Files
ModelRouter/internal/gateway/ui_plugin_test.go
JianFeeeee 1c690611f8 feat(gui): WebUI 与 Electron 壳的插件安装/删除/禁用/编辑
## WebUI:新增「插件」页
- 列表来自 on_disk(不是 loaded 集合)——**加载失败的插件也必须显示并带错误**,
  否则一个语法错误看起来和"插件没装"完全一样
- 启用/禁用(PUT {"enabled":bool})、删除、编辑源码、安装/覆盖
- 显示 hook_errors:插件抛异常在别处毫无痕迹,没有这一栏的症状就是
  "功能就是不work"
- 插到 dropzone 与代码编辑器都做了泛型化(bindDropzone / openCodeModal),
  适配器与插件共用一份,而不是复制第二份只改 4 个 id 的函数

## TABS 收敛为单一常量
tab 清单原本是字面量散在三处:goTab、refresh()、admin-only 隐藏列表。
加一个 tab 意味着三处都要记得改,漏一处就是"路由认得但界面不显示"——
和今天早些时候 chain_step 漏报同一类静默缺口。现在只有 const TABS。

## Electron 壳:设置面板里的插件管理
渲染进程不能直连内嵌核心(没有 key、不知道端口),所以走 IPC:
  renderer → plugins:proxy → main → HTTP /api/plugins
代理是 (method, path, body) 透传而不是固定命令表:固定表每加一个端点就要扩,
而"按钮存在但什么都不做"比"没有这个按钮"更糟。透传让渲染层能调用核心将来
新增的任何 /api/plugins 路由,路径在主进程校验。

## ★ GUI 此前零测试,而本次改动就引入了三类"看起来没事"的问题
1. 引用了不存在的 CSS 类(.tag / .sm)——渲染成无样式文本
2. 引用了不存在的 helper(esc / escAttr)——那是 WebUI 的,renderer/app.js
   是独立文档,点击时 ReferenceError
3. .ghost/.primary 只在 .form .actions 作用域内生效,插件按钮在 .pl-acts 里
   于是是无样式裸按钮

补 4 个静态判据(不启动 Electron,守卫的正是"打开应用才看得见"那一类):
  TestGUICSSClassesExist          用到的类必须在样式表里定义
  TestGUIHelperFunctionsAreDefined 被调用的函数必须有定义
  TestGUIPluginPanelIsReachable  面板在 overlay 内、按钮已绑定、打开设置会加载
  TestGUIIPCPathIsConstrained    代理必须限定 /api/plugins 前缀并拒绝路径穿越

写第一个判据时我错了三次:CSS 解析器先丢最后一个 selector、再把变量块当
selector、最后漏掉复合选择器(.tb-btn.tb-close)。两次"判据自己坏了"的
教训和本项目一贯一致——**判据出错的信号是它报了一个假问题**。现在改用宽松的
token 提取 + 显式的 guiKnownUnstyled 豁免表(blob/tgl/rail 是既有无样式类,
不是本次引入,失败它们只会让判据对新工作失去意义)。

## 变异验证
  改坏唯一的 CSS 定义(.pl-empty)→ TestGUICSSClassesExist 红
  改坏 helper 名 → TestGUIHelperFunctionsAreDefined 红
★ 第一次变异我改了 .pl-broken,判据**正确地没报**——因为它还被另一条规则定义。
  这是变异选错目标,不是判据有洞;换 .pl-empty 后如期变红。

