user-routes.integration.test.ts 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567
  1. import { describe, it, expect, beforeEach, vi, afterEach } from 'vitest';
  2. import { testClient } from 'hono/testing';
  3. import { IntegrationTestDatabase, setupIntegrationDatabaseHooksWithEntities } from '@d8d/shared-test-util';
  4. import { JWTUtil } from '@d8d/shared-utils';
  5. import { UserEntity, Role } from '@d8d/user-module';
  6. import { AreaEntity, AreaLevel } from '@d8d/geo-areas';
  7. import { File } from '@d8d/file-module';
  8. import { userDeliveryAddressRoutes } from '../../src/routes';
  9. import { DeliveryAddress } from '../../src/entities';
  10. // 设置集成测试钩子
  11. setupIntegrationDatabaseHooksWithEntities([UserEntity, Role, AreaEntity, DeliveryAddress, File])
  12. describe('用户配送地址管理API集成测试', () => {
  13. let client: ReturnType<typeof testClient<typeof userDeliveryAddressRoutes>>;
  14. let userToken: string;
  15. let otherUserToken: string;
  16. let testUser: UserEntity;
  17. let otherUser: UserEntity;
  18. let testProvince: AreaEntity;
  19. let testCity: AreaEntity;
  20. let testDistrict: AreaEntity;
  21. beforeEach(async () => {
  22. // 创建测试客户端
  23. client = testClient(userDeliveryAddressRoutes);
  24. // 获取数据源
  25. const dataSource = await IntegrationTestDatabase.getDataSource();
  26. // 创建测试用户
  27. const userRepository = dataSource.getRepository(UserEntity);
  28. testUser = userRepository.create({
  29. username: `test_user_${Date.now()}`,
  30. password: 'test_password',
  31. nickname: '测试用户',
  32. registrationSource: 'web'
  33. });
  34. await userRepository.save(testUser);
  35. // 创建其他用户
  36. otherUser = userRepository.create({
  37. username: `other_user_${Date.now()}`,
  38. password: 'other_password',
  39. nickname: '其他用户',
  40. registrationSource: 'web'
  41. });
  42. await userRepository.save(otherUser);
  43. // 创建测试地区数据 - 省
  44. const areaRepository = dataSource.getRepository(AreaEntity);
  45. testProvince = areaRepository.create({
  46. name: '北京市',
  47. code: '110000',
  48. level: AreaLevel.PROVINCE,
  49. parentId: null
  50. });
  51. await areaRepository.save(testProvince);
  52. // 创建测试地区数据 - 市
  53. testCity = areaRepository.create({
  54. name: '北京市',
  55. code: '110100',
  56. level: AreaLevel.CITY,
  57. parentId: testProvince.id
  58. });
  59. await areaRepository.save(testCity);
  60. // 创建测试地区数据 - 区
  61. testDistrict = areaRepository.create({
  62. name: '朝阳区',
  63. code: '110105',
  64. level: AreaLevel.DISTRICT,
  65. parentId: testCity.id
  66. });
  67. await areaRepository.save(testDistrict);
  68. // 生成测试用户的token
  69. userToken = JWTUtil.generateToken({
  70. id: testUser.id,
  71. username: testUser.username,
  72. roles: [{name:'user'}]
  73. });
  74. // 生成其他用户的token
  75. otherUserToken = JWTUtil.generateToken({
  76. id: otherUser.id,
  77. username: otherUser.username,
  78. roles: [{name:'user'}]
  79. });
  80. });
  81. describe('GET /delivery-address', () => {
  82. it('应该返回当前用户的配送地址列表', async () => {
  83. // 为测试用户创建一些地址
  84. const dataSource = await IntegrationTestDatabase.getDataSource();
  85. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  86. const userAddress1 = deliveryAddressRepository.create({
  87. userId: testUser.id,
  88. name: '用户地址1',
  89. phone: '13800138001',
  90. address: '用户地址1',
  91. receiverProvince: testProvince.id,
