: 430511, roomcode: '100001' },
{ location: null, ip: '127.0.0.1', match_id } as never,
),
new RegExp(`\\$\\.environment\\.match_id.*${type}`),
);
}
assert.equal(buildJoinRoomRequest(
runtimeConfig,
{ playerid: 430511, roomcode: '100001' },
{ location: null, ip: '127.0.0.1', match_id: 7 },
).data.match_id, 7);
});
test('座位事件 parser 校验实际消费字段并保留 raw', () => {
const prepare = { seat: 1, deskwar: 1, extension: 'kept' };
assert.equal(parsePlayerPreparePayload(prepare).raw, prepare);