fix(aihr): reject unknown interview sessions

This commit is contained in:
2026-07-15 01:12:36 +08:00
parent cb429908e0
commit 217edb09d2
4 changed files with 16 additions and 1 deletions
@@ -629,7 +629,7 @@ public class AihrInterviewService {
}
private static void requireSessionTenant(InterviewSession session, String tenantId) {
if (session != null && !clean(tenantId).equals(clean(session.tenantId()))) {
if (session == null || !clean(tenantId).equals(clean(session.tenantId()))) {
throw new IllegalArgumentException("面试会话不存在或无权访问");
}
}
@@ -334,6 +334,19 @@ class AihrInterviewServiceTest {
service.answer(new AnswerRequest(ownerSession.sessionId(), "q1", "本人回答", null), "candidate-a");
}
@Test
@Tag("dev")
void interviewAnswerRejectsUnknownSessionForSystemFlow() {
JdbcTemplate jdbcTemplate = mock(JdbcTemplate.class);
AihrInterviewService service = new AihrInterviewService(new ObjectMapper(), null, jdbcTemplate);
IllegalArgumentException error = assertThrows(IllegalArgumentException.class, () -> service.answer(
new AnswerRequest("iv-not-started", "q1", "不存在会话的回答", null)
));
assertEquals("面试会话不存在或无权访问", error.getMessage());
}
@Test
@Tag("dev")
void interviewMemorySessionsCarryTenantBoundary() throws Exception {