fix(aihr): reject unknown interview sessions
This commit is contained in:
+1
-1
@@ -629,7 +629,7 @@ public class AihrInterviewService {
|
||||
}
|
||||
|
||||
private static void requireSessionTenant(InterviewSession session, String tenantId) {
|
||||
if (session != null && !clean(tenantId).equals(clean(session.tenantId()))) {
|
||||
if (session == null || !clean(tenantId).equals(clean(session.tenantId()))) {
|
||||
throw new IllegalArgumentException("面试会话不存在或无权访问");
|
||||
}
|
||||
}
|
||||
|
||||
+13
@@ -334,6 +334,19 @@ class AihrInterviewServiceTest {
|
||||
service.answer(new AnswerRequest(ownerSession.sessionId(), "q1", "本人回答", null), "candidate-a");
|
||||
}
|
||||
|
||||
@Test
|
||||
@Tag("dev")
|
||||
void interviewAnswerRejectsUnknownSessionForSystemFlow() {
|
||||
JdbcTemplate jdbcTemplate = mock(JdbcTemplate.class);
|
||||
AihrInterviewService service = new AihrInterviewService(new ObjectMapper(), null, jdbcTemplate);
|
||||
|
||||
IllegalArgumentException error = assertThrows(IllegalArgumentException.class, () -> service.answer(
|
||||
new AnswerRequest("iv-not-started", "q1", "不存在会话的回答", null)
|
||||
));
|
||||
|
||||
assertEquals("面试会话不存在或无权访问", error.getMessage());
|
||||
}
|
||||
|
||||
@Test
|
||||
@Tag("dev")
|
||||
void interviewMemorySessionsCarryTenantBoundary() throws Exception {
|
||||
|
||||
Reference in New Issue
Block a user