fix:sql表名整理

This commit is contained in:
waner 2026-05-15 17:10:03 +08:00
parent 8fa76cd99e
commit 1225cf04ce
30 changed files with 177 additions and 422 deletions

View File

@ -3,9 +3,28 @@ set -euo pipefail
STANDARD_HOME_DIR="${STANDARD_HOME_DIR:?STANDARD_HOME_DIR is required}"
STANDARD_RUN_USER="${STANDARD_RUN_USER:?STANDARD_RUN_USER is required}"
STANDARD_JAVA_HOME="${STANDARD_JAVA_HOME:-${STANDARD_HOME_DIR}/jdk}"
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
run_as_standard_user() {
local app_dir="$1"
local script_name="$2"
sudo -n -u "${STANDARD_RUN_USER}" /bin/bash -lc '
set -euo pipefail
app_dir="$1"
script_name="$2"
java_home="$3"
cd "${app_dir}"
export JAVA_HOME="${java_home}"
export PATH="${JAVA_HOME}/bin:/usr/local/bin:/usr/bin:/bin:${PATH:-}"
exec /bin/bash "./${script_name}"
' -- "${app_dir}" "${script_name}" "${STANDARD_JAVA_HOME}"
}
"${SCRIPT_DIR}/stop_standard_apps.sh" || true
su - "${STANDARD_RUN_USER}" -s /bin/bash "${STANDARD_HOME_DIR}/cmsp/start_cmsp.sh"
su - "${STANDARD_RUN_USER}" -s /bin/bash "${STANDARD_HOME_DIR}/cmtp/start_cmtp.sh"
run_as_standard_user "${STANDARD_HOME_DIR}/cmsp" "start_cmsp.sh"
run_as_standard_user "${STANDARD_HOME_DIR}/cmtp" "start_cmtp.sh"

View File

@ -3,8 +3,27 @@ set -euo pipefail
STANDARD_HOME_DIR="${STANDARD_HOME_DIR:?STANDARD_HOME_DIR is required}"
STANDARD_RUN_USER="${STANDARD_RUN_USER:?STANDARD_RUN_USER is required}"
STANDARD_JAVA_HOME="${STANDARD_JAVA_HOME:-${STANDARD_HOME_DIR}/jdk}"
STOP_TIMEOUT_SECONDS="${STOP_TIMEOUT_SECONDS:-30}"
run_as_standard_user() {
local app_dir="$1"
local script_name="$2"
sudo -n -u "${STANDARD_RUN_USER}" /bin/bash -lc '
set -euo pipefail
app_dir="$1"
script_name="$2"
java_home="$3"
cd "${app_dir}"
export JAVA_HOME="${java_home}"
export PATH="${JAVA_HOME}/bin:/usr/local/bin:/usr/bin:/bin:${PATH:-}"
exec /bin/bash "./${script_name}"
' -- "${app_dir}" "${script_name}" "${STANDARD_JAVA_HOME}"
}
wait_until_stopped() {
local pattern="$1"
local label="$2"
@ -30,13 +49,13 @@ stop_by_pattern() {
}
if [ -x "${STANDARD_HOME_DIR}/cmsp/stop_cmsp.sh" ]; then
su - "${STANDARD_RUN_USER}" -s /bin/bash "${STANDARD_HOME_DIR}/cmsp/stop_cmsp.sh" || true
run_as_standard_user "${STANDARD_HOME_DIR}/cmsp" "stop_cmsp.sh" || true
fi
stop_by_pattern "${STANDARD_HOME_DIR}/cmsp" "CMEP-CMSP path"
stop_by_pattern "CMEP-CMSP" "CMEP-CMSP jar"
if [ -x "${STANDARD_HOME_DIR}/cmtp/stop_cmtp.sh" ]; then
su - "${STANDARD_RUN_USER}" -s /bin/bash "${STANDARD_HOME_DIR}/cmtp/stop_cmtp.sh" || true
run_as_standard_user "${STANDARD_HOME_DIR}/cmtp" "stop_cmtp.sh" || true
fi
stop_by_pattern "${STANDARD_HOME_DIR}/cmtp" "CMEP-CMTP path"
stop_by_pattern "CMEP-CMTP" "CMEP-CMTP jar"

View File

@ -120,8 +120,8 @@ public class AuthSecurityResetServiceImpl implements AuthSecurityResetService {
1,
"super-admin-full-01",
"超级管理员UKey席位一",
"Viuew8WE+qziUZwGGU0x25cUpzsTF+QvQFU0uhb+yVA=",
"init-super-admin-salt-20260325"
"u70ZBltsrr8ncTyFgBkoziqvU2PfgpBYFqeoZUz4k6Y=",
"3df85c2988a5de2b9eeaa8109639641a"
),
new SeedFullAccount(
12102L,
@ -129,8 +129,8 @@ public class AuthSecurityResetServiceImpl implements AuthSecurityResetService {
2,
"super-admin-full-02",
"超级管理员UKey席位二",
"Viuew8WE+qziUZwGGU0x25cUpzsTF+QvQFU0uhb+yVA=",
"init-super-admin-salt-20260325"
"A5GWgv2UmFc+r6O5fkdAZkuWXcF/c7B13mSivSf7vQg=",
"50de03346bb1f6afc74938acf5e88560"
),
new SeedFullAccount(
12103L,
@ -138,8 +138,8 @@ public class AuthSecurityResetServiceImpl implements AuthSecurityResetService {
1,
"key-admin-full-01",
"密钥管理员UKey席位",
"/xqmDy3A/q9X5p7XWznIPSBabQ6bxTLAPgtHQ6Be33c=",
"init-key-admin-salt-20260325"
"Lbhpr63UUBjRkRuXZKCMZhhinXXOz0LkvjiIJYcnvJs=",
"073cd5fd30701edfcf033e8f501b2b43"
),
new SeedFullAccount(
12104L,
@ -147,8 +147,8 @@ public class AuthSecurityResetServiceImpl implements AuthSecurityResetService {
1,
"audit-admin-full-01",
"审计管理员UKey席位",
"j/J1LKyUOzVEJfbbHe2dwKBKNdabRk502olk/LWIwhg=",
"init-audit-admin-salt-20260325"
"SsqLWKlWRlxmWaxxBaxy6nSXfvu7McBfmXfOYQBXKE0=",
"57e2616077bd8af5cb90fc9790f69573"
),
new SeedFullAccount(
12105L,
@ -156,8 +156,8 @@ public class AuthSecurityResetServiceImpl implements AuthSecurityResetService {
1,
"ops-admin-full-01",
"运维管理员UKey席位",
"2e9F4aCgsDb+AuD1LrBEqEg8yjy3ODo27UHtx06vj/A=",
"init-ops-admin-salt-20260325"
"k0a3X9siC6Nyj72U/BavF8XSSXAAIXGKte+y6JgkCTc=",
"a6bea7601138e90a540b39c73d53df81"
)
);
}

