2026-07-28 10:42:26 +08:00
|
|
|
package common
|
|
|
|
|
|
|
|
|
|
import (
|
|
|
|
|
"net/http"
|
2026-07-29 14:03:10 +08:00
|
|
|
"strings"
|
2026-07-28 10:42:26 +08:00
|
|
|
"testing"
|
|
|
|
|
|
|
|
|
|
"git.apinb.com/heqiapp/platforms/backend/api/internal/models"
|
2026-07-29 14:03:10 +08:00
|
|
|
"github.com/DATA-DOG/go-sqlmock"
|
|
|
|
|
"gorm.io/driver/postgres"
|
|
|
|
|
"gorm.io/gorm"
|
2026-07-28 10:42:26 +08:00
|
|
|
)
|
|
|
|
|
|
|
|
|
|
func TestFilterFieldsKeepsOnlyAllowedKeys(t *testing.T) {
|
|
|
|
|
got := FilterFields(map[string]any{"name": "n", "password_hash": "x"}, []string{"name"})
|
|
|
|
|
if len(got) != 1 || got["name"] != "n" {
|
|
|
|
|
t.Fatalf("unexpected filtered fields: %#v", got)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-07-29 14:03:10 +08:00
|
|
|
func TestOperationalQueriesExcludeArchivedRecords(t *testing.T) {
|
|
|
|
|
sqlDatabase, _, err := sqlmock.New()
|
|
|
|
|
if err != nil {
|
|
|
|
|
t.Fatal(err)
|
|
|
|
|
}
|
|
|
|
|
defer sqlDatabase.Close()
|
|
|
|
|
database, err := gorm.Open(postgres.New(postgres.Config{Conn: sqlDatabase}), &gorm.Config{})
|
|
|
|
|
if err != nil {
|
|
|
|
|
t.Fatal(err)
|
|
|
|
|
}
|
|
|
|
|
statement := database.ToSQL(func(tx *gorm.DB) *gorm.DB {
|
|
|
|
|
return ActiveRecords(tx.Model(&models.EcProduct{})).Find(&[]models.EcProduct{})
|
|
|
|
|
})
|
|
|
|
|
if !strings.Contains(statement, `status <> 3`) {
|
|
|
|
|
t.Fatalf("archive filter missing from operational query: %s", statement)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-07-28 10:42:26 +08:00
|
|
|
func TestResourceResponseStripsInternalIDsRecursively(t *testing.T) {
|
|
|
|
|
got := ResourceResponse(map[string]any{
|
|
|
|
|
"id": uint64(1), "identity": "root",
|
|
|
|
|
"child": map[string]any{"gasorder_basic_id": uint64(2), "identity": "child"},
|
|
|
|
|
}).(map[string]any)
|
|
|
|
|
if _, exists := got["id"]; exists {
|
|
|
|
|
t.Fatal("root database ID was exposed")
|
|
|
|
|
}
|
|
|
|
|
child := got["child"].(map[string]any)
|
|
|
|
|
if _, exists := child["gasorder_basic_id"]; exists {
|
|
|
|
|
t.Fatal("relation database ID was exposed")
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-07-29 17:55:59 +08:00
|
|
|
func TestPublicResourceResponsePreservesOnlyRecordID(t *testing.T) {
|
|
|
|
|
got, err := PublicResourceResponse(map[string]any{
|
|
|
|
|
"id": uint64(7), "identity": "record",
|
|
|
|
|
"child": map[string]any{"id": uint64(8), "identity": "child"},
|
|
|
|
|
})
|
|
|
|
|
if err != nil {
|
|
|
|
|
t.Fatal(err)
|
|
|
|
|
}
|
|
|
|
|
record := got.(map[string]any)
|
|
|
|
|
if record["id"] != float64(7) {
|
|
|
|
|
t.Fatalf("record ID = %#v, want 7", record["id"])
|
|
|
|
|
}
|
|
|
|
|
if _, exists := record["child"].(map[string]any)["id"]; exists {
|
|
|
|
|
t.Fatal("nested database ID was exposed")
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestPublicResourceResponsePreservesListRecordIDs(t *testing.T) {
|
|
|
|
|
got, err := PublicResourceResponse([]map[string]any{
|
|
|
|
|
{"id": uint64(11), "identity": "first"},
|
|
|
|
|
{"id": uint64(12), "identity": "second"},
