2
0

payment-callback.integration.test.ts 7.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182
  1. import { describe, it, expect, beforeEach, vi, afterEach } from 'vitest';
  2. import { testClient } from 'hono/testing';
  3. import {
  4. IntegrationTestDatabase,
  5. setupIntegrationDatabaseHooksWithEntities
  6. } from '@d8d/shared-test-util';
  7. import { PaymentRoutes } from '../../src/routes/payment.routes.js';
  8. import { PaymentEntity } from '../../src/entities/payment.entity.js';
  9. import { PaymentStatus } from '../../src/entities/payment.types.js';
  10. import { UserEntity } from '@d8d/user-module';
  11. import { Role } from '@d8d/user-module';
  12. import { File } from '@d8d/file-module';
  13. import { PaymentService } from '../../src/services/payment.service.js';
  14. import { config } from 'dotenv';
  15. import { resolve } from 'path';
  16. // 在测试环境中加载环境变量
  17. config({ path: resolve(process.cwd(), '.env.test') });
  18. // 设置集成测试钩子
  19. setupIntegrationDatabaseHooksWithEntities([PaymentEntity, UserEntity, File, Role])
  20. describe('支付回调API集成测试', () => {
  21. let client: ReturnType<typeof testClient<typeof PaymentRoutes>>;
  22. let testUser: UserEntity;
  23. let testPayment: PaymentEntity;
  24. let verifySignSpy: any;
  25. // 使用真实的微信支付回调数据 - 直接使用原始请求体字符串
  26. const rawBody = '{"id":"495e231b-9fd8-54a1-8a30-2a38a807744c","create_time":"2025-10-25T12:48:11+08:00","resource_type":"encrypt-resource","event_type":"TRANSACTION.SUCCESS","summary":"支付成功","resource":{"original_type":"transaction","algorithm":"AEAD_AES_256_GCM","ciphertext":"tl1/8FRRn6g0gRq8IoVR8+95VuIADYBDOt6N9PKiHVhiD6l++W5g/wg6VlsCRIZJ+KWMYTaf5FzQHMjCs8o9otIkLLuJA2aZC+kCQtGxNfyVBwxool/tLT9mHd0dFGThqbj8vb/lm+jjNcmmiWHz+J1ZRvGl7mH4I714vudok7JRt5Q0u0tYaLWr76TTXuQErlA7T4KbeVeGAj8iMpu2ErCpR9QRif36Anc5ARjNYrIWfraXlmUXVbXermDyJ8r4o/4QCFfGk8L1u1WqNYASrRTQvQ8OPqj/J21OkDxbPPrOiEmAX1jOvONvIVEe9Lbkm6rdhW4aLRoZYtiusAk/Vm7MI/UYPwRZbyuc4wwdA1T1D4RdJd/m2I4KSvZHQgs0DM0tLqlb0z3880XYNr8iPFnyu2r8Z8LGcXD+COm06vc7bvNWh3ODwmMrmZQkym/Y/T3X/h/4MZj7+1h2vYHqnnrsgtNPHc/2IwWC/fQlPwtSrLh6iUxSd0betFpKLSq08CaJZvnenpDf1ORRMvd8EhTtIJJ4mV4v+VzCOYNhIcBhKp9XwsuhxIdkpGGmNPpow2c2BXY=","associated_data":"transaction","nonce":"sTnWce32BTQP"}}';
  27. const callbackHeader = {
  28. 'wechatpay-timestamp': '1761367693',
  29. 'wechatpay-nonce': 'PVDFxrQiJclkR28HpAYPDiIlS2VaGp9U',
  30. 'wechatpay-signature': 'hwR1KKN1bIPAhatIHTen7fwNDyvONS/picpcqSHtUCGkbvhYLVUqC87ksBJs6bovNI0cKNvrLr6gqp/HR4TK/ijgrD6w9W/oYc6bKyO9lNarggsQKHBv5x5yX8OjBOzqtgiHOVj44RCPrglJ5bFDlxIhnhs9jnGUine0qlvrVwBZAylt5X4oFmPammHoV4lLHtGt0L4zr5y6LoZL80LpctDCOCtwC4JdUUY5AumkMYo8lNs+xK0NAN7EVNKCWUzoQ1pVdBTGZWDP+b8+6gswP6JDsL3a4H4Fw3WGh4DZPskDQAe0sn85UGXO3m03OkDq3WkiCkOut4YZMuKBeCBpWA==',
  31. 'wechatpay-serial': '6C2C991E621267BFA5BFD5F32476427343A0B2AD'
  32. };
  33. beforeEach(async () => {
  34. // 创建测试客户端
  35. client = testClient(PaymentRoutes);
  36. // 创建测试用户
  37. const dataSource = await IntegrationTestDatabase.getDataSource();
  38. const userRepository = dataSource.getRepository(UserEntity);
  39. testUser = userRepository.create({
  40. username: `test_user_${Date.now()}`,
  41. password: 'test_password',
  42. nickname: '测试用户',
  43. openid: 'oJy1-16IIG18XZLl7G32k1hHMUFg'
  44. });
  45. await userRepository.save(testUser);
