user-routes.integration.test.ts 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581
  1. import { describe, it, expect, beforeEach, vi, afterEach } from 'vitest';
  2. import { testClient } from 'hono/testing';
  3. import { IntegrationTestDatabase, setupIntegrationDatabaseHooksWithEntities } from '@d8d/shared-test-util';
  4. import { JWTUtil } from '@d8d/shared-utils';
  5. import { UserEntity, Role } from '@d8d/user-module';
  6. import { File } from '@d8d/file-module';
  7. import { userMerchantRoutes } from '../../src/routes';
  8. import { Merchant } from '../../src/entities';
  9. // 设置集成测试钩子
  10. setupIntegrationDatabaseHooksWithEntities([UserEntity, Role, Merchant, File])
  11. describe('用户商户管理API集成测试', () => {
  12. let client: ReturnType<typeof testClient<typeof userMerchantRoutes>>;
  13. let userToken: string;
  14. let otherUserToken: string;
  15. let testUser: UserEntity;
  16. let otherUser: UserEntity;
  17. beforeEach(async () => {
  18. // 创建测试客户端
  19. client = testClient(userMerchantRoutes);
  20. // 获取数据源
  21. const dataSource = await IntegrationTestDatabase.getDataSource();
  22. // 创建测试用户
  23. const userRepository = dataSource.getRepository(UserEntity);
  24. testUser = userRepository.create({
  25. username: `test_user_${Date.now()}`,
  26. password: 'test_password',
  27. nickname: '测试用户',
  28. registrationSource: 'web'
  29. });
  30. await userRepository.save(testUser);
  31. // 创建其他用户
  32. otherUser = userRepository.create({
  33. username: `other_user_${Date.now()}`,
  34. password: 'other_password',
  35. nickname: '其他用户',
  36. registrationSource: 'web'
  37. });
  38. await userRepository.save(otherUser);
  39. // 生成测试用户的token
  40. userToken = JWTUtil.generateToken({
  41. id: testUser.id,
  42. username: testUser.username,
  43. roles: [{name:'user'}]
  44. });
  45. // 生成其他用户的token
  46. otherUserToken = JWTUtil.generateToken({
  47. id: otherUser.id,
  48. username: otherUser.username,
  49. roles: [{name:'user'}]
  50. });
  51. });
  52. describe('GET /merchants', () => {
  53. it('应该返回当前用户的商户列表', async () => {
  54. // 为测试用户创建一些商户
  55. const dataSource = await IntegrationTestDatabase.getDataSource();
  56. const merchantRepository = dataSource.getRepository(Merchant);
  57. const userMerchant1 = merchantRepository.create({
  58. name: '用户商户1',
  59. username: `u1_${Date.now()}`,
  60. password: 'password123',
  61. phone: '13800138001',
  62. realname: '张三',
  63. state: 1,
  64. createdBy: testUser.id
  65. });
  66. await merchantRepository.save(userMerchant1);
  67. const userMerchant2 = merchantRepository.create({
  68. name: '用户商户2',
  69. username: `u2_${Date.now()}`,
  70. password: 'password123',
  71. phone: '13800138002',
  72. realname: '李四',
  73. state: 1,
  74. createdBy: testUser.id
  75. });
  76. await merchantRepository.save(userMerchant2);
  77. // 为其他用户创建一个商户,确保不会返回
  78. const otherUserMerchant = merchantRepository.create({
  79. name: '其他用户商户',
  80. username: `o_${Date.now()}`,
  81. password: 'password123',
  82. phone: '13800138003',
  83. realname: '王五',
  84. state: 1,
  85. createdBy: otherUser.id
  86. });
  87. await merchantRepository.save(otherUserMerchant);
  88. const response = await client.index.$get({
  89. query: {}
  90. }, {
  91. headers: {
  92. 'Authorization': `Bearer ${userToken}`
  93. }
  94. });
  95. console.debug('用户商户列表响应状态:', response.status);
