payment-callback.integration.test.ts 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291
  1. import { describe, it, expect, beforeEach, vi, afterEach } from 'vitest';
  2. import { testClient } from 'hono/testing';
  3. import {
  4. IntegrationTestDatabase,
  5. setupIntegrationDatabaseHooksWithEntities
  6. } from '@d8d/shared-test-util';
  7. import { PaymentMtRoutes } from '../../src/routes/payment.mt.routes.js';
  8. import { PaymentMtEntity } from '../../src/entities/payment.mt.entity.js';
  9. import { PaymentStatus } from '../../src/entities/payment.types.js';
  10. import { UserEntityMt } from '@d8d/user-module-mt';
  11. import { RoleMt } from '@d8d/user-module-mt';
  12. import { FileMt } from '@d8d/file-module-mt';
  13. import { OrderMt } from '@d8d/orders-module-mt';
  14. import { MerchantMt } from '@d8d/merchant-module-mt';
  15. import { SupplierMt } from '@d8d/supplier-module-mt';
  16. import { DeliveryAddressMt } from '@d8d/delivery-address-module-mt';
  17. import { AreaEntityMt } from '@d8d/geo-areas-mt';
  18. import { config } from 'dotenv';
  19. import { resolve } from 'path';
  20. // 导入微信支付SDK用于模拟
  21. import WxPay from 'wechatpay-node-v3';
  22. // 导入测试数据工厂
  23. import { PaymentTestFactory } from '../factories/payment-test.factory.js';
  24. // 在测试环境中加载环境变量
  25. config({ path: resolve(process.cwd(), '.env.test') });
  26. vi.mock('wechatpay-node-v3')
  27. // 设置集成测试钩子
  28. setupIntegrationDatabaseHooksWithEntities([PaymentMtEntity, UserEntityMt, FileMt, RoleMt, OrderMt, MerchantMt, SupplierMt, DeliveryAddressMt, AreaEntityMt])
  29. describe('支付回调API集成测试 - 多租户版本', () => {
  30. let client: ReturnType<typeof testClient<typeof PaymentMtRoutes>>;
  31. let testFactory: PaymentTestFactory;
  32. let testData: {
  33. user: UserEntityMt;
  34. merchant: MerchantMt;
  35. supplier: SupplierMt;
  36. address: DeliveryAddressMt;
  37. order: OrderMt;
  38. payment: PaymentMtEntity;
  39. };
  40. // 使用真实的微信支付回调数据 - 直接使用原始请求体字符串
  41. const rawBody = '{"id":"495e231b-9fd8-54a1-8a30-2a38a807744c","create_time":"2025-10-25T12:48:11+08:00","resource_type":"encrypt-resource","event_type":"TRANSACTION.SUCCESS","summary":"支付成功","resource":{"original_type":"transaction","algorithm":"AEAD_AES_256_GCM","ciphertext":"tl1/8FRRn6g0gRq8IoVR8+95VuIADYBDOt6N9PKiHVhiD6l++W5g/wg6VlsCRIZJ+KWMYTaf5FzQHMjCs8o9otIkLLuJA2aZC+kCQtGxNfyVBwxool/tLT9mHd0dFGThqbj8vb/lm+jjNcmmiWHz+J1ZRvGl7mH4I714vudok7JRt5Q0u0tYaLWr76TTXuQErlA7T4KbeVeGAj8iMpu2ErCpR9QRif36Anc5ARjNYrIWfraXlmUXVbXermDyJ8r4o/4QCFfGk8L1u1WqNYASrRTQvQ8OPqj/J21OkDxbPPrOiEmAX1jOvONvIVEe9Lbkm6rdhW4aLRoZYtiusAk/Vm7MI/UYPwRZbyuc4wwdA1T1D4RdJd/m2I4KSvZHQgs0DM0tLqlb0z3880XYNr8iPFnyu2r8Z8LGcXD+COm06vc7bvNWh3ODwmMrmZQkym/Y/T3X/h/4MZj7+1h2vYHqnnrsgtNPHc/2IwWC/fQlPwtSrLh6iUxSd0betFpKLSq08CaJZvnenpDf1ORRMvd8EhTtIJJ4mV4v+VzCOYNhIcBhKp9XwsuhxIdkpGGmNPpow2c2BXY=","associated_data":"transaction","nonce":"sTnWce32BTQP"}}';
  42. const callbackHeader = {
  43. 'wechatpay-timestamp': '1761367693',
  44. 'wechatpay-nonce': 'PVDFxrQiJclkR28HpAYPDiIlS2VaGp9U',
  45. 'wechatpay-signature': 'hwR1KKN1bIPAhatIHTen7fwNDyvONS/picpcqSHtUCGkbvhYLVUqC87ksBJs6bovNI0cKNvrLr6gqp/HR4TK/ijgrD6w9W/oYc6bKyO9lNarggsQKHBv5x5yX8OjBOzqtgiHOVj44RCPrglJ5bFDlxIhnhs9jnGUine0qlvrVwBZAylt5X4oFmPammHoV4lLHtGt0L4zr5y6LoZL80LpctDCOCtwC4JdUUY5AumkMYo8lNs+xK0NAN7EVNKCWUzoQ1pVdBTGZWDP+b8+6gswP6JDsL3a4H4Fw3WGh4DZPskDQAe0sn85UGXO3m03OkDq3WkiCkOut4YZMuKBeCBpWA==',
