data-overview-routes.integration.test.ts 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343
  1. import { describe, it, expect, beforeEach } from 'vitest';
  2. import { testClient } from 'hono/testing';
  3. import { IntegrationTestDatabase, setupIntegrationDatabaseHooksWithEntities } from '@d8d/shared-test-util';
  4. import { UserEntityMt, RoleMt } from '@d8d/core-module-mt/user-module-mt/entities';
  5. import { FileMt } from '@d8d/core-module-mt/file-module-mt/entities';
  6. import { OrderMt, OrderGoodsMt } from '@d8d/orders-module-mt';
  7. import { MerchantMt } from '@d8d/merchant-module-mt';
  8. import { SupplierMt } from '@d8d/supplier-module-mt';
  9. import { DeliveryAddressMt } from '@d8d/delivery-address-module-mt';
  10. import { AreaEntityMt } from '@d8d/geo-areas-mt';
  11. import { GoodsMt, GoodsCategoryMt } from '@d8d/goods-module-mt';
  12. import dataOverviewRoutes from '../../src/routes';
  13. import { DataOverviewTestDataFactory } from '../utils/test-data-factory';
  14. // 设置集成测试钩子 - 需要User、Role、File、Order及相关实体
  15. setupIntegrationDatabaseHooksWithEntities([
  16. UserEntityMt,
  17. RoleMt,
  18. FileMt,
  19. OrderMt,
  20. OrderGoodsMt,
  21. MerchantMt,
  22. SupplierMt,
  23. DeliveryAddressMt,
  24. AreaEntityMt,
  25. GoodsMt,
  26. GoodsCategoryMt
  27. ])
  28. describe('多租户数据概览API集成测试', () => {
  29. let client: ReturnType<typeof testClient<typeof dataOverviewRoutes>>;
  30. let userToken: string;
  31. let adminToken: string;
  32. let testUser: UserEntityMt;
  33. beforeEach(async () => {
  34. // 创建测试客户端
  35. client = testClient(dataOverviewRoutes);
  36. // 获取数据源并创建测试用户
  37. const dataSource = await IntegrationTestDatabase.getDataSource();
  38. // 创建租户1的测试用户
  39. testUser = await DataOverviewTestDataFactory.createTestUser(dataSource, 1);
  40. // 生成JWT令牌
  41. userToken = DataOverviewTestDataFactory.generateUserToken(testUser);
  42. adminToken = DataOverviewTestDataFactory.generateAdminToken(1);
  43. });
  44. describe('租户数据隔离验证', () => {
  45. it('应该确保订单数据的租户隔离', async () => {
  46. const dataSource = await IntegrationTestDatabase.getDataSource();
  47. const orderRepository = dataSource.getRepository(OrderMt);
  48. // 创建租户1的订单数据
  49. await DataOverviewTestDataFactory.createTestOrders(dataSource, 1, 2);
  50. // 创建租户2的订单数据
  51. await DataOverviewTestDataFactory.createTestOrders(dataSource, 2, 3);
  52. // 验证租户1只能看到租户1的订单
  53. const tenant1Orders = await orderRepository.find({
  54. where: { tenantId: 1 }
  55. });
  56. // 验证租户2只能看到租户2的订单
  57. const tenant2Orders = await orderRepository.find({
  58. where: { tenantId: 2 }
  59. });
  60. expect(tenant1Orders).toHaveLength(2);
  61. expect(tenant1Orders[0].tenantId).toBe(1);
  62. expect(tenant2Orders).toHaveLength(3);
  63. expect(tenant2Orders[0].tenantId).toBe(2);
  64. });
  65. it('应该防止跨租户数据访问', async () => {
  66. const dataSource = await IntegrationTestDatabase.getDataSource();
  67. const orderRepository = dataSource.getRepository(OrderMt);
  68. // 创建租户1的订单
  69. const tenant1Orders = await DataOverviewTestDataFactory.createTestOrders(dataSource, 1, 1);
  70. const tenant1Order = tenant1Orders[0];
  71. // 尝试使用租户2的ID查询租户1的订单
  72. const crossTenantOrder = await orderRepository.findOne({
  73. where: {
  74. orderNo: tenant1Order.orderNo,
  75. tenantId: 2 // 错误的租户ID
  76. }
  77. });
  78. expect(crossTenantOrder).toBeNull();
  79. });
  80. it('应该在创建数据时正确设置租户ID', async () => {
  81. const dataSource = await IntegrationTestDatabase.getDataSource();
  82. const orderRepository = dataSource.getRepository(OrderMt);
  83. const tenantId = 5;
  84. const orders = await DataOverviewTestDataFactory.createTestOrders(dataSource, tenantId, 1);
