diff --git a/backend/script/sql/aihr_personal_knowledge_mysql8.sql b/backend/script/sql/aihr_personal_knowledge_mysql8.sql index 7358cdee..11b37049 100644 --- a/backend/script/sql/aihr_personal_knowledge_mysql8.sql +++ b/backend/script/sql/aihr_personal_knowledge_mysql8.sql @@ -7,7 +7,7 @@ INSERT INTO `sys_oss_config` `endpoint`, `domain`, `is_https`, `region`, `access_policy`, `status`, `ext1`, `create_dept`, `create_by`, `create_time`, `update_by`, `update_time`, `remark`) SELECT 9001, source.`tenant_id`, 'personal-minio', source.`access_key`, source.`secret_key`, - 'ruoyi-personal', 'personal', source.`endpoint`, source.`domain`, source.`is_https`, source.`region`, + 'ruoyi-personal', '', source.`endpoint`, source.`domain`, source.`is_https`, source.`region`, '0', '1', '', source.`create_dept`, source.`create_by`, CURRENT_TIMESTAMP, source.`update_by`, CURRENT_TIMESTAMP, '个人AI助理专用私有对象存储' FROM `sys_oss_config` source diff --git a/docker-compose.dev.yml b/docker-compose.dev.yml index f02cbf64..2f4ea95d 100644 --- a/docker-compose.dev.yml +++ b/docker-compose.dev.yml @@ -74,5 +74,6 @@ services: entrypoint: ["/bin/sh", "-c"] command: > "mc alias set local http://minio:9000 ruoyi ruoyi123 && - mc mb -p local/ruoyi || true; - mc mb -p local/ruoyi-personal || true" + mc mb --ignore-existing local/ruoyi && + mc mb --ignore-existing local/ruoyi-personal && + mc anonymous set none local/ruoyi-personal" diff --git a/scripts/personal-assistant-smoke.sh b/scripts/personal-assistant-smoke.sh index c26c808e..92faa63f 100755 --- a/scripts/personal-assistant-smoke.sh +++ b/scripts/personal-assistant-smoke.sh @@ -14,11 +14,14 @@ PHONE_A="138$(printf '%08d' "$PHONE_SUFFIX")" PHONE_B="138$(printf '%08d' $((PHONE_SUFFIX % 99999999 + 1)))" TITLE="personal-assistant-smoke-$RUN_ID" CONTENT="个人助理隔离烟测唯一标记 ${RUN_ID},物业催费沟通资料。" +TMP_ROOT="$(mktemp -d "${TMPDIR:-/tmp}/wygj-personal-smoke.XXXXXX")" +chmod 700 "$TMP_ROOT" TOKEN_A="" CLIENT_A="" TOKEN_B="" CLIENT_B="" -USER_A="" USER_B="" ITEM_ID="" OSS_ID="" OBJECT_KEY="" JOB_ID="" SESSION_ID="" -CREATED_USER_A=0 CREATED_USER_B=0 CLEANED=0 +USER_A="" USER_B="" ITEM_ID="" OSS_ID="" OBJECT_KEY="" OSS_URL="" JOB_ID="" SESSION_ID="" +OWN_PHONE_A=0 OWN_PHONE_B=0 CLEANED=0 HTTP_STATUS="" HTTP_BODY="" LOGIN_TOKEN="" LOGIN_CLIENT="" +TEMP_FILES=() fail() { echo "FAIL: $*" >&2; exit 1; } need() { command -v "$1" >/dev/null 2>&1 || fail "missing command: $1"; } @@ -29,12 +32,37 @@ expect_code() { mysql() { docker exec "$DB_CONTAINER" mysql -uroot -proot --default-character-set=utf8mb4 -N -B -D "$DB_NAME" -e "$1" 2>/dev/null } +register_tmp() { + local path="$1" + chmod 600 "$path" + TEMP_FILES+=("$path") +} cleanup_once() { [[ "$CLEANED" == 0 ]] || return 0 CLEANED=1 - [[ "${AIHR_SMOKE_CLEANUP_DRY_RUN:-0}" != 1 ]] || return 0 set +e + [[ ${#TEMP_FILES[@]} == 0 ]] || rm -f -- "${TEMP_FILES[@]}" + rm -rf -- "$TMP_ROOT" + [[ "${AIHR_SMOKE_CLEANUP_DRY_RUN:-0}" != 1 ]] || return 0 + if [[ "$OWN_PHONE_A" == 1 && ! "$USER_A" =~ ^[0-9]+$ ]]; then + USER_A="$(mysql "select user_id from sys_user where phonenumber='$PHONE_A' and remark='移动端短信自动注册' order by user_id desc limit 1" | head -1)" + fi + if [[ "$OWN_PHONE_B" == 1 && ! "$USER_B" =~ ^[0-9]+$ ]]; then + USER_B="$(mysql "select user_id from sys_user where phonenumber='$PHONE_B' and