fix(housekeeping): validate grant mutations

This commit is contained in:
simoleo89
2026-06-14 17:12:58 +02:00
parent 4b81997e62
commit fe0ba3b9e9
6 changed files with 140 additions and 4 deletions
@@ -0,0 +1,53 @@
package com.eu.habbo.messages.incoming.housekeeping;
import org.junit.jupiter.api.Test;
import java.io.IOException;
import java.nio.file.Files;
import java.nio.file.Path;
import static org.junit.jupiter.api.Assertions.assertTrue;
class HousekeepingGrantMutationContractTest {
private static final Path CREDITS_SOURCE = Path.of(
"src/main/java/com/eu/habbo/messages/incoming/housekeeping/HousekeepingGiveCreditsEvent.java");
private static final Path CURRENCY_SOURCE = Path.of(
"src/main/java/com/eu/habbo/messages/incoming/housekeeping/HousekeepingGiveCurrencyEvent.java");
private static final Path GRANT_ITEM_SOURCE = Path.of(
"src/main/java/com/eu/habbo/messages/incoming/housekeeping/HousekeepingGrantItemEvent.java");
@Test
void housekeepingGrantsRejectNegativeOrOversizedAmountsServerSide() throws IOException {
String credits = Files.readString(CREDITS_SOURCE);
String currency = Files.readString(CURRENCY_SOURCE);
assertTrue(credits.contains("HousekeepingMutationGuard.isPositiveGrantAmount(amount)"),
"credit grants must only accept positive bounded amounts");
assertTrue(currency.contains("HousekeepingMutationGuard.isPositiveGrantAmount(amount)"),
"currency grants must only accept positive bounded amounts");
}
@Test
void housekeepingCurrencyGrantsRejectInvalidTypesAndMissingUsers() throws IOException {
String currency = Files.readString(CURRENCY_SOURCE);
assertTrue(currency.contains("HousekeepingMutationGuard.isCurrencyType(currencyType)"),
"currency grants must reject negative currency types");
assertTrue(currency.contains("HousekeepingMutationGuard.userExists(userId)"),
"offline currency grants must not create orphan users_currency rows");
}
@Test
void housekeepingItemGrantsRequireRealUsersAndItemsBeforeInsert() throws IOException {
String grantItem = Files.readString(GRANT_ITEM_SOURCE);
int userCheck = grantItem.indexOf("HousekeepingMutationGuard.userExists(userId)");
int itemCheck = grantItem.indexOf("HousekeepingMutationGuard.itemExists(itemId)");
int insert = grantItem.indexOf("INSERT INTO items");
assertTrue(userCheck >= 0, "item grants must check the target user exists");
assertTrue(itemCheck >= 0, "item grants must check the item base exists");
assertTrue(userCheck < insert, "target user must be validated before item insert");
assertTrue(itemCheck < insert, "item base must be validated before item insert");
}
}
@@ -0,0 +1,24 @@
package com.eu.habbo.messages.incoming.housekeeping;
import org.junit.jupiter.api.Test;
import static org.junit.jupiter.api.Assertions.assertFalse;
import static org.junit.jupiter.api.Assertions.assertTrue;
class HousekeepingMutationGuardTest {
@Test
void positiveGrantAmountsMustBeStrictlyPositiveAndBounded() {
assertFalse(HousekeepingMutationGuard.isPositiveGrantAmount(-1));
assertFalse(HousekeepingMutationGuard.isPositiveGrantAmount(0));
assertTrue(HousekeepingMutationGuard.isPositiveGrantAmount(1));
assertTrue(HousekeepingMutationGuard.isPositiveGrantAmount(HousekeepingMutationGuard.MAX_GRANT));
assertFalse(HousekeepingMutationGuard.isPositiveGrantAmount(HousekeepingMutationGuard.MAX_GRANT + 1));
}
@Test
void currencyTypesCannotBeNegative() {
assertFalse(HousekeepingMutationGuard.isCurrencyType(-1));
assertTrue(HousekeepingMutationGuard.isCurrencyType(0));
assertTrue(HousekeepingMutationGuard.isCurrencyType(101));
}
}