  96. expect(response.status).toBe(200);
  97. if (response.status === 200) {
  98. const data = await response.json();
  99. if (data && 'data' in data) {
  100. expect(Array.isArray(data.data)).toBe(true);
  101. // 应该只返回当前用户的商户
  102. data.data.forEach((merchant: any) => {
  103. expect(merchant.createdBy).toBe(testUser.id);
  104. });
  105. }
  106. }
  107. });
  108. it('应该拒绝未认证用户的访问', async () => {
  109. const response = await client.index.$get({
  110. query: {}
  111. });
  112. expect(response.status).toBe(401);
  113. });
  114. });
  115. describe('POST /merchants', () => {
  116. it('应该成功创建商户并自动使用当前用户ID', async () => {
  117. const createData = {
  118. name: '新商户',
  119. username: `new_${Date.now()}`,
  120. password: 'password123',
  121. phone: '13800138000',
  122. realname: '张三',
  123. state: 1
  124. };
  125. const response = await client.index.$post({
  126. json: createData
  127. }, {
  128. headers: {
  129. 'Authorization': `Bearer ${userToken}`
  130. }
  131. });
  132. console.debug('用户创建商户响应状态:', response.status);
  133. expect(response.status).toBe(201);
  134. if (response.status === 201) {
  135. const data = await response.json();
  136. console.debug('用户创建商户响应数据:', JSON.stringify(data, null, 2));
  137. expect(data).toHaveProperty('id');
  138. expect(data.createdBy).toBe(testUser.id); // 自动使用当前用户ID
  139. expect(data.name).toBe(createData.name);
  140. expect(data.username).toBe(createData.username);
  141. expect(data.phone).toBe(createData.phone);
  142. expect(data.realname).toBe(createData.realname);
  143. }
  144. });
  145. it('应该验证创建商户的必填字段', async () => {
  146. const invalidData = {
  147. // 缺少必填字段
  148. name: '',
  149. username: '',
  150. password: ''
  151. };
  152. const response = await client.index.$post({
  153. json: invalidData
  154. }, {
  155. headers: {
  156. 'Authorization': `Bearer ${userToken}`
  157. }
  158. });
  159. expect(response.status).toBe(400);
  160. });
  161. });
  162. describe('GET /merchants/:id', () => {
  163. it('应该返回当前用户的商户详情', async () => {
  164. // 先为当前用户创建一个商户
  165. const dataSource = await IntegrationTestDatabase.getDataSource();
  166. const merchantRepository = dataSource.getRepository(Merchant);
  167. const testMerchant = merchantRepository.create({
  168. name: '测试商户',
  169. username: `tm_${Date.now()}`,
  170. password: 'password123',
  171. phone: '13800138000',
  172. realname: '张三',
  173. state: 1,
  174. createdBy: testUser.id
  175. });
  176. await merchantRepository.save(testMerchant);
  177. const response = await client[':id'].$get({
  178. param: { id: testMerchant.id }
  179. }, {
  180. headers: {
  181. 'Authorization': `Bearer ${userToken}`
  182. }
  183. });
  184. console.debug('用户商户详情响应状态:', response.status);
  185. expect(response.status).toBe(200);
  186. if (response.status === 200) {
  187. const data = await response.json();
  188. expect(data.id).toBe(testMerchant.id);
  189. expect(data.createdBy).toBe(testUser.id);
  190. expect(data.name).toBe(testMerchant.name);
  191. expect(data.username).toBe(testMerchant.username);
  192. expect(data.phone).toBe(testMerchant.phone);
  193. expect(data.realname).toBe(testMerchant.realname);
  194. }
  195. });
  196. it('应该拒绝访问其他用户的商户', async () => {
  197. // 为其他用户创建一个商户
  198. const dataSource = await IntegrationTestDatabase.getDataSource();
