fix(case): require project scope for uploads

This commit is contained in:
2026-07-14 05:33:03 +08:00
parent b47faebe83
commit cc8ce7c372
5 changed files with 107 additions and 5 deletions
@@ -339,7 +339,11 @@ public class AihrCaseService {
private String resolveUploadProject(String requestedProject, List<String> projectScopes) {
if (projectScopes == null) {
return firstNonBlank(requestedProject, "");
String project = clean(requestedProject);
if (project.isBlank()) {
throw new IllegalArgumentException("系统用户上传案例必须明确所属项目");
}
return project;
}
if (projectScopes.isEmpty()) {
throw new IllegalArgumentException("当前账号没有可用项目身份,暂不能提交案例");
@@ -15,6 +15,7 @@ import java.util.Optional;
import static org.junit.jupiter.api.Assertions.assertEquals;
import static org.junit.jupiter.api.Assertions.assertFalse;
import static org.junit.jupiter.api.Assertions.assertThrows;
import static org.junit.jupiter.api.Assertions.assertTrue;
import static org.mockito.Mockito.mock;
import static org.mockito.Mockito.when;
@@ -82,6 +83,16 @@ class AihrCaseServiceTest {
assertTrue(AihrCaseService.caseProjectAllowed("P1", null));
}
@Test
@Tag("dev")
void systemUploadRequiresExplicitProject() {
AihrCaseService service = new AihrCaseService(null, null, new ObjectMapper(), new CaseJdbcTemplate());
assertThrows(IllegalArgumentException.class, () -> service.upload(
new MockMultipartFile("file", "case.webm", "audio/webm", new byte[]{1}), "", null
));
}
@Test
@Tag("dev")
void caseContributorPositionRecognizesProjectManagersAndLeads() {