payment-callback.integration.test.ts 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362
  1. import { describe, it, expect, beforeEach, vi, afterEach } from 'vitest';
  2. import { testClient } from 'hono/testing';
  3. import {
  4. IntegrationTestDatabase,
  5. setupIntegrationDatabaseHooksWithEntities
  6. } from '@d8d/shared-test-util';
  7. import { PaymentMtRoutes } from '../../src/routes/payment.mt.routes.js';
  8. import { PaymentMtEntity } from '../../src/entities/payment.mt.entity.js';
  9. import { PaymentStatus } from '../../src/entities/payment.types.js';
  10. import { UserEntityMt } from '@d8d/user-module-mt';
  11. import { RoleMt } from '@d8d/user-module-mt';
  12. import { FileMt } from '@d8d/file-module-mt';
  13. import { OrderMt } from '@d8d/orders-module-mt';
  14. import { MerchantMt } from '@d8d/merchant-module-mt';
  15. import { SupplierMt } from '@d8d/supplier-module-mt';
  16. import { DeliveryAddressMt } from '@d8d/delivery-address-module-mt';
  17. import { config } from 'dotenv';
  18. import { resolve } from 'path';
  19. // 导入微信支付SDK用于模拟
  20. import WxPay from 'wechatpay-node-v3';
  21. // 在测试环境中加载环境变量
  22. config({ path: resolve(process.cwd(), '.env.test') });
  23. vi.mock('wechatpay-node-v3')
  24. // 设置集成测试钩子
  25. setupIntegrationDatabaseHooksWithEntities([PaymentMtEntity, UserEntityMt, FileMt, RoleMt, OrderMt, MerchantMt, SupplierMt, DeliveryAddressMt])
  26. describe('支付回调API集成测试 - 多租户版本', () => {
  27. let client: ReturnType<typeof testClient<typeof PaymentMtRoutes>>;
  28. let testUser: UserEntityMt;
  29. let testPayment: PaymentMtEntity;
  30. let testOrder: OrderMt;
  31. // 使用真实的微信支付回调数据 - 直接使用原始请求体字符串
  32. const rawBody = '{"id":"495e231b-9fd8-54a1-8a30-2a38a807744c","create_time":"2025-10-25T12:48:11+08:00","resource_type":"encrypt-resource","event_type":"TRANSACTION.SUCCESS","summary":"支付成功","resource":{"original_type":"transaction","algorithm":"AEAD_AES_256_GCM","ciphertext":"tl1/8FRRn6g0gRq8IoVR8+95VuIADYBDOt6N9PKiHVhiD6l++W5g/wg6VlsCRIZJ+KWMYTaf5FzQHMjCs8o9otIkLLuJA2aZC+kCQtGxNfyVBwxool/tLT9mHd0dFGThqbj8vb/lm+jjNcmmiWHz+J1ZRvGl7mH4I714vudok7JRt5Q0u0tYaLWr76TTXuQErlA7T4KbeVeGAj8iMpu2ErCpR9QRif36Anc5ARjNYrIWfraXlmUXVbXermDyJ8r4o/4QCFfGk8L1u1WqNYASrRTQvQ8OPqj/J21OkDxbPPrOiEmAX1jOvONvIVEe9Lbkm6rdhW4aLRoZYtiusAk/Vm7MI/UYPwRZbyuc4wwdA1T1D4RdJd/m2I4KSvZHQgs0DM0tLqlb0z3880XYNr8iPFnyu2r8Z8LGcXD+COm06vc7bvNWh3ODwmMrmZQkym/Y/T3X/h/4MZj7+1h2vYHqnnrsgtNPHc/2IwWC/fQlPwtSrLh6iUxSd0betFpKLSq08CaJZvnenpDf1ORRMvd8EhTtIJJ4mV4v+VzCOYNhIcBhKp9XwsuhxIdkpGGmNPpow2c2BXY=","associated_data":"transaction","nonce":"sTnWce32BTQP"}}';
  33. const callbackHeader = {
  34. 'wechatpay-timestamp': '1761367693',
  35. 'wechatpay-nonce': 'PVDFxrQiJclkR28HpAYPDiIlS2VaGp9U',
  36. 'wechatpay-signature': 'hwR1KKN1bIPAhatIHTen7fwNDyvONS/picpcqSHtUCGkbvhYLVUqC87ksBJs6bovNI0cKNvrLr6gqp/HR4TK/ijgrD6w9W/oYc6bKyO9lNarggsQKHBv5x5yX8OjBOzqtgiHOVj44RCPrglJ5bFDlxIhnhs9jnGUine0qlvrVwBZAylt5X4oFmPammHoV4lLHtGt0L4zr5y6LoZL80LpctDCOCtwC4JdUUY5AumkMYo8lNs+xK0NAN7EVNKCWUzoQ1pVdBTGZWDP+b8+6gswP6JDsL3a4H4Fw3WGh4DZPskDQAe0sn85UGXO3m03OkDq3WkiCkOut4YZMuKBeCBpWA==',
