data-overview-routes.integration.test.ts 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384
  1. import { describe, it, expect, beforeEach } from 'vitest';
  2. import { testClient } from 'hono/testing';
  3. import { IntegrationTestDatabase, setupIntegrationDatabaseHooksWithEntities } from '@d8d/shared-test-util';
  4. import { UserEntityMt, RoleMt } from '@d8d/core-module-mt/user-module-mt/entities';
  5. import { FileMt } from '@d8d/core-module-mt/file-module-mt/entities';
  6. import { OrderMt, OrderGoodsMt } from '@d8d/orders-module-mt';
  7. import { MerchantMt } from '@d8d/merchant-module-mt';
  8. import { SupplierMt } from '@d8d/supplier-module-mt';
  9. import { DeliveryAddressMt } from '@d8d/delivery-address-module-mt';
  10. import { AreaEntityMt } from '@d8d/geo-areas-mt';
  11. import { GoodsMt, GoodsCategoryMt } from '@d8d/goods-module-mt';
  12. import dataOverviewRoutes from '../../src/routes';
  13. import { DataOverviewTestDataFactory } from '../utils/test-data-factory';
  14. // 设置集成测试钩子 - 需要User、Role、File、Order及相关实体
  15. setupIntegrationDatabaseHooksWithEntities([
  16. UserEntityMt,
  17. RoleMt,
  18. FileMt,
  19. OrderMt,
  20. OrderGoodsMt,
  21. MerchantMt,
  22. SupplierMt,
  23. DeliveryAddressMt,
  24. AreaEntityMt,
  25. GoodsMt,
  26. GoodsCategoryMt
  27. ])
  28. describe('多租户数据概览API集成测试', () => {
  29. let client: ReturnType<typeof testClient<typeof dataOverviewRoutes>>;
  30. let userToken: string;
  31. let adminToken: string;
  32. let testUser: UserEntityMt;
  33. beforeEach(async () => {
  34. // 创建测试客户端
  35. client = testClient(dataOverviewRoutes);
  36. // 获取数据源并创建测试用户
  37. const dataSource = await IntegrationTestDatabase.getDataSource();
  38. // 创建租户1的测试用户
  39. testUser = await DataOverviewTestDataFactory.createTestUser(dataSource, 1);
  40. // 生成JWT令牌
  41. userToken = DataOverviewTestDataFactory.generateUserToken(testUser);
  42. adminToken = DataOverviewTestDataFactory.generateAdminToken(1);
  43. });
  44. describe('租户数据隔离验证', () => {
  45. it('应该确保订单数据的租户隔离', async () => {
  46. const dataSource = await IntegrationTestDatabase.getDataSource();
  47. const orderRepository = dataSource.getRepository(OrderMt);
  48. // 创建租户1的订单数据
  49. await DataOverviewTestDataFactory.createTestOrders(dataSource, 1, 2);
  50. // 创建租户2的订单数据
  51. await DataOverviewTestDataFactory.createTestOrders(dataSource, 2, 3);
  52. // 验证租户1只能看到租户1的订单
  53. const tenant1Orders = await orderRepository.find({
  54. where: { tenantId: 1 }
  55. });
  56. // 验证租户2只能看到租户2的订单
  57. const tenant2Orders = await orderRepository.find({
  58. where: { tenantId: 2 }
  59. });
  60. expect(tenant1Orders).toHaveLength(2);
  61. expect(tenant1Orders[0].tenantId).toBe(1);
  62. expect(tenant2Orders).toHaveLength(3);
  63. expect(tenant2Orders[0].tenantId).toBe(2);
  64. });
  65. it('应该防止跨租户数据访问', async () => {
  66. const dataSource = await IntegrationTestDatabase.getDataSource();
  67. const orderRepository = dataSource.getRepository(OrderMt);
  68. // 创建租户1的订单
  69. const tenant1Orders = await DataOverviewTestDataFactory.createTestOrders(dataSource, 1, 1);
  70. const tenant1Order = tenant1Orders[0];
  71. // 尝试使用租户2的ID查询租户1的订单
  72. const crossTenantOrder = await orderRepository.findOne({
  73. where: {
  74. orderNo: tenant1Order.orderNo,
  75. tenantId: 2 // 错误的租户ID
  76. }
  77. });
  78. expect(crossTenantOrder).toBeNull();
  79. });
  80. it('应该在创建数据时正确设置租户ID', async () => {
  81. const dataSource = await IntegrationTestDatabase.getDataSource();
  82. const orderRepository = dataSource.getRepository(OrderMt);
  83. const tenantId = 5;
  84. const orders = await DataOverviewTestDataFactory.createTestOrders(dataSource, tenantId, 1);
  85. const order = orders[0];
  86. expect(order.tenantId).toBe(tenantId);
  87. expect(order.createdBy).toBeDefined();
  88. });
  89. });
  90. describe('GET /api/data-overview/summary', () => {
  91. it('应该返回今日数据概览统计(默认时间范围)', async () => {
  92. // 创建测试订单数据
  93. const dataSource = await IntegrationTestDatabase.getDataSource();
  94. await DataOverviewTestDataFactory.createTestOrders(dataSource, testUser.tenantId, 5);
  95. const response = await client.summary.$get({
  96. query: { year: undefined }
  97. }, {
