data-overview-routes.integration.test.ts 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382
  1. import { describe, it, expect, beforeEach } from 'vitest';
  2. import { testClient } from 'hono/testing';
  3. import { IntegrationTestDatabase, setupIntegrationDatabaseHooksWithEntities } from '@d8d/shared-test-util';
  4. import { UserEntityMt, RoleMt } from '@d8d/core-module-mt/user-module-mt/entities';
  5. import { FileMt } from '@d8d/core-module-mt/file-module-mt/entities';
  6. import { OrderMt, OrderGoodsMt } from '@d8d/orders-module-mt';
  7. import { MerchantMt } from '@d8d/merchant-module-mt';
  8. import { SupplierMt } from '@d8d/supplier-module-mt';
  9. import { DeliveryAddressMt } from '@d8d/delivery-address-module-mt';
  10. import { AreaEntityMt } from '@d8d/geo-areas-mt';
  11. import { GoodsMt, GoodsCategoryMt } from '@d8d/goods-module-mt';
  12. import dataOverviewRoutes from '../../src/routes';
  13. import { DataOverviewTestDataFactory } from '../utils/test-data-factory';
  14. // 设置集成测试钩子 - 需要User、Role、File、Order及相关实体
  15. setupIntegrationDatabaseHooksWithEntities([
  16. UserEntityMt,
  17. RoleMt,
  18. FileMt,
  19. OrderMt,
  20. OrderGoodsMt,
  21. MerchantMt,
  22. SupplierMt,
  23. DeliveryAddressMt,
  24. AreaEntityMt,
  25. GoodsMt,
  26. GoodsCategoryMt
  27. ])
  28. describe('多租户数据概览API集成测试', () => {
  29. let client: ReturnType<typeof testClient<typeof dataOverviewRoutes>>;
  30. let userToken: string;
  31. let adminToken: string;
  32. let testUser: UserEntityMt;
  33. beforeEach(async () => {
  34. // 创建测试客户端
  35. client = testClient(dataOverviewRoutes);
  36. // 获取数据源并创建测试用户
  37. const dataSource = await IntegrationTestDatabase.getDataSource();
  38. // 创建租户1的测试用户
  39. testUser = await DataOverviewTestDataFactory.createTestUser(dataSource, 1);
  40. // 生成JWT令牌
  41. userToken = DataOverviewTestDataFactory.generateUserToken(testUser);
  42. adminToken = DataOverviewTestDataFactory.generateAdminToken(1);
  43. });
  44. describe('租户数据隔离验证', () => {
  45. it('应该确保订单数据的租户隔离', async () => {
  46. const dataSource = await IntegrationTestDatabase.getDataSource();
  47. const orderRepository = dataSource.getRepository(OrderMt);
  48. // 创建租户1的订单数据
  49. await DataOverviewTestDataFactory.createTestOrders(dataSource, 1, 2);
  50. // 创建租户2的订单数据
  51. await DataOverviewTestDataFactory.createTestOrders(dataSource, 2, 3);
  52. // 验证租户1只能看到租户1的订单
  53. const tenant1Orders = await orderRepository.find({
  54. where: { tenantId: 1 }
  55. });
  56. // 验证租户2只能看到租户2的订单
  57. const tenant2Orders = await orderRepository.find({
  58. where: { tenantId: 2 }
  59. });
  60. expect(tenant1Orders).toHaveLength(2);
  61. expect(tenant1Orders[0].tenantId).toBe(1);
  62. expect(tenant2Orders).toHaveLength(3);
  63. expect(tenant2Orders[0].tenantId).toBe(2);
  64. });
  65. it('应该防止跨租户数据访问', async () => {
  66. const dataSource = await IntegrationTestDatabase.getDataSource();
  67. const orderRepository = dataSource.getRepository(OrderMt);
  68. // 创建租户1的订单
  69. const tenant1Orders = await DataOverviewTestDataFactory.createTestOrders(dataSource, 1, 1);
  70. const tenant1Order = tenant1Orders[0];
  71. // 尝试使用租户2的ID查询租户1的订单
  72. const crossTenantOrder = await orderRepository.findOne({
  73. where: {
  74. orderNo: tenant1Order.orderNo,
  75. tenantId: 2 // 错误的租户ID
  76. }
  77. });
  78. expect(crossTenantOrder).toBeNull();
  79. });
  80. it('应该在创建数据时正确设置租户ID', async () => {
  81. const dataSource = await IntegrationTestDatabase.getDataSource();
  82. const orderRepository = dataSource.getRepository(OrderMt);
  83. const tenantId = 5;
  84. const orders = await DataOverviewTestDataFactory.createTestOrders(dataSource, tenantId, 1);
  85. const order = orders[0];
  86. expect(order.tenantId).toBe(tenantId);
  87. expect(order.createdBy).toBeDefined();
  88. });
  89. });
  90. describe('GET /api/data-overview/summary', () => {
  91. it('应该返回今日数据概览统计(默认时间范围)', async () => {
  92. // 创建测试订单数据
  93. const dataSource = await IntegrationTestDatabase.getDataSource();
  94. await DataOverviewTestDataFactory.createTestOrders(dataSource, testUser.tenantId, 5);
  95. const response = await client.summary.$get({
