// 私人剪贴板 API 验证测试 const http = require('http') const BASE = 'http://localhost:8976' const API = `${BASE}/api/v1/ingest/private_clipboard` const HEADERS = { 'X-API-Id': 'private_clipboard', 'X-API-Key': 'pcb_nuS0qf-W63qcvAPsrG5ePA', 'Content-Type': 'application/json; charset=utf-8' } function post(path, body) { return new Promise((resolve, reject) => { const data = JSON.stringify(body) const req = http.request(`${API}${path}`, { method: 'POST', headers: { ...HEADERS, 'Content-Length': Buffer.byteLength(data) } }, (res) => { let body = '' res.on('data', d => body += d) res.on('end', () => { try { resolve({ status: res.statusCode, body: JSON.parse(body) }) } catch { resolve({ status: res.statusCode, body }) } }) }) req.on('error', reject) req.write(data) req.end() }) } function get(path) { return new Promise((resolve, reject) => { http.get(`${API}${path}`, { headers: HEADERS }, (res) => { let body = '' res.on('data', d => body += d) res.on('end', () => { try { resolve({ status: res.statusCode, body: JSON.parse(body) }) } catch { resolve({ status: res.statusCode, body }) } }) }).on('error', reject) }) } async function sleep(ms) { return new Promise(r => setTimeout(r, ms)) } async function runTests() { let pass = 0, fail = 0 console.log('=== 1. 中文编码测试 ===') const r1 = await post('/text', { text: '你好世界' }) if (r1.status === 200 && r1.body.ok) { // 查询最新一条 const r1q = await get('/latest?limit=1') const text = r1q.body.items[0].text_content if (text === '你好世界') { console.log(' ✅ 中文存储和查询正常') pass++ } else { console.log(` ❌ 查询返回: "${text}" (期望: "你好世界")`) fail++ } } else { console.log(` ❌ 写入失败: ${JSON.stringify(r1)}`) fail++ } console.log('\n=== 2. XSS 转义测试 ===') const xssPayload = '' const r2 = await post('/text', { text: xssPayload }) if (r2.status === 200 && r2.body.ok) { const r2q = await get('/latest?limit=1') const text = r2q.body.items[0].text_content if (text.includes('<') && text.includes('>') && !text.includes('