  98. headers: {
  99. 'Authorization': `Bearer ${userToken}`
  100. }
  101. });
  102. expect(response.status).toBe(200);
  103. if (response.status === 200) {
  104. const data = await response.json();
  105. expect(data.success).toBe(true);
  106. expect(data.data).toBeDefined();
  107. expect(typeof data.data.totalSales).toBe('number');
  108. expect(typeof data.data.totalOrders).toBe('number');
  109. expect(typeof data.data.wechatSales).toBe('number');
  110. expect(typeof data.data.wechatOrders).toBe('number');
  111. expect(typeof data.data.creditSales).toBe('number');
  112. expect(typeof data.data.creditOrders).toBe('number');
  113. expect(typeof data.data.todaySales).toBe('number');
  114. expect(typeof data.data.todayOrders).toBe('number');
  115. }
  116. });
  117. it('应该支持自定义时间范围参数', async () => {
  118. const startDate = '2025-01-01T00:00:00Z';
  119. const endDate = '2025-01-31T23:59:59Z';
  120. const response = await client.summary.$get({
  121. query: {
  122. timeRange: 'custom',
  123. startDate,
  124. endDate,
  125. year: undefined
  126. }
  127. }, {
  128. headers: {
  129. 'Authorization': `Bearer ${userToken}`
  130. }
  131. });
  132. expect(response.status).toBe(200);
  133. if (response.status === 200) {
  134. const data = await response.json();
  135. expect(data.success).toBe(true);
  136. }
  137. });
  138. it('当时间范围参数无效时应该返回400错误', async () => {
  139. // 提供自定义时间范围但不提供startDate和endDate
  140. const response = await client.summary.$get({
  141. query: {
  142. timeRange: 'custom',
  143. year: undefined
  144. // 缺少startDate和endDate
  145. }
  146. }, {
  147. headers: {
  148. 'Authorization': `Bearer ${userToken}`
  149. }
  150. });
  151. expect(response.status).toBe(400);
  152. });
  153. it('当startDate晚于endDate时应该返回400错误', async () => {
  154. const response = await client.summary.$get({
  155. query: {
  156. timeRange: 'custom',
  157. startDate: '2025-01-31T00:00:00Z',
  158. endDate: '2025-01-01T00:00:00Z',
  159. year: undefined
  160. }
  161. }, {
  162. headers: {
  163. 'Authorization': `Bearer ${userToken}`
  164. }
  165. });
  166. expect(response.status).toBe(400);
  167. });
  168. it('应该验证多租户数据隔离', async () => {
  169. // 创建租户100的订单数据
  170. const dataSource = await IntegrationTestDatabase.getDataSource();
  171. const tenant100User = await DataOverviewTestDataFactory.createTestUser(dataSource, 100);
  172. const tenant100Token = DataOverviewTestDataFactory.generateUserToken(tenant100User);
  173. await DataOverviewTestDataFactory.createTestOrders(dataSource, 100, 3);
  174. // 创建租户101的用户和订单
  175. const tenant101User = await DataOverviewTestDataFactory.createTestUser(dataSource, 101);
  176. const tenant101Token = DataOverviewTestDataFactory.generateUserToken(tenant101User);
  177. await DataOverviewTestDataFactory.createTestOrders(dataSource, 101, 2);
  178. // 租户100查询应该只看到租户100的数据
  179. const response1 = await client.summary.$get({
  180. query: { year: undefined }
  181. }, {
  182. headers: {
  183. 'Authorization': `Bearer ${tenant100Token}`
  184. }
  185. });
  186. // 租户101查询应该只看到租户101的数据
  187. const response2 = await client.summary.$get({
  188. query: { year: undefined }
  189. }, {
  190. headers: {
  191. 'Authorization': `Bearer ${tenant101Token}`
  192. }
  193. });
  194. expect(response1.status).toBe(200);
  195. expect(response2.status).toBe(200);
  196. if (response1.status === 200 && response2.status === 200) {
  197. const data1 = await response1.json();
  198. const data2 = await response2.json();
  199. console.debug('租户100统计数据:', data1.data);
  200. console.debug('租户101统计数据:', data2.data);
  201. // 两个租户的统计数据应该独立
  202. expect(data1.data.totalOrders).toBe(3);
  203. expect(data2.data.totalOrders).toBe(2);
  204. }
  205. });
  206. it('应该支持缓存机制', async () => {
  207. // 第一次查询应该从数据库获取
  208. const dataSource = await IntegrationTestDatabase.getDataSource();
  209. await DataOverviewTestDataFactory.createTestOrders(dataSource, testUser.tenantId, 2);
  210. const response1 = await client.summary.$get({
  211. query: { year: undefined }
  212. }, {
  213. headers: {
  214. 'Authorization': `Bearer ${userToken}`
  215. }
  216. });
  217. expect(response1.status).toBe(200);
