post.test.ts 6.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216
  1. import { describe, it, expect, beforeEach, vi } from 'vitest';
  2. import { testClient } from 'hono/testing';
  3. import {
  4. IntegrationTestDatabase,
  5. setupIntegrationDatabaseHooks,
  6. TestDataFactory
  7. } from '~/utils/server/integration-test-db';
  8. import { authRoutes } from '@d8d/server/api';
  9. import { AuthService } from '@d8d/server/modules/auth/auth.service';
  10. import { UserService } from '@d8d/server/modules/users/user.service';
  11. // 设置集成测试钩子
  12. setupIntegrationDatabaseHooks()
  13. // Mock MiniAuthService 的 decryptPhoneNumber 方法
  14. vi.mock('@d8d/server/modules/auth/mini-auth.service', () => ({
  15. MiniAuthService: vi.fn().mockImplementation(() => ({
  16. decryptPhoneNumber: vi.fn().mockImplementation(async (encryptedData: string, iv: string, sessionKey: string) => {
  17. // 模拟解密过程
  18. if (!encryptedData || !iv || !sessionKey) {
  19. throw { code: 400, message: '加密数据或初始向量不能为空' };
  20. }
  21. // 根据不同的加密数据返回不同的手机号用于测试
  22. if (encryptedData === 'valid_encrypted_data') {
  23. return '13800138000';
  24. } else if (encryptedData === 'another_valid_data') {
  25. return '13900139000';
  26. } else {
  27. throw { code: 400, message: '解密失败' };
  28. }
  29. })
  30. }))
  31. }));
  32. describe('手机号解密API集成测试', () => {
  33. let client: ReturnType<typeof testClient<typeof authRoutes>>['api']['v1'];
  34. let testToken: string;
  35. let testUser: any;
  36. beforeEach(async () => {
  37. // 创建测试客户端
  38. client = testClient(authRoutes).api.v1;
  39. // 创建测试用户并生成token
  40. const dataSource = await IntegrationTestDatabase.getDataSource();
  41. const userService = new UserService(dataSource);
  42. const authService = new AuthService(userService);
  43. // 创建测试用户
  44. testUser = await TestDataFactory.createTestUser(dataSource, {
  45. phone: null // 初始手机号为null
  46. });
  47. // 生成测试用户的token
  48. testToken = authService.generateToken(testUser);
  49. });
  50. describe('POST /auth/phone-decrypt', () => {
  51. it('应该成功解密手机号并更新用户信息', async () => {
  52. const requestData = {
  53. encryptedData: 'valid_encrypted_data',
  54. iv: 'encryption_iv'
  55. };
  56. const response = await client.auth['phone-decrypt'].$post({
  57. json: requestData
  58. },
  59. {
  60. headers: {
  61. 'Authorization': `Bearer ${testToken}`
  62. }
  63. });
  64. expect(response.status).toBe(200);
  65. if (response.status === 200) {
  66. const data = await response.json();
  67. // 验证响应数据格式
  68. expect(data).toHaveProperty('phoneNumber');
  69. expect(data).toHaveProperty('user');
  70. expect(data.phoneNumber).toBe('13800138000');
  71. expect(data.user.phone).toBe('13800138000');
  72. expect(data.user.id).toBe(testUser.id);
  73. }
  74. // 验证数据库中的用户手机号已更新
  75. const dataSource = await IntegrationTestDatabase.getDataSource();
  76. const userRepository = dataSource.getRepository('UserEntity');
  77. const updatedUser = await userRepository.findOne({
  78. where: { id: testUser.id }
  79. });
  80. expect(updatedUser?.phone).toBe('13800138000');
  81. });
  82. it('应该处理用户不存在的情况', async () => {
  83. // 创建另一个用户的token
  84. const dataSource = await IntegrationTestDatabase.getDataSource();
  85. const userService = new UserService(dataSource);
  86. const authService = new AuthService(userService);
  87. // 创建一个不存在的用户实体
  88. const nonExistentUser = await TestDataFactory.createTestUser(dataSource, {
  89. username: 'nonexistent_user',
  90. phone: null
  91. });
  92. // 删除这个用户以确保它不存在
  93. await dataSource.getRepository('UserEntity').delete({ id: nonExistentUser.id });
  94. // 使用已删除用户的ID生成token
  95. const nonExistentUserToken = authService.generateToken(nonExistentUser);
  96. const requestData = {
  97. encryptedData: 'valid_encrypted_data',
  98. iv: 'encryption_iv'
  99. };
  100. const response = await client.auth['phone-decrypt'].$post({
  101. json: requestData
  102. },
  103. {
  104. headers: {
  105. 'Authorization': `Bearer ${nonExistentUserToken}`
  106. }
  107. });
  108. // 当用户不存在时,auth中间件应该返回401
  109. expect(response.status).toBe(401);
  110. if (response.status === 401) {
  111. const data = await response.json();
  112. expect(data.message).toBe('User not found');
  113. }
  114. });
  115. it('应该处理解密失败的情况', async () => {
  116. const requestData = {
  117. encryptedData: '', // 空加密数据
  118. iv: 'encryption_iv'
  119. };
  120. const response = await client.auth['phone-decrypt'].$post({
  121. json: requestData
  122. },
  123. {
  124. headers: {
  125. 'Authorization': `Bearer ${testToken}`
  126. }
  127. });
  128. expect(response.status).toBe(400);
  129. if (response.status === 400) {
  130. const data = await response.json();
  131. expect(data.message).toBe('加密数据或初始向量不能为空');
  132. }
  133. });
  134. it('应该处理无效的加密数据', async () => {
  135. const requestData = {
  136. encryptedData: 'invalid_encrypted_data',
  137. iv: 'encryption_iv'
  138. };
  139. const response = await client.auth['phone-decrypt'].$post({
  140. json: requestData
  141. },
  142. {
  143. headers: {
  144. 'Authorization': `Bearer ${testToken}`
  145. }
  146. });
  147. expect(response.status).toBe(400);
  148. if (response.status === 400) {
  149. const data = await response.json();
  150. expect(data.message).toBe('解密失败');
  151. }
  152. });
  153. it('应该拒绝未认证用户的访问', async () => {
  154. const requestData = {
  155. encryptedData: 'valid_encrypted_data',
  156. iv: 'encryption_iv'
  157. };
  158. const response = await client.auth['phone-decrypt'].$post({
  159. json: requestData
  160. });
  161. expect(response.status).toBe(401);
  162. });
  163. it('应该拒绝无效token的访问', async () => {
  164. const requestData = {
  165. encryptedData: 'valid_encrypted_data',
  166. iv: 'encryption_iv'
  167. };
  168. const response = await client.auth['phone-decrypt'].$post({
  169. json: requestData
  170. },
  171. {
  172. headers: {
  173. 'Authorization': 'Bearer invalid_token'
  174. }
  175. });
  176. expect(response.status).toBe(401);
  177. });
  178. });
  179. });