chore(aihr): harden release evidence checks
This commit is contained in:
@@ -49,6 +49,10 @@ require_file "$frontend_asset_path"
|
||||
require_file "$mobile_asset_path"
|
||||
grep -q '/h5/' "$mobile_index" || fail "mobile H5 index does not contain the /h5/ base path"
|
||||
|
||||
if [[ "${RELEASE_VERIFY_REMOTE_BACKEND:-false}" == "true" && "${RELEASE_VERIFY_REMOTE_MATCH:-false}" != "true" ]]; then
|
||||
fail "RELEASE_VERIFY_REMOTE_BACKEND=true requires RELEASE_VERIFY_REMOTE_MATCH=true"
|
||||
fi
|
||||
|
||||
head_epoch="$(git show -s --format=%ct HEAD)"
|
||||
|
||||
file_epoch() {
|
||||
@@ -102,6 +106,7 @@ if [[ -n "${RELEASE_REMOTE_URL:-}" ]]; then
|
||||
curl -fsS --max-time 15 "$remote/" >/dev/null || fail "remote root check failed: $remote/"
|
||||
echo "remote_root=200 $remote/"
|
||||
require_remote_business_success "remote_tenant_list" "$remote/prod-api/auth/tenant/list"
|
||||
require_remote_business_success "remote_mobile_home" "$remote/prod-api/api/aihr/mobile/home/user"
|
||||
|
||||
if [[ "${RELEASE_VERIFY_REMOTE_MATCH:-false}" == "true" ]]; then
|
||||
remote_frontend_asset="$(curl -fsS --max-time 15 "$remote/" | sed -nE 's/.*src="(\/assets\/[^" ]+\.js)".*/\1/p' | head -n 1)"
|
||||
@@ -124,7 +129,7 @@ if [[ -n "${RELEASE_REMOTE_URL:-}" ]]; then
|
||||
if [[ "${RELEASE_VERIFY_REMOTE_BACKEND:-false}" == "true" ]]; then
|
||||
command -v ssh >/dev/null 2>&1 || fail "ssh is required for remote backend verification"
|
||||
remote_ssh="${RELEASE_REMOTE_SSH:-YCWY}"
|
||||
remote_backend_path="/opt/wygj/app/ruoyi-admin.jar"
|
||||
remote_backend_path="${RELEASE_REMOTE_BACKEND_PATH:-/opt/wygj/app/ruoyi-admin.jar}"
|
||||
remote_backend_sha256="$(ssh -o BatchMode=yes -o ConnectTimeout=10 "$remote_ssh" "sha256sum '$remote_backend_path'" | awk '{print $1}')" || fail "remote backend hash check failed: $remote_ssh:$remote_backend_path"
|
||||
[[ "$remote_backend_sha256" =~ ^[0-9a-f]{64}$ ]] || fail "remote backend hash is invalid: $remote_ssh:$remote_backend_path"
|
||||
local_backend_sha256="$(sha256 "$backend_jar")"
|
||||
|
||||
Regular → Executable
+2
@@ -1,3 +1,5 @@
|
||||
#!/usr/bin/env node
|
||||
|
||||
import assert from 'node:assert/strict';
|
||||
import test from 'node:test';
|
||||
|
||||
|
||||
Reference in New Issue
Block a user