  96. query: { year: undefined }
  97. }, {
  98. headers: {
  99. 'Authorization': `Bearer ${userToken}`
  100. }
  101. });
  102. expect(response.status).toBe(200);
  103. if (response.status === 200) {
  104. const data = await response.json();
  105. expect(data.success).toBe(true);
  106. expect(data.data).toBeDefined();
  107. expect(typeof data.data.totalSales).toBe('number');
  108. expect(typeof data.data.totalOrders).toBe('number');
  109. expect(typeof data.data.wechatSales).toBe('number');
  110. expect(typeof data.data.wechatOrders).toBe('number');
  111. expect(typeof data.data.creditSales).toBe('number');
  112. expect(typeof data.data.creditOrders).toBe('number');
  113. }
  114. });
  115. it('应该支持自定义时间范围参数', async () => {
  116. const startDate = '2025-01-01T00:00:00Z';
  117. const endDate = '2025-01-31T23:59:59Z';
  118. const response = await client.summary.$get({
  119. query: {
  120. timeRange: 'custom',
  121. startDate,
  122. endDate,
  123. year: undefined
  124. }
  125. }, {
  126. headers: {
  127. 'Authorization': `Bearer ${userToken}`
  128. }
  129. });
  130. expect(response.status).toBe(200);
  131. if (response.status === 200) {
  132. const data = await response.json();
  133. expect(data.success).toBe(true);
  134. }
  135. });
  136. it('当时间范围参数无效时应该返回400错误', async () => {
  137. // 提供自定义时间范围但不提供startDate和endDate
  138. const response = await client.summary.$get({
  139. query: {
  140. timeRange: 'custom',
  141. year: undefined
  142. // 缺少startDate和endDate
  143. }
  144. }, {
  145. headers: {
  146. 'Authorization': `Bearer ${userToken}`
  147. }
  148. });
  149. expect(response.status).toBe(400);
  150. });
  151. it('当startDate晚于endDate时应该返回400错误', async () => {
  152. const response = await client.summary.$get({
  153. query: {
  154. timeRange: 'custom',
  155. startDate: '2025-01-31T00:00:00Z',
  156. endDate: '2025-01-01T00:00:00Z',
  157. year: undefined
  158. }
  159. }, {
  160. headers: {
  161. 'Authorization': `Bearer ${userToken}`
  162. }
  163. });
  164. expect(response.status).toBe(400);
  165. });
  166. it('应该验证多租户数据隔离', async () => {
  167. // 创建租户100的订单数据
  168. const dataSource = await IntegrationTestDatabase.getDataSource();
  169. const tenant100User = await DataOverviewTestDataFactory.createTestUser(dataSource, 100);
  170. const tenant100Token = DataOverviewTestDataFactory.generateUserToken(tenant100User);
  171. await DataOverviewTestDataFactory.createTestOrders(dataSource, 100, 3);
  172. // 创建租户101的用户和订单
  173. const tenant101User = await DataOverviewTestDataFactory.createTestUser(dataSource, 101);
  174. const tenant101Token = DataOverviewTestDataFactory.generateUserToken(tenant101User);
  175. await DataOverviewTestDataFactory.createTestOrders(dataSource, 101, 2);
  176. // 租户100查询应该只看到租户100的数据
  177. const response1 = await client.summary.$get({
  178. query: { year: undefined }
  179. }, {
  180. headers: {
  181. 'Authorization': `Bearer ${tenant100Token}`
  182. }
  183. });
  184. // 租户101查询应该只看到租户101的数据
  185. const response2 = await client.summary.$get({
  186. query: { year: undefined }
  187. }, {
  188. headers: {
  189. 'Authorization': `Bearer ${tenant101Token}`
  190. }
  191. });
  192. expect(response1.status).toBe(200);
  193. expect(response2.status).toBe(200);
  194. if (response1.status === 200 && response2.status === 200) {
  195. const data1 = await response1.json();
  196. const data2 = await response2.json();
  197. console.debug('租户100统计数据:', data1.data);
  198. console.debug('租户101统计数据:', data2.data);
  199. // 两个租户的统计数据应该独立
  200. expect(data1.data.totalOrders).toBe(3);
  201. expect(data2.data.totalOrders).toBe(2);
  202. }
  203. });
  204. it('应该支持缓存机制', async () => {
  205. // 第一次查询应该从数据库获取
  206. const dataSource = await IntegrationTestDatabase.getDataSource();
  207. await DataOverviewTestDataFactory.createTestOrders(dataSource, testUser.tenantId, 2);
  208. const response1 = await client.summary.$get({
  209. query: { year: undefined }
  210. }, {
  211. headers: {
  212. 'Authorization': `Bearer ${userToken}`
  213. }
  214. });
  215. expect(response1.status).toBe(200);
  216. // 第二次查询(短时间内)应该从缓存获取相同结果
  217. const response2 = await client.summary.$get({