  85. const order = orders[0];
  86. expect(order.tenantId).toBe(tenantId);
  87. expect(order.createdBy).toBeDefined();
  88. });
  89. });
  90. describe('GET /api/data-overview/summary', () => {
  91. it('应该返回今日数据概览统计(默认时间范围)', async () => {
  92. // 创建测试订单数据
  93. const dataSource = await IntegrationTestDatabase.getDataSource();
  94. await DataOverviewTestDataFactory.createTestOrders(dataSource, testUser.tenantId, 5);
  95. const response = await client.summary.$get({
  96. query: {}
  97. }, {
  98. headers: {
  99. 'Authorization': `Bearer ${userToken}`
  100. }
  101. });
  102. expect(response.status).toBe(200);
  103. if (response.status === 200) {
  104. const data = await response.json();
  105. expect(data.success).toBe(true);
  106. expect(data.data).toBeDefined();
  107. expect(typeof data.data.totalSales).toBe('number');
  108. expect(typeof data.data.totalOrders).toBe('number');
  109. expect(typeof data.data.wechatSales).toBe('number');
  110. expect(typeof data.data.wechatOrders).toBe('number');
  111. expect(typeof data.data.creditSales).toBe('number');
  112. expect(typeof data.data.creditOrders).toBe('number');
  113. expect(typeof data.data.todaySales).toBe('number');
  114. expect(typeof data.data.todayOrders).toBe('number');
  115. }
  116. });
  117. it('应该支持自定义时间范围参数', async () => {
  118. const startDate = '2025-01-01T00:00:00Z';
  119. const endDate = '2025-01-31T23:59:59Z';
  120. const response = await client.summary.$get({
  121. query: {
  122. timeRange: 'custom',
  123. startDate,
  124. endDate
  125. }
  126. }, {
  127. headers: {
  128. 'Authorization': `Bearer ${userToken}`
  129. }
  130. });
  131. expect(response.status).toBe(200);
  132. if (response.status === 200) {
  133. const data = await response.json();
  134. expect(data.success).toBe(true);
  135. }
  136. });
  137. it('当时间范围参数无效时应该返回400错误', async () => {
  138. // 提供自定义时间范围但不提供startDate和endDate
  139. const response = await client.summary.$get({
  140. query: {
  141. timeRange: 'custom'
  142. // 缺少startDate和endDate
  143. }
  144. }, {
  145. headers: {
  146. 'Authorization': `Bearer ${userToken}`
  147. }
  148. });
  149. expect(response.status).toBe(400);
  150. });
  151. it('当startDate晚于endDate时应该返回400错误', async () => {
  152. const response = await client.summary.$get({
  153. query: {
  154. timeRange: 'custom',
  155. startDate: '2025-01-31T00:00:00Z',
  156. endDate: '2025-01-01T00:00:00Z'
  157. }
  158. }, {
  159. headers: {
  160. 'Authorization': `Bearer ${userToken}`
  161. }
  162. });
  163. expect(response.status).toBe(400);
  164. });
  165. it('应该验证多租户数据隔离', async () => {
  166. // 创建租户100的订单数据
  167. const dataSource = await IntegrationTestDatabase.getDataSource();
  168. const tenant100User = await DataOverviewTestDataFactory.createTestUser(dataSource, 100);
  169. const tenant100Token = DataOverviewTestDataFactory.generateUserToken(tenant100User);
  170. await DataOverviewTestDataFactory.createTestOrders(dataSource, 100, 3);
  171. // 创建租户101的用户和订单
  172. const tenant101User = await DataOverviewTestDataFactory.createTestUser(dataSource, 101);
  173. const tenant101Token = DataOverviewTestDataFactory.generateUserToken(tenant101User);
  174. await DataOverviewTestDataFactory.createTestOrders(dataSource, 101, 2);
  175. // 租户100查询应该只看到租户100的数据
  176. const response1 = await client.summary.$get({
  177. query: {}
  178. }, {
  179. headers: {
  180. 'Authorization': `Bearer ${tenant100Token}`
  181. }
  182. });
  183. // 租户101查询应该只看到租户101的数据
  184. const response2 = await client.summary.$get({
  185. query: {}
  186. }, {
  187. headers: {
  188. 'Authorization': `Bearer ${tenant101Token}`