  37. 'wechatpay-serial': '6C2C991E621267BFA5BFD5F32476427343A0B2AD'
  38. };
  39. beforeEach(async () => {
  40. // 创建测试客户端
  41. client = testClient(PaymentMtRoutes);
  42. // 创建测试用户
  43. const dataSource = await IntegrationTestDatabase.getDataSource();
  44. const userRepository = dataSource.getRepository(UserEntityMt);
  45. testUser = userRepository.create({
  46. username: `test_user_${Date.now()}`,
  47. password: 'test_password',
  48. nickname: '测试用户',
  49. openid: 'oJy1-16IIG18XZLl7G32k1hHMUFg',
  50. tenantId: 1
  51. });
  52. await userRepository.save(testUser);
  53. // 创建测试订单
  54. const orderRepository = dataSource.getRepository(OrderMt);
  55. testOrder = orderRepository.create({
  56. tenantId: 1,
  57. orderNo: `ORD${Date.now()}`,
  58. userId: testUser.id,
  59. amount: 1,
  60. costAmount: 0.5,
  61. payAmount: 1,
  62. orderType: 1,
  63. payType: 2,
  64. payState: 0, // 未支付
  65. state: 0,
  66. addressId: 0,
  67. merchantId: 0,
  68. supplierId: 0,
  69. createdBy: testUser.id,
  70. updatedBy: testUser.id
  71. });
  72. await orderRepository.save(testOrder);
  73. // 创建测试支付记录,使用与真实回调数据一致的金额
  74. const paymentRepository = dataSource.getRepository(PaymentMtEntity);
  75. testPayment = paymentRepository.create({
  76. externalOrderId: testOrder.id, // 使用订单ID作为外部订单ID
  77. userId: testUser.id,
  78. totalAmount: 1, // 1分钱,与真实回调数据一致
  79. description: '测试支付',
  80. paymentStatus: PaymentStatus.PROCESSING, // 设置为处理中状态,模拟已发起支付
  81. openid: testUser.openid!,
  82. outTradeNo: `ORDER_${testOrder.id}_${Date.now()}`,
  83. tenantId: 1
  84. });
  85. await paymentRepository.save(testPayment);
  86. // 设置微信支付SDK的全局mock
  87. const mockWxPay = {
  88. transactions_jsapi: vi.fn().mockResolvedValue({
  89. package: 'prepay_id=wx_test_prepay_id_123456',
  90. timeStamp: Math.floor(Date.now() / 1000).toString(),
  91. nonceStr: 'test_nonce_string',
  92. signType: 'RSA',
  93. paySign: 'test_pay_sign'
  94. }),
  95. verifySign: vi.fn().mockResolvedValue(true),
  96. decipher_gcm: vi.fn().mockReturnValue(JSON.stringify({
  97. out_trade_no: testPayment.outTradeNo, // 使用数据库中保存的 outTradeNo
  98. trade_state: 'SUCCESS',
  99. transaction_id: 'test_transaction_id',
  100. amount: {
  101. total: 1
  102. }
  103. })),
  104. getSignature: vi.fn().mockReturnValue('mock_signature')
  105. };
  106. // 模拟PaymentService的wxPay实例
  107. vi.mocked(WxPay).mockImplementation(() => mockWxPay as any);
  108. });
  109. afterEach(() => {
  110. // 清理 mock
  111. vi.mocked(WxPay).mockClear();
  112. });
  113. describe('POST /payment/callback - 支付回调', () => {
  114. it('应该成功处理支付成功回调并更新订单状态', async () => {
  115. const response = await client.payment.callback.$post({
  116. // 使用空的json参数,通过init传递原始请求体
  117. json: {}
  118. }, {
  119. headers: callbackHeader,
  120. init: {
  121. body: rawBody
  122. }
  123. });
  124. // 现在支付记录存在,回调处理应该成功
  125. expect(response.status).toBe(200);
  126. if (response.status === 200) {
  127. const result = await response.text();
