sysUserModel_test.go 79 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218
  1. package user_test
  2. import (
  3. "context"
  4. "database/sql"
  5. "errors"
  6. "fmt"
  7. "github.com/go-sql-driver/mysql"
  8. "github.com/stretchr/testify/assert"
  9. "github.com/stretchr/testify/require"
  10. "github.com/zeromicro/go-zero/core/stores/redis"
  11. "github.com/zeromicro/go-zero/core/stores/sqlx"
  12. "perms-system-server/internal/model/user"
  13. "perms-system-server/internal/testutil"
  14. "strings"
  15. "sync"
  16. "sync/atomic"
  17. "testing"
  18. "time"
  19. )
  20. func newTestSysUser(username string, deptId int64) *user.SysUser {
  21. now := time.Now().Unix()
  22. return &user.SysUser{
  23. Username: username,
  24. Password: "hashed",
  25. Nickname: "nick",
  26. Avatar: sql.NullString{Valid: false},
  27. Email: "[email protected]",
  28. Phone: "13800000000",
  29. Remark: "",
  30. DeptId: deptId,
  31. IsSuperAdmin: 2,
  32. MustChangePassword: 2,
  33. Status: 1,
  34. CreateTime: now,
  35. UpdateTime: now,
  36. }
  37. }
  38. func newModel(t *testing.T) (user.SysUserModel, sqlx.SqlConn) {
  39. t.Helper()
  40. conn := testutil.GetTestSqlConn()
  41. m := user.NewSysUserModel(conn, testutil.GetTestCacheConf(), testutil.GetTestCachePrefix())
  42. return m, conn
  43. }
  44. // TC-0333: 获取表名
  45. func TestSysUserModel_TableName(t *testing.T) {
  46. m, _ := newModel(t)
  47. require.Equal(t, "`sys_user`", m.TableName())
  48. }
  49. // TC-0310: 正常插入
  50. func TestSysUserModel_CRUD(t *testing.T) {
  51. ctx := context.Background()
  52. m, conn := newModel(t)
  53. username := "crud_" + testutil.UniqueId()
  54. data := newTestSysUser(username, 1)
  55. res, err := m.Insert(ctx, data)
  56. require.NoError(t, err)
  57. id, err := res.LastInsertId()
  58. require.NoError(t, err)
  59. require.Greater(t, id, int64(0))
  60. defer testutil.CleanTable(ctx, conn, m.TableName(), id)
  61. got, err := m.FindOne(ctx, id)
  62. require.NoError(t, err)
  63. require.Equal(t, username, got.Username)
  64. require.Equal(t, data.Email, got.Email)
  65. data.Id = id
  66. data.Nickname = "updated_nick"
  67. data.UpdateTime = time.Now().Unix()
  68. require.NoError(t, m.Update(ctx, data))
  69. after, err := m.FindOne(ctx, id)
  70. require.NoError(t, err)
  71. require.Equal(t, "updated_nick", after.Nickname)
  72. require.NoError(t, m.Delete(ctx, id))
  73. _, err = m.FindOne(ctx, id)
  74. require.ErrorIs(t, err, user.ErrNotFound)
  75. }
  76. // TC-0359: FindOneByUsername
  77. func TestSysUserModel_FindOneByUsername(t *testing.T) {
  78. ctx := context.Background()
  79. m, conn := newModel(t)
  80. username := "findname_" + testutil.UniqueId()
  81. data := newTestSysUser(username, 1)
  82. res, err := m.Insert(ctx, data)
  83. require.NoError(t, err)
  84. id, err := res.LastInsertId()
  85. require.NoError(t, err)
  86. defer testutil.CleanTable(ctx, conn, m.TableName(), id)
  87. found, err := m.FindOneByUsername(ctx, username)
  88. require.NoError(t, err)
  89. require.Equal(t, id, found.Id)
  90. require.Equal(t, username, found.Username)
  91. _, err = m.FindOneByUsername(ctx, "no_such_"+testutil.UniqueId())
  92. require.ErrorIs(t, err, user.ErrNotFound)
  93. }
  94. // TC-0336: 多条记录(3条)
  95. func TestSysUserModel_BatchInsert_BatchDelete(t *testing.T) {
  96. ctx := context.Background()
  97. m, conn := newModel(t)
  98. names := []string{
  99. "batch_a_" + testutil.UniqueId(),
  100. "batch_b_" + testutil.UniqueId(),
  101. "batch_c_" + testutil.UniqueId(),
  102. }
  103. list := []*user.SysUser{
  104. newTestSysUser(names[0], 10),
  105. newTestSysUser(names[1], 10),
  106. newTestSysUser(names[2], 10),
  107. }
  108. require.NoError(t, m.BatchInsert(ctx, list))
  109. var ids []int64
  110. for _, name := range names {
  111. u, err := m.FindOneByUsername(ctx, name)
  112. require.NoError(t, err)
  113. ids = append(ids, u.Id)
  114. }
  115. defer testutil.CleanTable(ctx, conn, m.TableName(), ids...)
  116. require.NoError(t, m.BatchDelete(ctx, ids))
  117. for _, name := range names {
  118. _, err := m.FindOneByUsername(ctx, name)
  119. require.ErrorIs(t, err, user.ErrNotFound)
  120. }
  121. }
  122. // TC-0345: 多条记录(3条)
  123. func TestSysUserModel_BatchUpdate(t *testing.T) {
  124. ctx := context.Background()
  125. m, conn := newModel(t)
  126. u1 := "bupd1_" + testutil.UniqueId()
  127. u2 := "bupd2_" + testutil.UniqueId()
  128. d1 := newTestSysUser(u1, 20)
  129. d2 := newTestSysUser(u2, 20)
  130. r1, err := m.Insert(ctx, d1)
  131. require.NoError(t, err)
  132. id1, err := r1.LastInsertId()
  133. require.NoError(t, err)
  134. r2, err := m.Insert(ctx, d2)
  135. require.NoError(t, err)
  136. id2, err := r2.LastInsertId()
  137. require.NoError(t, err)
  138. defer testutil.CleanTable(ctx, conn, m.TableName(), id1, id2)
  139. now := time.Now().Unix()
  140. upd := []*user.SysUser{
  141. {Id: id1, Username: u1, Password: d1.Password, Nickname: "n1_new", Avatar: sql.NullString{}, Email: d1.Email, Phone: d1.Phone, Remark: d1.Remark, DeptId: 21, IsSuperAdmin: 2, MustChangePassword: 2, Status: 1, CreateTime: d1.CreateTime, UpdateTime: now},
  142. {Id: id2, Username: u2, Password: d2.Password, Nickname: "n2_new", Avatar: sql.NullString{}, Email: d2.Email, Phone: d2.Phone, Remark: d2.Remark, DeptId: 22, IsSuperAdmin: 2, MustChangePassword: 2, Status: 2, CreateTime: d2.CreateTime, UpdateTime: now},
  143. }
  144. require.NoError(t, m.BatchUpdate(ctx, upd))
  145. g1, err := m.FindOne(ctx, id1)
  146. require.NoError(t, err)
  147. require.Equal(t, "n1_new", g1.Nickname)
  148. require.Equal(t, int64(21), g1.DeptId)
  149. g2, err := m.FindOne(ctx, id2)
  150. require.NoError(t, err)
  151. require.Equal(t, "n2_new", g2.Nickname)
  152. require.Equal(t, int64(22), g2.DeptId)
  153. require.Equal(t, int64(2), g2.Status)
  154. }
  155. // TC-0331: 正常事务
  156. func TestSysUserModel_TransactCtx_Commit(t *testing.T) {
  157. ctx := context.Background()
  158. m, conn := newModel(t)
  159. username := "tx_ok_" + testutil.UniqueId()
  160. data := newTestSysUser(username, 3)
  161. var insertedID int64
  162. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  163. res, err := m.InsertWithTx(c, session, data)
  164. if err != nil {
  165. return err
  166. }
  167. insertedID, err = res.LastInsertId()
