user-routes.integration.test.ts 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565
  1. import { describe, it, expect, beforeEach, vi, afterEach } from 'vitest';
  2. import { testClient } from 'hono/testing';
  3. import { IntegrationTestDatabase, setupIntegrationDatabaseHooksWithEntities } from '@d8d/shared-test-util';
  4. import { JWTUtil } from '@d8d/shared-utils';
  5. import { UserEntity, Role } from '@d8d/user-module';
  6. import { AreaEntity, AreaLevel } from '@d8d/geo-areas';
  7. import { userDeliveryAddressRoutes } from '../../src/routes';
  8. import { DeliveryAddress } from '../../src/entities';
  9. // 设置集成测试钩子
  10. setupIntegrationDatabaseHooksWithEntities([UserEntity, Role, AreaEntity, DeliveryAddress])
  11. describe('用户配送地址管理API集成测试', () => {
  12. let client: ReturnType<typeof testClient<typeof userDeliveryAddressRoutes>>;
  13. let userToken: string;
  14. let otherUserToken: string;
  15. let testUser: UserEntity;
  16. let otherUser: UserEntity;
  17. let testProvince: AreaEntity;
  18. let testCity: AreaEntity;
  19. let testDistrict: AreaEntity;
  20. beforeEach(async () => {
  21. // 创建测试客户端
  22. client = testClient(userDeliveryAddressRoutes);
  23. // 获取数据源
  24. const dataSource = await IntegrationTestDatabase.getDataSource();
  25. // 创建测试用户
  26. const userRepository = dataSource.getRepository(UserEntity);
  27. testUser = userRepository.create({
  28. username: `test_user_${Date.now()}`,
  29. password: 'test_password',
  30. nickname: '测试用户',
  31. registrationSource: 'web'
  32. });
  33. await userRepository.save(testUser);
  34. // 创建其他用户
  35. otherUser = userRepository.create({
  36. username: `other_user_${Date.now()}`,
  37. password: 'other_password',
  38. nickname: '其他用户',
  39. registrationSource: 'web'
  40. });
  41. await userRepository.save(otherUser);
  42. // 创建测试地区数据 - 省
  43. const areaRepository = dataSource.getRepository(AreaEntity);
  44. testProvince = areaRepository.create({
  45. name: '北京市',
  46. code: '110000',
  47. level: AreaLevel.PROVINCE,
  48. parentId: null
  49. });
  50. await areaRepository.save(testProvince);
  51. // 创建测试地区数据 - 市
  52. testCity = areaRepository.create({
  53. name: '北京市',
  54. code: '110100',
  55. level: AreaLevel.CITY,
  56. parentId: testProvince.id
  57. });
  58. await areaRepository.save(testCity);
  59. // 创建测试地区数据 - 区
  60. testDistrict = areaRepository.create({
  61. name: '朝阳区',
  62. code: '110105',
  63. level: AreaLevel.DISTRICT,
  64. parentId: testCity.id
  65. });
  66. await areaRepository.save(testDistrict);
  67. // 生成测试用户的token
  68. userToken = JWTUtil.generateToken({
  69. id: testUser.id,
  70. username: testUser.username,
  71. roles: [{name:'user'}]
  72. });
  73. // 生成其他用户的token
  74. otherUserToken = JWTUtil.generateToken({
  75. id: otherUser.id,
  76. username: otherUser.username,
  77. roles: [{name:'user'}]
  78. });
  79. });
  80. describe('GET /delivery-address', () => {
  81. it('应该返回当前用户的配送地址列表', async () => {
  82. // 为测试用户创建一些地址
  83. const dataSource = await IntegrationTestDatabase.getDataSource();
  84. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  85. const userAddress1 = deliveryAddressRepository.create({
  86. userId: testUser.id,
  87. name: '用户地址1',
  88. phone: '13800138001',
  89. address: '用户地址1',
  90. receiverProvince: testProvince.id,
  91. receiverCity: testCity.id,