View File

@ -31,8 +31,6 @@ public class ResourceBackupProperties {
"tms_role_ukey_binding",
"tms_auth_full_account",
"tms_auth_session",
"tms_auth_challenge",
"tms_auth_audit_log",
"tms_resource_backup_task",
"tms_resource_restore_task"
);

View File

@ -44,7 +44,7 @@ public class ResourceUserKeyBackupCollector {
}
int collect(ZipOutputStream zipOutputStream, Map<String, Object> resourceEntry) throws IOException {
// USER_KEY 资源的来源不是文件路径而是实体证书表 t_key_entity 中已经分配过的 keyIdx
// USER_KEY 资源的来源不是文件路径而是实体证书表 tms_key_entity 中已经分配过的 keyIdx
// 每个 keyIdx 对应密码卡内的一把用户签名密钥备份包要保证这些索引在新机器恢复后仍可用
resourceEntry.put("kind", "USER_KEY");
resourceEntry.put("keyType", USER_KEY_TYPE);

View File

@ -11,7 +11,7 @@ import java.time.LocalDateTime;
@Data
@Accessors(chain = true)
@EqualsAndHashCode(callSuper = true)
@TableName("t_certificate_crl")
@TableName("tms_certificate_crl")
public class CertificateCrlEntity extends BaseEntity {
private String issuerDn;

View File

@ -11,7 +11,7 @@ import java.time.LocalDateTime;
@Data
@Accessors(chain = true)
@EqualsAndHashCode(callSuper = true)
@TableName("t_certificate_crl_import_task")
@TableName("tms_certificate_crl_import_task")
public class CertificateCrlImportTaskEntity extends BaseEntity {
private String taskId;

View File

@ -11,7 +11,7 @@ import java.time.LocalDateTime;
@Data
@Accessors(chain = true)
@EqualsAndHashCode(callSuper = true)
@TableName("t_certificate_crl_revoked")
@TableName("tms_certificate_crl_revoked")
public class CertificateCrlRevokedEntity extends BaseEntity {
private Long crlId;

View File

@ -11,7 +11,7 @@ import java.time.LocalDateTime;
@Data
@Accessors(chain = true)
@EqualsAndHashCode(callSuper = true)
@TableName("t_certificate")
@TableName("tms_certificate")
public class CertificateEntity extends BaseEntity {
private Long entityId;

View File

@ -9,7 +9,7 @@ import lombok.experimental.Accessors;
@Data
@Accessors(chain = true)
@EqualsAndHashCode(callSuper = true)
@TableName("t_key_entity")
@TableName("tms_key_entity")
public class KeyEntity extends BaseEntity {
private String orgCode;

View File

@ -11,7 +11,7 @@ import java.time.LocalDateTime;
@Data
@Accessors(chain = true)
@EqualsAndHashCode(callSuper = true)
@TableName("t_trusted_cert")
@TableName("tms_trusted_cert")
public class TrustedCertEntity extends BaseEntity {
private String alias;

View File

@ -77,7 +77,7 @@ public class CertificateRepositoryImpl implements CertificateRepository {
LambdaQueryWrapper<CertificateEntity> wrapper = new LambdaQueryWrapper<>();
if (StringUtils.hasText(request.getOrgCode())) {
wrapper.apply(
"entity_id IN (SELECT id FROM t_key_entity WHERE org_code LIKE CONCAT('%', {0}, '%'))",
"entity_id IN (SELECT id FROM tms_key_entity WHERE org_code LIKE CONCAT('%', {0}, '%'))",
request.getOrgCode()
);
}

View File

@ -183,6 +183,6 @@ public class CrlRepositoryImpl implements CrlRepository {
.eq(CertificateCrlRevokedEntity::getIssuerDn, issuerDn)
.eq(CertificateCrlRevokedEntity::getSerialNumber, serialNumber)
// 吊销状态只来自仍在有效期内的 CRL过期或缺失 nextUpdate CRL 不能继续影响运行态
.apply("EXISTS (SELECT 1 FROM t_certificate_crl c WHERE c.id = crl_id AND c.next_update >= NOW())");
.apply("EXISTS (SELECT 1 FROM tms_certificate_crl c WHERE c.id = crl_id AND c.next_update >= NOW())");
}
}

View File

@ -4,7 +4,7 @@ import com.baomidou.mybatisplus.annotation.TableName;
import com.cisd.tms.infrastructure.persistence.entity.BaseEntity;
import java.time.LocalDateTime;
@TableName("t_upgrade_task")
@TableName("tms_upgrade_task")
public class UpgradeTaskEntity extends BaseEntity {
private String taskId;