  199. const merchantRepository = dataSource.getRepository(Merchant);
  200. const otherUserMerchant = merchantRepository.create({
  201. name: '其他用户商户',
  202. username: `om_${Date.now()}`,
  203. password: 'password123',
  204. phone: '13800138001',
  205. realname: '李四',
  206. state: 1,
  207. createdBy: otherUser.id
  208. });
  209. await merchantRepository.save(otherUserMerchant);
  210. // 当前用户尝试访问其他用户的商户
  211. const response = await client[':id'].$get({
  212. param: { id: otherUserMerchant.id }
  213. }, {
  214. headers: {
  215. 'Authorization': `Bearer ${userToken}`
  216. }
  217. });
  218. console.debug('用户访问其他用户商户响应状态:', response.status);
  219. expect(response.status).toBe(404); // 应该返回404,而不是403
  220. });
  221. it('应该处理不存在的商户', async () => {
  222. const response = await client[':id'].$get({
  223. param: { id: 999999 }
  224. }, {
  225. headers: {
  226. 'Authorization': `Bearer ${userToken}`
  227. }
  228. });
  229. expect(response.status).toBe(404);
  230. });
  231. });
  232. describe('PUT /merchants/:id', () => {
  233. it('应该成功更新当前用户的商户', async () => {
  234. // 先为当前用户创建一个商户
  235. const dataSource = await IntegrationTestDatabase.getDataSource();
  236. const merchantRepository = dataSource.getRepository(Merchant);
  237. const testMerchant = merchantRepository.create({
  238. name: '原始商户',
  239. username: `om_${Date.now()}`,
  240. password: 'password123',
  241. phone: '13800138000',
  242. realname: '原始姓名',
  243. state: 1,
  244. createdBy: testUser.id
  245. });
  246. await merchantRepository.save(testMerchant);
  247. const updateData = {
  248. name: '更新后的商户',
  249. phone: '13900139000',
  250. realname: '更新后的姓名',
  251. state: 2
  252. };
  253. const response = await client[':id'].$put({
  254. param: { id: testMerchant.id },
  255. json: updateData
  256. }, {
  257. headers: {
  258. 'Authorization': `Bearer ${userToken}`
  259. }
  260. });
  261. console.debug('用户更新商户响应状态:', response.status);
  262. expect(response.status).toBe(200);
  263. if (response.status === 200) {
  264. const data = await response.json();
  265. expect(data.name).toBe(updateData.name);
  266. expect(data.phone).toBe(updateData.phone);
  267. expect(data.realname).toBe(updateData.realname);
  268. expect(data.state).toBe(updateData.state);
  269. }
  270. });
  271. it('应该拒绝更新其他用户的商户', async () => {
  272. // 为其他用户创建一个商户
  273. const dataSource = await IntegrationTestDatabase.getDataSource();
  274. const merchantRepository = dataSource.getRepository(Merchant);
  275. const otherUserMerchant = merchantRepository.create({
  276. name: '其他用户商户',
  277. username: `om_${Date.now()}`,
  278. password: 'password123',
  279. phone: '13800138001',
  280. realname: '李四',
  281. state: 1,
  282. createdBy: otherUser.id
  283. });
  284. await merchantRepository.save(otherUserMerchant);
  285. const updateData = {
  286. name: '尝试更新的商户',
  287. phone: '13900139001',
  288. realname: '尝试更新的姓名'
  289. };
  290. // 当前用户尝试更新其他用户的商户
  291. const response = await client[':id'].$put({
  292. param: { id: otherUserMerchant.id },
  293. json: updateData
  294. }, {
  295. headers: {
  296. 'Authorization': `Bearer ${userToken}`
  297. }
  298. });
  299. console.debug('用户更新其他用户商户响应状态:', response.status);
  300. expect(response.status).toBe(403); // 数据权限控制返回403
  301. });
  302. });
  303. describe('DELETE /merchants/:id', () => {
