payment-callback.integration.test.ts 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332
  1. import { describe, it, expect, beforeEach, vi, afterEach } from 'vitest';
  2. import { testClient } from 'hono/testing';
  3. import {
  4. IntegrationTestDatabase,
  5. setupIntegrationDatabaseHooksWithEntities
  6. } from '@d8d/shared-test-util';
  7. import { PaymentMtRoutes } from '../../src/routes/payment.mt.routes.js';
  8. import { PaymentMtEntity } from '../../src/entities/payment.mt.entity.js';
  9. import { PaymentStatus } from '../../src/entities/payment.types.js';
  10. import { UserEntityMt } from '@d8d/user-module-mt';
  11. import { RoleMt } from '@d8d/user-module-mt';
  12. import { FileMt } from '@d8d/file-module-mt';
  13. import { OrderMt, OrderGoodsMt, OrderRefundMt } from '@d8d/orders-module-mt';
  14. import { PayStatus, PayType } from '@d8d/orders-module-mt';
  15. import { MerchantMt } from '@d8d/merchant-module-mt';
  16. import { SupplierMt } from '@d8d/supplier-module-mt';
  17. import { DeliveryAddressMt } from '@d8d/delivery-address-module-mt';
  18. import { AreaEntityMt } from '@d8d/geo-areas-mt';
  19. import { SystemConfigMt } from '@d8d/core-module-mt/system-config-module-mt/entities';
  20. import { GoodsMt, GoodsCategoryMt } from '@d8d/goods-module-mt';
  21. import { config } from 'dotenv';
  22. import { resolve } from 'path';
  23. // 导入微信支付SDK用于模拟
  24. import WxPay from 'wechatpay-node-v3';
  25. // 导入测试数据工厂
  26. import { PaymentTestFactory } from '../factories/payment-test.factory.js';
  27. // 在测试环境中加载环境变量
  28. config({ path: resolve(process.cwd(), '.env.test') });
  29. vi.mock('wechatpay-node-v3')
  30. // 设置集成测试钩子
  31. setupIntegrationDatabaseHooksWithEntities([
  32. PaymentMtEntity, UserEntityMt, FileMt, RoleMt, OrderMt, OrderGoodsMt, OrderRefundMt,
  33. MerchantMt, SupplierMt, DeliveryAddressMt, AreaEntityMt, SystemConfigMt, GoodsMt, GoodsCategoryMt
  34. ])
  35. describe('支付回调API集成测试 - 多租户版本', () => {
  36. let client: ReturnType<typeof testClient<typeof PaymentMtRoutes>>;
  37. let testFactory: PaymentTestFactory;
  38. let testData: {
  39. user: UserEntityMt;
  40. merchant: MerchantMt;
  41. supplier: SupplierMt;
  42. address: DeliveryAddressMt;
  43. order: OrderMt;
  44. payment: PaymentMtEntity;
  45. };
  46. // 使用真实的微信支付回调数据 - 直接使用原始请求体字符串
  47. const rawBody = '{"id":"495e231b-9fd8-54a1-8a30-2a38a807744c","create_time":"2025-10-25T12:48:11+08:00","resource_type":"encrypt-resource","event_type":"TRANSACTION.SUCCESS","summary":"支付成功","resource":{"original_type":"transaction","algorithm":"AEAD_AES_256_GCM","ciphertext":"tl1/8FRRn6g0gRq8IoVR8+95VuIADYBDOt6N9PKiHVhiD6l++W5g/wg6VlsCRIZJ+KWMYTaf5FzQHMjCs8o9otIkLLuJA2aZC+kCQtGxNfyVBwxool/tLT9mHd0dFGThqbj8vb/lm+jjNcmmiWHz+J1ZRvGl7mH4I714vudok7JRt5Q0u0tYaLWr76TTXuQErlA7T4KbeVeGAj8iMpu2ErCpR9QRif36Anc5ARjNYrIWfraXlmUXVbXermDyJ8r4o/4QCFfGk8L1u1WqNYASrRTQvQ8OPqj/J21OkDxbPPrOiEmAX1jOvONvIVEe9Lbkm6rdhW4aLRoZYtiusAk/Vm7MI/UYPwRZbyuc4wwdA1T1D4RdJd/m2I4KSvZHQgs0DM0tLqlb0z3880XYNr8iPFnyu2r8Z8LGcXD+COm06vc7bvNWh3ODwmMrmZQkym/Y/T3X/h/4MZj7+1h2vYHqnnrsgtNPHc/2IwWC/fQlPwtSrLh6iUxSd0betFpKLSq08CaJZvnenpDf1ORRMvd8EhTtIJJ4mV4v+VzCOYNhIcBhKp9XwsuhxIdkpGGmNPpow2c2BXY=","associated_data":"transaction","nonce":"sTnWce32BTQP"}}';
