import { expect, test } from "@playwright/test"; test("GET /api/users 转发 tRPC user.list 返回用户列表", async ({ request }) => { const res = await request.get("/api/users"); expect(res.ok()).toBeTruthy(); const body = await res.json(); expect(Array.isArray(body?.result?.data?.users)).toBe(true); // 安全:任何对外出口不得泄露 passwordHash expect(JSON.stringify(body)).not.toContain("passwordHash"); }); test("tRPC user.list 直接调用不返回 passwordHash", async ({ request }) => { const input = encodeURIComponent(JSON.stringify({ limit: 20, offset: 0 })); const res = await request.get(`/api/trpc/user.list?input=${input}`); expect(res.ok()).toBeTruthy(); expect(JSON.stringify(await res.json())).not.toContain("passwordHash"); }); test("tRPC HTTP 适配可调用", async ({ request }) => { const res = await request.get("/api/trpc/user.list"); // 未登录/无输入时允许 200 或 4xx,但服务必须可达且返回 JSON expect(res.headers()["content-type"]).toContain("application/json"); const body = await res.text(); expect(body.length).toBeGreaterThan(0); });