363 个测试全绿。
2026-10-02 08:47:08 +08:00

263 lines
11 KiB
Go

package gateway
import (
"strings"
"testing"
)
// The plugin UI injection is JavaScript inside the embedded index.html, and it
// is the ONLY thing that turns a plugin's `ui` block into a visible page or
// element. These tests pin the wiring on the JS side; the server side (what the
// payload contains) is covered by TestUIInjectServesPluginUI and the lua
// package's TestBillingPluginDeclaresUI.
//
// What makes this worth pinning: a missing hook here fails SILENTLY. The page
// simply never appears, there is no error anywhere, and it looks like "the
// plugin didn't declare a page" rather than "the UI forgot to inject it".
// uiSource returns the embedded WebUI document.
func uiSourceX(t *testing.T) string {
t.Helper()
return uiSource(t)
}
// TestUIFetchesPluginInjection: the boot sequence must ask the kernel what to
// inject. Without this fetch the whole feature is inert.
func TestUIFetchesPluginInjection(t *testing.T) {
src := uiSourceX(t)
if !strings.Contains(src, "/api/ui-inject") {
t.Error("the WebUI never calls /api/ui-inject; plugin pages and elements can never appear")
}
}
// TestUIInjectsBeforeFirstRender: injection must be awaited before the first
// refresh, otherwise the sidebar is built without the plugin entry and the
// first paint races the fetch. This is an ordering contract, so it is asserted
// on the source order rather than trusted.
func TestUIInjectsBeforeFirstRender(t *testing.T) {
src := uiSourceX(t)
iInject := strings.Index(src, "injectPluginUI()")
iRefresh := strings.LastIndex(src, `refresh("status")`)
if iInject < 0 {
t.Fatal("injectPluginUI() is never called")
}
if iRefresh < 0 {
t.Fatal("the boot sequence no longer calls refresh(\"status\")")
}
if iInject > iRefresh {
t.Error("injectPluginUI() is called after the first refresh; the sidebar " +
"and #main would be built before the plugin page exists")
}
// And it must be awaited, not fire-and-forget.
window := src[iInject:]
if !strings.Contains(window[:200], ".finally") && !strings.Contains(window[:200], "await") {
t.Error("injectPluginUI() is not awaited before refresh; a slow response " +
"would race the first paint")
}
}
// TestUIPluginScriptsRunAfterMarkup is the subtle one. Setting innerHTML with a
// <script> tag does NOT execute it; appending via a template neither does. The
// mount therefore has to be inserted first and its scripts re-created
// afterwards, or a plugin's script runs before its own DOM exists — which is
// exactly the "document.getElementById returns null" failure mode.
func TestUIPluginScriptsRunAfterMarkup(t *testing.T) {
src := uiSourceX(t)
// A <template> is used to parse the mount without executing scripts...
if !strings.Contains(src, "createElement(\"template\")") {
t.Error("the mount is not parsed via <template>; scripts could execute before their DOM")
}
// ...and scripts are then re-created as fresh elements so they DO run.
if !strings.Contains(src, "document.createElement(\"script\")") {
t.Error("plugin <script> blocks are never re-created, so they never execute")
}
if !strings.Contains(src, "replaceWith(s)") {
t.Error("the original inert <script> is not replaced by an executable one")
}
}
// TestUIPluginAPISurface: the documented browser API must exist with the exact
// names docs/plugins.md promises, since plugin authors code against it.
func TestUIPluginAPISurface(t *testing.T) {
src := uiSourceX(t)
for _, member := range []string{"fetchState", "postState", "onTabShown"} {
if !strings.Contains(src, member+":") && !strings.Contains(src, member+"(") {
t.Errorf("window.pluginAPI.%s is missing; docs/plugins.md documents it", member)
}
}
}
// TestUIPluginPageBecomesRealTab: a plugin page must get a pane in #main AND a
// sidebar button wired to goTab, otherwise the page is unreachable.
func TestUIPluginPageBecomesRealTab(t *testing.T) {
src := uiSourceX(t)
// pane in #main
if !strings.Contains(src, `pane.id = "tab-" + id`) {
t.Error("no pane is created for a plugin page")
}
if !strings.Contains(src, "main.appendChild(pane)") {
t.Error("the plugin pane is not appended to #main")
}
// sidebar button wired to the tab router
if !strings.Contains(src, "btn.dataset.tab = id") {
t.Error("the sidebar button is not given a data-tab, so goTab() will not route to it")
}
if !strings.Contains(src, "btn.onclick = () => goTab(id)") {
t.Error("the sidebar button is not wired to goTab()")
}
// and the router must know about it
if !strings.Contains(src, "PLUGIN_PAGES.has(tab)") {
t.Error("refresh() does not route plugin pages, so opening one renders nothing")
}
}
// TestUIPluginElementsHonorAnchor: elements declare top / bottom / before:sel /
// after:sel. Silently ignoring the anchor would put a "top" tile at the bottom
// of the status page, which looks like a layout bug rather than a plugin bug.
func TestUIPluginElementsHonorAnchor(t *testing.T) {
src := uiSourceX(t)
for _, anchor := range []string{`anchor === "top"`, `anchor.startsWith("before:")`, `"after:"`} {
if !strings.Contains(src, anchor) {
t.Errorf("the anchor form %s is not handled; elements would all land at the bottom", anchor)
}
}
}
// TestUIPluginInjectionFailureIsNonFatal: plugins are optional, so a failed
// /api/ui-inject must still leave a working UI (the dashboard has to render).