View File

@ -178,11 +178,12 @@ ON DUPLICATE KEY UPDATE
-- 升级任务
-- -----------------------------------------------------------------------------
CREATE TABLE IF NOT EXISTS t_upgrade_task (
CREATE TABLE IF NOT EXISTS tms_upgrade_task (
id BIGINT PRIMARY KEY,
task_id VARCHAR(64) NOT NULL,
upgrade_mode VARCHAR(16) NOT NULL,
target_component VARCHAR(32) NOT NULL,
task_type VARCHAR(32) NOT NULL,
product_type VARCHAR(16) NULL,
package_file_id VARCHAR(64) NOT NULL,
package_name VARCHAR(255) NOT NULL,
package_hash VARCHAR(128) NOT NULL,
@ -199,10 +200,10 @@ CREATE TABLE IF NOT EXISTS t_upgrade_task (
finished_at DATETIME(3) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
UNIQUE KEY uk_t_upgrade_task_task_id (task_id),
KEY idx_t_upgrade_task_status (status),
KEY idx_t_upgrade_task_component (target_component),
KEY idx_t_upgrade_task_create_time (create_time)
UNIQUE KEY uk_tms_upgrade_task_task_id (task_id),
KEY idx_tms_upgrade_task_status (status),
KEY idx_tms_upgrade_task_task_type (task_type),
KEY idx_tms_upgrade_task_create_time (create_time)
);
-- -----------------------------------------------------------------------------
@ -276,33 +277,6 @@ CREATE TABLE IF NOT EXISTS tms_auth_session (
KEY idx_tms_auth_session_role_code (role_code)
);
CREATE TABLE IF NOT EXISTS tms_auth_challenge (
id BIGINT PRIMARY KEY,
challenge_id VARCHAR(128) NOT NULL,
role_code VARCHAR(64) NOT NULL,
purpose VARCHAR(32) NOT NULL,
nonce VARCHAR(256) NOT NULL,
expires_at DATETIME(3) NOT NULL,
used TINYINT(1) NOT NULL DEFAULT 0,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
UNIQUE KEY uk_tms_auth_challenge_challenge_id (challenge_id)
);
CREATE TABLE IF NOT EXISTS tms_auth_audit_log (
id BIGINT PRIMARY KEY,
event_type VARCHAR(64) NOT NULL,
role_code VARCHAR(64) NULL,
operator_role_code VARCHAR(64) NULL,
result VARCHAR(32) NOT NULL,
detail_json JSON NULL,
remote_ip VARCHAR(64) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
KEY idx_tms_auth_audit_log_event_type (event_type),
KEY idx_tms_auth_audit_log_role_code (role_code)
);
-- -----------------------------------------------------------------------------
-- 防重放与安全事件
-- -----------------------------------------------------------------------------
@ -414,8 +388,8 @@ VALUES
1,
'super-admin-full-01',
'超级管理员UKey席位一',
'Viuew8WE+qziUZwGGU0x25cUpzsTF+QvQFU0uhb+yVA=',
'init-super-admin-salt-20260325',
'u70ZBltsrr8ncTyFgBkoziqvU2PfgpBYFqeoZUz4k6Y=',
'3df85c2988a5de2b9eeaa8109639641a',
'ACTIVE',
1,
CURRENT_TIMESTAMP(3),
@ -432,8 +406,8 @@ VALUES
2,
'super-admin-full-02',
'超级管理员UKey席位二',
'Viuew8WE+qziUZwGGU0x25cUpzsTF+QvQFU0uhb+yVA=',
'init-super-admin-salt-20260325',
'A5GWgv2UmFc+r6O5fkdAZkuWXcF/c7B13mSivSf7vQg=',
'50de03346bb1f6afc74938acf5e88560',
'ACTIVE',
1,
CURRENT_TIMESTAMP(3),
@ -450,8 +424,8 @@ VALUES
1,
'key-admin-full-01',
'密钥管理员UKey席位',
'/xqmDy3A/q9X5p7XWznIPSBabQ6bxTLAPgtHQ6Be33c=',
'init-key-admin-salt-20260325',
'Lbhpr63UUBjRkRuXZKCMZhhinXXOz0LkvjiIJYcnvJs=',
'073cd5fd30701edfcf033e8f501b2b43',
'ACTIVE',
1,
CURRENT_TIMESTAMP(3),
@ -468,8 +442,8 @@ VALUES
1,
'audit-admin-full-01',
'审计管理员UKey席位',
'j/J1LKyUOzVEJfbbHe2dwKBKNdabRk502olk/LWIwhg=',
'init-audit-admin-salt-20260325',
'SsqLWKlWRlxmWaxxBaxy6nSXfvu7McBfmXfOYQBXKE0=',
'57e2616077bd8af5cb90fc9790f69573',
'ACTIVE',
1,
CURRENT_TIMESTAMP(3),
@ -486,8 +460,8 @@ VALUES
1,
'ops-admin-full-01',
'运维管理员UKey席位',
'2e9F4aCgsDb+AuD1LrBEqEg8yjy3ODo27UHtx06vj/A=',
'init-ops-admin-salt-20260325',
'k0a3X9siC6Nyj72U/BavF8XSSXAAIXGKte+y6JgkCTc=',
'a6bea7601138e90a540b39c73d53df81',
'ACTIVE',
1,
CURRENT_TIMESTAMP(3),
@ -515,7 +489,7 @@ CREATE TABLE IF NOT EXISTS tms_access_whitelist (
-- -----------------------------------------------------------------------------
-- Cert module tables
-- -----------------------------------------------------------------------------
CREATE TABLE IF NOT EXISTS t_key_entity (
CREATE TABLE IF NOT EXISTS tms_key_entity (
id BIGINT PRIMARY KEY,
org_code VARCHAR(64) NOT NULL COMMENT 'organization code',
org_name VARCHAR(255) NOT NULL COMMENT 'organization name',
@ -533,14 +507,14 @@ CREATE TABLE IF NOT EXISTS t_key_entity (
create_by VARCHAR(64) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
UNIQUE KEY uk_t_key_entity_key_idx (key_idx),
KEY idx_t_key_entity_org_code (org_code),
KEY idx_t_key_entity_algo (algo_type),
KEY idx_t_key_entity_status (status),
KEY idx_t_key_entity_create_time (create_time)
UNIQUE KEY uk_tms_key_entity_key_idx (key_idx),
KEY idx_tms_key_entity_org_code (org_code),
KEY idx_tms_key_entity_algo (algo_type),
KEY idx_tms_key_entity_status (status),
KEY idx_tms_key_entity_create_time (create_time)
);
CREATE TABLE IF NOT EXISTS t_certificate (
CREATE TABLE IF NOT EXISTS tms_certificate (
id BIGINT PRIMARY KEY,
entity_id BIGINT NULL COMMENT 'required when cert_type=ENTITY',
cert_type VARCHAR(16) NOT NULL COMMENT 'ENTITY / USER',
@ -557,15 +531,15 @@ CREATE TABLE IF NOT EXISTS t_certificate (
create_by VARCHAR(64) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
UNIQUE KEY uk_t_certificate_fingerprint (fingerprint),
KEY idx_t_certificate_entity_id (entity_id),
KEY idx_t_certificate_cert_type (cert_type),
KEY idx_t_certificate_issuer_dn (issuer_dn(512)),
KEY idx_t_certificate_valid_to (valid_to),
KEY idx_t_certificate_import_time (import_time)
UNIQUE KEY uk_tms_certificate_fingerprint (fingerprint),
KEY idx_tms_certificate_entity_id (entity_id),
KEY idx_tms_certificate_cert_type (cert_type),
KEY idx_tms_certificate_issuer_dn (issuer_dn(512)),
KEY idx_tms_certificate_valid_to (valid_to),
KEY idx_tms_certificate_import_time (import_time)
);
CREATE TABLE IF NOT EXISTS t_trusted_cert (
CREATE TABLE IF NOT EXISTS tms_trusted_cert (
id BIGINT PRIMARY KEY,
alias VARCHAR(128) NULL,
subject_dn VARCHAR(1024) NOT NULL,
@ -582,13 +556,13 @@ CREATE TABLE IF NOT EXISTS t_trusted_cert (
create_by VARCHAR(64) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
UNIQUE KEY uk_t_trusted_cert_fingerprint (fingerprint),
KEY idx_t_trusted_cert_subject_dn (subject_dn(512)),
KEY idx_t_trusted_cert_issuer_dn (issuer_dn(512)),
KEY idx_t_trusted_cert_valid_to (valid_to)
UNIQUE KEY uk_tms_trusted_cert_fingerprint (fingerprint),
KEY idx_tms_trusted_cert_subject_dn (subject_dn(512)),
KEY idx_tms_trusted_cert_issuer_dn (issuer_dn(512)),
KEY idx_tms_trusted_cert_valid_to (valid_to)
);
CREATE TABLE IF NOT EXISTS t_certificate_crl (
CREATE TABLE IF NOT EXISTS tms_certificate_crl (
id BIGINT PRIMARY KEY,
issuer_dn VARCHAR(1024) NOT NULL,
crl_number VARCHAR(128) NULL,
@ -602,13 +576,13 @@ CREATE TABLE IF NOT EXISTS t_certificate_crl (
create_by VARCHAR(64) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
UNIQUE KEY uk_t_certificate_crl_fingerprint (fingerprint),
KEY idx_t_certificate_crl_issuer_dn (issuer_dn(512)),
KEY idx_t_certificate_crl_this_update (this_update),
KEY idx_t_certificate_crl_next_update (next_update)
UNIQUE KEY uk_tms_certificate_crl_fingerprint (fingerprint),
KEY idx_tms_certificate_crl_issuer_dn (issuer_dn(512)),
KEY idx_tms_certificate_crl_this_update (this_update),
KEY idx_tms_certificate_crl_next_update (next_update)
);
CREATE TABLE IF NOT EXISTS t_certificate_crl_revoked (
CREATE TABLE IF NOT EXISTS tms_certificate_crl_revoked (
id BIGINT PRIMARY KEY,
crl_id BIGINT NOT NULL,
issuer_dn VARCHAR(1024) NOT NULL,
@ -620,13 +594,13 @@ CREATE TABLE IF NOT EXISTS t_certificate_crl_revoked (
revocation_reason VARCHAR(64) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
KEY idx_t_certificate_crl_revoked_crl_id (crl_id),
KEY idx_t_certificate_crl_revoked_issuer_serial (issuer_dn(512), serial_number),
KEY idx_t_certificate_crl_revoked_subject_dn (subject_dn(512)),
KEY idx_t_certificate_crl_revoked_revocation_time (revocation_time)
KEY idx_tms_certificate_crl_revoked_crl_id (crl_id),
KEY idx_tms_certificate_crl_revoked_issuer_serial (issuer_dn(512), serial_number),
KEY idx_tms_certificate_crl_revoked_subject_dn (subject_dn(512)),
KEY idx_tms_certificate_crl_revoked_revocation_time (revocation_time)
);
CREATE TABLE IF NOT EXISTS t_certificate_crl_import_task (
CREATE TABLE IF NOT EXISTS tms_certificate_crl_import_task (
id BIGINT PRIMARY KEY,
task_id VARCHAR(64) NOT NULL,
original_filename VARCHAR(255) NULL,
@ -640,9 +614,9 @@ CREATE TABLE IF NOT EXISTS t_certificate_crl_import_task (
finished_at DATETIME(3) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
UNIQUE KEY uk_t_certificate_crl_import_task_task_id (task_id),
KEY idx_t_certificate_crl_import_task_status (status),
KEY idx_t_certificate_crl_import_task_create_time (create_time)
UNIQUE KEY uk_tms_certificate_crl_import_task_task_id (task_id),
KEY idx_tms_certificate_crl_import_task_status (status),
KEY idx_tms_certificate_crl_import_task_create_time (create_time)
);
@ -676,7 +650,7 @@ CREATE TABLE IF NOT EXISTS tms_operation_audit_log (
KEY idx_tms_operation_audit_log_result (operation_result),
KEY idx_tms_operation_audit_log_audit_status (audit_status),
KEY idx_tms_operation_audit_log_occurred_at (occurred_at)
);
);
@ -698,7 +672,7 @@ CREATE TABLE IF NOT EXISTS tms_log_backup_record (
UNIQUE KEY `uk_record_id` (`record_id`),
KEY `idx_create_time` (`create_time`),
KEY `idx_backup_type` (`backup_type`)
)
);
@ -713,10 +687,10 @@ CREATE TABLE IF NOT EXISTS tms_backup_config (
last_backup_time datetime DEFAULT NULL COMMENT '上次执行时间',
sign_data varchar(255) NOT NULL COMMENT '其他字段的签名值',
PRIMARY KEY (`id`)
)
);
CREATE TABLE tms_master_key_activate (
CREATE TABLE IF NOT EXISTS tms_master_key_activate (
id BIGINT PRIMARY KEY AUTO_INCREMENT,
ever_initialized BOOLEAN NOT NULL,
@ -727,7 +701,8 @@ CREATE TABLE tms_master_key_activate (
update_time DATETIME(3) NOT NULL DEFAULT CURRENT_TIMESTAMP(3) ON UPDATE CURRENT_TIMESTAMP(3)
);
INSERT INTO tms_master_key_activate (
INSERT IGNORE INTO tms_master_key_activate (
id,
ever_initialized,
activation_status
) VALUES (true,true);
) VALUES (1, true, true);

