Repository navigation
Expand file tree
/
Copy pathtest_api.py
More file actions
143 lines (116 loc) · 4.89 KB
/
Copy pathtest_api.py
File metadata and controls
143 lines (116 loc) · 4.89 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
#!/usr/bin/env python3
# -*- coding: utf-8 -*-
"""
API测试脚本
"""
import requests
import json
import time
BASE_URL = "http://localhost:8080"
HEADERS = {"X-Requested-With": "XMLHttpRequest"}
def test_health():
"""测试健康检查"""
print("\n=== 测试健康检查 ===")
response = requests.get(f"{BASE_URL}/health", headers=HEADERS)
print(f"状态码: {response.status_code}")
print(f"响应: {json.dumps(response.json(), ensure_ascii=False, indent=2)}")
return response.status_code == 200
def test_search():
"""测试文件搜索"""
print("\n=== 测试文件搜索 ===")
# 测试按文件名搜索
print("\n测试: 搜索所有.py文件")
response = requests.get(f"{BASE_URL}/search", headers=HEADERS,
params={"path": "D:\\WORK\\webToLocal\\webToLocal\\test_data", "name_pattern": "*.py"})
print(f"状态码: {response.status_code}")
data = response.json()
print(f"响应: {json.dumps(data, ensure_ascii=False, indent=2)}")
return data.get("code") == 0
def test_list():
"""测试目录列表"""
print("\n=== 测试目录列表 ===")
# 测试基本列表
print("\n测试: 列出test_data目录")
response = requests.get(f"{BASE_URL}/list", headers=HEADERS,
params={"path": "D:\\WORK\\webToLocal\\webToLocal\\test_data"})
print(f"状态码: {response.status_code}")
data = response.json()
print(f"响应: {json.dumps(data, ensure_ascii=False, indent=2)}")
return data.get("code") == 0
def test_info():
"""测试文件信息查询"""
print("\n=== 测试文件信息查询 ===")
print("\n测试: 查询test1.py文件信息")
response = requests.get(f"{BASE_URL}/info", headers=HEADERS,
params={"path": "D:\\WORK\\webToLocal\\webToLocal\\test_data\\test1.py"})
print(f"状态码: {response.status_code}")
data = response.json()
print(f"响应: {json.dumps(data, ensure_ascii=False, indent=2)}")
return data.get("code") == 0
def test_delete():
"""测试文件删除"""
print("\n=== 测试文件删除 ===")
# 先创建一个测试文件
test_file = "D:\\WORK\\webToLocal\\webToLocal\\test_data\\test_delete.py"
with open(test_file, 'w') as f:
f.write("# test file to delete")
print(f"\n测试: 删除文件 {test_file}")
response = requests.post(f"{BASE_URL}/delete", headers=HEADERS,
json={"path": test_file, "backup": True})
print(f"状态码: {response.status_code}")
data = response.json()
print(f"响应: {json.dumps(data, ensure_ascii=False, indent=2)}")
return data.get("code") == 0
def test_security():
"""测试安全机制"""
print("\n=== 测试安全机制 ===")
# 测试路径穿越
print("\n测试: 路径穿越攻击")
response = requests.get(f"{BASE_URL}/read", headers=HEADERS,
params={"path": "../Windows/system32/drivers/etc/hosts"})
print(f"状态码: {response.status_code}")
data = response.json()
print(f"响应: {json.dumps(data, ensure_ascii=False, indent=2)}")
path_traversal_blocked = response.status_code == 403
# 测试非白名单目录
print("\n测试: 访问非白名单目录")
response = requests.get(f"{BASE_URL}/read", headers=HEADERS,
params={"path": "C:\\Windows\\system.ini"})
print(f"状态码: {response.status_code}")
data = response.json()
print(f"响应: {json.dumps(data, ensure_ascii=False, indent=2)}")
whitelist_blocked = response.status_code == 403
# 测试CSRF防护
print("\n测试: CSRF防护")
response = requests.get(f"{BASE_URL}/read",
params={"path": "D:\\WORK\\webToLocal\\webToLocal\\test_data\\test1.py"})
print(f"状态码: {response.status_code}")
data = response.json()
print(f"响应: {json.dumps(data, ensure_ascii=False, indent=2)}")
csrf_blocked = response.status_code == 403
return path_traversal_blocked and whitelist_blocked and csrf_blocked
if __name__ == "__main__":
print("开始API测试...")
print(f"BASE_URL: {BASE_URL}")
time.sleep(1) # 等待服务启动
results = []
# 执行测试
results.append(("健康检查", test_health()))
results.append(("文件搜索", test_search()))
results.append(("目录列表", test_list()))
results.append(("文件信息查询", test_info()))
results.append(("文件删除", test_delete()))
results.append(("安全机制", test_security()))
# 打印测试结果
print("\n" + "="*50)
print("测试结果汇总:")
print("="*50)
for name, result in results:
status = "[通过]" if result else "[失败]"
print(f"{name}: {status}")
all_passed = all(result for _, result in results)
print("="*50)
if all_passed:
print("所有测试通过!")
else:
print("部分测试失败,请检查日志。")