  92. receiverCity: testCity.id,
  93. receiverDistrict: testDistrict.id,
  94. receiverTown: 1,
  95. state: 1,
  96. isDefault: 0,
  97. createdBy: testUser.id
  98. });
  99. await deliveryAddressRepository.save(userAddress1);
  100. const userAddress2 = deliveryAddressRepository.create({
  101. userId: testUser.id,
  102. name: '用户地址2',
  103. phone: '13800138002',
  104. address: '用户地址2',
  105. receiverProvince: testProvince.id,
  106. receiverCity: testCity.id,
  107. receiverDistrict: testDistrict.id,
  108. receiverTown: 1,
  109. state: 1,
  110. isDefault: 0,
  111. createdBy: testUser.id
  112. });
  113. await deliveryAddressRepository.save(userAddress2);
  114. // 为其他用户创建一个地址,确保不会返回
  115. const otherUserAddress = deliveryAddressRepository.create({
  116. userId: otherUser.id,
  117. name: '其他用户地址',
  118. phone: '13800138003',
  119. address: '其他用户地址',
  120. receiverProvince: testProvince.id,
  121. receiverCity: testCity.id,
  122. receiverDistrict: testDistrict.id,
  123. receiverTown: 1,
  124. state: 1,
  125. isDefault: 0,
  126. createdBy: otherUser.id
  127. });
  128. await deliveryAddressRepository.save(otherUserAddress);
  129. const response = await client.index.$get({
  130. query: {}
  131. }, {
  132. headers: {
  133. 'Authorization': `Bearer ${userToken}`
  134. }
  135. });
  136. console.debug('用户配送地址列表响应状态:', response.status);
  137. expect(response.status).toBe(200);
  138. if (response.status === 200) {
  139. const data = await response.json();
  140. if (data && 'data' in data) {
  141. expect(Array.isArray(data.data)).toBe(true);
  142. // 应该只返回当前用户的地址
  143. data.data.forEach((address: any) => {
  144. expect(address.user?.id).toBe(testUser.id);
  145. });
  146. }
  147. }
  148. });
  149. it('应该拒绝未认证用户的访问', async () => {
  150. const response = await client.index.$get({
  151. query: {}
  152. });
  153. expect(response.status).toBe(401);
  154. });
  155. });
  156. describe('POST /delivery-address', () => {
  157. it('应该成功创建配送地址并自动使用当前用户ID', async () => {
  158. const createData = {
  159. name: '张三',
  160. phone: '13800138000',
  161. address: '朝阳区建国路88号',
  162. receiverProvince: testProvince.id,
  163. receiverCity: testCity.id,
  164. receiverDistrict: testDistrict.id,
  165. receiverTown: 1,
  166. state: 1,
  167. isDefault: 1
  168. };
  169. const response = await client.index.$post({
  170. json: createData
  171. }, {
  172. headers: {
  173. 'Authorization': `Bearer ${userToken}`
  174. }
  175. });
  176. console.debug('用户创建配送地址响应状态:', response.status);
  177. expect(response.status).toBe(201);
  178. if (response.status === 201) {
  179. const data = await response.json();
  180. console.debug('用户创建地址响应数据:', JSON.stringify(data, null, 2));
  181. expect(data).toHaveProperty('id');
  182. expect(data.userId).toBe(testUser.id); // 自动使用当前用户ID
  183. expect(data.name).toBe(createData.name);
  184. expect(data.phone).toBe(createData.phone);
  185. expect(data.address).toBe(createData.address);
  186. }
  187. });
  188. it('应该验证创建配送地址的必填字段', async () => {
  189. const invalidData = {
  190. // 缺少必填字段
  191. name: '',
  192. phone: '',
  193. address: '',
  194. receiverProvince: 0,
  195. receiverCity: 0,
  196. receiverDistrict: 0
  197. };
  198. const response = await client.index.$post({
  199. json: invalidData
  200. }, {
  201. headers: {
  202. 'Authorization': `Bearer ${userToken}`