View File

@ -1,6 +0,0 @@
ALTER TABLE t_upgrade_task
ADD COLUMN product_type VARCHAR(16) NULL AFTER target_component;
UPDATE t_upgrade_task
SET product_type = 'ENTERPRISE'
WHERE product_type IS NULL OR product_type = '';

View File

@ -1,6 +0,0 @@
ALTER TABLE t_upgrade_task
CHANGE COLUMN target_component task_type VARCHAR(32) NOT NULL;
ALTER TABLE t_upgrade_task
DROP INDEX idx_t_upgrade_task_component,
ADD INDEX idx_t_upgrade_task_task_type (task_type);

View File

@ -1,19 +0,0 @@
-- 组件版本表统一使用 RECEIVER 表示标准收发器,废弃旧编码 APP。
-- 若环境中已存在 RECEIVER 行,则保留 RECEIVER 并删除旧 APP避免唯一键冲突。
DELETE FROM tms_device_software_version
WHERE component_code = 'APP'
AND EXISTS (
SELECT 1
FROM (SELECT id FROM tms_device_software_version WHERE component_code = 'RECEIVER') receiver_row
);
UPDATE tms_device_software_version
SET component_code = 'RECEIVER',
component_name = '标准收发器',
update_time = CURRENT_TIMESTAMP
WHERE component_code = 'APP';
UPDATE tms_device_software_version
SET component_name = '标准收发器',
update_time = CURRENT_TIMESTAMP
WHERE component_code = 'RECEIVER';