// Two places have to cooperate: the function swallows the fetch error, and the
// caller catches anything that still escapes so refresh() always runs.
func TestUIPluginInjectionFailureIsNonFatal(t *testing.T) {
src := uiSourceX(t)
// inside the function: the fetch is wrapped in try/catch
fnStart := strings.Index(src, "async function injectPluginUI()")
if fnStart < 0 {
t.Fatal("injectPluginUI() is not defined")
}
fn := src[fnStart:]
if !strings.Contains(fn, "plugins are optional; the UI must work without them") {
t.Error("injectPluginUI does not guard its own fetch failure")
}
// at the call site: the rejection cannot escape before the first render
// LastIndex, not Index: the DEFINITION of injectPluginUI also matches, and
// the definition has no .catch on it.
iCall := strings.LastIndex(src, "injectPluginUI()")
if iCall < 0 {
t.Fatal("injectPluginUI() is never called")
}
// Bound the window at len(src): the call site sits near EOF and a fixed
// slice overruns it (a panic in a test is worse than a skipped assertion).
end := iCall + 220
if end > len(src) {
end = len(src)
}
if !strings.Contains(src[iCall:end], ".catch") {
t.Error("a failed /api/ui-inject would reject before refresh(\"status\"), " +
"leaving the dashboard blank")
}
}
// ---- plugin management UI contract ---------------------------------------
//
// The management page is the operator's only way to take a broken plugin out
// of the request path. Every one of these assertions guards a link that, if it
// silently broke, would leave the gateway running with a plugin it cannot
// disable — the worst kind of gap: everything looks fine and nothing is
// reachable.
func TestUIHasPluginTabAndPane(t *testing.T) {
src := uiSourceX(t)
if !strings.Contains(src, `data-tab="plugins"`) {
t.Error("no sidebar entry for the plugin page")
}
if !strings.Contains(src, `id="tab-plugins"`) {
t.Error("no #tab-plugins pane")
}
// The tab list is now a single constant; a new tab must be added there or
// goTab will not un-hide its pane.
if !strings.Contains(src, `const TABS = [`) {
t.Error("TABS is gone; the tab list went back to a duplicated literal")
}
for _, tn := range []string{"status", "chat", "keys", "sort", "sources", "adapters", "plugins"} {
if !strings.Contains(src, `"`+tn+`"`) {
t.Errorf("TABS is missing %q", tn)
}
}
// goTab must iterate TABS, not its own list.
if !strings.Contains(src, "TABS.forEach((tn) =>") {
t.Error("goTab does not iterate TABS")
}
if strings.Contains(src, `["status", "chat", "keys", "sort", "sources", "adapters"].forEach`) {
t.Error("a duplicated tab literal survived; it will drift from TABS")
}
}
func TestUIRendersPluginManagement(t *testing.T) {
src := uiSourceX(t)
body, ok := jsFunctionBody(src, "renderPlugins")
if !ok {
t.Fatal("renderPlugins() not found")
}
// It must read the DISK listing, not just the loaded set: a plugin that
// failed to compile is absent from the loaded set, and showing only the
// loaded set makes a syntax error look like "the plugin is not installed".
if !strings.Contains(body, "on_disk") {
t.Error("renderPlugins reads only the loaded set; a failed plugin would " +
"be invisible instead of shown with its error")
}
if !strings.Contains(body, "/api/plugins") {
t.Error("renderPlugins does not call /api/plugins")
}
// Hook errors must be surfaced: a plugin that throws in every stage leaves
// no other trace, so without this the symptom is "the feature just doesn't
// work".
if !strings.Contains(body, "hook_errors") {
t.Error("renderPlugins ignores hook_errors; a silently broken plugin is undebuggable")
}
// Enable / disable / remove / edit.
for _, fn := range []string{"togglePlugin", "delPlugin", "installPlugin", "editPlugin"} {
if _, ok := jsFunctionBody(src, fn); !ok {
t.Errorf("%s() is missing from the WebUI", fn)
}
}
// The toggle must go through the enable/disable endpoint, not delete.
tb, ok := jsFunctionBody(src, "togglePlugin")
if !ok {
t.Fatal("togglePlugin() missing")
}
if !strings.Contains(tb, `method: "PUT"`) {
t.Error("togglePlugin does not use PUT")
}
if !strings.Contains(tb, "enabled:") {
t.Error("togglePlugin does not send an \"enabled\" field")
}
// And the admin-only tab list must include plugins, or a non-admin would
// see a page whose every action 403s.
if !strings.Contains(src, `["sort", "sources", "adapters", "plugins"]`) {
t.Error("the admin-only tab list omits \"plugins\"; a user key would see a " +
"page full of actions that all fail with 403")
}
}
// TestUIBindDropzoneIsParameterised guards the refactor: the adapter and plugin
// upload forms share one dropzone, so a hard-coded id would send a dropped
// plugin file into the adapter name field.
func TestUIBindDropzoneIsParameterised(t *testing.T) {
src := uiSourceX(t)
body, ok := jsFunctionBody(src, "bindDropzone")
if !ok {
t.Fatal("bindDropzone() not found")
}
if strings.Contains(body, `$("#dz")`) || strings.Contains(body, `$("#adp-name")`) {
t.Error("bindDropzone still hard-codes the adapter's element ids; the " +
"plugin form would write into the adapter form")
}
if !strings.Contains(body, "dzId") || !strings.Contains(body, "nameSel") {
t.Error("bindDropzone does not accept the ids to bind")
}
// Both forms must call it.
if !strings.Contains(src, `bindDropzone("pl-dz", "pl-file", "#pl-name", "#pl-code")`) {
t.Error("the plugin upload form does not use the parameterised dropzone")
}
}