  218. // 第二次查询(短时间内)应该从缓存获取相同结果
  219. const response2 = await client.summary.$get({
  220. query: { year: undefined }
  221. }, {
  222. headers: {
  223. 'Authorization': `Bearer ${userToken}`
  224. }
  225. });
  226. expect(response2.status).toBe(200);
  227. if (response1.status === 200 && response2.status === 200) {
  228. const data1 = await response1.json();
  229. const data2 = await response2.json();
  230. expect(data1.data.totalOrders).toBe(data2.data.totalOrders);
  231. }
  232. });
  233. it('应该排除已取消的订单', async () => {
  234. // 创建新租户的用户和token
  235. const dataSource = await IntegrationTestDatabase.getDataSource();
  236. const tenant105User = await DataOverviewTestDataFactory.createTestUser(dataSource, 105);
  237. const tenant105Token = DataOverviewTestDataFactory.generateUserToken(tenant105User);
  238. const orderRepository = dataSource.getRepository(OrderMt);
  239. // 创建3个正常订单(支付成功,未取消)
  240. const normalOrders = await DataOverviewTestDataFactory.createTestOrders(dataSource, 105, 3);
  241. // 创建2个已取消的订单(设置cancelTime)
  242. const cancelledOrders = await DataOverviewTestDataFactory.createTestOrders(dataSource, 105, 2);
  243. for (const order of cancelledOrders) {
  244. order.cancelTime = new Date();
  245. order.cancelReason = '测试取消';
  246. await orderRepository.save(order);
  247. }
  248. const response = await client.summary.$get({
  249. query: { year: undefined }
  250. }, {
  251. headers: {
  252. 'Authorization': `Bearer ${tenant105Token}`
  253. }
  254. });
  255. expect(response.status).toBe(200);
  256. if (response.status === 200) {
  257. const data = await response.json();
  258. // 应该只统计3个正常订单,排除2个取消订单
  259. expect(data.data.totalOrders).toBe(3);
  260. expect(data.data.totalSales).toBeGreaterThan(0);
  261. // 验证支付方式分类统计也正确
  262. const totalFromPaymentTypes = data.data.wechatOrders + data.data.creditOrders;
  263. expect(totalFromPaymentTypes).toBe(3); // 3个正常订单
  264. }
  265. });
  266. });
  267. describe('GET /api/data-overview/today', () => {
  268. it('应该返回今日实时统计数据', async () => {
  269. // 创建新租户的用户和token
  270. const dataSource = await IntegrationTestDatabase.getDataSource();
  271. const tenant103User = await DataOverviewTestDataFactory.createTestUser(dataSource, 103);
  272. const tenant103Token = DataOverviewTestDataFactory.generateUserToken(tenant103User);
  273. // 创建今日订单数据
  274. await DataOverviewTestDataFactory.createTodayTestOrders(dataSource, 103, 3);
  275. const response = await client.today.$get({}, {
  276. headers: {
  277. 'Authorization': `Bearer ${tenant103Token}`
  278. }
  279. });
  280. expect(response.status).toBe(200);
  281. if (response.status === 200) {
  282. const data = await response.json();
  283. expect(data.success).toBe(true);
  284. expect(data.data).toBeDefined();
  285. expect(typeof data.data.todaySales).toBe('number');
  286. expect(typeof data.data.todayOrders).toBe('number');
  287. expect(data.data.todayOrders).toBe(3);
  288. }
  289. });
  290. it('当没有今日订单时应该返回零值', async () => {
  291. // 创建新租户的用户和token(确保没有订单)
  292. const dataSource = await IntegrationTestDatabase.getDataSource();
  293. const tenant104User = await DataOverviewTestDataFactory.createTestUser(dataSource, 104);
  294. const tenant104Token = DataOverviewTestDataFactory.generateUserToken(tenant104User);
  295. const response = await client.today.$get({}, {
  296. headers: {
  297. 'Authorization': `Bearer ${tenant104Token}`
  298. }
  299. });
  300. expect(response.status).toBe(200);
  301. if (response.status === 200) {
  302. const data = await response.json();
  303. expect(data.data.todaySales).toBe(0);
  304. expect(data.data.todayOrders).toBe(0);
  305. }
  306. });
  307. });
  308. describe('认证和授权', () => {
  309. it('当缺少认证头时应该返回401错误', async () => {
  310. const response = await client.summary.$get({
  311. query: { year: undefined }
  312. }); // 没有Authorization头
  313. expect(response.status).toBe(401);
  314. });
  315. it('当令牌无效时应该返回401错误', async () => {
  316. const response = await client.summary.$get({
  317. query: { year: undefined }
  318. }, {
  319. headers: {
  320. 'Authorization': 'Bearer invalid-token'
  321. }
  322. });
  323. expect(response.status).toBe(401);
  324. });
  325. });
  326. });