  168. return err
  169. })
  170. require.NoError(t, err)
  171. require.Greater(t, insertedID, int64(0))
  172. defer testutil.CleanTable(ctx, conn, m.TableName(), insertedID)
  173. got, err := m.FindOne(ctx, insertedID)
  174. require.NoError(t, err)
  175. require.Equal(t, username, got.Username)
  176. }
  177. // TC-0332: fn返回错误
  178. func TestSysUserModel_TransactCtx_Rollback(t *testing.T) {
  179. ctx := context.Background()
  180. m, _ := newModel(t)
  181. username := "tx_rb_" + testutil.UniqueId()
  182. data := newTestSysUser(username, 3)
  183. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  184. if _, e := m.InsertWithTx(c, session, data); e != nil {
  185. return e
  186. }
  187. return errors.New("force rollback")
  188. })
  189. require.Error(t, err)
  190. require.Contains(t, err.Error(), "force rollback")
  191. _, err = m.FindOneByUsername(ctx, username)
  192. require.ErrorIs(t, err, user.ErrNotFound)
  193. }
  194. // TC-0314: 事务内插入
  195. func TestSysUserModel_InsertWithTx_DeleteWithTx_SameTransaction(t *testing.T) {
  196. ctx := context.Background()
  197. m, conn := newModel(t)
  198. username := "tx_del_" + testutil.UniqueId()
  199. data := newTestSysUser(username, 4)
  200. // DeleteWithTx 会先 FindOne;未提交事务内的插入对默认连接不可见,因此分两个 TransactCtx:
  201. // 先提交插入,再在独立事务中 DeleteWithTx。
  202. var insertedID int64
  203. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  204. res, err := m.InsertWithTx(c, session, data)
  205. if err != nil {
  206. return err
  207. }
  208. insertedID, err = res.LastInsertId()
  209. return err
  210. })
  211. require.NoError(t, err)
  212. require.Greater(t, insertedID, int64(0))
  213. defer testutil.CleanTable(ctx, conn, m.TableName(), insertedID)
  214. err = m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  215. return m.DeleteWithTx(c, session, insertedID)
  216. })
  217. require.NoError(t, err)
  218. _, err = m.FindOne(ctx, insertedID)
  219. require.ErrorIs(t, err, user.ErrNotFound)
  220. }
  221. // TC-0405: 正常分页
  222. func TestSysUserModel_FindListByPage(t *testing.T) {
  223. ctx := context.Background()
  224. m, conn := newModel(t)
  225. var cnt int64
  226. err := conn.QueryRowCtx(ctx, &cnt, "SELECT COUNT(*) FROM "+m.TableName())
  227. require.NoError(t, err)
  228. username := "page_" + testutil.UniqueId()
  229. res, err := m.Insert(ctx, newTestSysUser(username, 5))
  230. require.NoError(t, err)
  231. id, err := res.LastInsertId()
  232. require.NoError(t, err)
  233. defer testutil.CleanTable(ctx, conn, m.TableName(), id)
  234. list, total, err := m.FindListByPage(ctx, 1, 10)
  235. require.NoError(t, err)
  236. var cntAfter int64
  237. require.NoError(t, conn.QueryRowCtx(ctx, &cntAfter, "SELECT COUNT(*) FROM "+m.TableName()))
  238. require.Equal(t, cntAfter, total)
  239. require.GreaterOrEqual(t, len(list), 1)
  240. require.LessOrEqual(t, len(list), 10)
  241. list2, total2, err := m.FindListByPage(ctx, 1, 1)
  242. require.NoError(t, err)
  243. require.Equal(t, cntAfter, total2)
  244. require.Len(t, list2, 1)
  245. }
  246. // TC-0410: FindListByProductMembers 正常查询
  247. func TestSysUserModel_FindListByProductMembers(t *testing.T) {
  248. ctx := context.Background()
  249. m, conn := newModel(t)
  250. productCode := "t_fpm_" + testutil.UniqueId()
  251. list, mtMap, total, err := m.FindListByProductMembers(ctx, productCode, 1, 10)
  252. require.NoError(t, err)
  253. require.Empty(t, list)
  254. require.Empty(t, mtMap)
  255. require.Equal(t, int64(0), total)
  256. u1 := "fpm1_" + testutil.UniqueId()
  257. u2 := "fpm2_" + testutil.UniqueId()
  258. u3 := "fpm3_" + testutil.UniqueId()
  259. r1, err := m.Insert(ctx, newTestSysUser(u1, 1))
  260. require.NoError(t, err)
  261. id1, _ := r1.LastInsertId()
  262. r2, err := m.Insert(ctx, newTestSysUser(u2, 1))
  263. require.NoError(t, err)
  264. id2, _ := r2.LastInsertId()
  265. r3, err := m.Insert(ctx, newTestSysUser(u3, 1))
  266. require.NoError(t, err)
  267. id3, _ := r3.LastInsertId()
  268. defer testutil.CleanTable(ctx, conn, m.TableName(), id1, id2, id3)
  269. now := time.Now().Unix()
  270. memberQ := "INSERT INTO `sys_product_member` (`productCode`,`userId`,`memberType`,`createTime`,`updateTime`) VALUES (?,?,?,?,?),(?,?,?,?,?)"
  271. res, err := conn.ExecCtx(ctx, memberQ, productCode, id1, "MEMBER", now, now, productCode, id2, "MEMBER", now, now)
  272. require.NoError(t, err)
  273. _ = res
  274. defer func() {
  275. _, _ = conn.ExecCtx(ctx, "DELETE FROM `sys_product_member` WHERE `productCode`=?", productCode)
  276. }()
  277. list, mtMap, total, err = m.FindListByProductMembers(ctx, productCode, 1, 10)
  278. require.NoError(t, err)
  279. require.Equal(t, int64(2), total)
  280. found := map[int64]struct{}{}
  281. for _, u := range list {
  282. found[u.Id] = struct{}{}
  283. }
  284. _, ok1 := found[id1]
  285. _, ok2 := found[id2]
  286. _, ok3 := found[id3]
  287. require.True(t, ok1 && ok2, "expected u1 and u2 to be in product members")
  288. require.False(t, ok3, "u3 should not appear since not a product member")
  289. // -G 修复:FindListByProductMembers 同时返回 memberType,验证 map 字段完整性
  290. require.Equal(t, "MEMBER", mtMap[id1])
  291. require.Equal(t, "MEMBER", mtMap[id2])
  292. _, ok3m := mtMap[id3]
  293. require.False(t, ok3m, "u3 不是成员,不应出现在 memberMap 中")
  294. list2, _, _, err := m.FindListByProductMembers(ctx, productCode, 1, 1)
  295. require.NoError(t, err)
  296. require.Len(t, list2, 1)
  297. }
  298. // TC-0412: 正常批量查询
  299. func TestSysUserModel_FindByIds(t *testing.T) {
  300. ctx := context.Background()
  301. m, conn := newModel(t)
  302. list, err := m.FindByIds(ctx, nil)
  303. require.NoError(t, err)
  304. require.Nil(t, list)
  305. list, err = m.FindByIds(ctx, []int64{})
  306. require.NoError(t, err)
  307. require.Nil(t, list)
  308. r1, err := m.Insert(ctx, newTestSysUser("fid1_"+testutil.UniqueId(), 6))
  309. require.NoError(t, err)
  310. id1, err := r1.LastInsertId()
  311. require.NoError(t, err)
  312. r2, err := m.Insert(ctx, newTestSysUser("fid2_"+testutil.UniqueId(), 6))
  313. require.NoError(t, err)
  314. id2, err := r2.LastInsertId()
  315. require.NoError(t, err)
  316. defer testutil.CleanTable(ctx, conn, m.TableName(), id1, id2)
  317. list, err = m.FindByIds(ctx, []int64{id1, id2})