View File

@ -1,38 +0,0 @@
-- -----------------------------------------------------------------------------
-- Replay protection tables
-- -----------------------------------------------------------------------------
CREATE TABLE IF NOT EXISTS tms_replay_nonce (
id BIGINT PRIMARY KEY,
scope VARCHAR(32) NOT NULL COMMENT '防重放作用域OPENAPI / INTERNAL_API',
principal_id VARCHAR(128) NOT NULL COMMENT '主体标识appId / sessionToken',
nonce VARCHAR(128) NOT NULL,
request_timestamp BIGINT NOT NULL,
request_method VARCHAR(16) NULL,
request_path VARCHAR(256) NULL,
body_hash VARCHAR(128) NULL,
remote_ip VARCHAR(64) NULL,
user_agent VARCHAR(512) NULL,
expires_at DATETIME(3) NOT NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
UNIQUE KEY uk_tms_replay_nonce_scope_principal_nonce (scope, principal_id, nonce),
KEY idx_tms_replay_nonce_expires_at (expires_at),
KEY idx_tms_replay_nonce_principal_time (principal_id, create_time)
);
CREATE TABLE IF NOT EXISTS tms_security_event (
id BIGINT PRIMARY KEY,
event_type VARCHAR(64) NOT NULL,
scope VARCHAR(32) NOT NULL,
principal_id VARCHAR(128) NULL,
request_method VARCHAR(16) NULL,
request_path VARCHAR(256) NULL,
nonce VARCHAR(128) NULL,
remote_ip VARCHAR(64) NULL,
detail_json JSON NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
KEY idx_tms_security_event_event_type (event_type),
KEY idx_tms_security_event_scope_principal (scope, principal_id)
);

View File

@ -1,64 +0,0 @@
-- -----------------------------------------------------------------------------
-- Resource backup and restore tables
-- -----------------------------------------------------------------------------
CREATE TABLE IF NOT EXISTS tms_resource_backup_task (
id BIGINT PRIMARY KEY,
task_id VARCHAR(64) NOT NULL,
backup_id VARCHAR(64) NOT NULL,
status VARCHAR(32) NOT NULL,
product_type VARCHAR(16) NOT NULL,
mq_type VARCHAR(32) NULL,
org_code VARCHAR(32) NULL,
source_device_id VARCHAR(128) NULL,
package_name VARCHAR(255) NULL,
package_path VARCHAR(1024) NULL,
package_size BIGINT NULL,
package_hash VARCHAR(128) NULL,
storage_enc_key_fingerprint VARCHAR(128) NOT NULL,
authenticity_key_fingerprint VARCHAR(128) NOT NULL,
manifest_summary_json JSON NULL,
error_code VARCHAR(64) NULL,
error_message VARCHAR(1024) NULL,
remark VARCHAR(1024) NULL,
create_by VARCHAR(64) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
start_time DATETIME(3) NULL,
finish_time DATETIME(3) NULL,
UNIQUE KEY uk_tms_resource_backup_task_task_id (task_id),
UNIQUE KEY uk_tms_resource_backup_task_backup_id (backup_id),
KEY idx_tms_resource_backup_task_status (status),
KEY idx_tms_resource_backup_task_create_time (create_time)
);
CREATE TABLE IF NOT EXISTS tms_resource_restore_task (
id BIGINT PRIMARY KEY,
task_id VARCHAR(64) NOT NULL,
precheck_id VARCHAR(64) NOT NULL,
backup_id VARCHAR(64) NOT NULL,
status VARCHAR(32) NOT NULL,
source_device_id VARCHAR(128) NULL,
source_product_type VARCHAR(16) NOT NULL,
target_product_type VARCHAR(16) NOT NULL,
package_file_id VARCHAR(64) NOT NULL,
package_path VARCHAR(1024) NULL,
staging_dir VARCHAR(1024) NULL,
runner_state_path VARCHAR(1024) NULL,
storage_enc_key_fingerprint VARCHAR(128) NOT NULL,
authenticity_key_fingerprint VARCHAR(128) NOT NULL,
restore_plan_json JSON NULL,
consistency_report_json JSON NULL,
error_code VARCHAR(64) NULL,
error_message VARCHAR(1024) NULL,
remark VARCHAR(1024) NULL,
create_by VARCHAR(64) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
start_time DATETIME(3) NULL,
finish_time DATETIME(3) NULL,
UNIQUE KEY uk_tms_resource_restore_task_task_id (task_id),
UNIQUE KEY uk_tms_resource_restore_task_precheck_id (precheck_id),
KEY idx_tms_resource_restore_task_status (status),
KEY idx_tms_resource_restore_task_create_time (create_time)
);