  48. const callbackHeader = {
  49. 'wechatpay-timestamp': '1761367693',
  50. 'wechatpay-nonce': 'PVDFxrQiJclkR28HpAYPDiIlS2VaGp9U',
  51. 'wechatpay-signature': 'hwR1KKN1bIPAhatIHTen7fwNDyvONS/picpcqSHtUCGkbvhYLVUqC87ksBJs6bovNI0cKNvrLr6gqp/HR4TK/ijgrD6w9W/oYc6bKyO9lNarggsQKHBv5x5yX8OjBOzqtgiHOVj44RCPrglJ5bFDlxIhnhs9jnGUine0qlvrVwBZAylt5X4oFmPammHoV4lLHtGt0L4zr5y6LoZL80LpctDCOCtwC4JdUUY5AumkMYo8lNs+xK0NAN7EVNKCWUzoQ1pVdBTGZWDP+b8+6gswP6JDsL3a4H4Fw3WGh4DZPskDQAe0sn85UGXO3m03OkDq3WkiCkOut4YZMuKBeCBpWA==',
  52. 'wechatpay-serial': '6C2C991E621267BFA5BFD5F32476427343A0B2AD'
  53. };
  54. beforeEach(async () => {
  55. // 创建测试客户端
  56. client = testClient(PaymentMtRoutes);
  57. // 创建测试数据工厂
  58. const dataSource = await IntegrationTestDatabase.getDataSource();
  59. testFactory = new PaymentTestFactory(dataSource);
  60. // 创建完整的测试数据
  61. testData = await testFactory.createCompleteTestData(1);
  62. // 设置微信支付SDK的全局mock
  63. const mockWxPay = {
  64. transactions_jsapi: vi.fn().mockResolvedValue({
  65. package: 'prepay_id=wx_test_prepay_id_123456',
  66. timeStamp: Math.floor(Date.now() / 1000).toString(),
  67. nonceStr: 'test_nonce_string',
  68. signType: 'RSA',
  69. paySign: 'test_pay_sign'
  70. }),
  71. verifySign: vi.fn().mockResolvedValue(true),
  72. decipher_gcm: vi.fn().mockReturnValue(JSON.stringify({
  73. out_trade_no: testData.payment.outTradeNo, // 使用数据库中保存的 outTradeNo
  74. trade_state: 'SUCCESS',
  75. transaction_id: 'test_transaction_id',
  76. amount: {
  77. total: 1
  78. }
  79. })),
  80. getSignature: vi.fn().mockReturnValue('mock_signature')
  81. };
  82. // 模拟PaymentService的wxPay实例
  83. vi.mocked(WxPay).mockImplementation(() => mockWxPay as any);
  84. });
  85. afterEach(() => {
  86. // 清理 mock
  87. vi.mocked(WxPay).mockClear();
  88. });
  89. describe('POST /payment/callback - 支付回调', () => {
  90. it('应该成功处理支付成功回调并更新订单状态', async () => {
  91. const response = await client.payment.callback.$post({
  92. // 使用空的json参数,通过init传递原始请求体
  93. json: {}
  94. }, {
  95. headers: callbackHeader,
  96. init: {
  97. body: rawBody
  98. }
  99. });
  100. // 现在支付记录存在,回调处理应该成功
  101. expect(response.status).toBe(200);
  102. if (response.status === 200) {
  103. const result = await response.text();
  104. expect(result).toBe('SUCCESS');
  105. // 验证订单状态已更新为已支付 (2),支付类型为微信支付 (4)
  106. const dataSource = await IntegrationTestDatabase.getDataSource();
  107. const orderRepository = dataSource.getRepository(OrderMt);
  108. const updatedOrder = await orderRepository.findOne({
  109. where: { id: testData.order.id, tenantId: 1 }
  110. });
  111. expect(updatedOrder).toBeDefined();
  112. expect(updatedOrder?.payState).toBe(PayStatus.SUCCESS); // 已支付
  113. expect(updatedOrder?.payType).toBe(PayType.WECHAT); // 微信支付
  114. }
  115. });
  116. it('应该处理支付失败回调并更新订单状态', async () => {
  117. // 模拟支付失败的回调数据
  118. const mockWxPay = {
  119. verifySign: vi.fn().mockResolvedValue(true),
  120. decipher_gcm: vi.fn().mockReturnValue(JSON.stringify({