  318. require.NoError(t, err)
  319. require.Len(t, list, 2)
  320. ids := map[int64]struct{}{list[0].Id: {}, list[1].Id: {}}
  321. _, ok1 := ids[id1]
  322. _, ok2 := ids[id2]
  323. require.True(t, ok1 && ok2)
  324. list, err = m.FindByIds(ctx, []int64{id1, 999999999999999})
  325. require.NoError(t, err)
  326. require.Len(t, list, 1)
  327. require.Equal(t, id1, list[0].Id)
  328. }
  329. // TC-0312: 唯一索引冲突
  330. func TestSysUserModel_Insert_DuplicateUsername(t *testing.T) {
  331. ctx := context.Background()
  332. m, conn := newModel(t)
  333. username := "dup_" + testutil.UniqueId()
  334. data := newTestSysUser(username, 7)
  335. res, err := m.Insert(ctx, data)
  336. require.NoError(t, err)
  337. id, err := res.LastInsertId()
  338. require.NoError(t, err)
  339. defer testutil.CleanTable(ctx, conn, m.TableName(), id)
  340. _, err = m.Insert(ctx, newTestSysUser(username, 8))
  341. require.Error(t, err)
  342. var me *mysql.MySQLError
  343. if errors.As(err, &me) {
  344. require.Equal(t, uint16(1062), me.Number)
  345. } else {
  346. require.True(t, strings.Contains(strings.ToLower(err.Error()), "duplicate"), "expected duplicate key error, got: %v", err)
  347. }
  348. }
  349. // TC-0319: 记录不存在
  350. func TestSysUserModel_FindOne_NotFound(t *testing.T) {
  351. m, _ := newModel(t)
  352. _, err := m.FindOne(context.Background(), 999999999999)
  353. require.ErrorIs(t, err, user.ErrNotFound)
  354. }
  355. // TC-0326: 记录不存在
  356. func TestSysUserModel_Update_NotFound(t *testing.T) {
  357. m, _ := newModel(t)
  358. err := m.Update(context.Background(), &user.SysUser{
  359. Id: 999999999999, Username: "ghost", Password: "x",
  360. Nickname: "n", Email: "e", Phone: "p",
  361. IsSuperAdmin: 2, MustChangePassword: 2, Status: 1,
  362. CreateTime: time.Now().Unix(), UpdateTime: time.Now().Unix(),
  363. })
  364. require.ErrorIs(t, err, user.ErrNotFound)
  365. }
  366. // TC-0329: 记录不存在
  367. func TestSysUserModel_Delete_NotFound(t *testing.T) {
  368. m, _ := newModel(t)
  369. err := m.Delete(context.Background(), 999999999999)
  370. require.ErrorIs(t, err, user.ErrNotFound)
  371. }
  372. // TC-0334: 空列表
  373. func TestSysUserModel_BatchInsert_Empty(t *testing.T) {
  374. m, _ := newModel(t)
  375. require.NoError(t, m.BatchInsert(context.Background(), nil))
  376. require.NoError(t, m.BatchInsert(context.Background(), []*user.SysUser{}))
  377. }
  378. // TC-0343: 空列表
  379. func TestSysUserModel_BatchUpdate_Empty(t *testing.T) {
  380. m, _ := newModel(t)
  381. require.NoError(t, m.BatchUpdate(context.Background(), nil))
  382. require.NoError(t, m.BatchUpdate(context.Background(), []*user.SysUser{}))
  383. }
  384. // TC-0353: 空ids
  385. func TestSysUserModel_BatchDelete_Empty(t *testing.T) {
  386. m, _ := newModel(t)
  387. require.NoError(t, m.BatchDelete(context.Background(), nil))
  388. require.NoError(t, m.BatchDelete(context.Background(), []int64{}))
  389. }
  390. // TC-0406: 第二页
  391. func TestSysUserModel_FindListByPage_SecondPage(t *testing.T) {
  392. ctx := context.Background()
  393. m, conn := newModel(t)
  394. var ids []int64
  395. for i := 0; i < 3; i++ {
  396. res, err := m.Insert(ctx, newTestSysUser("p2_"+testutil.UniqueId(), 0))
  397. require.NoError(t, err)
  398. id, _ := res.LastInsertId()
  399. ids = append(ids, id)
  400. }
  401. t.Cleanup(func() { testutil.CleanTable(ctx, conn, m.TableName(), ids...) })
  402. _, total, err := m.FindListByPage(ctx, 1, 1)
  403. require.NoError(t, err)
  404. if total >= 2 {
  405. list2, _, err := m.FindListByPage(ctx, 2, 1)
  406. require.NoError(t, err)
  407. require.Len(t, list2, 1)
  408. }
  409. }
  410. // TC-0411: FindListByProductMembers productCode 不存在
  411. func TestSysUserModel_FindListByProductMembers_NotExist(t *testing.T) {
  412. m, _ := newModel(t)
  413. list, mtMap, total, err := m.FindListByProductMembers(context.Background(), "not_exist_pc_"+testutil.UniqueId(), 1, 10)
  414. require.NoError(t, err)
  415. require.Equal(t, int64(0), total)
  416. require.Len(t, list, 0)
  417. require.Empty(t, mtMap)
  418. }
  419. // TC-0327: 事务内更新
  420. func TestSysUserModel_UpdateWithTx(t *testing.T) {
  421. ctx := context.Background()
  422. m, conn := newModel(t)
  423. username := "upd_tx_" + testutil.UniqueId()
  424. data := newTestSysUser(username, 1)
  425. res, err := m.Insert(ctx, data)
  426. require.NoError(t, err)
  427. id, err := res.LastInsertId()
  428. require.NoError(t, err)
  429. defer testutil.CleanTable(ctx, conn, m.TableName(), id)
  430. err = m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  431. data.Id = id
  432. data.Nickname = "tx_updated"
  433. data.UpdateTime = time.Now().Unix()
  434. return m.UpdateWithTx(c, session, data)
  435. })
  436. require.NoError(t, err)
  437. got, err := m.FindOne(ctx, id)
  438. require.NoError(t, err)
  439. require.Equal(t, "tx_updated", got.Nickname)
  440. }
  441. // TC-0335: 单条记录
  442. func TestSysUserModel_BatchInsert_Single(t *testing.T) {
  443. ctx := context.Background()
  444. m, conn := newModel(t)
  445. username := "bi_single_" + testutil.UniqueId()
  446. list := []*user.SysUser{newTestSysUser(username, 1)}
  447. require.NoError(t, m.BatchInsert(ctx, list))
  448. found, err := m.FindOneByUsername(ctx, username)
  449. require.NoError(t, err)
  450. defer testutil.CleanTable(ctx, conn, m.TableName(), found.Id)
  451. require.Equal(t, username, found.Username)
  452. }
  453. // TC-0338: 唯一索引冲突
  454. func TestSysUserModel_BatchInsert_UniqueConflict(t *testing.T) {
  455. ctx := context.Background()
  456. m, conn := newModel(t)
  457. username := "bi_dup_" + testutil.UniqueId()
  458. list := []*user.SysUser{
  459. newTestSysUser(username, 1),
  460. newTestSysUser(username, 2),
  461. }
  462. err := m.BatchInsert(ctx, list)
  463. require.Error(t, err)
  464. t.Cleanup(func() {
  465. if found, e := m.FindOneByUsername(ctx, username); e == nil {
  466. testutil.CleanTable(ctx, conn, m.TableName(), found.Id)
  467. }
  468. })
  469. var me *mysql.MySQLError
  470. if errors.As(err, &me) {
  471. require.Equal(t, uint16(1062), me.Number)
  472. } else {
  473. require.True(t, strings.Contains(strings.ToLower(err.Error()), "duplicate"), "expected duplicate key error, got: %v", err)
  474. }
  475. }
  476. // TC-0341: 正常多条
