Files
wangjia bd8f974a25 feat(M6): 控制面联调 — mock connect server + 客户端 ConnectApi 透传
tsk_nuoKSM4Vt-zK

## 服务端(server/cmd/mockserver)
- `main.go`(79 行):独立 mock HTTP server,实现 POST /v1/nodes/:id/connect
  - 路径/请求体/响应体字段名与 §3.1 契约逐字一致
  - Bearer token 鉴权(-token 参数,空值跳过,不入库)
  - 缺少 device_id → 400;未授权 → 401;非 POST → 405
  - 返回完整 sing-box config JSON(tun + REALITY/Hy2 outbound + urltest + route/dns)
  - 注:mock 联调;待 #5/#6 真实 connect 接口就绪后替换
- `main_test.go`:6 项单测,覆盖 §3.1 结构校验、auth、method、path

## 客户端(client/)
- `lib/services/connect_api.dart`:ConnectApi 类
  - fetchConfig(nodeId, deviceId) → 原始响应体字符串(不做任何修改)
  - 错误路径:HTTP 非 200 / 超时 / 非法 JSON → ConnectApiException(含双语 message)
- `lib/services/vpn_bridge.dart`:VpnBridge stub(M6 联调,libbox 绑定待 11C)
  - start(configJson) 原样存储,不修改;stop() 清空
- `lib/widgets/home_shell.dart`:_toggle/_pick 替换为真实 API 流程
  - ConnectApi.fetchConfig → VpnBridge.start(透传,无中间变换)
  - 错误路径:ConnectApiException → SnackBar,status 回 off,无残留半开隧道
  - API URL/token/deviceId 由 --dart-define 注入(不入库)
- `lib/widgets/server_tile.dart`:ServerInfo 新增 nodeId 字段
- `pubspec.yaml`:新增 http: ^1.2.1 依赖
- `test/connect_passthrough_test.dart`:4 项透传断言单测
  - 核心:fetchConfig 返回字符串 === VpnBridge.start 接收字符串(逐字节相等)
  - 空格/格式原样保留(不经 jsonEncode 重序列化)
  - HTTP 错误、非法 JSON 错误路径覆盖

## 运行方式(M6 联调)
```
# 启动 mock server(无 auth)
go run ./server/cmd/mockserver -addr :8081

# 启动客户端(指向 mock server)
flutter run \
  --dart-define=PANGOLIN_API_URL=http://localhost:8081 \
  --dart-define=PANGOLIN_API_TOKEN=dev-mock-token \
  --dart-define=PANGOLIN_DEVICE_ID=demo-device-001
```

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-13 14:16:29 +08:00

131 lines
3.7 KiB
Go

package main
import (
"bytes"
"encoding/json"
"net/http"
"net/http/httptest"
"testing"
)
func post(t *testing.T, handler http.Handler, path, body, auth string) *httptest.ResponseRecorder {
t.Helper()
req := httptest.NewRequest(http.MethodPost, path, bytes.NewBufferString(body))
req.Header.Set("Content-Type", "application/json")
if auth != "" {
req.Header.Set("Authorization", "Bearer "+auth)
}
w := httptest.NewRecorder()
handler.ServeHTTP(w, req)
return w
}
// TestConnectReturnsValidConfig verifies that a well-formed request returns
// a 200 with all four §3.1 top-level blocks present.
func TestConnectReturnsValidConfig(t *testing.T) {
h := makeHandler("test-token")
w := post(t, h, "/v1/nodes/sg-1/connect", `{"device_id":"dev-001"}`, "test-token")
if w.Code != http.StatusOK {
t.Fatalf("want 200, got %d: %s", w.Code, w.Body.String())
}
var out map[string]any
if err := json.Unmarshal(w.Body.Bytes(), &out); err != nil {
t.Fatalf("response is not valid JSON: %v\nbody: %s", err, w.Body.String())
}
for _, key := range []string{"inbounds", "outbounds", "route", "dns"} {
if _, ok := out[key]; !ok {
t.Errorf("§3.1 block missing: %q", key)
}
}
// outbounds must include urltest group named "auto"
outs, _ := out["outbounds"].([]any)
found := false
for _, o := range outs {
m, _ := o.(map[string]any)
if m["type"] == "urltest" && m["tag"] == "auto" {
found = true
}
}
if !found {
t.Error("outbounds: missing urltest group 'auto'")
}
// inbound must have strict_route:true (Kill-switch)
ins, _ := out["inbounds"].([]any)
if len(ins) == 0 {
t.Fatal("inbounds is empty")
}
tun, _ := ins[0].(map[string]any)
if tun["strict_route"] != true {
t.Error("inbounds[0].strict_route must be true (Kill-switch)")
}
}
// TestConnectRequiresAuth verifies that a missing / wrong token yields 401.
func TestConnectRequiresAuth(t *testing.T) {
h := makeHandler("secret")
cases := []struct{ name, token string }{
{"no-header", ""},
{"wrong-token", "wrong"},
}
for _, c := range cases {
t.Run(c.name, func(t *testing.T) {
w := post(t, h, "/v1/nodes/sg-1/connect", `{"device_id":"x"}`, c.token)
if w.Code != http.StatusUnauthorized {
t.Errorf("want 401, got %d", w.Code)
}
})
}
}
// TestConnectNoAuthCheck verifies that an empty token skips auth entirely.
func TestConnectNoAuthCheck(t *testing.T) {
h := makeHandler("")
w := post(t, h, "/v1/nodes/sg-1/connect", `{"device_id":"x"}`, "")
if w.Code != http.StatusOK {
t.Errorf("want 200, got %d", w.Code)
}
}
// TestConnectRequiresDeviceID verifies that missing device_id yields 400.
func TestConnectRequiresDeviceID(t *testing.T) {
h := makeHandler("")
cases := []struct{ name, body string }{
{"empty-object", `{}`},
{"blank-id", `{"device_id":""}`},
{"not-json", `not-json`},
}
for _, c := range cases {
t.Run(c.name, func(t *testing.T) {
req := httptest.NewRequest(http.MethodPost, "/v1/nodes/sg-1/connect", bytes.NewBufferString(c.body))
rw := httptest.NewRecorder()
h.ServeHTTP(rw, req)
if rw.Code != http.StatusBadRequest {
t.Errorf("want 400, got %d", rw.Code)
}
})
}
}
// TestConnectMethodNotAllowed verifies that GET returns 405.
func TestConnectMethodNotAllowed(t *testing.T) {
h := makeHandler("")
req := httptest.NewRequest(http.MethodGet, "/v1/nodes/sg-1/connect", nil)
w := httptest.NewRecorder()
h.ServeHTTP(w, req)
if w.Code != http.StatusMethodNotAllowed {
t.Errorf("want 405, got %d", w.Code)
}
}
// TestConnectWrongPath verifies that unrelated paths return 404.
func TestConnectWrongPath(t *testing.T) {
h := makeHandler("")
req := httptest.NewRequest(http.MethodPost, "/v1/nodes/sg-1/disconnect", nil)
w := httptest.NewRecorder()
h.ServeHTTP(w, req)
if w.Code != http.StatusNotFound {
t.Errorf("want 404, got %d", w.Code)
}
}