View File

@ -1,133 +0,0 @@
-- -----------------------------------------------------------------------------
-- Cert module tables
-- -----------------------------------------------------------------------------
CREATE TABLE IF NOT EXISTS t_key_entity (
id BIGINT PRIMARY KEY,
org_code VARCHAR(64) NOT NULL COMMENT 'organization code',
org_name VARCHAR(255) NOT NULL COMMENT 'organization name',
algo_type VARCHAR(16) NOT NULL COMMENT 'SM2 / RSA',
key_len INT NOT NULL COMMENT 'SM2 fixed 256 in V1',
key_idx INT NOT NULL COMMENT 'card key index, allowed range [2..8]',
backup_data TEXT NOT NULL COMMENT 'SDFE_BackupUserKey output',
public_key VARCHAR(500) NOT NULL COMMENT 'public key, Base64/PEM',
p10_data VARCHAR(2000) NULL COMMENT 'PKCS#10 PEM content',
subject_dn VARCHAR(500) NULL COMMENT 'DN used when generating P10',
cert_mode VARCHAR(16) NULL COMMENT 'SINGLE / DOUBLE',
status VARCHAR(32) NOT NULL COMMENT 'CREATED / P10_GENERATED / CERT_IMPORTED',
allow_ips VARCHAR(500) NULL COMMENT 'allowed source IP list',
sign_data VARCHAR(512) NULL COMMENT 'reserved, not used in V1',
create_by VARCHAR(64) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
UNIQUE KEY uk_t_key_entity_key_idx (key_idx),
KEY idx_t_key_entity_org_code (org_code),
KEY idx_t_key_entity_algo (algo_type),
KEY idx_t_key_entity_status (status),
KEY idx_t_key_entity_create_time (create_time)
);
CREATE TABLE IF NOT EXISTS t_certificate (
id BIGINT PRIMARY KEY,
entity_id BIGINT NULL COMMENT 'required when cert_type=ENTITY',
cert_type VARCHAR(16) NOT NULL COMMENT 'ENTITY / USER',
subject_dn VARCHAR(500) NOT NULL,
issuer_dn VARCHAR(1024) NOT NULL,
serial_number VARCHAR(128) NOT NULL,
algo_type VARCHAR(16) NOT NULL COMMENT 'SM2 in V1',
fingerprint VARCHAR(128) NOT NULL COMMENT 'SHA-256 fingerprint',
cert_data VARCHAR(2000) NOT NULL COMMENT 'certificate PEM content',
valid_from DATETIME(3) NOT NULL,
valid_to DATETIME(3) NOT NULL,
import_time DATETIME(3) NOT NULL,
sign_data VARCHAR(512) NULL COMMENT 'reserved, not used in V1',
create_by VARCHAR(64) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
UNIQUE KEY uk_t_certificate_fingerprint (fingerprint),
KEY idx_t_certificate_entity_id (entity_id),
KEY idx_t_certificate_cert_type (cert_type),
KEY idx_t_certificate_issuer_dn (issuer_dn(512)),
KEY idx_t_certificate_valid_to (valid_to),
KEY idx_t_certificate_import_time (import_time)
);
CREATE TABLE IF NOT EXISTS t_trusted_cert (
id BIGINT PRIMARY KEY,
alias VARCHAR(128) NULL,
subject_dn VARCHAR(1024) NOT NULL,
issuer_dn VARCHAR(1024) NOT NULL,
serial_number VARCHAR(128) NOT NULL,
algo_type VARCHAR(16) NOT NULL COMMENT 'SM2 in V1',
fingerprint VARCHAR(128) NOT NULL COMMENT 'SHA-256 fingerprint',
cert_data VARCHAR(2000) NOT NULL COMMENT 'certificate PEM content',
ca_level TINYINT NOT NULL COMMENT '0:Root, 1:Intermediate',
valid_from DATETIME(3) NOT NULL,
valid_to DATETIME(3) NOT NULL,
import_time DATETIME(3) NOT NULL,
sign_data VARCHAR(512) NULL COMMENT 'reserved, not used in V1',
create_by VARCHAR(64) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
UNIQUE KEY uk_t_trusted_cert_fingerprint (fingerprint),
KEY idx_t_trusted_cert_subject_dn (subject_dn(512)),
KEY idx_t_trusted_cert_issuer_dn (issuer_dn(512)),
KEY idx_t_trusted_cert_valid_to (valid_to)
);
CREATE TABLE IF NOT EXISTS t_certificate_crl (
id BIGINT PRIMARY KEY,
issuer_dn VARCHAR(1024) NOT NULL,
crl_number VARCHAR(128) NULL,
algo_type VARCHAR(16) NOT NULL COMMENT 'SM2 in V1',
fingerprint VARCHAR(128) NOT NULL COMMENT 'SHA-256 fingerprint',
crl_data MEDIUMTEXT NOT NULL COMMENT 'reserved legacy CRL PEM content; large CRLs are not stored inline',
this_update DATETIME(3) NOT NULL,
next_update DATETIME(3) NULL,
revoked_count INT NOT NULL,
import_time DATETIME(3) NOT NULL,
create_by VARCHAR(64) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
UNIQUE KEY uk_t_certificate_crl_fingerprint (fingerprint),
KEY idx_t_certificate_crl_issuer_dn (issuer_dn(512)),
KEY idx_t_certificate_crl_this_update (this_update),
KEY idx_t_certificate_crl_next_update (next_update)
);
CREATE TABLE IF NOT EXISTS t_certificate_crl_revoked (
id BIGINT PRIMARY KEY,
crl_id BIGINT NOT NULL,
issuer_dn VARCHAR(1024) NOT NULL,
serial_number VARCHAR(128) NOT NULL,
subject_dn VARCHAR(1024) NULL,
algo_type VARCHAR(16) NOT NULL COMMENT 'SM2 in V1',
crl_number VARCHAR(128) NULL,
revocation_time DATETIME(3) NOT NULL,
revocation_reason VARCHAR(64) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
KEY idx_t_certificate_crl_revoked_crl_id (crl_id),
KEY idx_t_certificate_crl_revoked_issuer_serial (issuer_dn(512), serial_number),
KEY idx_t_certificate_crl_revoked_subject_dn (subject_dn(512)),
KEY idx_t_certificate_crl_revoked_revocation_time (revocation_time)
);
CREATE TABLE IF NOT EXISTS t_certificate_crl_import_task (
id BIGINT PRIMARY KEY,
task_id VARCHAR(64) NOT NULL,
original_filename VARCHAR(255) NULL,
file_size BIGINT NULL,
status VARCHAR(32) NOT NULL COMMENT 'PENDING/RUNNING/SUCCESS/FAILED',
fingerprint VARCHAR(128) NULL COMMENT 'SHA-256 fingerprint after successful parse',
crl_id BIGINT NULL,
revoked_count INT NOT NULL DEFAULT 0,
error_message VARCHAR(512) NULL,
started_at DATETIME(3) NULL,
finished_at DATETIME(3) NULL,
create_time DATETIME(3) NOT NULL,
update_time DATETIME(3) NOT NULL,
UNIQUE KEY uk_t_certificate_crl_import_task_task_id (task_id),
KEY idx_t_certificate_crl_import_task_status (status),
KEY idx_t_certificate_crl_import_task_create_time (create_time)
);

View File

@ -27,13 +27,13 @@
<select id="selectByTaskId" parameterType="string" resultMap="CertificateCrlImportTaskResultMap">
SELECT <include refid="CertificateCrlImportTaskColumns"/>
FROM t_certificate_crl_import_task
FROM tms_certificate_crl_import_task
WHERE task_id = #{taskId}
LIMIT 1
</select>
<update id="updateRunning">
UPDATE t_certificate_crl_import_task
UPDATE tms_certificate_crl_import_task
SET status = 'RUNNING',
error_message = NULL,
started_at = #{startedAt},
@ -42,7 +42,7 @@
</update>
<update id="updateSuccess">
UPDATE t_certificate_crl_import_task
UPDATE tms_certificate_crl_import_task
SET status = 'SUCCESS',
crl_id = #{crlId},
fingerprint = #{fingerprint},
@ -54,7 +54,7 @@
</update>
<update id="updateFailed">
UPDATE t_certificate_crl_import_task
UPDATE tms_certificate_crl_import_task
SET status = 'FAILED',
error_message = #{errorMessage},
finished_at = #{finishedAt},