  121. out_trade_no: testData.payment.outTradeNo,
  122. trade_state: 'FAIL',
  123. transaction_id: null,
  124. amount: {
  125. total: 1
  126. }
  127. }))
  128. };
  129. vi.mocked(WxPay).mockImplementation(() => mockWxPay as any);
  130. const response = await client.payment.callback.$post({
  131. json: {}
  132. }, {
  133. headers: callbackHeader,
  134. init: {
  135. body: rawBody
  136. }
  137. });
  138. expect(response.status).toBe(200);
  139. if (response.status === 200) {
  140. const result = await response.text();
  141. expect(result).toBe('SUCCESS');
  142. // 验证订单状态已更新为支付失败 (4),支付类型为微信支付 (4)
  143. const dataSource = await IntegrationTestDatabase.getDataSource();
  144. const orderRepository = dataSource.getRepository(OrderMt);
  145. const updatedOrder = await orderRepository.findOne({
  146. where: { id: testData.order.id, tenantId: 1 }
  147. });
  148. expect(updatedOrder).toBeDefined();
  149. expect(updatedOrder?.payState).toBe(PayStatus.FAILED); // 支付失败
  150. expect(updatedOrder?.payType).toBe(PayType.WECHAT); // 微信支付
  151. }
  152. });
  153. it('应该处理退款回调并更新订单状态', async () => {
  154. // 模拟退款回调数据
  155. const mockWxPay = {
  156. verifySign: vi.fn().mockResolvedValue(true),
  157. decipher_gcm: vi.fn().mockReturnValue(JSON.stringify({
  158. out_trade_no: testData.payment.outTradeNo,
  159. trade_state: 'REFUND',
  160. transaction_id: 'test_refund_transaction_id',
  161. amount: {
  162. total: 1
  163. }
  164. }))
  165. };
  166. vi.mocked(WxPay).mockImplementation(() => mockWxPay as any);
  167. const response = await client.payment.callback.$post({
  168. json: {}
  169. }, {
  170. headers: callbackHeader,
  171. init: {
  172. body: rawBody
  173. }
  174. });
  175. expect(response.status).toBe(200);
  176. if (response.status === 200) {
  177. const result = await response.text();
  178. expect(result).toBe('SUCCESS');
  179. // 验证订单状态已更新为已退款 (3)
  180. const dataSource = await IntegrationTestDatabase.getDataSource();
  181. const orderRepository = dataSource.getRepository(OrderMt);
  182. const updatedOrder = await orderRepository.findOne({
  183. where: { id: testData.order.id, tenantId: 1 }
  184. });
  185. expect(updatedOrder).toBeDefined();
  186. expect(updatedOrder?.payState).toBe(PayStatus.REFUNDED); // 已退款
  187. expect(updatedOrder?.payType).toBe(PayType.WECHAT); // 微信支付
  188. }
  189. });
  190. it('应该验证多租户数据隔离', async () => {
  191. // 创建第二个租户的测试数据
  192. const multiTenantData = await testFactory.createMultiTenantTestData();
  193. const tenant1Data = multiTenantData.tenant1;
  194. const tenant2Data = multiTenantData.tenant2;
  195. // 为租户1创建特定的回调数据,使用租户1支付记录的outTradeNo
  196. const tenant1RawBody = JSON.stringify({
  197. "id": "495e231b-9fd8-54a1-8a30-2a38a807744c",
  198. "create_time": "2025-10-25T12:48:11+08:00",
  199. "resource_type": "encrypt-resource",
  200. "event_type": "TRANSACTION.SUCCESS",
  201. "summary": "支付成功",
  202. "resource": {
  203. "original_type": "transaction",
  204. "algorithm": "AEAD_AES_256_GCM",