  46. 'wechatpay-serial': '6C2C991E621267BFA5BFD5F32476427343A0B2AD'
  47. };
  48. beforeEach(async () => {
  49. // 创建测试客户端
  50. client = testClient(PaymentMtRoutes);
  51. // 创建测试数据工厂
  52. const dataSource = await IntegrationTestDatabase.getDataSource();
  53. testFactory = new PaymentTestFactory(dataSource);
  54. // 创建完整的测试数据
  55. testData = await testFactory.createCompleteTestData(1);
  56. // 设置微信支付SDK的全局mock
  57. const mockWxPay = {
  58. transactions_jsapi: vi.fn().mockResolvedValue({
  59. package: 'prepay_id=wx_test_prepay_id_123456',
  60. timeStamp: Math.floor(Date.now() / 1000).toString(),
  61. nonceStr: 'test_nonce_string',
  62. signType: 'RSA',
  63. paySign: 'test_pay_sign'
  64. }),
  65. verifySign: vi.fn().mockResolvedValue(true),
  66. decipher_gcm: vi.fn().mockReturnValue(JSON.stringify({
  67. out_trade_no: testData.payment.outTradeNo, // 使用数据库中保存的 outTradeNo
  68. trade_state: 'SUCCESS',
  69. transaction_id: 'test_transaction_id',
  70. amount: {
  71. total: 1
  72. }
  73. })),
  74. getSignature: vi.fn().mockReturnValue('mock_signature')
  75. };
  76. // 模拟PaymentService的wxPay实例
  77. vi.mocked(WxPay).mockImplementation(() => mockWxPay as any);
  78. });
  79. afterEach(() => {
  80. // 清理 mock
  81. vi.mocked(WxPay).mockClear();
  82. });
  83. describe('POST /payment/callback - 支付回调', () => {
  84. it('应该成功处理支付成功回调并更新订单状态', async () => {
  85. const response = await client.payment.callback.$post({
  86. // 使用空的json参数,通过init传递原始请求体
  87. json: {}
  88. }, {
  89. headers: callbackHeader,
  90. init: {
  91. body: rawBody
  92. }
  93. });
  94. // 现在支付记录存在,回调处理应该成功
  95. expect(response.status).toBe(200);
  96. if (response.status === 200) {
  97. const result = await response.text();
  98. expect(result).toBe('SUCCESS');
  99. // 验证订单状态已更新为已支付 (2)
  100. const dataSource = await IntegrationTestDatabase.getDataSource();
  101. const orderRepository = dataSource.getRepository(OrderMt);
  102. const updatedOrder = await orderRepository.findOne({
  103. where: { id: testOrder.id, tenantId: 1 }
  104. });
  105. expect(updatedOrder).toBeDefined();
  106. expect(updatedOrder?.payState).toBe(2); // 已支付
  107. }
  108. });
  109. it('应该处理支付失败回调并更新订单状态', async () => {
  110. // 模拟支付失败的回调数据
  111. const mockWxPay = {
  112. verifySign: vi.fn().mockResolvedValue(true),
  113. decipher_gcm: vi.fn().mockReturnValue(JSON.stringify({
  114. out_trade_no: testPayment.outTradeNo,
  115. trade_state: 'FAIL',
  116. transaction_id: null,
  117. amount: {
  118. total: 1
  119. }
  120. }))
  121. };
  122. vi.mocked(WxPay).mockImplementation(() => mockWxPay as any);
  123. const response = await client.payment.callback.$post({
  124. json: {}
  125. }, {
  126. headers: callbackHeader,
  127. init: {
  128. body: rawBody
  129. }
  130. });
  131. expect(response.status).toBe(200);
  132. if (response.status === 200) {
  133. const result = await response.text();
  134. expect(result).toBe('SUCCESS');
  135. // 验证订单状态已更新为支付失败 (4)
  136. const dataSource = await IntegrationTestDatabase.getDataSource();
  137. const orderRepository = dataSource.getRepository(OrderMt);
  138. const updatedOrder = await orderRepository.findOne({
  139. where: { id: testOrder.id, tenantId: 1 }
  140. });
  141. expect(updatedOrder).toBeDefined();
  142. expect(updatedOrder?.payState).toBe(4); // 支付失败
  143. }
  144. });