View File

@ -5,7 +5,7 @@
<mapper namespace="com.cisd.tms.modules.cert.mapper.CertificateCrlRevokedEntityMapper">
<insert id="insertBatch">
INSERT INTO t_certificate_crl_revoked (
INSERT INTO tms_certificate_crl_revoked (
id, crl_id, issuer_dn, serial_number, subject_dn, algo_type, crl_number,
revocation_time, revocation_reason, create_time, update_time
)

View File

@ -36,14 +36,14 @@
<select id="selectByTaskId" parameterType="string" resultMap="UpgradeTaskResultMap">
SELECT <include refid="UpgradeTaskColumns"/>
FROM t_upgrade_task
FROM tms_upgrade_task
WHERE task_id = #{taskId}
LIMIT 1
</select>
<select id="selectRunningTask" resultMap="UpgradeTaskResultMap">
SELECT <include refid="UpgradeTaskColumns"/>
FROM t_upgrade_task
FROM tms_upgrade_task
WHERE status = 'RUNNING'
ORDER BY create_time DESC, id DESC
LIMIT 1
@ -51,7 +51,7 @@
<select id="selectPage" resultMap="UpgradeTaskResultMap">
SELECT <include refid="UpgradeTaskColumns"/>
FROM t_upgrade_task
FROM tms_upgrade_task
<where>
<if test="taskType != null and taskType != ''">
AND task_type = #{taskType}
@ -72,7 +72,7 @@
<select id="countPage" resultType="long">
SELECT COUNT(1)
FROM t_upgrade_task
FROM tms_upgrade_task
<where>
<if test="taskType != null and taskType != ''">
AND task_type = #{taskType}
@ -90,7 +90,7 @@
</select>
<update id="updateStatusByTaskId">
UPDATE t_upgrade_task
UPDATE tms_upgrade_task
SET status = #{status},
error_message = #{errorMessage},
detail_log_path = #{detailLogPath},

View File

@ -1,6 +1,8 @@
package com.cisd.tms;
import java.nio.charset.StandardCharsets;
import java.util.regex.Matcher;
import java.util.regex.Pattern;
import org.junit.jupiter.api.Test;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.test.context.SpringBootTest;
@ -17,6 +19,11 @@ import static org.springframework.test.web.servlet.result.MockMvcResultMatchers.
@AutoConfigureMockMvc
class TmsApplicationTests {
private static final Pattern AUTH_FULL_ACCOUNT_ROW = Pattern.compile(
"\\(\\s*1210[1-5],.*?'([^']+)'\\s*,\\s*'([0-9a-f]{32})'",
Pattern.DOTALL
);
@Autowired
private MockMvc mockMvc;
@ -54,17 +61,12 @@ class TmsApplicationTests {
@Test
void shouldCreateAuthRoleTablesAndSeedFixedRoleAccounts() {
ClassPathResource migration = new ClassPathResource("db/migration/V1__tms_schema_full.sql");
ClassPathResource replayMigration = new ClassPathResource("db/migration/V5__add_replay_protection_tables.sql");
org.junit.jupiter.api.Assertions.assertTrue(migration.exists());
org.junit.jupiter.api.Assertions.assertTrue(replayMigration.exists());
String sql = org.junit.jupiter.api.Assertions.assertDoesNotThrow(
() -> new String(migration.getInputStream().readAllBytes(), StandardCharsets.UTF_8)
);
String replaySql = org.junit.jupiter.api.Assertions.assertDoesNotThrow(
() -> new String(replayMigration.getInputStream().readAllBytes(), StandardCharsets.UTF_8)
);
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("CREATE TABLE IF NOT EXISTS tms_role_account"));
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("CREATE TABLE IF NOT EXISTS tms_role_ukey_binding"));
@ -72,17 +74,49 @@ class TmsApplicationTests {
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("auth_method VARCHAR(32) NOT NULL"));
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("uid INT NOT NULL"));
org.junit.jupiter.api.Assertions.assertFalse(sql.contains("rid VARCHAR(64) NULL"));
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("CREATE TABLE IF NOT EXISTS tms_auth_challenge"));
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("CREATE TABLE IF NOT EXISTS tms_auth_audit_log"));
org.junit.jupiter.api.Assertions.assertFalse(sql.contains("CREATE TABLE IF NOT EXISTS tms_auth_challenge"));
org.junit.jupiter.api.Assertions.assertFalse(sql.contains("CREATE TABLE IF NOT EXISTS tms_auth_audit_log"));
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("'KEY_ADMIN'"));
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("'ACTIVE'"));
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("'UNENABLED'"));
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("CREATE TABLE IF NOT EXISTS tms_replay_nonce"));
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("CREATE TABLE IF NOT EXISTS tms_security_event"));
}
org.junit.jupiter.api.Assertions.assertTrue(replaySql.contains("CREATE TABLE IF NOT EXISTS tms_replay_nonce"));
org.junit.jupiter.api.Assertions.assertTrue(replaySql.contains("CREATE TABLE IF NOT EXISTS tms_security_event"));
org.junit.jupiter.api.Assertions.assertTrue(replaySql.contains("UNIQUE KEY uk_tms_replay_nonce_scope_principal_nonce (scope, principal_id, nonce)"));
org.junit.jupiter.api.Assertions.assertTrue(replaySql.contains("KEY idx_tms_replay_nonce_expires_at (expires_at)"));
@Test
void shouldKeepOnlyOneFullMigrationWithTmsTableNamesAndRandomDefaultPasswordSalts() throws Exception {
ClassPathResource migration = new ClassPathResource("db/migration/V1__tms_schema_full.sql");
String sql = new String(migration.getInputStream().readAllBytes(), StandardCharsets.UTF_8);
long migrationCount;
try (java.util.stream.Stream<java.nio.file.Path> paths =
java.nio.file.Files.list(java.nio.file.Path.of("src/main/resources/db/migration"))) {
migrationCount = paths
.filter(path -> path.getFileName().toString().endsWith(".sql"))
.count();
}
org.junit.jupiter.api.Assertions.assertEquals(1, migrationCount);
org.junit.jupiter.api.Assertions.assertFalse(sql.contains("CREATE TABLE IF NOT EXISTS t_"));
org.junit.jupiter.api.Assertions.assertFalse(sql.contains("FROM t_"));
org.junit.jupiter.api.Assertions.assertFalse(sql.contains("INSERT INTO t_"));
org.junit.jupiter.api.Assertions.assertFalse(sql.contains("UPDATE t_"));
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("CREATE TABLE IF NOT EXISTS tms_upgrade_task"));
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("CREATE TABLE IF NOT EXISTS tms_certificate"));
org.junit.jupiter.api.Assertions.assertTrue(sql.contains("CREATE TABLE IF NOT EXISTS tms_key_entity"));
Matcher matcher = AUTH_FULL_ACCOUNT_ROW.matcher(sql);
java.util.Set<String> salts = new java.util.HashSet<>();
com.cisd.tms.modules.auth.service.impl.Pbkdf2PasswordHasher hasher =
new com.cisd.tms.modules.auth.service.impl.Pbkdf2PasswordHasher();
int rows = 0;
while (matcher.find()) {
rows++;
String hash = matcher.group(1);
String salt = matcher.group(2);
org.junit.jupiter.api.Assertions.assertTrue(salts.add(salt), "duplicate salt: " + salt);
org.junit.jupiter.api.Assertions.assertTrue(hasher.matches("Sunyard@123", salt, hash), "hash mismatch for salt: " + salt);
}
org.junit.jupiter.api.Assertions.assertEquals(5, rows);
}
}

