phone-decrypt.integration.test.ts 7.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245
  1. import { describe, it, expect, beforeEach, vi, afterEach } from 'vitest';
  2. import { testClient } from 'hono/testing';
  3. import { authRoutes } from '../../src/routes/index.mt';
  4. import { IntegrationTestDatabase, setupIntegrationDatabaseHooksWithEntities } from '@d8d/shared-test-util';
  5. import { RoleMt, UserEntityMt } from '@d8d/core-module-mt/user-module-mt';
  6. import { redisUtil, JWTUtil } from '@d8d/shared-utils';
  7. import { FileMt } from '@d8d/core-module-mt/file-module-mt';
  8. // Mock MiniAuthService 的 decryptPhoneNumber 方法
  9. vi.mock('../../src/services/mini-auth.service.mt', () => ({
  10. MiniAuthService: vi.fn().mockImplementation(() => ({
  11. decryptPhoneNumber: vi.fn().mockImplementation(async (encryptedData: string, iv: string, sessionKey: string) => {
  12. // 模拟解密过程
  13. if (!encryptedData || !iv || !sessionKey) {
  14. throw { code: 400, message: '加密数据或初始向量不能为空' };
  15. }
  16. // 根据不同的加密数据返回不同的手机号用于测试
  17. if (encryptedData === 'valid_encrypted_data') {
  18. return '13800138000';
  19. } else if (encryptedData === 'another_valid_data') {
  20. return '13900139000';
  21. } else {
  22. throw { code: 400, message: '解密失败' };
  23. }
  24. })
  25. }))
  26. }));
  27. // 设置集成测试钩子
  28. setupIntegrationDatabaseHooksWithEntities([UserEntityMt, FileMt, RoleMt])
  29. describe('手机号解密API集成测试', () => {
  30. let client: ReturnType<typeof testClient<typeof authRoutes>>;
  31. let testToken: string;
  32. let testUser: UserEntityMt;
  33. let getSessionKeySpy: any;
  34. beforeEach(async () => {
  35. // 创建测试客户端
  36. client = testClient(authRoutes);
  37. // 获取数据源
  38. const dataSource = await IntegrationTestDatabase.getDataSource();
  39. // 创建测试用户
  40. const userRepository = dataSource.getRepository(UserEntityMt);
  41. testUser = userRepository.create({
  42. username: `test_user_${Date.now()}`,
  43. password: 'test_password',
  44. nickname: '测试用户',
  45. phone: null, // 初始手机号为null
  46. registrationSource: 'web',
  47. tenantId: 1 // 设置租户ID
  48. });
  49. await userRepository.save(testUser);
  50. // 生成测试用户的token
  51. testToken = JWTUtil.generateToken({
  52. id: testUser.id,
  53. username: testUser.username,
  54. roles: [{name:'user'}]
  55. });
  56. // 使用 spyOn 来 mock getSessionKey 方法
  57. getSessionKeySpy = vi.spyOn(redisUtil, 'getSessionKey').mockResolvedValue('mock-session-key');
  58. });
  59. afterEach(() => {
  60. // 清理 spy
  61. if (getSessionKeySpy) {
  62. getSessionKeySpy.mockRestore();
  63. }
  64. });
  65. describe('POST /auth/phone-decrypt', () => {
  66. it('应该成功解密手机号并更新用户信息', async () => {
  67. const requestData = {
  68. encryptedData: 'valid_encrypted_data',
  69. iv: 'encryption_iv'
  70. };
  71. const response = await client['phone-decrypt'].$post({
  72. json: requestData
  73. },
  74. {
  75. headers: {
  76. 'Authorization': `Bearer ${testToken}`
  77. }
  78. });
  79. console.debug('响应状态:', response.status);
  80. if (response.status !== 200) {
  81. const errorData = await response.json();
  82. console.debug('错误响应:', errorData);
  83. }
  84. expect(response.status).toBe(200);
  85. if (response.status === 200) {
  86. const data = await response.json();
  87. // 验证响应数据格式
  88. expect(data).toHaveProperty('phoneNumber');
  89. expect(data).toHaveProperty('user');