  92. receiverDistrict: testDistrict.id,
  93. receiverTown: 0,
  94. state: 1,
  95. isDefault: 0,
  96. createdBy: testUser.id
  97. });
  98. await deliveryAddressRepository.save(userAddress1);
  99. const userAddress2 = deliveryAddressRepository.create({
  100. userId: testUser.id,
  101. name: '用户地址2',
  102. phone: '13800138002',
  103. address: '用户地址2',
  104. receiverProvince: testProvince.id,
  105. receiverCity: testCity.id,
  106. receiverDistrict: testDistrict.id,
  107. receiverTown: 0,
  108. state: 1,
  109. isDefault: 0,
  110. createdBy: testUser.id
  111. });
  112. await deliveryAddressRepository.save(userAddress2);
  113. // 为其他用户创建一个地址,确保不会返回
  114. const otherUserAddress = deliveryAddressRepository.create({
  115. userId: otherUser.id,
  116. name: '其他用户地址',
  117. phone: '13800138003',
  118. address: '其他用户地址',
  119. receiverProvince: testProvince.id,
  120. receiverCity: testCity.id,
  121. receiverDistrict: testDistrict.id,
  122. receiverTown: 0,
  123. state: 1,
  124. isDefault: 0,
  125. createdBy: otherUser.id
  126. });
  127. await deliveryAddressRepository.save(otherUserAddress);
  128. const response = await client.index.$get({
  129. query: {}
  130. }, {
  131. headers: {
  132. 'Authorization': `Bearer ${userToken}`
  133. }
  134. });
  135. console.debug('用户配送地址列表响应状态:', response.status);
  136. expect(response.status).toBe(200);
  137. if (response.status === 200) {
  138. const data = await response.json();
  139. if (data && 'data' in data) {
  140. expect(Array.isArray(data.data)).toBe(true);
  141. // 应该只返回当前用户的地址
  142. data.data.forEach((address: any) => {
  143. expect(address.userId).toBe(testUser.id);
  144. });
  145. }
  146. }
  147. });
  148. it('应该拒绝未认证用户的访问', async () => {
  149. const response = await client.index.$get({
  150. query: {}
  151. });
  152. expect(response.status).toBe(401);
  153. });
  154. });
  155. describe('POST /delivery-address', () => {
  156. it('应该成功创建配送地址并自动使用当前用户ID', async () => {
  157. const createData = {
  158. name: '张三',
  159. phone: '13800138000',
  160. address: '朝阳区建国路88号',
  161. receiverProvince: testProvince.id,
  162. receiverCity: testCity.id,
  163. receiverDistrict: testDistrict.id,
  164. receiverTown: 0,
  165. state: 1,
  166. isDefault: 1
  167. };
  168. const response = await client.index.$post({
  169. json: createData
  170. }, {
  171. headers: {
  172. 'Authorization': `Bearer ${userToken}`
  173. }
  174. });
  175. console.debug('用户创建配送地址响应状态:', response.status);
  176. expect(response.status).toBe(201);
  177. if (response.status === 201) {
  178. const data = await response.json();
  179. expect(data).toHaveProperty('id');
  180. expect(data.userId).toBe(testUser.id); // 自动使用当前用户ID
  181. expect(data.name).toBe(createData.name);
  182. expect(data.phone).toBe(createData.phone);
  183. expect(data.address).toBe(createData.address);
  184. }
  185. });
  186. it('应该验证创建配送地址的必填字段', async () => {
  187. const invalidData = {
  188. // 缺少必填字段
  189. name: '',
  190. phone: '',
  191. address: '',
  192. receiverProvince: 0,
  193. receiverCity: 0,
  194. receiverDistrict: 0
  195. };
  196. const response = await client.index.$post({
  197. json: invalidData
  198. }, {
  199. headers: {
  200. 'Authorization': `Bearer ${userToken}`
  201. }
  202. });
  203. expect(response.status).toBe(400);