  46. // 创建测试支付记录,使用与真实回调数据一致的金额
  47. const paymentRepository = dataSource.getRepository(PaymentEntity);
  48. testPayment = paymentRepository.create({
  49. externalOrderId: 13, // 与真实回调数据一致
  50. userId: testUser.id,
  51. totalAmount: 1, // 1分钱,与真实回调数据一致
  52. description: '测试支付',
  53. paymentStatus: PaymentStatus.PROCESSING, // 设置为处理中状态,模拟已发起支付
  54. openid: testUser.openid!,
  55. outTradeNo: `ORDER_13_${Date.now()}`
  56. });
  57. await paymentRepository.save(testPayment);
  58. // 手动更新支付记录ID为13,与真实回调数据一致
  59. await dataSource.query('UPDATE payments SET external_order_id = 13 WHERE id = $1', [testPayment.id]);
  60. // Mock PaymentService 的验签方法
  61. verifySignSpy = vi.spyOn(PaymentService.prototype as any, 'wxPay').mockImplementation(() => ({
  62. verifySign: vi.fn().mockResolvedValue(true),
  63. decipher_gcm: vi.fn().mockReturnValue(JSON.stringify({
  64. out_trade_no: `ORDER_13_${Date.now()}`,
  65. trade_state: 'SUCCESS',
  66. transaction_id: 'test_transaction_id',
  67. amount: {
  68. total: 1
  69. }
  70. }))
  71. }));
  72. });
  73. afterEach(() => {
  74. // 清理 spy
  75. if (verifySignSpy) {
  76. verifySignSpy.mockRestore();
  77. }
  78. });
  79. describe('POST /payment/callback - 支付回调', () => {
  80. it('应该成功处理支付成功回调', async () => {
  81. const response = await client.payment.callback.$post({
  82. // 使用空的json参数,通过init传递原始请求体
  83. json: {}
  84. }, {
  85. headers: callbackHeader,
  86. init: {
  87. body: rawBody
  88. }
  89. });
  90. // 现在支付记录存在,回调处理应该成功
  91. expect(response.status).toBe(200);
  92. if (response.status === 200) {
  93. const result = await response.text();
  94. expect(result).toBe('SUCCESS');
  95. }
  96. });
  97. it('应该处理支付失败回调', async () => {
  98. // 使用统一的真实回调数据
  99. const response = await client.payment.callback.$post({
  100. // 使用空的json参数,通过init传递原始请求体
  101. json: {}
  102. }, {
  103. headers: callbackHeader,
  104. init: {
  105. body: rawBody
  106. }
  107. });
  108. // 由于真实数据是支付成功的,回调处理应该成功
  109. expect(response.status).toBe(200);
  110. if (response.status === 200) {
  111. const result = await response.text();
  112. expect(result).toBe('SUCCESS');
  113. }
  114. });
  115. it('应该处理无效的回调数据格式', async () => {
  116. const response = await client.payment.callback.$post({
  117. // 使用空的json参数,通过init传递无效的JSON数据
  118. json: {}
  119. }, {
  120. headers: callbackHeader,
  121. init: {
  122. body: 'invalid json data'
  123. }
  124. });
  125. // 由于JSON解析失败,应该返回500错误
  126. expect(response.status).toBe(500);
  127. });
  128. it('应该处理缺少必要头信息的情况', async () => {
  129. const response = await client.payment.callback.$post({
  130. body: rawBody
  131. }, {
  132. headers: {
  133. // 缺少必要的微信支付头信息
  134. 'Content-Type': 'text/plain'
  135. }
  136. });
  137. // 由于缺少必要头信息,应该返回500错误
  138. expect(response.status).toBe(500);
  139. });
  140. it('应该验证回调数据解密后的支付处理', async () => {
  141. const response = await client.payment.callback.$post({
  142. // 使用空的json参数,通过init传递原始请求体
  143. json: {}
  144. }, {
  145. headers: callbackHeader,
  146. init: {
  147. body: rawBody
  148. }
  149. });
  150. // 现在支付记录存在,回调处理应该成功
  151. expect(response.status).toBe(200);
  152. if (response.status === 200) {
  153. const result = await response.text();
  154. expect(result).toBe('SUCCESS');
  155. }
  156. });
  157. });
  158. });