payment.integration.test.ts 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397
  1. import { describe, it, expect, beforeEach, vi, afterEach } from 'vitest';
  2. import { testClient } from 'hono/testing';
  3. import {
  4. IntegrationTestDatabase,
  5. setupIntegrationDatabaseHooksWithEntities
  6. } from '@d8d/shared-test-util';
  7. import { PaymentRoutes } from '../../src/routes/payment.routes.js';
  8. import { PaymentEntity } from '../../src/entities/payment.entity.js';
  9. import { PaymentStatus } from '../../src/entities/payment.types.js';
  10. import { UserEntity } from '@d8d/user-module';
  11. import { Role } from '@d8d/user-module';
  12. import { File } from '@d8d/file-module';
  13. import { JWTUtil } from '@d8d/shared-utils';
  14. import { config } from 'dotenv';
  15. import { resolve } from 'path';
  16. // 导入微信支付SDK用于模拟
  17. import WxPay from 'wechatpay-node-v3';
  18. // 在测试环境中加载环境变量
  19. config({ path: resolve(process.cwd(), '.env.test') });
  20. vi.mock('wechatpay-node-v3')
  21. // 设置集成测试钩子
  22. setupIntegrationDatabaseHooksWithEntities([PaymentEntity, UserEntity, File, Role])
  23. describe('支付API集成测试', () => {
  24. let client: ReturnType<typeof testClient<typeof PaymentRoutes>>;
  25. let testToken: string;
  26. let testUser: UserEntity;
  27. let testPayment: PaymentEntity;
  28. beforeEach(async () => {
  29. // 创建测试客户端
  30. client = testClient(PaymentRoutes);
  31. // 创建测试用户并生成token
  32. const dataSource = await IntegrationTestDatabase.getDataSource();
  33. const userRepository = dataSource.getRepository(UserEntity);
  34. testUser = userRepository.create({
  35. username: `test_user_${Date.now()}`,
  36. password: 'test_password',
  37. nickname: '测试用户',
  38. openid: 'oJy1-16IIG18XZLl7G32k1hHMUFg'
  39. });
  40. await userRepository.save(testUser);
  41. // 生成测试用户的token
  42. testToken = JWTUtil.generateToken({
  43. id: testUser.id,
  44. username: testUser.username,
  45. roles: [{name:'user'}]
  46. });
  47. // 创建测试支付记录
  48. const paymentRepository = dataSource.getRepository(PaymentEntity);
  49. testPayment = paymentRepository.create({
  50. externalOrderId: 1,
  51. userId: testUser.id,
  52. totalAmount: 20000,
  53. description: '测试支付',
  54. paymentStatus: PaymentStatus.PENDING,
  55. openid: testUser.openid!
  56. });
  57. await paymentRepository.save(testPayment);
  58. // 设置微信支付SDK的全局mock
  59. const mockWxPay = {
  60. transactions_jsapi: vi.fn().mockResolvedValue({
  61. package: 'prepay_id=wx_test_prepay_id_123456',
  62. timeStamp: Math.floor(Date.now() / 1000).toString(),
  63. nonceStr: 'test_nonce_string',
  64. signType: 'RSA',
  65. paySign: 'test_pay_sign'
  66. }),
  67. verifySign: vi.fn().mockResolvedValue(true),
  68. decipher_gcm: vi.fn().mockReturnValue(JSON.stringify({
  69. out_trade_no: `ORDER_${testPayment.id}_${Date.now()}`,
  70. trade_state: 'SUCCESS',
  71. transaction_id: 'test_transaction_id',
  72. amount: {
  73. total: 20000
  74. }
  75. })),
  76. getSignature: vi.fn().mockReturnValue('mock_signature')
  77. };
  78. // 模拟PaymentService的wxPay实例
  79. vi.mocked(WxPay).mockImplementation(() => mockWxPay as any);
  80. });
  81. describe('POST /payment - 创建支付', () => {
  82. it('应该成功创建支付订单', async () => {
  83. const response = await client.payment.$post({
  84. json: {
  85. externalOrderId: testPayment.externalOrderId,
  86. totalAmount: 20000, // 200元,单位分
  87. description: '测试支付订单'
  88. },
  89. },
  90. {
  91. headers: {
  92. 'Authorization': `Bearer ${testToken}`
  93. }
  94. });
  95. expect(response.status).toBe(200);
  96. if (response.status === 200) {
  97. const result = await response.json();
  98. console.debug('支付创建返回结果:', result);
  99. expect(result).toHaveProperty('paymentId');
  100. expect(result).toHaveProperty('timeStamp');
  101. expect(result).toHaveProperty('nonceStr');
  102. expect(result).toHaveProperty('package');
  103. expect(result).toHaveProperty('signType');
  104. expect(result).toHaveProperty('paySign');
