fix: explain missing Feishu image permission

This commit is contained in:
xmanrui 2026-08-19 03:13:11 +08:00
parent 0e7a0931c4
commit 26558e5e71
4 changed files with 288 additions and 109 deletions

View file

@ -277,6 +277,51 @@ test('bridge downloads an inbound Feishu image once and submits structured Harne
assert.deepEqual(sent, ['看到了一张图片']);
});
test('bridge tells users to grant im:message:readonly when Feishu rejects image access', async () => {
const fixture = stateFixture([['p2p:ou_user', 'session-image-permission']]);
const sent = [];
const providerError = new Error('Request failed with status code 400');
providerError.code = 'ERR_BAD_REQUEST';
providerError.response = {
status: 400,
data: Readable.from([Buffer.from(JSON.stringify({
code: 99991672,
msg: 'secret-shaped provider detail /private/path',
}))]),
};
const client = {
im: { v1: {
messageResource: { get: async () => { throw providerError; } },
message: { create: async (request) => {
sent.push(JSON.parse(request.data.content).text);
return { code: 0, data: { message_id: 'om_permission_reply' } };
} },
} },
};
const bridge = new FeishuHarnessBridge({
client,
channel: {},
harness: {
sessionExists: async () => true,
ask: async () => assert.fail('permission failures must not reach Harness'),
},
state: fixture.state,
status: bridgeStatus(),
allowedSenderOpenIds: new Set(['ou_user']),
});
await bridge.accept(event('om_image_permission', '', {
message_type: 'image',
content: JSON.stringify({ image_key: 'img_permission' }),
}));
await bridge.waitForIdle();
assert.equal(sent.length, 1);
assert.match(sent[0], /im:message:readonly/);
assert.match(sent[0], /发布新版本/);
assert.doesNotMatch(sent[0], /99991672|HTTP 400|secret-shaped|private\/path/);
});
test('bridge sends Feishu post text and all embedded images as one structured prompt', async () => {
const fixture = stateFixture([['group:oc_post_group', 'session-post']]);
const downloaded = [];

View file

@ -132,6 +132,53 @@ test('Feishu image loading rejects declared or streamed data above the caller li
}
});
test('Feishu image loading maps the missing message scope to an actionable error', async () => {
const providerError = new Error('Request failed with status code 400');
const body = Buffer.from(JSON.stringify({
code: 99991672,
msg: 'missing required tenant scope',
}));
providerError.response = {
status: 400,
data: Readable.from([body.subarray(0, 9), body.subarray(9)]),
};
const message = extractInboundMessage({
message: {
message_id: 'om_permission',
message_type: 'image',
content: JSON.stringify({ image_key: 'img_permission' }),
},
}, { im: { v1: { messageResource: { get: async () => { throw providerError; } } } } });
await assert.rejects(message.images[0].load({ maxBytes: 1024 }), (error) => {
assert.equal(error.code, 'feishu-image-permission-required');
assert.match(error.userMessage, /im:message:readonly/);
assert.match(error.userMessage, /发布新版本/);
assert.equal(error.cause, providerError);
return true;
});
});
test('Feishu image loading leaves unrelated provider failures on the generic path', async () => {
const providerError = new Error('Request failed with status code 400');
providerError.response = {
status: 400,
data: Readable.from([Buffer.from(JSON.stringify({ code: 99991400 }))]),
};
const message = extractInboundMessage({
message: {
message_id: 'om_other_error',
message_type: 'image',
content: JSON.stringify({ image_key: 'img_other_error' }),
},
}, { im: { v1: { messageResource: { get: async () => { throw providerError; } } } } });
await assert.rejects(
message.images[0].load({ maxBytes: 1024 }),
(error) => error === providerError,
);
});
test('malformed Feishu image content does not create a downloadable image reference', () => {
assert.deepEqual(extractInboundMessage({
message: { message_type: 'image', content: '{not-json' },