  90. expect(data.phoneNumber).toBe('13800138000');
  91. expect(data.user.phone).toBe('13800138000');
  92. expect(data.user.id).toBe(testUser.id);
  93. }
  94. // 验证数据库中的用户手机号已更新
  95. const dataSource = await IntegrationTestDatabase.getDataSource();
  96. const userRepository = dataSource.getRepository(UserEntityMt);
  97. const updatedUser = await userRepository.findOne({
  98. where: { id: testUser.id }
  99. });
  100. expect(updatedUser?.phone).toBe('13800138000');
  101. });
  102. it('应该处理用户不存在的情况', async () => {
  103. const requestData = {
  104. encryptedData: 'valid_encrypted_data',
  105. iv: 'encryption_iv'
  106. };
  107. // 使用不存在的用户ID生成token
  108. const nonExistentUserToken = 'non_existent_user_token';
  109. const response = await client['phone-decrypt'].$post({
  110. json: requestData
  111. },
  112. {
  113. headers: {
  114. 'Authorization': `Bearer ${nonExistentUserToken}`
  115. }
  116. });
  117. // 当用户不存在时,应该返回401或404
  118. expect(response.status).toBe(401);
  119. });
  120. it('应该处理解密失败的情况', async () => {
  121. const requestData = {
  122. encryptedData: '', // 空加密数据
  123. iv: 'encryption_iv'
  124. };
  125. const response = await client['phone-decrypt'].$post({
  126. json: requestData
  127. },
  128. {
  129. headers: {
  130. 'Authorization': `Bearer ${testToken}`
  131. }
  132. });
  133. expect(response.status).toBe(400);
  134. if (response.status === 400) {
  135. const data = await response.json();
  136. expect(data.message).toBe('加密数据或初始向量不能为空');
  137. }
  138. });
  139. it('应该处理无效的加密数据', async () => {
  140. const requestData = {
  141. encryptedData: 'invalid_encrypted_data',
  142. iv: 'encryption_iv'
  143. };
  144. const response = await client['phone-decrypt'].$post({
  145. json: requestData
  146. },
  147. {
  148. headers: {
  149. 'Authorization': `Bearer ${testToken}`
  150. }
  151. });
  152. expect(response.status).toBe(400);
  153. if (response.status === 400) {
  154. const data = await response.json();
  155. expect(data.message).toBe('解密失败');
  156. }
  157. });
  158. it('应该拒绝未认证用户的访问', async () => {
  159. const requestData = {
  160. encryptedData: 'valid_encrypted_data',
  161. iv: 'encryption_iv'
  162. };
  163. const response = await client['phone-decrypt'].$post({
  164. json: requestData
  165. });
  166. expect(response.status).toBe(401);
  167. });
  168. it('应该拒绝无效token的访问', async () => {
  169. const requestData = {
  170. encryptedData: 'valid_encrypted_data',
  171. iv: 'encryption_iv'
  172. };
  173. const response = await client['phone-decrypt'].$post({
  174. json: requestData
  175. },
  176. {
  177. headers: {
  178. 'Authorization': 'Bearer invalid_token'
  179. }
  180. });
  181. expect(response.status).toBe(401);
  182. });
  183. it('应该处理sessionKey过期的情况', async () => {
  184. const requestData = {
  185. encryptedData: 'valid_encrypted_data',
  186. iv: 'encryption_iv'
  187. };
  188. // 模拟 sessionKey 过期的情况
  189. getSessionKeySpy.mockResolvedValue(null);
  190. const response = await client['phone-decrypt'].$post({
  191. json: requestData
  192. },
  193. {
  194. headers: {
  195. 'Authorization': `Bearer ${testToken}`
  196. }
  197. });
  198. expect(response.status).toBe(400);
  199. if (response.status === 400) {
  200. const data = await response.json();
  201. expect(data.message).toBe('sessionKey已过期,请重新登录');
  202. }
  203. });
  204. });
  205. });