HH-683: propagate subscription fetch failures (#1)
Build and Publish Docker Image / build-and-push (push) Failing after 9m58s

This commit was merged in pull request #1.
This commit is contained in:
2026-08-26 14:18:53 +08:00
parent c73c2b55cd
commit 9a4e60cf10
4 changed files with 119 additions and 43 deletions
+31
View File
@@ -1836,6 +1836,37 @@ func TestHandleDownloadSourceDisabled(t *testing.T) {
assertStatus(t, "DownloadSource disabled", code, 404)
}
func TestHandleDownloadBuildErrorDoesNotLeakUpstreamURL(t *testing.T) {
for _, kind := range []string{"source", "collection"} {
t.Run(kind, func(t *testing.T) {
server := httptest.NewServer(http.HandlerFunc(func(http.ResponseWriter, *http.Request) {}))
upstreamURL := server.URL + "/subscription?token=upstream-secret"
server.Close()
deps := newTestDeps(t)
app := newApp(deps)
deps.SourceRepo.Upsert(model.SourceRecord{ID: "remote", Name: "Remote", Type: "remote", URL: upstreamURL, Enabled: true})
path := "/sources/remote/dl-tok?target=json"
if kind == "collection" {
deps.CollectionRepo.Upsert(model.CollectionRecord{ID: "remote", Name: "Remote", SourceIds: []string{"remote"}, Enabled: true})
path = "/collections/remote/dl-tok?target=json"
}
code, body := doRequest(t, app, "GET", path, "", nil)
assertStatus(t, kind, code, http.StatusInternalServerError)
errorBody, ok := body["error"].(map[string]any)
if !ok || errorBody["message"] != "Failed to build subscription" {
t.Fatalf("response = %v, want fixed generic error", body)
}
response, _ := json.Marshal(body)
if strings.Contains(string(response), "upstream-secret") || strings.Contains(string(response), upstreamURL) {
t.Fatalf("response leaked upstream URL: %s", response)
}
})
}
}
// ---------------------------------------------------------------------------
// Preview handlers
// ---------------------------------------------------------------------------