  128. expect(result).toBe('SUCCESS');
  129. // 验证订单状态已更新为已支付 (2)
  130. const dataSource = await IntegrationTestDatabase.getDataSource();
  131. const orderRepository = dataSource.getRepository(OrderMt);
  132. const updatedOrder = await orderRepository.findOne({
  133. where: { id: testOrder.id, tenantId: 1 }
  134. });
  135. expect(updatedOrder).toBeDefined();
  136. expect(updatedOrder?.payState).toBe(2); // 已支付
  137. }
  138. });
  139. it('应该处理支付失败回调并更新订单状态', async () => {
  140. // 模拟支付失败的回调数据
  141. const mockWxPay = {
  142. verifySign: vi.fn().mockResolvedValue(true),
  143. decipher_gcm: vi.fn().mockReturnValue(JSON.stringify({
  144. out_trade_no: testPayment.outTradeNo,
  145. trade_state: 'FAIL',
  146. transaction_id: null,
  147. amount: {
  148. total: 1
  149. }
  150. }))
  151. };
  152. vi.mocked(WxPay).mockImplementation(() => mockWxPay as any);
  153. const response = await client.payment.callback.$post({
  154. json: {}
  155. }, {
  156. headers: callbackHeader,
  157. init: {
  158. body: rawBody
  159. }
  160. });
  161. expect(response.status).toBe(200);
  162. if (response.status === 200) {
  163. const result = await response.text();
  164. expect(result).toBe('SUCCESS');
  165. // 验证订单状态已更新为支付失败 (4)
  166. const dataSource = await IntegrationTestDatabase.getDataSource();
  167. const orderRepository = dataSource.getRepository(OrderMt);
  168. const updatedOrder = await orderRepository.findOne({
  169. where: { id: testOrder.id, tenantId: 1 }
  170. });
  171. expect(updatedOrder).toBeDefined();
  172. expect(updatedOrder?.payState).toBe(4); // 支付失败
  173. }
  174. });
  175. it('应该处理退款回调并更新订单状态', async () => {
  176. // 模拟退款回调数据
  177. const mockWxPay = {
  178. verifySign: vi.fn().mockResolvedValue(true),
  179. decipher_gcm: vi.fn().mockReturnValue(JSON.stringify({
  180. out_trade_no: testPayment.outTradeNo,
  181. trade_state: 'REFUND',
  182. transaction_id: 'test_refund_transaction_id',
  183. amount: {
  184. total: 1
  185. }
  186. }))
  187. };
  188. vi.mocked(WxPay).mockImplementation(() => mockWxPay as any);
  189. const response = await client.payment.callback.$post({
  190. json: {}
  191. }, {
  192. headers: callbackHeader,
  193. init: {
  194. body: rawBody
  195. }
  196. });
  197. expect(response.status).toBe(200);
  198. if (response.status === 200) {
  199. const result = await response.text();
  200. expect(result).toBe('SUCCESS');
  201. // 验证订单状态已更新为已退款 (3)
  202. const dataSource = await IntegrationTestDatabase.getDataSource();
  203. const orderRepository = dataSource.getRepository(OrderMt);
  204. const updatedOrder = await orderRepository.findOne({
  205. where: { id: testOrder.id, tenantId: 1 }
  206. });
  207. expect(updatedOrder).toBeDefined();
  208. expect(updatedOrder?.payState).toBe(3); // 已退款
  209. }
  210. });
  211. it('应该验证多租户数据隔离', async () => {
  212. // 创建第二个租户的测试数据
  213. const dataSource = await IntegrationTestDatabase.getDataSource();
  214. const userRepository = dataSource.getRepository(UserEntityMt);