  205. "ciphertext": "tl1/8FRRn6g0gRq8IoVR8+95VuIADYBDOt6N9PKiHVhiD6l++W5g/wg6VlsCRIZJ+KWMYTaf5FzQHMjCs8o9otIkLLuJA2aZC+kCQtGxNfyVBwxool/tLT9mHd0dFGThqbj8vb/lm+jjNcmmiWHz+J1ZRvGl7mH4I714vudok7JRt5Q0u0tYaLWr76TTXuQErlA7T4KbeVeGAj8iMpu2ErCpR9QRif36Anc5ARjNYrIWfraXlmUXVbXermDyJ8r4o/4QCFfGk8L1u1WqNYASrRTQvQ8OPqj/J21OkDxbPPrOiEmAX1jOvONvIVEe9Lbkm6rdhW4aLRoZYtiusAk/Vm7MI/UYPwRZbyuc4wwdA1T1D4RdJd/m2I4KSvZHQgs0DM0tLqlb0z3880XYNr8iPFnyu2r8Z8LGcXD+COm06vc7bvNWh3ODwmMrmZQkym/Y/T3X/h/4MZj7+1h2vYHqnnrsgtNPHc/2IwWC/fQlPwtSrLh6iUxSd0betFpKLSq08CaJZvnenpDf1ORRMvd8EhTtIJJ4mV4v+VzCOYNhIcBhKp9XwsuhxIdkpGGmNPpow2c2BXY=",
  206. "associated_data": "transaction",
  207. "nonce": "sTnWce32BTQP"
  208. }
  209. });
  210. // 模拟微信支付SDK解密,返回租户1的商户订单号
  211. const mockWxPay = {
  212. verifySign: vi.fn().mockResolvedValue(true),
  213. decipher_gcm: vi.fn().mockReturnValue(JSON.stringify({
  214. out_trade_no: tenant1Data.payment.outTradeNo, // 使用租户1的支付记录outTradeNo
  215. trade_state: 'SUCCESS',
  216. transaction_id: 'test_transaction_id',
  217. amount: {
  218. total: 1
  219. }
  220. }))
  221. };
  222. vi.mocked(WxPay).mockImplementation(() => mockWxPay as any);
  223. // 处理租户1的支付回调
  224. const response = await client.payment.callback.$post({
  225. json: {}
  226. }, {
  227. headers: callbackHeader,
  228. init: {
  229. body: tenant1RawBody
  230. }
  231. });
  232. expect(response.status).toBe(200);
  233. // 验证租户1的订单状态已更新
  234. const dataSource = await IntegrationTestDatabase.getDataSource();
  235. const orderRepository = dataSource.getRepository(OrderMt);
  236. const updatedOrder1 = await orderRepository.findOne({
  237. where: { id: tenant1Data.order.id, tenantId: 1 }
  238. });
  239. expect(updatedOrder1?.payState).toBe(PayStatus.SUCCESS); // 已支付
  240. expect(updatedOrder1?.payType).toBe(PayType.WECHAT); // 微信支付
  241. // 验证租户2的订单状态未受影响
  242. const updatedOrder2 = await orderRepository.findOne({
  243. where: { id: tenant2Data.order.id, tenantId: 2 }
  244. });
  245. expect(updatedOrder2?.payState).toBe(PayStatus.UNPAID); // 仍为未支付
  246. expect(updatedOrder2?.payType).toBe(0); // 支付类型未设置
  247. });
  248. it('应该处理无效的回调数据格式', async () => {
  249. const response = await client.payment.callback.$post({
  250. body: 'invalid json data'
  251. }, {
  252. headers: {
  253. ...callbackHeader,
  254. 'content-type': 'text/plain'
  255. }
  256. });
  257. // 由于JSON解析失败,应该返回500错误
  258. expect(response.status).toBe(500);
  259. });
  260. it('应该处理缺少必要头信息的情况', async () => {
  261. const response = await client.payment.callback.$post({
  262. body: rawBody
  263. }, {
  264. headers: {
  265. // 缺少必要的微信支付头信息
  266. 'Content-Type': 'text/plain'
  267. }
  268. });
  269. // 由于缺少必要头信息,应该返回500错误
  270. expect(response.status).toBe(500);
  271. });
  272. it('应该验证回调数据解密后的支付处理', async () => {
  273. const response = await client.payment.callback.$post({
  274. // 使用空的json参数,通过init传递原始请求体
  275. json: {}
  276. }, {
  277. headers: callbackHeader,
  278. init: {
  279. body: rawBody
  280. }
  281. });
  282. // 现在支付记录存在,回调处理应该成功
  283. expect(response.status).toBe(200);
  284. if (response.status === 200) {
  285. const result = await response.text();
  286. expect(result).toBe('SUCCESS');
  287. }
  288. });
  289. });
  290. });