  477. func TestSysUserModel_BatchInsertWithTx_Normal(t *testing.T) {
  478. ctx := context.Background()
  479. m, conn := newModel(t)
  480. u1 := "bitx_a_" + testutil.UniqueId()
  481. u2 := "bitx_b_" + testutil.UniqueId()
  482. list := []*user.SysUser{
  483. newTestSysUser(u1, 1),
  484. newTestSysUser(u2, 1),
  485. }
  486. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  487. return m.BatchInsertWithTx(c, session, list)
  488. })
  489. require.NoError(t, err)
  490. f1, err := m.FindOneByUsername(ctx, u1)
  491. require.NoError(t, err)
  492. f2, err := m.FindOneByUsername(ctx, u2)
  493. require.NoError(t, err)
  494. defer testutil.CleanTable(ctx, conn, m.TableName(), f1.Id, f2.Id)
  495. require.Equal(t, u1, f1.Username)
  496. require.Equal(t, u2, f2.Username)
  497. }
  498. // TC-0340: 空列表
  499. func TestSysUserModel_BatchInsertWithTx_Empty(t *testing.T) {
  500. ctx := context.Background()
  501. m, _ := newModel(t)
  502. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  503. return m.BatchInsertWithTx(c, session, nil)
  504. })
  505. require.NoError(t, err)
  506. }
  507. // TC-0342: 事务回滚
  508. func TestSysUserModel_BatchInsertWithTx_Rollback(t *testing.T) {
  509. ctx := context.Background()
  510. m, _ := newModel(t)
  511. u1 := "bitx_rb_" + testutil.UniqueId()
  512. u2 := "bitx_rb_" + testutil.UniqueId()
  513. list := []*user.SysUser{
  514. newTestSysUser(u1, 1),
  515. newTestSysUser(u2, 1),
  516. }
  517. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  518. if e := m.BatchInsertWithTx(c, session, list); e != nil {
  519. return e
  520. }
  521. return errors.New("force rollback")
  522. })
  523. require.Error(t, err)
  524. _, err = m.FindOneByUsername(ctx, u1)
  525. require.ErrorIs(t, err, user.ErrNotFound)
  526. _, err = m.FindOneByUsername(ctx, u2)
  527. require.ErrorIs(t, err, user.ErrNotFound)
  528. }
  529. // TC-0349: 正常多条
  530. func TestSysUserModel_BatchUpdateWithTx_Normal(t *testing.T) {
  531. ctx := context.Background()
  532. m, conn := newModel(t)
  533. u1 := "butx_a_" + testutil.UniqueId()
  534. u2 := "butx_b_" + testutil.UniqueId()
  535. r1, err := m.Insert(ctx, newTestSysUser(u1, 1))
  536. require.NoError(t, err)
  537. id1, _ := r1.LastInsertId()
  538. r2, err := m.Insert(ctx, newTestSysUser(u2, 1))
  539. require.NoError(t, err)
  540. id2, _ := r2.LastInsertId()
  541. defer testutil.CleanTable(ctx, conn, m.TableName(), id1, id2)
  542. now := time.Now().Unix()
  543. err = m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  544. return m.BatchUpdateWithTx(c, session, []*user.SysUser{
  545. {Id: id1, Username: u1, Password: "hashed", Nickname: "new1", Avatar: sql.NullString{}, Email: "[email protected]", Phone: "13800000000", DeptId: 1, IsSuperAdmin: 2, MustChangePassword: 2, Status: 1, CreateTime: now, UpdateTime: now},
  546. {Id: id2, Username: u2, Password: "hashed", Nickname: "new2", Avatar: sql.NullString{}, Email: "[email protected]", Phone: "13800000000", DeptId: 1, IsSuperAdmin: 2, MustChangePassword: 2, Status: 1, CreateTime: now, UpdateTime: now},
  547. })
  548. })
  549. require.NoError(t, err)
  550. g1, err := m.FindOne(ctx, id1)
  551. require.NoError(t, err)
  552. require.Equal(t, "new1", g1.Nickname)
  553. g2, err := m.FindOne(ctx, id2)
  554. require.NoError(t, err)
  555. require.Equal(t, "new2", g2.Nickname)
  556. }
  557. // TC-0348: 空列表
  558. func TestSysUserModel_BatchUpdateWithTx_Empty(t *testing.T) {
  559. ctx := context.Background()
  560. m, _ := newModel(t)
  561. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  562. return m.BatchUpdateWithTx(c, session, nil)
  563. })
  564. require.NoError(t, err)
  565. }
  566. // TC-0354: 单个id
  567. func TestSysUserModel_BatchDelete_Single(t *testing.T) {
  568. ctx := context.Background()
  569. m, conn := newModel(t)
  570. username := "bd_single_" + testutil.UniqueId()
  571. res, err := m.Insert(ctx, newTestSysUser(username, 1))
  572. require.NoError(t, err)
  573. id, _ := res.LastInsertId()
  574. defer testutil.CleanTable(ctx, conn, m.TableName(), id)
  575. require.NoError(t, m.BatchDelete(ctx, []int64{id}))
  576. _, err = m.FindOne(ctx, id)
  577. require.ErrorIs(t, err, user.ErrNotFound)
  578. }
  579. // TC-0356: 包含不存在id
  580. func TestSysUserModel_BatchDelete_ContainsNonExist(t *testing.T) {
  581. ctx := context.Background()
  582. m, conn := newModel(t)
  583. username := "bd_nonex_" + testutil.UniqueId()
  584. res, err := m.Insert(ctx, newTestSysUser(username, 1))
  585. require.NoError(t, err)
  586. id, _ := res.LastInsertId()
  587. defer testutil.CleanTable(ctx, conn, m.TableName(), id)
  588. require.NoError(t, m.BatchDelete(ctx, []int64{id, 999999999}))
  589. _, err = m.FindOne(ctx, id)
  590. require.ErrorIs(t, err, user.ErrNotFound)
  591. }
  592. // TC-0358: 正常多条
  593. func TestSysUserModel_BatchDeleteWithTx_Normal(t *testing.T) {
  594. ctx := context.Background()
  595. m, conn := newModel(t)
  596. u1 := "bdtx_a_" + testutil.UniqueId()
  597. u2 := "bdtx_b_" + testutil.UniqueId()
  598. r1, err := m.Insert(ctx, newTestSysUser(u1, 1))
  599. require.NoError(t, err)
  600. id1, _ := r1.LastInsertId()
  601. r2, err := m.Insert(ctx, newTestSysUser(u2, 1))
  602. require.NoError(t, err)
  603. id2, _ := r2.LastInsertId()
  604. defer testutil.CleanTable(ctx, conn, m.TableName(), id1, id2)
  605. err = m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  606. return m.BatchDeleteWithTx(c, session, []int64{id1, id2})
  607. })
  608. require.NoError(t, err)
  609. _, err = m.FindOne(ctx, id1)
  610. require.ErrorIs(t, err, user.ErrNotFound)
  611. _, err = m.FindOne(ctx, id2)
  612. require.ErrorIs(t, err, user.ErrNotFound)
  613. }
  614. // TC-0357: 空ids
  615. func TestSysUserModel_BatchDeleteWithTx_Empty(t *testing.T) {
  616. ctx := context.Background()
  617. m, _ := newModel(t)
  618. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  619. return m.BatchDeleteWithTx(c, session, nil)
  620. })
  621. require.NoError(t, err)
  622. }
  623. // TC-0323: 事务内可见性
  624. func TestSysUserModel_FindOneWithTx_InsertThenFind(t *testing.T) {
  625. ctx := context.Background()
  626. m, conn := newModel(t)
  627. username := "fone_tx_" + testutil.UniqueId()
  628. data := newTestSysUser(username, 1)
  629. var insertedID int64
  630. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  631. res, err := m.InsertWithTx(c, session, data)