  218. query: { year: undefined }
  219. }, {
  220. headers: {
  221. 'Authorization': `Bearer ${userToken}`
  222. }
  223. });
  224. expect(response2.status).toBe(200);
  225. if (response1.status === 200 && response2.status === 200) {
  226. const data1 = await response1.json();
  227. const data2 = await response2.json();
  228. expect(data1.data.totalOrders).toBe(data2.data.totalOrders);
  229. }
  230. });
  231. it('应该排除已取消的订单', async () => {
  232. // 创建新租户的用户和token
  233. const dataSource = await IntegrationTestDatabase.getDataSource();
  234. const tenant105User = await DataOverviewTestDataFactory.createTestUser(dataSource, 105);
  235. const tenant105Token = DataOverviewTestDataFactory.generateUserToken(tenant105User);
  236. const orderRepository = dataSource.getRepository(OrderMt);
  237. // 创建3个正常订单(支付成功,未取消)
  238. const normalOrders = await DataOverviewTestDataFactory.createTestOrders(dataSource, 105, 3);
  239. // 创建2个已取消的订单(设置cancelTime)
  240. const cancelledOrders = await DataOverviewTestDataFactory.createTestOrders(dataSource, 105, 2);
  241. for (const order of cancelledOrders) {
  242. order.cancelTime = new Date();
  243. order.cancelReason = '测试取消';
  244. await orderRepository.save(order);
  245. }
  246. const response = await client.summary.$get({
  247. query: { year: undefined }
  248. }, {
  249. headers: {
  250. 'Authorization': `Bearer ${tenant105Token}`
  251. }
  252. });
  253. expect(response.status).toBe(200);
  254. if (response.status === 200) {
  255. const data = await response.json();
  256. // 应该只统计3个正常订单,排除2个取消订单
  257. expect(data.data.totalOrders).toBe(3);
  258. expect(data.data.totalSales).toBeGreaterThan(0);
  259. // 验证支付方式分类统计也正确
  260. const totalFromPaymentTypes = data.data.wechatOrders + data.data.creditOrders;
  261. expect(totalFromPaymentTypes).toBe(3); // 3个正常订单
  262. }
  263. });
  264. });
  265. describe('GET /api/data-overview/today', () => {
  266. it('应该返回今日实时统计数据', async () => {
  267. // 创建新租户的用户和token
  268. const dataSource = await IntegrationTestDatabase.getDataSource();
  269. const tenant103User = await DataOverviewTestDataFactory.createTestUser(dataSource, 103);
  270. const tenant103Token = DataOverviewTestDataFactory.generateUserToken(tenant103User);
  271. // 创建今日订单数据
  272. await DataOverviewTestDataFactory.createTodayTestOrders(dataSource, 103, 3);
  273. const response = await client.today.$get({ query: {} }, {
  274. headers: {
  275. 'Authorization': `Bearer ${tenant103Token}`
  276. }
  277. });
  278. expect(response.status).toBe(200);
  279. if (response.status === 200) {
  280. const data = await response.json();
  281. expect(data.success).toBe(true);
  282. expect(data.data).toBeDefined();
  283. expect(typeof data.data.todaySales).toBe('number');
  284. expect(typeof data.data.todayOrders).toBe('number');
  285. expect(data.data.todayOrders).toBe(3);
  286. }
  287. });
  288. it('当没有今日订单时应该返回零值', async () => {
  289. // 创建新租户的用户和token(确保没有订单)
  290. const dataSource = await IntegrationTestDatabase.getDataSource();
  291. const tenant104User = await DataOverviewTestDataFactory.createTestUser(dataSource, 104);
  292. const tenant104Token = DataOverviewTestDataFactory.generateUserToken(tenant104User);
  293. const response = await client.today.$get({ query: {} }, {
  294. headers: {
  295. 'Authorization': `Bearer ${tenant104Token}`
  296. }
  297. });
  298. expect(response.status).toBe(200);
  299. if (response.status === 200) {
  300. const data = await response.json();
  301. expect(data.data.todaySales).toBe(0);
  302. expect(data.data.todayOrders).toBe(0);
  303. }
  304. });
  305. });
  306. describe('认证和授权', () => {
  307. it('当缺少认证头时应该返回401错误', async () => {
  308. const response = await client.summary.$get({
  309. query: { year: undefined }
  310. }); // 没有Authorization头
  311. expect(response.status).toBe(401);
  312. });
  313. it('当令牌无效时应该返回401错误', async () => {
  314. const response = await client.summary.$get({
  315. query: { year: undefined }
  316. }, {
  317. headers: {
  318. 'Authorization': 'Bearer invalid-token'
  319. }
  320. });
  321. expect(response.status).toBe(401);
  322. });
  323. });
  324. });