  304. it('应该成功删除当前用户的商户', async () => {
  305. // 先为当前用户创建一个商户
  306. const dataSource = await IntegrationTestDatabase.getDataSource();
  307. const merchantRepository = dataSource.getRepository(Merchant);
  308. const testMerchant = merchantRepository.create({
  309. name: '待删除商户',
  310. username: `dm_${Date.now()}`,
  311. password: 'password123',
  312. phone: '13800138000',
  313. realname: '张三',
  314. state: 1,
  315. createdBy: testUser.id
  316. });
  317. await merchantRepository.save(testMerchant);
  318. const response = await client[':id'].$delete({
  319. param: { id: testMerchant.id }
  320. }, {
  321. headers: {
  322. 'Authorization': `Bearer ${userToken}`
  323. }
  324. });
  325. console.debug('用户删除商户响应状态:', response.status);
  326. expect(response.status).toBe(204);
  327. // 验证商户确实被删除
  328. const deletedMerchant = await merchantRepository.findOne({
  329. where: { id: testMerchant.id }
  330. });
  331. expect(deletedMerchant).toBeNull();
  332. });
  333. it('应该拒绝删除其他用户的商户', async () => {
  334. // 为其他用户创建一个商户
  335. const dataSource = await IntegrationTestDatabase.getDataSource();
  336. const merchantRepository = dataSource.getRepository(Merchant);
  337. const otherUserMerchant = merchantRepository.create({
  338. name: '其他用户商户',
  339. username: `om_${Date.now()}`,
  340. password: 'password123',
  341. phone: '13800138001',
  342. realname: '李四',
  343. state: 1,
  344. createdBy: otherUser.id
  345. });
  346. await merchantRepository.save(otherUserMerchant);
  347. // 当前用户尝试删除其他用户的商户
  348. const response = await client[':id'].$delete({
  349. param: { id: otherUserMerchant.id }
  350. }, {
  351. headers: {
  352. 'Authorization': `Bearer ${userToken}`
  353. }
  354. });
  355. console.debug('用户删除其他用户商户响应状态:', response.status);
  356. expect(response.status).toBe(403); // 数据权限控制返回403
  357. });
  358. });
  359. describe('数据权限验证', () => {
  360. it('用户应该只能访问和操作自己的数据', async () => {
  361. // 为两个用户都创建商户
  362. const dataSource = await IntegrationTestDatabase.getDataSource();
  363. const merchantRepository = dataSource.getRepository(Merchant);
  364. const userMerchant = merchantRepository.create({
  365. name: '用户商户',
  366. username: `um_${Date.now()}`,
  367. password: 'password123',
  368. phone: '13800138004',
  369. realname: '张三',
  370. state: 1,
  371. createdBy: testUser.id
  372. });
  373. await merchantRepository.save(userMerchant);
  374. const otherUserMerchant = merchantRepository.create({
  375. name: '其他用户商户',
  376. username: `om_${Date.now()}`,
  377. password: 'password123',
  378. phone: '13800138005',
  379. realname: '李四',
  380. state: 1,
  381. createdBy: otherUser.id
  382. });
  383. await merchantRepository.save(otherUserMerchant);
  384. // 当前用户应该只能看到自己的商户
  385. const listResponse = await client.index.$get({
  386. query: {}
  387. }, {
  388. headers: {
  389. 'Authorization': `Bearer ${userToken}`
  390. }
  391. });
  392. expect(listResponse.status).toBe(200);
  393. const listData = await listResponse.json();
  394. if (listData && 'data' in listData) {
  395. expect(Array.isArray(listData.data)).toBe(true);
  396. // 应该只包含当前用户的商户
  397. listData.data.forEach((merchant: any) => {
  398. expect(merchant.createdBy).toBe(testUser.id);
  399. });
  400. }
  401. // 当前用户应该无法访问其他用户的商户详情
  402. const getResponse = await client[':id'].$get({
  403. param: { id: otherUserMerchant.id }