  204. });
  205. });
  206. describe('GET /delivery-address/:id', () => {
  207. it('应该返回当前用户的配送地址详情', async () => {
  208. // 先为当前用户创建一个配送地址
  209. const dataSource = await IntegrationTestDatabase.getDataSource();
  210. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  211. const testDeliveryAddress = deliveryAddressRepository.create({
  212. userId: testUser.id,
  213. name: '王五',
  214. phone: '13600136000',
  215. address: '海淀区中关村大街1号',
  216. receiverProvince: testProvince.id,
  217. receiverCity: testCity.id,
  218. receiverDistrict: testDistrict.id,
  219. receiverTown: 0,
  220. state: 1,
  221. isDefault: 0,
  222. createdBy: testUser.id
  223. });
  224. await deliveryAddressRepository.save(testDeliveryAddress);
  225. const response = await client[':id'].$get({
  226. param: { id: testDeliveryAddress.id }
  227. }, {
  228. headers: {
  229. 'Authorization': `Bearer ${userToken}`
  230. }
  231. });
  232. console.debug('用户配送地址详情响应状态:', response.status);
  233. expect(response.status).toBe(200);
  234. if (response.status === 200) {
  235. const data = await response.json();
  236. expect(data.id).toBe(testDeliveryAddress.id);
  237. expect(data.userId).toBe(testUser.id);
  238. expect(data.name).toBe(testDeliveryAddress.name);
  239. expect(data.phone).toBe(testDeliveryAddress.phone);
  240. expect(data.address).toBe(testDeliveryAddress.address);
  241. }
  242. });
  243. it('应该拒绝访问其他用户的配送地址', async () => {
  244. // 为其他用户创建一个配送地址
  245. const dataSource = await IntegrationTestDatabase.getDataSource();
  246. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  247. const otherUserAddress = deliveryAddressRepository.create({
  248. userId: otherUser.id,
  249. name: '其他用户地址',
  250. phone: '13600136001',
  251. address: '其他用户地址',
  252. receiverProvince: testProvince.id,
  253. receiverCity: testCity.id,
  254. receiverDistrict: testDistrict.id,
  255. receiverTown: 0,
  256. state: 1,
  257. isDefault: 0,
  258. createdBy: otherUser.id
  259. });
  260. await deliveryAddressRepository.save(otherUserAddress);
  261. // 当前用户尝试访问其他用户的地址
  262. const response = await client[':id'].$get({
  263. param: { id: otherUserAddress.id }
  264. }, {
  265. headers: {
  266. 'Authorization': `Bearer ${userToken}`
  267. }
  268. });
  269. console.debug('用户访问其他用户地址响应状态:', response.status);
  270. expect(response.status).toBe(404); // 应该返回404,而不是403
  271. });
  272. it('应该处理不存在的配送地址', async () => {
  273. const response = await client[':id'].$get({
  274. param: { id: 999999 }
  275. }, {
  276. headers: {
  277. 'Authorization': `Bearer ${userToken}`
  278. }
  279. });
  280. expect(response.status).toBe(404);
  281. });
  282. });
  283. describe('PUT /delivery-address/:id', () => {
  284. it('应该成功更新当前用户的配送地址', async () => {
  285. // 先为当前用户创建一个配送地址
  286. const dataSource = await IntegrationTestDatabase.getDataSource();
  287. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  288. const testDeliveryAddress = deliveryAddressRepository.create({
  289. userId: testUser.id,
  290. name: '原始姓名',
  291. phone: '13500135000',
  292. address: '原始地址',
  293. receiverProvince: testProvince.id,
  294. receiverCity: testCity.id,
  295. receiverDistrict: testDistrict.id,
  296. receiverTown: 0,
  297. state: 1,
  298. isDefault: 0,
  299. createdBy: testUser.id
  300. });
  301. await deliveryAddressRepository.save(testDeliveryAddress);