  632. if err != nil {
  633. return err
  634. }
  635. insertedID, err = res.LastInsertId()
  636. if err != nil {
  637. return err
  638. }
  639. got, err := m.FindOneWithTx(c, session, insertedID)
  640. if err != nil {
  641. return err
  642. }
  643. require.Equal(t, insertedID, got.Id)
  644. require.Equal(t, username, got.Username)
  645. assert.Equal(t, data.Email, got.Email)
  646. assert.Equal(t, data.Phone, got.Phone)
  647. assert.Equal(t, data.DeptId, got.DeptId)
  648. return nil
  649. })
  650. require.NoError(t, err)
  651. defer testutil.CleanTable(ctx, conn, m.TableName(), insertedID)
  652. }
  653. // TC-0322: 事务内记录不存在
  654. func TestSysUserModel_FindOneWithTx_NotFound(t *testing.T) {
  655. ctx := context.Background()
  656. m, _ := newModel(t)
  657. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  658. _, err := m.FindOneWithTx(c, session, 999999999999)
  659. require.ErrorIs(t, err, user.ErrNotFound)
  660. return nil
  661. })
  662. require.NoError(t, err)
  663. }
  664. // TC-0361: FindOneByUsernameWithTx
  665. func TestSysUserModel_FindOneByUsernameWithTx_InsertThenFind(t *testing.T) {
  666. ctx := context.Background()
  667. m, conn := newModel(t)
  668. username := "fuser_tx_" + testutil.UniqueId()
  669. data := newTestSysUser(username, 1)
  670. var insertedID int64
  671. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  672. res, err := m.InsertWithTx(c, session, data)
  673. if err != nil {
  674. return err
  675. }
  676. insertedID, err = res.LastInsertId()
  677. if err != nil {
  678. return err
  679. }
  680. got, err := m.FindOneByUsernameWithTx(c, session, username)
  681. if err != nil {
  682. return err
  683. }
  684. require.Equal(t, insertedID, got.Id)
  685. require.Equal(t, username, got.Username)
  686. assert.Equal(t, data.Email, got.Email)
  687. return nil
  688. })
  689. require.NoError(t, err)
  690. defer testutil.CleanTable(ctx, conn, m.TableName(), insertedID)
  691. }
  692. // TC-0362: FindOneByUsernameWithTx
  693. func TestSysUserModel_FindOneByUsernameWithTx_NotFound(t *testing.T) {
  694. ctx := context.Background()
  695. m, _ := newModel(t)
  696. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  697. _, err := m.FindOneByUsernameWithTx(c, session, "no_such_"+testutil.UniqueId())
  698. require.ErrorIs(t, err, user.ErrNotFound)
  699. return nil
  700. })
  701. require.NoError(t, err)
  702. }
  703. // TC-0416: FindIdsByDeptId 正常返回部门下用户ID列表
  704. func TestSysUserModel_FindIdsByDeptId_Normal(t *testing.T) {
  705. ctx := context.Background()
  706. m, conn := newModel(t)
  707. deptId := time.Now().UnixNano()%100_000_000 + 600_000_000
  708. u1 := "fbd1_" + testutil.UniqueId()
  709. u2 := "fbd2_" + testutil.UniqueId()
  710. r1, err := m.Insert(ctx, newTestSysUser(u1, deptId))
  711. require.NoError(t, err)
  712. id1, err := r1.LastInsertId()
  713. require.NoError(t, err)
  714. r2, err := m.Insert(ctx, newTestSysUser(u2, deptId))
  715. require.NoError(t, err)
  716. id2, err := r2.LastInsertId()
  717. require.NoError(t, err)
  718. t.Cleanup(func() { testutil.CleanTable(ctx, conn, m.TableName(), id1, id2) })
  719. ids, err := m.FindIdsByDeptId(ctx, deptId)
  720. require.NoError(t, err)
  721. require.Len(t, ids, 2)
  722. assert.ElementsMatch(t, []int64{id1, id2}, ids)
  723. }
  724. // TC-0417: FindIdsByDeptId 部门无用户返回空
  725. func TestSysUserModel_FindIdsByDeptId_Empty(t *testing.T) {
  726. m, _ := newModel(t)
  727. deptId := time.Now().UnixNano()%100_000_000 + 700_000_000
  728. ids, err := m.FindIdsByDeptId(context.Background(), deptId)
  729. require.NoError(t, err)
  730. require.Empty(t, ids)
  731. }
  732. // TC-0409: FindListByPage list查询失败(DB异常)
  733. func TestSysUserModel_FindListByPage_DBError(t *testing.T) {
  734. badConn := sqlx.NewMysql("root:bad@tcp(127.0.0.1:1)/bad?timeout=1s")
  735. m := user.NewSysUserModel(badConn, testutil.GetTestCacheConf(), testutil.GetTestCachePrefix())
  736. _, _, err := m.FindListByPage(context.Background(), 1, 10)
  737. require.Error(t, err)
  738. }
  739. // TC-0415: FindByIds DB异常
  740. func TestSysUserModel_FindByIds_DBError(t *testing.T) {
  741. badConn := sqlx.NewMysql("root:bad@tcp(127.0.0.1:1)/bad?timeout=1s")
  742. m := user.NewSysUserModel(badConn, testutil.GetTestCacheConf(), testutil.GetTestCachePrefix())
  743. list, err := m.FindByIds(context.Background(), []int64{1, 2, 3})
  744. require.Error(t, err)
  745. require.Nil(t, list)
  746. }
  747. // TC-0407: FindListByPage - 空结果页
  748. func TestSysUserModel_FindListByPage_EmptyPage(t *testing.T) {
  749. ctx := context.Background()
  750. m, _ := newModel(t)
  751. list, total, err := m.FindListByPage(ctx, 999999, 10)
  752. require.NoError(t, err)
  753. require.GreaterOrEqual(t, total, int64(0))
  754. require.Empty(t, list)
  755. }
  756. // TC-0311: Insert 正常插入含TokenVersion
  757. func TestSysUserModel_Insert_WithTokenVersion(t *testing.T) {
  758. ctx := context.Background()
  759. m, conn := newModel(t)
  760. username := "tv_insert_" + testutil.UniqueId()
  761. data := newTestSysUser(username, 0)
  762. res, err := m.Insert(ctx, data)
  763. require.NoError(t, err, "Insert should include tokenVersion in SQL parameters")
  764. id, err := res.LastInsertId()
  765. require.NoError(t, err)
  766. defer testutil.CleanTable(ctx, conn, m.TableName(), id)
  767. got, err := m.FindOne(ctx, id)
  768. require.NoError(t, err)
  769. assert.Equal(t, int64(0), got.TokenVersion, "default tokenVersion should be 0")
  770. }
  771. // TC-0315: InsertWithTx 事务内插入含TokenVersion
  772. func TestSysUserModel_InsertWithTx_WithTokenVersion(t *testing.T) {
  773. ctx := context.Background()
  774. m, conn := newModel(t)
  775. username := "tv_instx_" + testutil.UniqueId()
  776. data := newTestSysUser(username, 0)
  777. var insertedId int64
  778. err := m.TransactCtx(ctx, func(txCtx context.Context, session sqlx.Session) error {
  779. res, err := m.InsertWithTx(txCtx, session, data)
  780. if err != nil {
  781. return err
  782. }
  783. insertedId, _ = res.LastInsertId()
  784. return nil
  785. })
  786. require.NoError(t, err, "InsertWithTx should include tokenVersion in SQL parameters")
  787. defer testutil.CleanTable(ctx, conn, m.TableName(), insertedId)
