test(release): verify Android production routes read-only

This commit is contained in:
key
2026-07-29 03:34:21 +08:00
parent 99958f42fc
commit 2d5568f94b
5 changed files with 160 additions and 2 deletions
+6
View File
@@ -360,6 +360,12 @@ Android 人工验收每完成一个步骤,用 `.\scripts\capture-android-accep
--approval 'ROLLBACK_BACKEND:<完整备份JAR-SHA256>'
```
发布前后均可重复运行下列无登录安全探针。它只对 APK 依赖的 20 个入口发送 GET:1 个公开首页必须返回业务 `200`,6 个鉴权 GET 必须返回 `401`,13 个仅允许 POST 的入口用 GET 必须返回 `405`。`/api/knowledge/answer-feedback` 同时存在员工 POST 和运营 GET,因此归入鉴权 GET。脚本明确排除短信验证码入口,不登录、不上传、不提交业务请求;通过只证明路由存在且无登录访问失败关闭,不能替代认证态业务验收:
```bash
./scripts/verify-aug1-production-api-readonly.sh
```
## MVP 页面验证
登录后侧栏应只展示以下入口: