## 后端安全加固 - 新增 UserUploadPathResolver: 用户上传文件路径安全解析, 防目录穿越 - LocalReportFileStorage: 文件存储路径安全加固 - local_account_file_cleanup: 账号删除时文件清理逻辑增强 - AuthService: 认证逻辑增强 - file_endpoints / report_endpoints: 文件访问接口安全加固 - ai_chat_endpoints / doctor_endpoints: 接口安全调整 - Program.cs: 服务注册调整 ## 前端认证与媒体 - 新增 authenticated_network_image.dart: 带认证的图片加载组件 - auth_provider: 认证状态管理大幅增强(+173) - api_client: 网络客户端增强(+124) - chat_provider: 聊天 provider 重构(+76) - omron_device_provider: 蓝牙设备 provider 增强(+53) - sse_handler: SSE 处理增强(+35) - consultation_provider / data_providers / conversation_history_provider: 调整 ## 页面调整 - remaining_pages: 健康档案/饮食记录等页面增强(+115) - home_page / chat_messages_view: 主页微调 - doctor 端多页微调(consultations/dashboard/followups/patient_detail/profile/report_detail/reports) - report_pages / settings_pages / notification_prefs_page: 微调 - device_scan_page / diet_capture_page / admin_home_page: 微调 ## 测试 - 新增 file_path_security_tests: 文件路径安全测试 - 新增 protected_media_url_test: 媒体URL保护测试 - 新增 user_session_identity_test: 用户会话身份测试 - account_deletion_tests / application_service_tests / auth_tests: 更新
41 lines
1.4 KiB
C#
41 lines
1.4 KiB
C#
using Health.Infrastructure.Files;
|
|
|
|
namespace Health.Tests;
|
|
|
|
public sealed class FilePathSecurityTests
|
|
{
|
|
private readonly Guid _userId = Guid.Parse("11111111-1111-1111-1111-111111111111");
|
|
private readonly string _fileName = "22222222-2222-2222-2222-222222222222.jpg";
|
|
|
|
[Fact]
|
|
public void ProtectedUrl_ResolvesInsideCurrentUserDirectory()
|
|
{
|
|
var path = UserUploadPathResolver.Resolve(
|
|
_userId,
|
|
$"/api/files/content/{_fileName}");
|
|
|
|
Assert.NotNull(path);
|
|
Assert.Contains(Path.Combine("users", _userId.ToString("N")), path);
|
|
Assert.EndsWith(_fileName, path, StringComparison.OrdinalIgnoreCase);
|
|
}
|
|
|
|
[Fact]
|
|
public void LegacyUrl_OnlyResolvesForItsOwner()
|
|
{
|
|
var legacy = $"/uploads/users/{_userId:N}/{_fileName}";
|
|
|
|
Assert.NotNull(UserUploadPathResolver.Resolve(_userId, legacy));
|
|
Assert.Null(UserUploadPathResolver.Resolve(Guid.NewGuid(), legacy));
|
|
}
|
|
|
|
[Theory]
|
|
[InlineData("/api/files/content/../../secret.jpg")]
|
|
[InlineData("/api/files/content/not-a-guid.jpg")]
|
|
[InlineData("/api/files/content/22222222-2222-2222-2222-222222222222.exe")]
|
|
[InlineData("/uploads/reports/22222222-2222-2222-2222-222222222222.jpg")]
|
|
public void UnsafeOrUnownedPath_IsRejected(string value)
|
|
{
|
|
Assert.Null(UserUploadPathResolver.Resolve(_userId, value));
|
|
}
|
|
}
|