  302. const updateData = {
  303. name: '更新后的姓名',
  304. phone: '13700137000',
  305. address: '更新后的地址',
  306. isDefault: 1
  307. };
  308. const response = await client[':id'].$put({
  309. param: { id: testDeliveryAddress.id },
  310. json: updateData
  311. }, {
  312. headers: {
  313. 'Authorization': `Bearer ${userToken}`
  314. }
  315. });
  316. console.debug('用户更新配送地址响应状态:', response.status);
  317. expect(response.status).toBe(200);
  318. if (response.status === 200) {
  319. const data = await response.json();
  320. expect(data.name).toBe(updateData.name);
  321. expect(data.phone).toBe(updateData.phone);
  322. expect(data.address).toBe(updateData.address);
  323. expect(data.isDefault).toBe(updateData.isDefault);
  324. }
  325. });
  326. it('应该拒绝更新其他用户的配送地址', async () => {
  327. // 为其他用户创建一个配送地址
  328. const dataSource = await IntegrationTestDatabase.getDataSource();
  329. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  330. const otherUserAddress = deliveryAddressRepository.create({
  331. userId: otherUser.id,
  332. name: '其他用户地址',
  333. phone: '13500135001',
  334. address: '其他用户地址',
  335. receiverProvince: testProvince.id,
  336. receiverCity: testCity.id,
  337. receiverDistrict: testDistrict.id,
  338. receiverTown: 0,
  339. state: 1,
  340. isDefault: 0,
  341. createdBy: otherUser.id
  342. });
  343. await deliveryAddressRepository.save(otherUserAddress);
  344. const updateData = {
  345. name: '尝试更新的姓名',
  346. phone: '13700137001',
  347. address: '尝试更新的地址'
  348. };
  349. // 当前用户尝试更新其他用户的地址
  350. const response = await client[':id'].$put({
  351. param: { id: otherUserAddress.id },
  352. json: updateData
  353. }, {
  354. headers: {
  355. 'Authorization': `Bearer ${userToken}`
  356. }
  357. });
  358. console.debug('用户更新其他用户地址响应状态:', response.status);
  359. expect(response.status).toBe(404); // 应该返回404,而不是403
  360. });
  361. });
  362. describe('DELETE /delivery-address/:id', () => {
  363. it('应该成功删除当前用户的配送地址', async () => {
  364. // 先为当前用户创建一个配送地址
  365. const dataSource = await IntegrationTestDatabase.getDataSource();
  366. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  367. const testDeliveryAddress = deliveryAddressRepository.create({
  368. userId: testUser.id,
  369. name: '待删除地址',
  370. phone: '13400134000',
  371. address: '待删除地址',
  372. receiverProvince: testProvince.id,
  373. receiverCity: testCity.id,
  374. receiverDistrict: testDistrict.id,
  375. receiverTown: 0,
  376. state: 1,
  377. isDefault: 0,
  378. createdBy: testUser.id
  379. });
  380. await deliveryAddressRepository.save(testDeliveryAddress);
  381. const response = await client[':id'].$delete({
  382. param: { id: testDeliveryAddress.id }
  383. }, {
  384. headers: {
  385. 'Authorization': `Bearer ${userToken}`
  386. }
  387. });
  388. console.debug('用户删除配送地址响应状态:', response.status);
  389. expect(response.status).toBe(204);
  390. // 验证配送地址确实被删除
  391. const deletedDeliveryAddress = await deliveryAddressRepository.findOne({
  392. where: { id: testDeliveryAddress.id }
  393. });
  394. expect(deletedDeliveryAddress).toBeNull();
  395. });
  396. it('应该拒绝删除其他用户的配送地址', async () => {
  397. // 为其他用户创建一个配送地址
  398. const dataSource = await IntegrationTestDatabase.getDataSource();
  399. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  400. const otherUserAddress = deliveryAddressRepository.create({