  145. it('应该处理退款回调并更新订单状态', async () => {
  146. // 模拟退款回调数据
  147. const mockWxPay = {
  148. verifySign: vi.fn().mockResolvedValue(true),
  149. decipher_gcm: vi.fn().mockReturnValue(JSON.stringify({
  150. out_trade_no: testPayment.outTradeNo,
  151. trade_state: 'REFUND',
  152. transaction_id: 'test_refund_transaction_id',
  153. amount: {
  154. total: 1
  155. }
  156. }))
  157. };
  158. vi.mocked(WxPay).mockImplementation(() => mockWxPay as any);
  159. const response = await client.payment.callback.$post({
  160. json: {}
  161. }, {
  162. headers: callbackHeader,
  163. init: {
  164. body: rawBody
  165. }
  166. });
  167. expect(response.status).toBe(200);
  168. if (response.status === 200) {
  169. const result = await response.text();
  170. expect(result).toBe('SUCCESS');
  171. // 验证订单状态已更新为已退款 (3)
  172. const dataSource = await IntegrationTestDatabase.getDataSource();
  173. const orderRepository = dataSource.getRepository(OrderMt);
  174. const updatedOrder = await orderRepository.findOne({
  175. where: { id: testOrder.id, tenantId: 1 }
  176. });
  177. expect(updatedOrder).toBeDefined();
  178. expect(updatedOrder?.payState).toBe(3); // 已退款
  179. }
  180. });
  181. it('应该验证多租户数据隔离', async () => {
  182. // 创建第二个租户的测试数据
  183. const multiTenantData = await testFactory.createMultiTenantTestData();
  184. const tenant1Data = multiTenantData.tenant1;
  185. const tenant2Data = multiTenantData.tenant2;
  186. // 处理租户1的支付回调
  187. const response = await client.payment.callback.$post({
  188. json: {}
  189. }, {
  190. headers: callbackHeader,
  191. init: {
  192. body: rawBody
  193. }
  194. });
  195. expect(response.status).toBe(200);
  196. // 验证租户1的订单状态已更新
  197. const dataSource = await IntegrationTestDatabase.getDataSource();
  198. const orderRepository = dataSource.getRepository(OrderMt);
  199. const updatedOrder1 = await orderRepository.findOne({
  200. where: { id: tenant1Data.order.id, tenantId: 1 }
  201. });
  202. expect(updatedOrder1?.payState).toBe(2); // 已支付
  203. // 验证租户2的订单状态未受影响
  204. const updatedOrder2 = await orderRepository.findOne({
  205. where: { id: tenant2Data.order.id, tenantId: 2 }
  206. });
  207. expect(updatedOrder2?.payState).toBe(0); // 仍为未支付
  208. });
  209. it('应该处理无效的回调数据格式', async () => {
  210. const response = await client.payment.callback.$post({
  211. body: 'invalid json data'
  212. }, {
  213. headers: {
  214. ...callbackHeader,
  215. 'content-type': 'text/plain'
  216. }
  217. });
  218. // 由于JSON解析失败,应该返回500错误
  219. expect(response.status).toBe(500);
  220. });
  221. it('应该处理缺少必要头信息的情况', async () => {
  222. const response = await client.payment.callback.$post({
  223. body: rawBody
  224. }, {
  225. headers: {
  226. // 缺少必要的微信支付头信息
  227. 'Content-Type': 'text/plain'
  228. }
  229. });
  230. // 由于缺少必要头信息,应该返回500错误
  231. expect(response.status).toBe(500);
  232. });
  233. it('应该验证回调数据解密后的支付处理', async () => {
  234. const response = await client.payment.callback.$post({
  235. // 使用空的json参数,通过init传递原始请求体
  236. json: {}
  237. }, {
  238. headers: callbackHeader,
  239. init: {
  240. body: rawBody
  241. }
  242. });
  243. // 现在支付记录存在,回调处理应该成功
  244. expect(response.status).toBe(200);
  245. if (response.status === 200) {
  246. const result = await response.text();
  247. expect(result).toBe('SUCCESS');
  248. }
  249. });
  250. });
  251. });