212dbc4e1d
这是一次大型重构和功能新增: 1. 将原 zen_box 工具重命名为 web_zen_box,调整所有相关路径与配置 2. 新增 web_order_box 原生Web应用的完整资源与部署脚本 3. 新增私人剪贴板后端技能与配套测试脚本 4. 修复订单盒子APP的API地址配置,避免路径重复拼接 5. 新增本地开发跨域白名单支持localhost 6. 清理旧版zen_box的冗余文件
79 lines
2.7 KiB
JavaScript
79 lines
2.7 KiB
JavaScript
// 快速测试:写入 + 查询
|
|
const http = require('http')
|
|
const API = 'http://localhost:8976/api/v1/ingest/private_clipboard'
|
|
|
|
function post(path, body) {
|
|
return new Promise((resolve, reject) => {
|
|
const data = JSON.stringify(body)
|
|
const req = http.request(`${API}${path}`, {
|
|
method: 'POST',
|
|
headers: {
|
|
'X-API-Id': 'private_clipboard',
|
|
'X-API-Key': 'pcb_nuS0qf-W63qcvAPsrG5ePA',
|
|
'Content-Type': 'application/json; charset=utf-8',
|
|
'Content-Length': Buffer.byteLength(data)
|
|
}
|
|
}, (res) => {
|
|
let b = ''
|
|
res.on('data', d => b += d)
|
|
res.on('end', () => resolve({ status: res.statusCode, body: b }))
|
|
})
|
|
req.on('error', reject)
|
|
req.write(data)
|
|
req.end()
|
|
})
|
|
}
|
|
|
|
async function run() {
|
|
let pass = 0, fail = 0
|
|
|
|
// 1. 中文
|
|
const r1 = await post('/text', { text: '你好世界' })
|
|
if (r1.status === 200) { console.log('✅ 中文写入成功'); pass++ }
|
|
else { console.log(`❌ 中文写入失败: ${r1.body}`); fail++ }
|
|
|
|
// 2. XSS
|
|
const r2 = await post('/text', { text: '<script>alert(1)</script>' })
|
|
if (r2.status === 200) { console.log('✅ XSS 写入成功'); pass++ }
|
|
else { console.log(`❌ XSS 写入失败: ${r2.body}`); fail++ }
|
|
|
|
// 3. 特殊字符
|
|
const r3 = await post('/text', { text: 'Tom & Jerry <best> "movie"' })
|
|
if (r3.status === 200) { console.log('✅ 特殊字符写入成功'); pass++ }
|
|
else { console.log(`❌ 特殊字符写入失败: ${r3.body}`); fail++ }
|
|
|
|
// 4. 查询验证
|
|
await new Promise((resolve) => {
|
|
http.get(`${API}/latest?limit=3`, {
|
|
headers: { 'X-API-Id': 'private_clipboard', 'X-API-Key': 'pcb_nuS0qf-W63qcvAPsrG5ePA' }
|
|
}, (res) => {
|
|
let b = ''
|
|
res.on('data', d => b += d)
|
|
res.on('end', () => {
|
|
const data = JSON.parse(b)
|
|
console.log('\n--- 查询结果 ---')
|
|
data.items.forEach((item, i) => {
|
|
console.log(`[${i}] "${item.text_content}"`)
|
|
})
|
|
// 验证转义
|
|
const xss = data.items.find(i => i.text_content.includes('<'))
|
|
if (xss) { console.log('\n✅ XSS 已转义'); pass++ }
|
|
else { console.log('\n❌ XSS 未转义'); fail++ }
|
|
|
|
const cn = data.items.find(i => i.text_content === '你好世界')
|
|
if (cn) { console.log('✅ 中文存储正确'); pass++ }
|
|
else { console.log('❌ 中文存储错误'); fail++ }
|
|
|
|
const sp = data.items.find(i => i.text_content.includes('&') && i.text_content.includes('<'))
|
|
if (sp) { console.log('✅ 特殊字符转义正确'); pass++ }
|
|
else { console.log('❌ 特殊字符转义错误'); fail++ }
|
|
|
|
console.log(`\n=== 结果: ${pass} 通过, ${fail} 失败 ===`)
|
|
resolve()
|
|
})
|
|
})
|
|
})
|
|
}
|
|
|
|
run()
|