  203. }
  204. });
  205. expect(response.status).toBe(400);
  206. });
  207. });
  208. describe('GET /delivery-address/:id', () => {
  209. it('应该返回当前用户的配送地址详情', async () => {
  210. // 先为当前用户创建一个配送地址
  211. const dataSource = await IntegrationTestDatabase.getDataSource();
  212. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  213. const testDeliveryAddress = deliveryAddressRepository.create({
  214. userId: testUser.id,
  215. name: '王五',
  216. phone: '13600136000',
  217. address: '海淀区中关村大街1号',
  218. receiverProvince: testProvince.id,
  219. receiverCity: testCity.id,
  220. receiverDistrict: testDistrict.id,
  221. receiverTown: 1,
  222. state: 1,
  223. isDefault: 0,
  224. createdBy: testUser.id
  225. });
  226. await deliveryAddressRepository.save(testDeliveryAddress);
  227. const response = await client[':id'].$get({
  228. param: { id: testDeliveryAddress.id }
  229. }, {
  230. headers: {
  231. 'Authorization': `Bearer ${userToken}`
  232. }
  233. });
  234. console.debug('用户配送地址详情响应状态:', response.status);
  235. expect(response.status).toBe(200);
  236. if (response.status === 200) {
  237. const data = await response.json();
  238. expect(data.id).toBe(testDeliveryAddress.id);
  239. expect(data.user?.id).toBe(testUser.id);
  240. expect(data.name).toBe(testDeliveryAddress.name);
  241. expect(data.phone).toBe(testDeliveryAddress.phone);
  242. expect(data.address).toBe(testDeliveryAddress.address);
  243. }
  244. });
  245. it('应该拒绝访问其他用户的配送地址', async () => {
  246. // 为其他用户创建一个配送地址
  247. const dataSource = await IntegrationTestDatabase.getDataSource();
  248. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  249. const otherUserAddress = deliveryAddressRepository.create({
  250. userId: otherUser.id,
  251. name: '其他用户地址',
  252. phone: '13600136001',
  253. address: '其他用户地址',
  254. receiverProvince: testProvince.id,
  255. receiverCity: testCity.id,
  256. receiverDistrict: testDistrict.id,
  257. receiverTown: 1,
  258. state: 1,
  259. isDefault: 0,
  260. createdBy: otherUser.id
  261. });
  262. await deliveryAddressRepository.save(otherUserAddress);
  263. // 当前用户尝试访问其他用户的地址
  264. const response = await client[':id'].$get({
  265. param: { id: otherUserAddress.id }
  266. }, {
  267. headers: {
  268. 'Authorization': `Bearer ${userToken}`
  269. }
  270. });
  271. console.debug('用户访问其他用户地址响应状态:', response.status);
  272. expect(response.status).toBe(404); // 应该返回404,而不是403
  273. });
  274. it('应该处理不存在的配送地址', async () => {
  275. const response = await client[':id'].$get({
  276. param: { id: 999999 }
  277. }, {
  278. headers: {
  279. 'Authorization': `Bearer ${userToken}`
  280. }
  281. });
  282. expect(response.status).toBe(404);
  283. });
  284. });
  285. describe('PUT /delivery-address/:id', () => {
  286. it('应该成功更新当前用户的配送地址', async () => {
  287. // 先为当前用户创建一个配送地址
  288. const dataSource = await IntegrationTestDatabase.getDataSource();
  289. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  290. const testDeliveryAddress = deliveryAddressRepository.create({
  291. userId: testUser.id,
  292. name: '原始姓名',
  293. phone: '13500135000',
  294. address: '原始地址',
  295. receiverProvince: testProvince.id,
  296. receiverCity: testCity.id,
  297. receiverDistrict: testDistrict.id,
  298. receiverTown: 1,
  299. state: 1,
  300. isDefault: 0,