  788. got, err := m.FindOne(ctx, insertedId)
  789. require.NoError(t, err)
  790. assert.Equal(t, int64(0), got.TokenVersion)
  791. }
  792. // TC-0325: Update 正常更新含TokenVersion
  793. func TestSysUserModel_Update_WithTokenVersion(t *testing.T) {
  794. ctx := context.Background()
  795. m, conn := newModel(t)
  796. username := "tv_update_" + testutil.UniqueId()
  797. data := newTestSysUser(username, 0)
  798. res, err := m.Insert(ctx, data)
  799. require.NoError(t, err)
  800. id, _ := res.LastInsertId()
  801. defer testutil.CleanTable(ctx, conn, m.TableName(), id)
  802. got, err := m.FindOne(ctx, id)
  803. require.NoError(t, err)
  804. got.TokenVersion = 5
  805. got.Nickname = "updated_nick"
  806. err = m.Update(ctx, got)
  807. require.NoError(t, err, "Update should include tokenVersion in SQL parameters")
  808. updated, err := m.FindOne(ctx, id)
  809. require.NoError(t, err)
  810. assert.Equal(t, int64(5), updated.TokenVersion)
  811. assert.Equal(t, "updated_nick", updated.Nickname)
  812. }
  813. // TC-0337: BatchInsert 批量插入含TokenVersion
  814. func TestSysUserModel_BatchInsert_WithTokenVersion(t *testing.T) {
  815. ctx := context.Background()
  816. m, conn := newModel(t)
  817. dataList := make([]*user.SysUser, 3)
  818. for i := range dataList {
  819. dataList[i] = newTestSysUser("tv_batch_"+testutil.UniqueId(), 0)
  820. }
  821. err := m.BatchInsert(ctx, dataList)
  822. require.NoError(t, err, "BatchInsert should include tokenVersion in SQL parameters")
  823. for _, d := range dataList {
  824. got, err := m.FindOneByUsername(ctx, d.Username)
  825. require.NoError(t, err)
  826. assert.Equal(t, int64(0), got.TokenVersion)
  827. t.Cleanup(func() { testutil.CleanTable(ctx, conn, m.TableName(), got.Id) })
  828. }
  829. }
  830. // TC-0346: BatchUpdate 批量更新不污染数据
  831. func TestSysUserModel_BatchUpdate_NoDataCorruption(t *testing.T) {
  832. ctx := context.Background()
  833. m, conn := newModel(t)
  834. now := time.Now().Unix()
  835. dataList := make([]*user.SysUser, 2)
  836. var ids []int64
  837. for i := range dataList {
  838. dataList[i] = newTestSysUser("tv_bupd_"+testutil.UniqueId(), 0)
  839. res, err := m.Insert(ctx, dataList[i])
  840. require.NoError(t, err)
  841. id, _ := res.LastInsertId()
  842. ids = append(ids, id)
  843. dataList[i].Id = id
  844. }
  845. t.Cleanup(func() { testutil.CleanTable(ctx, conn, m.TableName(), ids...) })
  846. dataList[0].TokenVersion = 10
  847. dataList[0].Nickname = "batch_updated_0"
  848. dataList[0].UpdateTime = now + 100
  849. dataList[1].TokenVersion = 20
  850. dataList[1].Nickname = "batch_updated_1"
  851. dataList[1].UpdateTime = now + 200
  852. err := m.BatchUpdate(ctx, dataList)
  853. require.NoError(t, err, "BatchUpdate should correctly assign values without offset")
  854. for i, id := range ids {
  855. got, err := m.FindOne(ctx, id)
  856. require.NoError(t, err)
  857. assert.Equal(t, dataList[i].TokenVersion, got.TokenVersion,
  858. "tokenVersion must not be corrupted (should not contain createTime value)")
  859. assert.Equal(t, dataList[i].Nickname, got.Nickname)
  860. assert.NotEqual(t, got.Id, got.UpdateTime,
  861. "updateTime must not be corrupted (should not contain Id value)")
  862. }
  863. }
  864. // TC-0418: UpdateProfile 正常更新(状态未变,不递增 tokenVersion)
  865. func TestSysUserModel_UpdateProfile_NoStatusChange(t *testing.T) {
  866. ctx := context.Background()
  867. m, conn := newModel(t)
  868. username := "up_nc_" + testutil.UniqueId()
  869. data := newTestSysUser(username, 1)
  870. res, err := m.Insert(ctx, data)
  871. require.NoError(t, err)
  872. id, _ := res.LastInsertId()
  873. defer testutil.CleanTable(ctx, conn, m.TableName(), id)
  874. orig, err := m.FindOne(ctx, id)
  875. require.NoError(t, err)
  876. origTv := orig.TokenVersion
  877. origStatus := orig.Status
  878. err = m.UpdateProfile(ctx, id, username, "new_nick", "[email protected]", "13900000000", "remark", 2, origStatus, false, orig.UpdateTime)
  879. require.NoError(t, err)
  880. got, err := m.FindOne(ctx, id)
  881. require.NoError(t, err)
  882. assert.Equal(t, "new_nick", got.Nickname)
  883. assert.Equal(t, "[email protected]", got.Email)
  884. assert.Equal(t, "13900000000", got.Phone)
  885. assert.Equal(t, "remark", got.Remark)
  886. assert.Equal(t, int64(2), got.DeptId)
  887. assert.Equal(t, origStatus, got.Status)
  888. assert.Equal(t, origTv, got.TokenVersion, "tokenVersion 未变(statusChanged=false)")
  889. }
  890. // TC-0419: UpdateProfile 状态改变时 tokenVersion+1
  891. func TestSysUserModel_UpdateProfile_StatusChange_IncrementsTokenVersion(t *testing.T) {
  892. ctx := context.Background()
  893. m, conn := newModel(t)
  894. username := "up_sc_" + testutil.UniqueId()
  895. data := newTestSysUser(username, 1)
  896. res, err := m.Insert(ctx, data)
  897. require.NoError(t, err)
  898. id, _ := res.LastInsertId()
  899. defer testutil.CleanTable(ctx, conn, m.TableName(), id)
  900. orig, err := m.FindOne(ctx, id)
  901. require.NoError(t, err)
  902. origTv := orig.TokenVersion
  903. err = m.UpdateProfile(ctx, id, username, orig.Nickname, orig.Email, orig.Phone, orig.Remark, orig.DeptId, 2, true, orig.UpdateTime)
  904. require.NoError(t, err)
  905. got, err := m.FindOne(ctx, id)
  906. require.NoError(t, err)
  907. assert.Equal(t, int64(2), got.Status)
  908. assert.Equal(t, origTv+1, got.TokenVersion, "statusChanged=true 时 tokenVersion 应递增")
  909. }
  910. // TC-0420: UpdateProfile 乐观锁冲突时返回 ErrUpdateConflict
  911. func TestSysUserModel_UpdateProfile_OptimisticLockConflict(t *testing.T) {
  912. ctx := context.Background()
  913. m, conn := newModel(t)
  914. username := "up_ol_" + testutil.UniqueId()
  915. data := newTestSysUser(username, 1)
  916. res, err := m.Insert(ctx, data)
  917. require.NoError(t, err)
  918. id, _ := res.LastInsertId()
  919. defer testutil.CleanTable(ctx, conn, m.TableName(), id)
  920. orig, err := m.FindOne(ctx, id)
  921. require.NoError(t, err)
  922. staleUpdateTime := orig.UpdateTime - 100
  923. err = m.UpdateProfile(ctx, id, username, "x", "[email protected]", "13900000000", "r", 1, 1, false, staleUpdateTime)
  924. require.ErrorIs(t, err, user.ErrUpdateConflict)
  925. }
  926. // TC-0421: UpdateProfile 串行两次更新: 第一次成功刷新 updateTime, 第二次基于旧 updateTime 触发 ErrUpdateConflict
  927. // 乐观锁依赖秒级 updateTime, 两次更新之间需 >= 1 秒的间隔.