  189. }
  190. });
  191. expect(response1.status).toBe(200);
  192. expect(response2.status).toBe(200);
  193. if (response1.status === 200 && response2.status === 200) {
  194. const data1 = await response1.json();
  195. const data2 = await response2.json();
  196. console.debug('租户100统计数据:', data1.data);
  197. console.debug('租户101统计数据:', data2.data);
  198. // 两个租户的统计数据应该独立
  199. expect(data1.data.totalOrders).toBe(3);
  200. expect(data2.data.totalOrders).toBe(2);
  201. }
  202. });
  203. it('应该支持缓存机制', async () => {
  204. // 第一次查询应该从数据库获取
  205. const dataSource = await IntegrationTestDatabase.getDataSource();
  206. await DataOverviewTestDataFactory.createTestOrders(dataSource, testUser.tenantId, 2);
  207. const response1 = await client.summary.$get({
  208. query: {}
  209. }, {
  210. headers: {
  211. 'Authorization': `Bearer ${userToken}`
  212. }
  213. });
  214. expect(response1.status).toBe(200);
  215. // 第二次查询(短时间内)应该从缓存获取相同结果
  216. const response2 = await client.summary.$get({
  217. query: {}
  218. }, {
  219. headers: {
  220. 'Authorization': `Bearer ${userToken}`
  221. }
  222. });
  223. expect(response2.status).toBe(200);
  224. if (response1.status === 200 && response2.status === 200) {
  225. const data1 = await response1.json();
  226. const data2 = await response2.json();
  227. expect(data1.data.totalOrders).toBe(data2.data.totalOrders);
  228. }
  229. });
  230. });
  231. describe('GET /api/data-overview/today', () => {
  232. it('应该返回今日实时统计数据', async () => {
  233. // 创建新租户的用户和token
  234. const dataSource = await IntegrationTestDatabase.getDataSource();
  235. const tenant103User = await DataOverviewTestDataFactory.createTestUser(dataSource, 103);
  236. const tenant103Token = DataOverviewTestDataFactory.generateUserToken(tenant103User);
  237. // 创建今日订单数据
  238. await DataOverviewTestDataFactory.createTodayTestOrders(dataSource, 103, 3);
  239. const response = await client.today.$get({}, {
  240. headers: {
  241. 'Authorization': `Bearer ${tenant103Token}`
  242. }
  243. });
  244. expect(response.status).toBe(200);
  245. if (response.status === 200) {
  246. const data = await response.json();
  247. expect(data.success).toBe(true);
  248. expect(data.data).toBeDefined();
  249. expect(typeof data.data.todaySales).toBe('number');
  250. expect(typeof data.data.todayOrders).toBe('number');
  251. expect(data.data.todayOrders).toBe(3);
  252. }
  253. });
  254. it('当没有今日订单时应该返回零值', async () => {
  255. // 创建新租户的用户和token(确保没有订单)
  256. const dataSource = await IntegrationTestDatabase.getDataSource();
  257. const tenant104User = await DataOverviewTestDataFactory.createTestUser(dataSource, 104);
  258. const tenant104Token = DataOverviewTestDataFactory.generateUserToken(tenant104User);
  259. const response = await client.today.$get({}, {
  260. headers: {
  261. 'Authorization': `Bearer ${tenant104Token}`
  262. }
  263. });
  264. expect(response.status).toBe(200);
  265. if (response.status === 200) {
  266. const data = await response.json();
  267. expect(data.data.todaySales).toBe(0);
  268. expect(data.data.todayOrders).toBe(0);
  269. }
  270. });
  271. });
  272. describe('认证和授权', () => {
  273. it('当缺少认证头时应该返回401错误', async () => {
  274. const response = await client.summary.$get({
  275. query: {}
  276. }); // 没有Authorization头
  277. expect(response.status).toBe(401);
  278. });
  279. it('当令牌无效时应该返回401错误', async () => {
  280. const response = await client.summary.$get({
  281. query: {}
  282. }, {
  283. headers: {
  284. 'Authorization': 'Bearer invalid-token'
  285. }
  286. });
  287. expect(response.status).toBe(401);
  288. });
  289. });
  290. });