|
|
|
|
|
})
|
|
|
|
|
if err != nil {
|
|
|
|
|
t.Fatal(err)
|
|
|
|
|
}
|
|
|
|
|
list := got.([]any)
|
|
|
|
|
if list[0].(map[string]any)["id"] != float64(11) ||
|
|
|
|
|
list[1].(map[string]any)["id"] != float64(12) {
|
|
|
|
|
t.Fatalf("list record IDs were not preserved: %#v", list)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-07-28 10:42:26 +08:00
|
|
|
func TestPublicFieldProtectionMasksGasorderContacts(t *testing.T) {
|
|
|
|
|
value := map[string]any{"contact_name": "张三", "contact_phone": "13800138000"}
|
|
|
|
|
ProtectPublicFields(value, false, false, false)
|
|
|
|
|
if _, exists := value["contact_name"]; exists {
|
|
|
|
|
t.Fatal("contact name remains public")
|
|
|
|
|
}
|
|
|
|
|
if _, exists := value["contact_phone"]; exists {
|
|
|
|
|
t.Fatal("contact phone remains public")
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestResourceRelationOptionalEmptyIdentityClearsRelation(t *testing.T) {
|
|
|
|
|
values, err := ResolveResourceRelations(
|
|
|
|
|
map[string]any{"warehouse_identity": ""},
|
|
|
|
|
nil,
|
|
|
|
|
[]ResourceRelation{{Input: "warehouse_identity", Column: "warehouse_id", Model: &models.ProductWarehouse{}}},
|
|
|
|
|
false,
|
|
|
|
|
)
|
|
|
|
|
if err != nil || values["warehouse_id"] != uint64(0) {
|
|
|
|
|
t.Fatalf("optional relation clear = (%#v, %v)", values, err)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestCommonMethodModesRemainHTTPCompatible(t *testing.T) {
|
|
|
|
|
if http.MethodGet == "" || http.MethodPost == "" {
|
|
|
|
|
t.Fatal("standard HTTP methods unavailable")
|
|
|
|
|
}
|
|
|
|
|
}
|
2026-07-29 14:03:10 +08:00
|
|
|
|
|
|
|
|
func TestGenericStatusRejectsDomainLifecycleValues(t *testing.T) {
|
|
|
|
|
for _, status := range []int{StatusDraft, StatusEnable, StatusDisable, StatusArchived, StatusFrozen} {
|
|
|
|
|
if !IsGenericRecordStatus(status) {
|
|
|
|
|
t.Fatalf("generic status %d was rejected", status)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
if IsGenericRecordStatus(StatusCompleted) {
|
|
|
|
|
t.Fatal("business lifecycle status was accepted as generic entity status")
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestCommerceAndFinanceRejectInvalidAmounts(t *testing.T) {
|
|
|
|
|
tests := []struct {
|
|
|
|
|
model any
|
|
|
|
|
values map[string]any
|
|
|
|
|
}{
|
|
|
|
|
{&models.EcProduct{}, map[string]any{"product_code": "p", "name": "P", "price_amount": -1.0}},
|
|
|
|
|
{&models.EcCart{}, map[string]any{"quantity": 0.0}},
|
|
|
|
|
{&models.EcOrder{}, map[string]any{"order_no": "o", "total_amount": -1.0}},
|
|
|
|
|
{&models.EcOrderItem{}, map[string]any{"product_snapshot": "{}", "quantity": -1.0, "sale_amount": 1.0}},
|
|
|
|
|
{&models.EcReview{}, map[string]any{"score": 6.0, "content": "bad"}},
|
|
|
|
|
{&models.FinPayment{}, map[string]any{"channel": "wallet", "amount": -1.0}},
|
|
|
|
|
}
|
|
|
|
|
for _, test := range tests {
|
|
|
|
|
if ValidateResourceValues(test.model, test.values, true) == nil {
|
|
|
|
|
t.Fatalf("%T accepted invalid values %#v", test.model, test.values)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|