  928. func TestSysUserModel_UpdateProfile_ConcurrentOnlyOneWins(t *testing.T) {
  929. ctx := context.Background()
  930. m, conn := newModel(t)
  931. username := "up_cc_" + testutil.UniqueId()
  932. data := newTestSysUser(username, 1)
  933. res, err := m.Insert(ctx, data)
  934. require.NoError(t, err)
  935. id, _ := res.LastInsertId()
  936. defer testutil.CleanTable(ctx, conn, m.TableName(), id)
  937. orig, err := m.FindOne(ctx, id)
  938. require.NoError(t, err)
  939. time.Sleep(1100 * time.Millisecond)
  940. expectedUT := orig.UpdateTime
  941. err1 := m.UpdateProfile(ctx, id, username, "n1", orig.Email, orig.Phone, orig.Remark, orig.DeptId, orig.Status, false, expectedUT)
  942. require.NoError(t, err1)
  943. err2 := m.UpdateProfile(ctx, id, username, "n2", orig.Email, orig.Phone, orig.Remark, orig.DeptId, orig.Status, false, expectedUT)
  944. require.ErrorIs(t, err2, user.ErrUpdateConflict, "基于旧 updateTime 的第二次更新应因乐观锁失败")
  945. got, err := m.FindOne(ctx, id)
  946. require.NoError(t, err)
  947. assert.Equal(t, "n1", got.Nickname, "仅第一次更新应生效")
  948. }
  949. // TC-0422: UpdateProfile userId 不存在时返回 ErrUpdateConflict
  950. func TestSysUserModel_UpdateProfile_NotFound(t *testing.T) {
  951. ctx := context.Background()
  952. m, _ := newModel(t)
  953. err := m.UpdateProfile(ctx, 999999999, "nouser", "n", "[email protected]", "13900000000", "r", 1, 1, false, time.Now().Unix())
  954. require.ErrorIs(t, err, user.ErrUpdateConflict)
  955. }
  956. func TestSysUserModel_IncrementTokenVersionIfMatch_Match(t *testing.T) {
  957. m, conn := newModel(t)
  958. ctx := context.Background()
  959. now := time.Now().Unix()
  960. username := "cas_match_" + testutil.UniqueId()
  961. res, err := m.Insert(ctx, &user.SysUser{
  962. Username: username, Password: "x", Nickname: "n",
  963. Avatar: sql.NullString{}, IsSuperAdmin: 2, MustChangePassword: 2,
  964. Status: 1, TokenVersion: 5, CreateTime: now, UpdateTime: now,
  965. })
  966. require.NoError(t, err)
  967. id, _ := res.LastInsertId()
  968. t.Cleanup(func() { testutil.CleanTable(ctx, conn, "`sys_user`", id) })
  969. got, err := m.IncrementTokenVersionIfMatch(ctx, id, username, 5)
  970. require.NoError(t, err)
  971. assert.Equal(t, int64(6), got, "expected 命中时返回 DB 真实递增后的新版本")
  972. fresh, err := m.FindOne(ctx, id)
  973. require.NoError(t, err)
  974. assert.Equal(t, int64(6), fresh.TokenVersion, "DB 落盘值必须也是 6")
  975. }
  976. // TC-0803: expected 与 DB 不一致时返回 ErrTokenVersionMismatch 且 DB 不得发生任何变更。
  977. // 这是会话劫持窗口的关键拦截:攻击者的 token 里 TokenVersion = V,但合法用户已刷新到 V+1,
  978. // 攻击者再来刷新时 expected=V 打不中 WHERE 子句 → 必须失败。
  979. func TestSysUserModel_IncrementTokenVersionIfMatch_Mismatch_NoSideEffect(t *testing.T) {
  980. m, conn := newModel(t)
  981. ctx := context.Background()
  982. now := time.Now().Unix()
  983. username := "cas_mismatch_" + testutil.UniqueId()
  984. res, err := m.Insert(ctx, &user.SysUser{
  985. Username: username, Password: "x", Nickname: "n",
  986. Avatar: sql.NullString{}, IsSuperAdmin: 2, MustChangePassword: 2,
  987. Status: 1, TokenVersion: 10, CreateTime: now, UpdateTime: now,
  988. })
  989. require.NoError(t, err)
  990. id, _ := res.LastInsertId()
  991. t.Cleanup(func() { testutil.CleanTable(ctx, conn, "`sys_user`", id) })
  992. got, err := m.IncrementTokenVersionIfMatch(ctx, id, username, 9)
  993. require.Error(t, err, "expected 未命中时必须返回错误")
  994. assert.True(t, errors.Is(err, user.ErrTokenVersionMismatch), "错误必须是 ErrTokenVersionMismatch 以供 logic 层分辨")
  995. assert.Equal(t, int64(0), got)
  996. fresh, err := m.FindOne(ctx, id)
  997. require.NoError(t, err)
  998. assert.Equal(t, int64(10), fresh.TokenVersion, "CAS 失败必须对 DB 零副作用")
  999. }
  1000. // 原 TC-0804 "用户不存在必须返回原生 NotFound 而非 ErrTokenVersionMismatch" 已按
  1001. // 新契约废止: 取消了模型内 FindOne 预检,所有 CAS 未命中(无论是版本不匹配还是
  1002. // 行根本不存在)都统一返回 ErrTokenVersionMismatch。logic 层 RefreshToken 改由
  1003. // 上游 UserDetailsLoader.Load 的 status 分支分辨"离职/冻结"。
  1004. // TC-0805: 并发回归 —— N 个 goroutine 用同一个 expected 去 CAS,
  1005. // 必须恰好只有 1 个返回 success,其余全部 ErrTokenVersionMismatch;
  1006. // 最终 DB 的 tokenVersion 必须只递增 1(攻击者无法劫持第二枚令牌)。
  1007. func TestSysUserModel_IncrementTokenVersionIfMatch_ConcurrentSingleWinner(t *testing.T) {
  1008. m, conn := newModel(t)
  1009. ctx := context.Background()
  1010. now := time.Now().Unix()
  1011. username := "cas_race_" + testutil.UniqueId()
  1012. res, err := m.Insert(ctx, &user.SysUser{
  1013. Username: username, Password: "x", Nickname: "n",
  1014. Avatar: sql.NullString{}, IsSuperAdmin: 2, MustChangePassword: 2,
  1015. Status: 1, TokenVersion: 20, CreateTime: now, UpdateTime: now,
  1016. })
  1017. require.NoError(t, err)
  1018. id, _ := res.LastInsertId()
  1019. t.Cleanup(func() { testutil.CleanTable(ctx, conn, "`sys_user`", id) })
  1020. // 限制在 8 并发以避免触发 go-zero sqlx breaker(单机 MySQL + breaker 对同批次突发
  1021. // 的并发 UPDATE 容易误伤;CAS 契约在 N=8 时已足以验证"唯一胜出")。
  1022. const N = 8
  1023. var (
  1024. wg sync.WaitGroup
  1025. successCnt int32
  1026. mismatchCnt int32
  1027. otherErr atomic.Value
  1028. winners sync.Map
  1029. )
  1030. start := make(chan struct{})
  1031. for i := 0; i < N; i++ {
  1032. wg.Add(1)
  1033. go func(idx int) {
  1034. defer wg.Done()
  1035. <-start // 最大程度对齐并发起跑线
  1036. v, e := m.IncrementTokenVersionIfMatch(ctx, id, username, 20)
  1037. switch {
  1038. case e == nil:
  1039. atomic.AddInt32(&successCnt, 1)
  1040. winners.Store(idx, v)
  1041. case errors.Is(e, user.ErrTokenVersionMismatch):
  1042. atomic.AddInt32(&mismatchCnt, 1)
  1043. default:
  1044. otherErr.Store(e)
  1045. }
  1046. }(i)
  1047. }
  1048. close(start)
  1049. wg.Wait()
  1050. if v := otherErr.Load(); v != nil {
  1051. t.Fatalf("并发 CAS 出现非预期错误:%v", v)
  1052. }
  1053. assert.Equal(t, int32(1), atomic.LoadInt32(&successCnt),
  1054. "会话劫持防线:N=16 的竞态中必须有且仅有 1 个 CAS 胜出")
  1055. assert.Equal(t, int32(N-1), atomic.LoadInt32(&mismatchCnt),
  1056. "其他并发者必须全部返回 ErrTokenVersionMismatch,即攻击者会被 401 下线")
  1057. // 唯一胜出者的返回值必须等于 21(起点 20 → +1)
  1058. winners.Range(func(_, v any) bool {
  1059. assert.Equal(t, int64(21), v.(int64), "唯一胜出的 CAS 应返回 expected+1")
  1060. return true
  1061. })
  1062. fresh, err := m.FindOne(ctx, id)
  1063. require.NoError(t, err)
  1064. assert.Equal(t, int64(21), fresh.TokenVersion, "DB 最终只能递增 1(CAS 原子性的外部可观察证据)")
  1065. }
  1066. // TC-0806: 成功后必须使 id-key / username-key 双路缓存失效,
  1067. // 否则 middleware 读缓存拿到的 tokenVersion 与 DB 不一致,依然存在"旧令牌合法误放"的旁路。