remark='移动端短信自动注册' order by user_id desc limit 1" | head -1)" + fi + if [[ "$USER_A" =~ ^[0-9]+$ && ! "$ITEM_ID" =~ ^[0-9]+$ ]]; then + ITEM_ID="$(mysql "select id from aihr_personal_item where tenant_id='000000' and owner_user_id=$USER_A and title='$TITLE' order by id desc limit 1" | head -1)" + fi + if [[ "$USER_A" =~ ^[0-9]+$ && "$ITEM_ID" =~ ^[0-9]+$ ]]; then + if [[ ! "$OSS_ID" =~ ^[0-9]+$ || -z "$OBJECT_KEY" ]]; then + read -r OSS_ID OBJECT_KEY OSS_URL <<<"$(mysql "select o.oss_id,o.file_name,o.url from sys_oss o join aihr_personal_item i on i.oss_id=o.oss_id where i.id=$ITEM_ID and i.owner_user_id=$USER_A and i.title='$TITLE' limit 1")" + fi + [[ "$JOB_ID" =~ ^[0-9]+$ ]] || JOB_ID="$(mysql "select id from aihr_personal_cleanup_job where tenant_id='000000' and owner_user_id=$USER_A and item_id=$ITEM_ID order by id desc limit 1" | head -1)" + fi + if [[ "$USER_A" =~ ^[0-9]+$ && ! "$SESSION_ID" =~ ^[0-9]+$ ]]; then + SESSION_ID="$(mysql "select s.id from aihr_personal_chat_session s join aihr_personal_chat_message m on m.session_id=s.id and m.owner_user_id=s.owner_user_id where s.tenant_id='000000' and s.owner_user_id=$USER_A and m.content like '%$RUN_ID%' order by s.id desc limit 1" | head -1)" + fi if [[ "$USER_A" =~ ^[0-9]+$ && "$ITEM_ID" =~ ^[0-9]+$ ]]; then curl -sS -X POST "$QDRANT_URL/collections/$QDRANT_COLLECTION/points/delete?wait=true" \ -H 'Content-Type: application/json' \ @@ -62,12 +90,12 @@ cleanup_once() { mysql "delete from aihr_personal_space where tenant_id='000000' and owner_user_id=$owner and not exists (select 1 from aihr_personal_item where tenant_id='000000' and owner_user_id=$owner);" >/dev/null 2>&1 || true done - if [[ "$CREATED_USER_A" == 1 && "$USER_A" =~ ^[0-9]+$ ]]; then + if [[ "$OWN_PHONE_A" == 1 && "$USER_A" =~ ^[0-9]+$ ]]; then mysql "delete from sys_user_role where user_id=$USER_A; delete from sys_user_post where user_id=$USER_A; delete from sys_user where user_id=$USER_A and phonenumber='$PHONE_A' and remark='移动端短信自动注册'; delete from sys_logininfor where user_name='$PHONE_A';" >/dev/null 2>&1 || true fi - if [[ "$CREATED_USER_B" == 1 && "$USER_B" =~ ^[0-9]+$ ]]; then + if [[ "$OWN_PHONE_B" == 1 && "$USER_B" =~ ^[0-9]+$ ]]; then mysql "delete from sys_user_role where user_id=$USER_B; delete from sys_user_post where user_id=$USER_B; delete from sys_user where user_id=$USER_B and phonenumber='$PHONE_B' and remark='移动端短信自动注册'; delete from sys_logininfor where user_name='$PHONE_B';" >/dev/null 2>&1 || true @@ -103,7 +131,8 @@ fi request() { local method="$1" path="$2" token="${3:-}" client="${4:-}" body="${5:-}" tmp - tmp="$(mktemp)" + tmp="$(mktemp "$TMP_ROOT/http.XXXXXX")" + register_tmp "$tmp" local args=(-k -sS -X "$method" "$API_URL$path" -o "$tmp" -w '%{http_code}') [[ -z "$token" ]] || args+=(-H "Authorization: Bearer $token" -H "clientid: $client") [[ -z "$body" ]] || args+=(-H 'Content-Type: application/json' --data "$body") @@ -141,19 +170,24 @@ mysql "select 1 from aihr_personal_item limit 1" >/dev/null || fail "personal sc expect_code "$(mysql "select access_policy from sys_oss_config where tenant_id='000000' and config_key='minio'")" 1 "shared minio policy unchanged" expect_code "$(mysql "select concat(bucket_name,':',access_policy) from sys_oss_config where tenant_id='000000' and