v0.5.6: fix аудит Соннета — apply_effect стенд, mock_services, XSS, paramId валидация, serviceId=0 test
This commit is contained in:
@@ -97,7 +97,7 @@ def mock_services():
|
||||
не дёргая реальный /api/v1/svc/services.
|
||||
"""
|
||||
result = {}
|
||||
for svc_id, svc_def in _cfg.SERVICES.items():
|
||||
for svc_id, svc_def in SERVICES.items():
|
||||
result[str(svc_id)] = {
|
||||
"name": svc_def.get("name", ""),
|
||||
"displayName": svc_def.get("service_display_name", ""),
|
||||
|
||||
@@ -429,7 +429,7 @@ def _build_paths():
|
||||
"content": {
|
||||
"application/json": {
|
||||
"schema": {"$ref": "#/components/schemas/CreateInstanceRequest"},
|
||||
"example": {"serviceId": 38, "displayName": "my-test-instance"},
|
||||
"example": {"serviceId": 1, "displayName": "my-test-instance"},
|
||||
},
|
||||
},
|
||||
},
|
||||
|
||||
@@ -237,6 +237,10 @@ def set_operation_param():
|
||||
if not op_uid or param_id is None:
|
||||
return jsonify({"error": "instanceOperationUid and svcOperationCfsParamId required"}), 400
|
||||
|
||||
# Валидация: svcOperationCfsParamId должен быть целым числом
|
||||
if not isinstance(param_id, int) or isinstance(param_id, bool):
|
||||
return jsonify({"error": "svcOperationCfsParamId must be an integer"}), 400
|
||||
|
||||
# Проверка что операция существует
|
||||
if not state.get_operation(op_uid):
|
||||
return jsonify({"error": "operation not found"}), 404
|
||||
|
||||
+1
-1
@@ -72,7 +72,7 @@ def run_operation(uid):
|
||||
|
||||
# Применить эффект операции к состоянию инстанса
|
||||
# (create → running+params, delete → удалить, modify → мерж params, ...)
|
||||
state_machine.apply_effect(uid, st, _cfg.SERVICES)
|
||||
state_machine.apply_effect(uid, st, SERVICES)
|
||||
|
||||
# Фиксируем время завершения — операция выполнена успешно
|
||||
op["dtFinish"] = _now()
|
||||
|
||||
Reference in New Issue
Block a user