  404. }, {
  405. headers: {
  406. 'Authorization': `Bearer ${userToken}`
  407. }
  408. });
  409. expect(getResponse.status).toBe(404);
  410. // 当前用户应该无法更新其他用户的商户
  411. const updateResponse = await client[':id'].$put({
  412. param: { id: otherUserMerchant.id },
  413. json: { name: '尝试更新' }
  414. }, {
  415. headers: {
  416. 'Authorization': `Bearer ${userToken}`
  417. }
  418. });
  419. expect(updateResponse.status).toBe(403);
  420. // 当前用户应该无法删除其他用户的商户
  421. const deleteResponse = await client[':id'].$delete({
  422. param: { id: otherUserMerchant.id }
  423. }, {
  424. headers: {
  425. 'Authorization': `Bearer ${userToken}`
  426. }
  427. });
  428. expect(deleteResponse.status).toBe(403);
  429. });
  430. });
  431. describe('商户状态管理测试', () => {
  432. it('应该支持商户状态管理', async () => {
  433. // 创建启用状态的商户
  434. const createData = {
  435. name: '状态测试商户',
  436. username: `stm_${Date.now()}`,
  437. password: 'password123',
  438. phone: '13800138006',
  439. realname: '状态测试',
  440. state: 1 // 启用
  441. };
  442. const createResponse = await client.index.$post({
  443. json: createData
  444. }, {
  445. headers: {
  446. 'Authorization': `Bearer ${userToken}`
  447. }
  448. });
  449. expect(createResponse.status).toBe(201);
  450. const createdMerchant = await createResponse.json();
  451. // 检查响应是否为错误对象
  452. if ('code' in createdMerchant && 'message' in createdMerchant) {
  453. throw new Error(`创建商户失败: ${createdMerchant.message}`);
  454. }
  455. expect(createdMerchant.state).toBe(1);
  456. // 更新为禁用状态
  457. const updateResponse = await client[':id'].$put({
  458. param: { id: createdMerchant.id },
  459. json: { state: 2 } // 禁用
  460. }, {
  461. headers: {
  462. 'Authorization': `Bearer ${userToken}`
  463. }
  464. });
  465. expect(updateResponse.status).toBe(200);
  466. const updatedMerchant = await updateResponse.json();
  467. // 检查响应是否为错误对象
  468. if ('code' in updatedMerchant && 'message' in updatedMerchant) {
  469. throw new Error(`更新商户失败: ${updatedMerchant.message}`);
  470. }
  471. expect(updatedMerchant.state).toBe(2);
  472. });
  473. });
  474. describe('商户登录统计功能测试', () => {
  475. it('应该支持商户登录统计字段', async () => {
  476. // 创建商户
  477. const createData = {
  478. name: '登录统计商户',
  479. username: `lsm_${Date.now()}`,
  480. password: 'password123',
  481. phone: '13800138007',
  482. realname: '登录统计',
  483. state: 1
  484. };
  485. const createResponse = await client.index.$post({
  486. json: createData
  487. }, {
  488. headers: {
  489. 'Authorization': `Bearer ${userToken}`
  490. }
  491. });
  492. expect(createResponse.status).toBe(201);
  493. const createdMerchant = await createResponse.json();
  494. // 检查响应是否为错误对象
  495. if ('code' in createdMerchant && 'message' in createdMerchant) {
  496. throw new Error(`创建商户失败: ${createdMerchant.message}`);
  497. }
  498. // 验证登录统计字段存在
  499. expect(createdMerchant).toHaveProperty('loginNum');
  500. expect(createdMerchant).toHaveProperty('loginTime');
  501. expect(createdMerchant).toHaveProperty('loginIp');
  502. expect(createdMerchant).toHaveProperty('lastLoginTime');
  503. expect(createdMerchant).toHaveProperty('lastLoginIp');
  504. // 初始值应该为0或null
  505. expect(createdMerchant.loginNum).toBe(0);
  506. expect(createdMerchant.loginTime).toBe(0);
  507. expect(createdMerchant.lastLoginTime).toBe(0);
  508. });
  509. });
  510. });