config_key='personal-minio'")" "ruoyi-personal:0" "personal private storage config" expect_code "$(mysql "select count(*) from sys_user where phonenumber in ('$PHONE_A','$PHONE_B')")" 0 "unique smoke users must not preexist" +OWN_PHONE_A=1 +OWN_PHONE_B=1 +bucket_policy="$(docker run --rm --network "$DOCKER_NETWORK" \ + -e 'MC_HOST_local=http://ruoyi:ruoyi123@wygj-minio:9000' minio/mc anonymous get local/ruoyi-personal 2>/dev/null)" +[[ "$bucket_policy" == *"private"* ]] || fail "personal bucket anonymous policy is not private" login "$PHONE_A"; TOKEN_A="$LOGIN_TOKEN"; CLIENT_A="$LOGIN_CLIENT" USER_A="$(mysql "select user_id from sys_user where phonenumber='$PHONE_A' and remark='移动端短信自动注册'")" -[[ "$USER_A" =~ ^[0-9]+$ ]] || fail "A smoke user was not created"; CREATED_USER_A=1 +[[ "$USER_A" =~ ^[0-9]+$ ]] || fail "A smoke user was not created" login "$PHONE_B"; TOKEN_B="$LOGIN_TOKEN"; CLIENT_B="$LOGIN_CLIENT" USER_B="$(mysql "select user_id from sys_user where phonenumber='$PHONE_B' and remark='移动端短信自动注册'")" -[[ "$USER_B" =~ ^[0-9]+$ && "$USER_A" != "$USER_B" ]] || fail "B smoke user was not created independently"; CREATED_USER_B=1 +[[ "$USER_B" =~ ^[0-9]+$ && "$USER_A" != "$USER_B" ]] || fail "B smoke user was not created independently" request POST /api/aihr/personal-assistant/items/text "$TOKEN_A" "$CLIENT_A" \ "{\"title\":\"$TITLE\",\"content\":\"$CONTENT\",\"tags\":[\"smoke\",\"$RUN_ID\"]}" expect_success "A create text item" ITEM_ID="$(jq -er '.data.itemId | tostring' <<<"$HTTP_BODY")" -read -r OSS_ID OBJECT_KEY <<<"$(mysql "select o.oss_id,o.file_name from sys_oss o join aihr_personal_item i on i.oss_id=o.oss_id where i.id=$ITEM_ID and i.owner_user_id=$USER_A and i.title='$TITLE'")" +read -r OSS_ID OBJECT_KEY OSS_URL <<<"$(mysql "select o.oss_id,o.file_name,o.url from sys_oss o join aihr_personal_item i on i.oss_id=o.oss_id where i.id=$ITEM_ID and i.owner_user_id=$USER_A and i.title='$TITLE'")" [[ "$OSS_ID" =~ ^[0-9]+$ && "$OBJECT_KEY" =~ ^personal/000000/$USER_A/$ITEM_ID/[A-Za-z0-9._/-]+$ ]] || fail "unexpected personal OSS ownership metadata" for _ in {1..40}; do @@ -163,12 +197,15 @@ for _ in {1..40}; do done expect_success "A item detail" expect_code "$(jq -r '.data.status' <<<"$HTTP_BODY")" READY "A text item processing" +anon_tmp="$(mktemp "$TMP_ROOT/anonymous.XXXXXX")"; register_tmp "$anon_tmp" +anon_status="$(curl -sS -o "$anon_tmp" -w '%{http_code}' "$OSS_URL" || printf '000')" +expect_code "$anon_status" 403 "personal object anonymous GET" request POST /api/aihr/personal-assistant/search "$TOKEN_A" "$CLIENT_A" \ "{\"queryText\":\"隔离烟测\",\"scope\":[\"PERSONAL\"],\"itemIds\":[\"$ITEM_ID\"],\"limit\":10}" expect_success "A itemIds search" [[ "$(jq --arg item "$ITEM_ID" '[.data.hits[] | select((.itemId|tostring)==$item)]|length' <<<"$HTTP_BODY")" -ge 1 ]] || fail "A search did not return own item" request POST /api/aihr/personal-assistant/ask "$TOKEN_A" "$CLIENT_A" \ - "{\"queryText\":\"隔离烟测资料是什么\",\"scope\":[\"PERSONAL\"],\"itemIds\":[\"$ITEM_ID\"]}" + "{\"queryText\":\"隔离烟测资料是什么 $RUN_ID\",\"scope\":[\"PERSONAL\"],\"itemIds\":[\"$ITEM_ID\"]}" expect_success "A personal answer" SESSION_ID="$(jq -er '.data.sessionId | tostring' <<<"$HTTP_BODY")" [[ "$SESSION_ID" =~ ^[0-9]+$ ]] || fail "A answer did not persist session"