  401. userId: otherUser.id,
  402. name: '其他用户地址',
  403. phone: '13400134001',
  404. address: '其他用户地址',
  405. receiverProvince: testProvince.id,
  406. receiverCity: testCity.id,
  407. receiverDistrict: testDistrict.id,
  408. receiverTown: 0,
  409. state: 1,
  410. isDefault: 0,
  411. createdBy: otherUser.id
  412. });
  413. await deliveryAddressRepository.save(otherUserAddress);
  414. // 当前用户尝试删除其他用户的地址
  415. const response = await client[':id'].$delete({
  416. param: { id: otherUserAddress.id }
  417. }, {
  418. headers: {
  419. 'Authorization': `Bearer ${userToken}`
  420. }
  421. });
  422. console.debug('用户删除其他用户地址响应状态:', response.status);
  423. expect(response.status).toBe(404); // 应该返回404,而不是403
  424. });
  425. });
  426. describe('数据权限验证', () => {
  427. it('用户应该只能访问和操作自己的数据', async () => {
  428. // 为两个用户都创建地址
  429. const dataSource = await IntegrationTestDatabase.getDataSource();
  430. const deliveryAddressRepository = dataSource.getRepository(DeliveryAddress);
  431. const userAddress = deliveryAddressRepository.create({
  432. userId: testUser.id,
  433. name: '用户地址',
  434. phone: '13800138004',
  435. address: '用户地址',
  436. receiverProvince: testProvince.id,
  437. receiverCity: testCity.id,
  438. receiverDistrict: testDistrict.id,
  439. receiverTown: 0,
  440. state: 1,
  441. isDefault: 0,
  442. createdBy: testUser.id
  443. });
  444. await deliveryAddressRepository.save(userAddress);
  445. const otherUserAddress = deliveryAddressRepository.create({
  446. userId: otherUser.id,
  447. name: '其他用户地址',
  448. phone: '13800138005',
  449. address: '其他用户地址',
  450. receiverProvince: testProvince.id,
  451. receiverCity: testCity.id,
  452. receiverDistrict: testDistrict.id,
  453. receiverTown: 0,
  454. state: 1,
  455. isDefault: 0,
  456. createdBy: otherUser.id
  457. });
  458. await deliveryAddressRepository.save(otherUserAddress);
  459. // 当前用户应该只能看到自己的地址
  460. const listResponse = await client.index.$get({
  461. query: {}
  462. }, {
  463. headers: {
  464. 'Authorization': `Bearer ${userToken}`
  465. }
  466. });
  467. expect(listResponse.status).toBe(200);
  468. const listData = await listResponse.json();
  469. if (listData && 'data' in listData) {
  470. expect(Array.isArray(listData.data)).toBe(true);
  471. // 应该只包含当前用户的地址
  472. listData.data.forEach((address: any) => {
  473. expect(address.userId).toBe(testUser.id);
  474. });
  475. }
  476. // 当前用户应该无法访问其他用户的地址详情
  477. const getResponse = await client[':id'].$get({
  478. param: { id: otherUserAddress.id }
  479. }, {
  480. headers: {
  481. 'Authorization': `Bearer ${userToken}`
  482. }
  483. });
  484. expect(getResponse.status).toBe(404);
  485. // 当前用户应该无法更新其他用户的地址
  486. const updateResponse = await client[':id'].$put({
  487. param: { id: otherUserAddress.id },
  488. json: { name: '尝试更新' }
  489. }, {
  490. headers: {
  491. 'Authorization': `Bearer ${userToken}`
  492. }
  493. });
  494. expect(updateResponse.status).toBe(404);
  495. // 当前用户应该无法删除其他用户的地址
  496. const deleteResponse = await client[':id'].$delete({
  497. param: { id: otherUserAddress.id }
  498. }, {
  499. headers: {
  500. 'Authorization': `Bearer ${userToken}`
  501. }
  502. });
  503. expect(deleteResponse.status).toBe(404);
  504. });
  505. });
  506. });