  215. const testUser2 = userRepository.create({
  216. username: `test_user2_${Date.now()}`,
  217. password: 'test_password',
  218. nickname: '测试用户2',
  219. openid: 'oJy1-16IIG18XZLl7G32k1hHMUFg2',
  220. tenantId: 2
  221. });
  222. await userRepository.save(testUser2);
  223. const orderRepository = dataSource.getRepository(OrderMt);
  224. const testOrder2 = orderRepository.create({
  225. tenantId: 2,
  226. orderNo: `ORD${Date.now()}_2`,
  227. userId: testUser2.id,
  228. amount: 1,
  229. costAmount: 0.5,
  230. payAmount: 1,
  231. orderType: 1,
  232. payType: 2,
  233. payState: 0,
  234. state: 0,
  235. addressId: 0,
  236. merchantId: 0,
  237. supplierId: 0,
  238. createdBy: testUser2.id,
  239. updatedBy: testUser2.id
  240. });
  241. await orderRepository.save(testOrder2);
  242. const paymentRepository = dataSource.getRepository(PaymentMtEntity);
  243. const testPayment2 = paymentRepository.create({
  244. externalOrderId: testOrder2.id,
  245. userId: testUser2.id,
  246. totalAmount: 1,
  247. description: '测试支付2',
  248. paymentStatus: PaymentStatus.PROCESSING,
  249. openid: testUser2.openid!,
  250. outTradeNo: `ORDER_${testOrder2.id}_${Date.now()}`,
  251. tenantId: 2
  252. });
  253. await paymentRepository.save(testPayment2);
  254. // 处理租户1的支付回调
  255. const response = await client.payment.callback.$post({
  256. json: {}
  257. }, {
  258. headers: callbackHeader,
  259. init: {
  260. body: rawBody
  261. }
  262. });
  263. expect(response.status).toBe(200);
  264. // 验证租户1的订单状态已更新
  265. const updatedOrder1 = await orderRepository.findOne({
  266. where: { id: testOrder.id, tenantId: 1 }
  267. });
  268. expect(updatedOrder1?.payState).toBe(2); // 已支付
  269. // 验证租户2的订单状态未受影响
  270. const updatedOrder2 = await orderRepository.findOne({
  271. where: { id: testOrder2.id, tenantId: 2 }
  272. });
  273. expect(updatedOrder2?.payState).toBe(0); // 仍为未支付
  274. });
  275. it('应该处理无效的回调数据格式', async () => {
  276. const response = await client.payment.callback.$post({
  277. body: 'invalid json data'
  278. }, {
  279. headers: {
  280. ...callbackHeader,
  281. 'content-type': 'text/plain'
  282. }
  283. });
  284. // 由于JSON解析失败,应该返回500错误
  285. expect(response.status).toBe(500);
  286. });
  287. it('应该处理缺少必要头信息的情况', async () => {
  288. const response = await client.payment.callback.$post({
  289. body: rawBody
  290. }, {
  291. headers: {
  292. // 缺少必要的微信支付头信息
  293. 'Content-Type': 'text/plain'
  294. }
  295. });
  296. // 由于缺少必要头信息,应该返回500错误
  297. expect(response.status).toBe(500);
  298. });
  299. it('应该验证回调数据解密后的支付处理', async () => {
  300. const response = await client.payment.callback.$post({
  301. // 使用空的json参数,通过init传递原始请求体
  302. json: {}
  303. }, {
  304. headers: callbackHeader,
  305. init: {
  306. body: rawBody
  307. }
  308. });
  309. // 现在支付记录存在,回调处理应该成功
  310. expect(response.status).toBe(200);
  311. if (response.status === 200) {
  312. const result = await response.text();
  313. expect(result).toBe('SUCCESS');
  314. }
  315. });
  316. });
  317. });