  301. createdBy: testUser.id
  302. });
  303. await deliveryAddressRepository.save(testDeliveryAddress);
  304. const updateData = {
  305. name: '更新后的姓名',
  306. phone: '13700137000',
  307. address: '更新后的地址',
  308. isDefault: 1
  309. };
  310. const response = await client[':id'].$put({
  311. param: { id: testDeliveryAddress.id },
  312. json: updateData
  313. }, {
  314. headers: {
  315. 'Authorization': `Bearer ${userToken}`
  316. }
  317. });
  318. console.debug('用户更新配送地址响应状态:', response.status);
  319. expect(response.status).toBe(200);
  320. if (response.status === 200) {
  321. const data = await response.json();
  322. expect(data.name).toBe(updateData.name);
  323. expect(data.phone).toBe(updateData.phone);
  324. expect(data.address).toBe(updateData.address);
  325. expect(data.isDefault).toBe(updateData.isDefault);
  326. }
  327. });
  328. it('应该拒绝更新其他用户的配送地址', async () => {
  329. // 为其他用户创建一个配送地址
  330. const dataSource = await IntegrationTestDatabase.getDataSource();
  331. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  332. const otherUserAddress = deliveryAddressRepository.create({
  333. userId: otherUser.id,
  334. name: '其他用户地址',
  335. phone: '13500135001',
  336. address: '其他用户地址',
  337. receiverProvince: testProvince.id,
  338. receiverCity: testCity.id,
  339. receiverDistrict: testDistrict.id,
  340. receiverTown: 1,
  341. state: 1,
  342. isDefault: 0,
  343. createdBy: otherUser.id
  344. });
  345. await deliveryAddressRepository.save(otherUserAddress);
  346. const updateData = {
  347. name: '尝试更新的姓名',
  348. phone: '13700137001',
  349. address: '尝试更新的地址'
  350. };
  351. // 当前用户尝试更新其他用户的地址
  352. const response = await client[':id'].$put({
  353. param: { id: otherUserAddress.id },
  354. json: updateData
  355. }, {
  356. headers: {
  357. 'Authorization': `Bearer ${userToken}`
  358. }
  359. });
  360. console.debug('用户更新其他用户地址响应状态:', response.status);
  361. expect(response.status).toBe(403); // 数据权限控制返回403
  362. });
  363. });
  364. describe('DELETE /delivery-address/:id', () => {
  365. it('应该成功删除当前用户的配送地址', async () => {
  366. // 先为当前用户创建一个配送地址
  367. const dataSource = await IntegrationTestDatabase.getDataSource();
  368. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  369. const testDeliveryAddress = deliveryAddressRepository.create({
  370. userId: testUser.id,
  371. name: '待删除地址',
  372. phone: '13400134000',
  373. address: '待删除地址',
  374. receiverProvince: testProvince.id,
  375. receiverCity: testCity.id,
  376. receiverDistrict: testDistrict.id,
  377. receiverTown: 1,
  378. state: 1,
  379. isDefault: 0,
  380. createdBy: testUser.id
  381. });
  382. await deliveryAddressRepository.save(testDeliveryAddress);
  383. const response = await client[':id'].$delete({
  384. param: { id: testDeliveryAddress.id }
  385. }, {
  386. headers: {
  387. 'Authorization': `Bearer ${userToken}`
  388. }
  389. });
  390. console.debug('用户删除配送地址响应状态:', response.status);
  391. expect(response.status).toBe(204);
  392. // 验证配送地址确实被删除
  393. const deletedDeliveryAddress = await deliveryAddressRepository.findOne({
  394. where: { id: testDeliveryAddress.id }
  395. });
  396. expect(deletedDeliveryAddress).toBeNull();
  397. });
  398. it('应该拒绝删除其他用户的配送地址', async () => {
  399. // 为其他用户创建一个配送地址
  400. const dataSource = await IntegrationTestDatabase.getDataSource();