  105. expect(result).toHaveProperty('totalAmount'); // 验证新增的金额字段
  106. expect(result.paymentId).toBeDefined();
  107. expect(result.paymentId).not.toBe('undefined');
  108. expect(result.totalAmount).toBe(20000); // 验证金额正确返回
  109. }
  110. });
  111. it('应该拒绝未认证的请求', async () => {
  112. const response = await client.payment.$post({
  113. json: {
  114. externalOrderId: testPayment.externalOrderId,
  115. totalAmount: 20000,
  116. description: '测试支付订单'
  117. }
  118. });
  119. expect(response.status).toBe(401);
  120. });
  121. it('应该验证外部订单存在性', async () => {
  122. const response = await client.payment.$post({
  123. json: {
  124. externalOrderId: 99999, // 不存在的外部订单ID
  125. totalAmount: 20000,
  126. description: '测试支付订单'
  127. },
  128. },
  129. {
  130. headers: {
  131. 'Authorization': `Bearer ${testToken}`
  132. }
  133. });
  134. expect(response.status).toBe(500);
  135. if (response.status === 500) {
  136. const result = await response.json();
  137. expect(result.message).toContain('支付记录不存在');
  138. }
  139. });
  140. it('应该验证支付金额匹配', async () => {
  141. const response = await client.payment.$post({
  142. json: {
  143. externalOrderId: testPayment.externalOrderId,
  144. totalAmount: 30000, // 金额不匹配
  145. description: '测试支付订单'
  146. },
  147. },
  148. {
  149. headers: {
  150. 'Authorization': `Bearer ${testToken}`
  151. }
  152. });
  153. expect(response.status).toBe(500);
  154. if (response.status === 500) {
  155. const result = await response.json();
  156. expect(result.message).toContain('支付金额与记录金额不匹配');
  157. }
  158. });
  159. it('应该验证支付状态', async () => {
  160. // 更新支付状态为已支付
  161. const dataSource = await IntegrationTestDatabase.getDataSource();
  162. const paymentRepository = dataSource.getRepository(PaymentEntity);
  163. await paymentRepository.update(testPayment.id, {
  164. paymentStatus: PaymentStatus.SUCCESS
  165. });
  166. const response = await client.payment.$post({
  167. json: {
  168. externalOrderId: testPayment.externalOrderId,
  169. totalAmount: 20000,
  170. description: '测试支付订单'
  171. },
  172. },
  173. {
  174. headers: {
  175. 'Authorization': `Bearer ${testToken}`
  176. }
  177. });
  178. expect(response.status).toBe(500);
  179. if (response.status === 500) {
  180. const result = await response.json();
  181. expect(result.message).toContain('支付状态不正确');
  182. }
  183. });
  184. it('应该拒绝没有openid的用户支付', async () => {
  185. // 创建没有openid的测试用户
  186. const dataSource = await IntegrationTestDatabase.getDataSource();
  187. const userRepository = dataSource.getRepository(UserEntity);
  188. const userWithoutOpenid = userRepository.create({
  189. username: `test_user_no_openid_${Date.now()}`,
  190. password: 'test_password',
  191. nickname: '测试用户无OpenID',
  192. openid: null
  193. });
  194. await userRepository.save(userWithoutOpenid);
  195. const tokenWithoutOpenid = JWTUtil.generateToken({
  196. id: userWithoutOpenid.id,
  197. username: userWithoutOpenid.username,
  198. roles: [{name:'user'}]
  199. });
  200. const response = await client.payment.$post({
  201. json: {
  202. externalOrderId: testPayment.externalOrderId,
  203. totalAmount: 20000,
  204. description: '测试支付订单'
  205. },
  206. },
  207. {
  208. headers: {
  209. 'Authorization': `Bearer ${tokenWithoutOpenid}`
  210. }
  211. });
  212. expect(response.status).toBe(400);
  213. if (response.status === 400) {
  214. const result = await response.json();
  215. expect(result.message).toContain('用户未绑定微信小程序');
  216. }
  217. });
  218. });
  219. describe('POST /payment/callback - 支付回调', () => {
  220. it('应该成功处理支付成功回调', async () => {
  221. const timestamp = Math.floor(Date.now() / 1000).toString();
  222. const nonce = Math.random().toString(36).substring(2, 15);
  223. const callbackData = {
  224. id: 'EV-201802251122332345',
  225. create_time: '2018-06-08T10:34:56+08:00',
  226. event_type: 'TRANSACTION.SUCCESS',
  227. resource_type: 'encrypt-resource',
  228. resource: {