View File

@ -77,8 +77,8 @@ class AuthSecurityResetServiceTest {
.orElseThrow();
Assertions.assertEquals("super-admin-full-01", firstSuperAdmin.getAccountName());
Assertions.assertEquals("超级管理员UKey席位一", firstSuperAdmin.getDisplayName());
Assertions.assertEquals("init-super-admin-salt-20260325", firstSuperAdmin.getPasswordSalt());
Assertions.assertEquals("Viuew8WE+qziUZwGGU0x25cUpzsTF+QvQFU0uhb+yVA=", firstSuperAdmin.getPasswordHash());
Assertions.assertEquals("3df85c2988a5de2b9eeaa8109639641a", firstSuperAdmin.getPasswordSalt());
Assertions.assertEquals("u70ZBltsrr8ncTyFgBkoziqvU2PfgpBYFqeoZUz4k6Y=", firstSuperAdmin.getPasswordHash());
Assertions.assertEquals(RoleAccountStatus.ACTIVE.name(), firstSuperAdmin.getStatus());
Assertions.assertTrue(Boolean.TRUE.equals(firstSuperAdmin.getNeedChangePassword()));
Assertions.assertEquals(0, firstSuperAdmin.getFailedCount());

View File

@ -9,26 +9,8 @@ class ResourceTaskSchemaContractTest {
@Test
void shouldExposeResourceTaskSchemaAndEnums() throws Exception {
String v6Sql = readClasspathResource("db/migration/V6__add_resource_backup_restore_tables.sql");
String v1Sql = readClasspathResource("db/migration/V1__tms_schema_full.sql");
assertContainsAll(v6Sql,
"CREATE TABLE IF NOT EXISTS tms_resource_backup_task",
"backup_id VARCHAR(64) NOT NULL",
"package_path VARCHAR(1024) NULL",
"manifest_summary_json JSON NULL",
"error_code VARCHAR(64) NULL",
"remark VARCHAR(1024) NULL",
"CREATE TABLE IF NOT EXISTS tms_resource_restore_task",
"precheck_id VARCHAR(64) NOT NULL",
"package_file_id VARCHAR(64) NOT NULL",
"staging_dir VARCHAR(1024) NULL",
"runner_state_path VARCHAR(1024) NULL",
"source_product_type VARCHAR(16) NOT NULL",
"target_product_type VARCHAR(16) NOT NULL",
"consistency_report_json JSON NULL",
"error_code VARCHAR(64) NULL");
assertContainsAll(v1Sql,
"CREATE TABLE IF NOT EXISTS tms_resource_backup_task",
"backup_id VARCHAR(64) NOT NULL",
@ -46,7 +28,6 @@ class ResourceTaskSchemaContractTest {
"consistency_report_json JSON NULL",
"error_code VARCHAR(64) NULL");
Assertions.assertFalse(v6Sql.contains("tms_resource_task_step"));
Assertions.assertFalse(v1Sql.contains("tms_resource_task_step"));
}

View File

@ -13,16 +13,11 @@ class CertSchemaContractTest {
@Test
void certSchemaShouldAllowTrustedAliasToBeNullAndStoreLargeKeyBackupData() throws Exception {
String v1Sql = readClasspathResource("db/migration/V1__tms_schema_full.sql");
String v7Sql = readClasspathResource("db/migration/V7__add_cert_module_tables.sql");
assertFalse(v1Sql.contains("alias VARCHAR(128) NOT NULL"), v1Sql);
assertFalse(v7Sql.contains("alias VARCHAR(128) NOT NULL"), v7Sql);
assertTrue(v1Sql.contains("alias VARCHAR(128) NULL"), v1Sql);
assertTrue(v7Sql.contains("alias VARCHAR(128) NULL"), v7Sql);
assertFalse(v1Sql.contains("backup_data VARCHAR(500)"), v1Sql);
assertFalse(v7Sql.contains("backup_data VARCHAR(500)"), v7Sql);
assertTrue(v1Sql.contains("backup_data TEXT NOT NULL"), v1Sql);
assertTrue(v7Sql.contains("backup_data TEXT NOT NULL"), v7Sql);
}
private String readClasspathResource(String location) throws Exception {

View File

@ -38,7 +38,7 @@ class CertificateRepositoryImplTest {
ArgumentCaptor<LambdaQueryWrapper<CertificateEntity>> captor = ArgumentCaptor.forClass(LambdaQueryWrapper.class);
Mockito.verify(mapper).selectCount(captor.capture());
String sqlSegment = captor.getValue().getSqlSegment();
assertTrue(sqlSegment.contains("t_key_entity"), sqlSegment);
assertTrue(sqlSegment.contains("tms_key_entity"), sqlSegment);
assertTrue(sqlSegment.contains("org_code"), sqlSegment);
assertTrue(sqlSegment.contains("algo"), sqlSegment);
assertTrue(sqlSegment.contains("cert"), sqlSegment);

View File

@ -66,7 +66,7 @@ class CrlRepositoryImplTest {
ArgumentCaptor<LambdaQueryWrapper<CertificateCrlRevokedEntity>> captor = ArgumentCaptor.forClass(LambdaQueryWrapper.class);
Mockito.verify(revokedMapper).selectCount(captor.capture());
String sqlSegment = captor.getValue().getSqlSegment();
assertTrue(sqlSegment.contains("t_certificate_crl"), sqlSegment);
assertTrue(sqlSegment.contains("tms_certificate_crl"), sqlSegment);
assertTrue(sqlSegment.contains("next_update"), sqlSegment);
org.junit.jupiter.api.Assertions.assertFalse(sqlSegment.contains("IS NULL"), sqlSegment);
}