  401. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  402. const otherUserAddress = deliveryAddressRepository.create({
  403. userId: otherUser.id,
  404. name: '其他用户地址',
  405. phone: '13400134001',
  406. address: '其他用户地址',
  407. receiverProvince: testProvince.id,
  408. receiverCity: testCity.id,
  409. receiverDistrict: testDistrict.id,
  410. receiverTown: 1,
  411. state: 1,
  412. isDefault: 0,
  413. createdBy: otherUser.id
  414. });
  415. await deliveryAddressRepository.save(otherUserAddress);
  416. // 当前用户尝试删除其他用户的地址
  417. const response = await client[':id'].$delete({
  418. param: { id: otherUserAddress.id }
  419. }, {
  420. headers: {
  421. 'Authorization': `Bearer ${userToken}`
  422. }
  423. });
  424. console.debug('用户删除其他用户地址响应状态:', response.status);
  425. expect(response.status).toBe(403); // 数据权限控制返回403
  426. });
  427. });
  428. describe('数据权限验证', () => {
  429. it('用户应该只能访问和操作自己的数据', async () => {
  430. // 为两个用户都创建地址
  431. const dataSource = await IntegrationTestDatabase.getDataSource();
  432. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  433. const userAddress = deliveryAddressRepository.create({
  434. userId: testUser.id,
  435. name: '用户地址',
  436. phone: '13800138004',
  437. address: '用户地址',
  438. receiverProvince: testProvince.id,
  439. receiverCity: testCity.id,
  440. receiverDistrict: testDistrict.id,
  441. receiverTown: 1,
  442. state: 1,
  443. isDefault: 0,
  444. createdBy: testUser.id
  445. });
  446. await deliveryAddressRepository.save(userAddress);
  447. const otherUserAddress = deliveryAddressRepository.create({
  448. userId: otherUser.id,
  449. name: '其他用户地址',
  450. phone: '13800138005',
  451. address: '其他用户地址',
  452. receiverProvince: testProvince.id,
  453. receiverCity: testCity.id,
  454. receiverDistrict: testDistrict.id,
  455. receiverTown: 1,
  456. state: 1,
  457. isDefault: 0,
  458. createdBy: otherUser.id
  459. });
  460. await deliveryAddressRepository.save(otherUserAddress);
  461. // 当前用户应该只能看到自己的地址
  462. const listResponse = await client.index.$get({
  463. query: {}
  464. }, {
  465. headers: {
  466. 'Authorization': `Bearer ${userToken}`
  467. }
  468. });
  469. expect(listResponse.status).toBe(200);
  470. const listData = await listResponse.json();
  471. if (listData && 'data' in listData) {
  472. expect(Array.isArray(listData.data)).toBe(true);
  473. // 应该只包含当前用户的地址
  474. listData.data.forEach((address: any) => {
  475. expect(address.user?.id).toBe(testUser.id);
  476. });
  477. }
  478. // 当前用户应该无法访问其他用户的地址详情
  479. const getResponse = await client[':id'].$get({
  480. param: { id: otherUserAddress.id }
  481. }, {
  482. headers: {
  483. 'Authorization': `Bearer ${userToken}`
  484. }
  485. });
  486. expect(getResponse.status).toBe(404);
  487. // 当前用户应该无法更新其他用户的地址
  488. const updateResponse = await client[':id'].$put({
  489. param: { id: otherUserAddress.id },
  490. json: { name: '尝试更新' }
  491. }, {
  492. headers: {
  493. 'Authorization': `Bearer ${userToken}`
  494. }
  495. });
  496. expect(updateResponse.status).toBe(403);
  497. // 当前用户应该无法删除其他用户的地址
  498. const deleteResponse = await client[':id'].$delete({
  499. param: { id: otherUserAddress.id }
  500. }, {
  501. headers: {
  502. 'Authorization': `Bearer ${userToken}`
  503. }
  504. });
  505. expect(deleteResponse.status).toBe(403);
  506. });
  507. });
  508. });