  229. algorithm: 'AEAD_AES_256_GCM',
  230. ciphertext: 'encrypted_data',
  231. nonce: 'random_nonce',
  232. associated_data: 'associated_data'
  233. },
  234. summary: 'payment_success'
  235. };
  236. const response = await client.payment.callback.$post({
  237. json: callbackData
  238. }, {
  239. headers: {
  240. 'wechatpay-timestamp': timestamp,
  241. 'wechatpay-nonce': nonce,
  242. 'wechatpay-signature': 'mock_signature_for_test',
  243. 'wechatpay-serial': process.env.WECHAT_PLATFORM_CERT_SERIAL_NO || ''
  244. }
  245. });
  246. expect(response.status).toBe(200);
  247. if (response.status === 200) {
  248. const result = await response.text();
  249. expect(result).toBe('SUCCESS');
  250. }
  251. });
  252. it('应该处理支付失败回调', async () => {
  253. const timestamp = Math.floor(Date.now() / 1000).toString();
  254. const nonce = Math.random().toString(36).substring(2, 15);
  255. const callbackData = {
  256. id: 'EV-201802251122332346',
  257. create_time: '2018-06-08T10:34:56+08:00',
  258. event_type: 'TRANSACTION.FAIL',
  259. resource_type: 'encrypt-resource',
  260. resource: {
  261. algorithm: 'AEAD_AES_256_GCM',
  262. ciphertext: 'encrypted_data',
  263. nonce: 'random_nonce',
  264. associated_data: 'associated_data'
  265. },
  266. summary: 'payment_failed'
  267. };
  268. const response = await client.payment.callback.$post({
  269. json: callbackData
  270. }, {
  271. headers: {
  272. 'wechatpay-timestamp': timestamp,
  273. 'wechatpay-nonce': nonce,
  274. 'wechatpay-signature': 'mock_signature_for_test',
  275. 'wechatpay-serial': process.env.WECHAT_PLATFORM_CERT_SERIAL_NO || ''
  276. }
  277. });
  278. expect(response.status).toBe(200);
  279. if (response.status === 200) {
  280. const result = await response.text();
  281. expect(result).toBe('SUCCESS');
  282. }
  283. });
  284. it('应该处理无效的回调数据', async () => {
  285. const response = await client.payment.callback.$post({
  286. json: { invalid: 'data' } as any
  287. }, {
  288. headers: {
  289. 'wechatpay-timestamp': '1622456896',
  290. 'wechatpay-nonce': 'random_nonce_string',
  291. 'wechatpay-signature': 'signature_data',
  292. 'wechatpay-serial': process.env.WECHAT_PLATFORM_CERT_SERIAL_NO || ''
  293. }
  294. });
  295. expect(response.status).toBe(400);
  296. });
  297. });
  298. describe('支付状态流转测试', () => {
  299. it('应该正确更新支付状态', async () => {
  300. // 创建支付
  301. const createResponse = await client.payment.$post({
  302. json: {
  303. externalOrderId: testPayment.externalOrderId,
  304. totalAmount: 20000,
  305. description: '测试支付订单'
  306. },
  307. },
  308. {
  309. headers: {
  310. 'Authorization': `Bearer ${testToken}`
  311. }
  312. });
  313. expect(createResponse.status).toBe(200);
  314. // 验证支付状态已更新为处理中
  315. const dataSource = await IntegrationTestDatabase.getDataSource();
  316. const paymentRepository = dataSource.getRepository(PaymentEntity);
  317. const updatedPayment = await paymentRepository.findOne({
  318. where: { id: testPayment.id }
  319. });
  320. expect(updatedPayment?.paymentStatus).toBe(PaymentStatus.PROCESSING);
  321. });
  322. });
  323. describe('微信支付JSAPI参数生成测试', () => {
  324. it('应该生成正确的支付参数格式', async () => {
  325. const response = await client.payment.$post({
  326. json: {
  327. externalOrderId: testPayment.externalOrderId,
  328. totalAmount: 20000,
  329. description: '测试支付订单'
  330. },
  331. },
  332. {
  333. headers: {
  334. 'Authorization': `Bearer ${testToken}`
  335. }
  336. });
  337. expect(response.status).toBe(200);
  338. if (response.status === 200) {
  339. const result = await response.json();
  340. // 验证返回参数格式
  341. expect(result.timeStamp).toMatch(/^\d+$/); // 时间戳应该是数字字符串
  342. expect(result.nonceStr).toBeTruthy(); // 随机字符串应该存在
  343. expect(result.package).toContain('prepay_id=');
  344. expect(result.signType).toBe('RSA');
  345. expect(result.paySign).toBeTruthy(); // 签名应该存在
  346. expect(result.totalAmount).toBe(20000); // 验证金额字段正确返回
  347. }
  348. });
  349. });
  350. });