  1068. func TestSysUserModel_IncrementTokenVersionIfMatch_InvalidatesCaches(t *testing.T) {
  1069. m, conn := newModel(t)
  1070. ctx := context.Background()
  1071. now := time.Now().Unix()
  1072. username := "cas_cache_" + testutil.UniqueId()
  1073. res, err := m.Insert(ctx, &user.SysUser{
  1074. Username: username, Password: "x", Nickname: "n",
  1075. Avatar: sql.NullString{}, IsSuperAdmin: 2, MustChangePassword: 2,
  1076. Status: 1, TokenVersion: 0, CreateTime: now, UpdateTime: now,
  1077. })
  1078. require.NoError(t, err)
  1079. id, _ := res.LastInsertId()
  1080. t.Cleanup(func() { testutil.CleanTable(ctx, conn, "`sys_user`", id) })
  1081. u0a, err := m.FindOne(ctx, id)
  1082. require.NoError(t, err)
  1083. require.Equal(t, int64(0), u0a.TokenVersion)
  1084. u0b, err := m.FindOneByUsername(ctx, username)
  1085. require.NoError(t, err)
  1086. require.Equal(t, int64(0), u0b.TokenVersion)
  1087. got, err := m.IncrementTokenVersionIfMatch(ctx, id, username, 0)
  1088. require.NoError(t, err)
  1089. require.Equal(t, int64(1), got)
  1090. // 再次读两路缓存,必须看到递增后的 1(而非 stale 0)
  1091. u1a, err := m.FindOne(ctx, id)
  1092. require.NoError(t, err)
  1093. assert.Equal(t, int64(1), u1a.TokenVersion, fmt.Sprintf(
  1094. "id-key 缓存未被清理,stale tokenVersion=%d(的缓存一致性防线)", u1a.TokenVersion))
  1095. u1b, err := m.FindOneByUsername(ctx, username)
  1096. require.NoError(t, err)
  1097. assert.Equal(t, int64(1), u1b.TokenVersion, fmt.Sprintf(
  1098. "username-key 缓存未被清理,stale tokenVersion=%d", u1b.TokenVersion))
  1099. }
  1100. func TestSysUserModel_IncrementTokenVersion_ReturnedEqualsPersisted(t *testing.T) {
  1101. m, conn := newModel(t)
  1102. ctx := context.Background()
  1103. now := time.Now().Unix()
  1104. username := "itv_eq_" + testutil.UniqueId()
  1105. res, err := m.Insert(ctx, &user.SysUser{
  1106. Username: username, Password: "x", Nickname: "n",
  1107. Avatar: sql.NullString{}, IsSuperAdmin: 2, MustChangePassword: 2,
  1108. Status: 1, TokenVersion: 7, CreateTime: now, UpdateTime: now,
  1109. })
  1110. require.NoError(t, err)
  1111. id, _ := res.LastInsertId()
  1112. t.Cleanup(func() { testutil.CleanTable(ctx, conn, "`sys_user`", id) })
  1113. for expected := int64(8); expected <= 12; expected++ {
  1114. got, err := m.IncrementTokenVersion(ctx, id, username)
  1115. require.NoError(t, err)
  1116. assert.Equal(t, expected, got,
  1117. "IncrementTokenVersion 必须返回 DB 真实递增后的值(H-B:不可再受 stale cache 影响)")
  1118. fresh, err := m.FindOne(ctx, id)
  1119. require.NoError(t, err)
  1120. assert.Equal(t, got, fresh.TokenVersion,
  1121. "返回值必须等于 DB 中真实持久化的 tokenVersion")
  1122. }
  1123. }
  1124. // TC-0737: -B 修复回归 —— 自增后缓存必须被主动清理,Load → tokenVersion 能读到新值。
  1125. // 旧实现只更新 DB,返回值基于缓存,并且未强制 DelCache,导致 JWT 中间件仍从缓存读到旧值。
  1126. func TestSysUserModel_IncrementTokenVersion_InvalidatesCache(t *testing.T) {
  1127. m, conn := newModel(t)
  1128. ctx := context.Background()
  1129. now := time.Now().Unix()
  1130. username := "itv_cache_" + testutil.UniqueId()
  1131. res, err := m.Insert(ctx, &user.SysUser{
  1132. Username: username, Password: "x", Nickname: "n",
  1133. Avatar: sql.NullString{}, IsSuperAdmin: 2, MustChangePassword: 2,
  1134. Status: 1, TokenVersion: 0, CreateTime: now, UpdateTime: now,
  1135. })
  1136. require.NoError(t, err)
  1137. id, _ := res.LastInsertId()
  1138. t.Cleanup(func() { testutil.CleanTable(ctx, conn, "`sys_user`", id) })
  1139. // 先 FindOne 让 id-key、username-key 双路缓存写入
  1140. u0, err := m.FindOne(ctx, id)
  1141. require.NoError(t, err)
  1142. require.Equal(t, int64(0), u0.TokenVersion)
  1143. u0b, err := m.FindOneByUsername(ctx, username)
  1144. require.NoError(t, err)
  1145. require.Equal(t, int64(0), u0b.TokenVersion)
  1146. _, err = m.IncrementTokenVersion(ctx, id, username)
  1147. require.NoError(t, err)
  1148. u1, err := m.FindOne(ctx, id)
  1149. require.NoError(t, err)
  1150. assert.Equal(t, int64(1), u1.TokenVersion, "按 id 读取缓存路径也必须拿到最新版本")
  1151. u1b, err := m.FindOneByUsername(ctx, username)
  1152. require.NoError(t, err)
  1153. assert.Equal(t, int64(1), u1b.TokenVersion, "按 username 读取缓存路径也必须失效")
  1154. }
  1155. // TC-0738: -B 修复并发回归 —— 10 个 goroutine 同时 Increment 同一用户,
  1156. // 每次返回值必须互不重复,最终 DB 里 tokenVersion = 起始值 + N。
  1157. func TestSysUserModel_IncrementTokenVersion_ConcurrentUnique(t *testing.T) {
  1158. m, conn := newModel(t)
  1159. ctx := context.Background()
  1160. now := time.Now().Unix()
  1161. username := "itv_conc_" + testutil.UniqueId()
  1162. res, err := m.Insert(ctx, &user.SysUser{
  1163. Username: username, Password: "x", Nickname: "n",
  1164. Avatar: sql.NullString{}, IsSuperAdmin: 2, MustChangePassword: 2,
  1165. Status: 1, TokenVersion: 0, CreateTime: now, UpdateTime: now,
  1166. })
  1167. require.NoError(t, err)
  1168. id, _ := res.LastInsertId()
  1169. t.Cleanup(func() { testutil.CleanTable(ctx, conn, "`sys_user`", id) })
  1170. const N = 10
  1171. var wg sync.WaitGroup
  1172. results := make([]int64, N)
  1173. errs := make([]error, N)
  1174. for i := 0; i < N; i++ {
  1175. wg.Add(1)
  1176. go func(idx int) {
  1177. defer wg.Done()
  1178. v, e := m.IncrementTokenVersion(ctx, id, username)
  1179. results[idx] = v
  1180. errs[idx] = e
  1181. }(i)
  1182. }
  1183. wg.Wait()
  1184. seen := make(map[int64]int, N)
  1185. for i := 0; i < N; i++ {
  1186. require.NoError(t, errs[i], "并发 IncrementTokenVersion 任一 goroutine 不得失败")
  1187. seen[results[i]]++
  1188. }
  1189. for v, cnt := range seen {
  1190. assert.Equal(t, 1, cnt, fmt.Sprintf("返回值 %d 被重复派发 %d 次,与 DB 实际递增序列脱节", v, cnt))
  1191. }
  1192. fresh, err := m.FindOne(ctx, id)
  1193. require.NoError(t, err)
  1194. assert.Equal(t, int64(N), fresh.TokenVersion, "DB 最终 tokenVersion 应为并发次数")
  1195. }
  1196. func sysUserUsernameCacheKey(username string) string {
  1197. return testutil.GetTestCachePrefix() + ":cache:sysUser:username:" + username
  1198. }
  1199. // TC-1044: UpdateStatus 失效 wrongUser cache,real username cache 不受影响
  1200. func TestSysUserModel_UpdateStatus_UsesSuppliedUsername_NoInternalFindOne(t *testing.T) {
  1201. ctx := context.Background()
  1202. m, conn := newModel(t)
  1203. realUsername := "mr112s_real_" + testutil.UniqueId()
  1204. wrongUsername := "mr112s_wrong_" + testutil.UniqueId()
  1205. data := newTestSysUser(realUsername, 1)
  1206. res, err := m.Insert(ctx, data)
  1207. require.NoError(t, err)
  1208. id, err := res.LastInsertId()
  1209. require.NoError(t, err)
  1210. t.Cleanup(func() { testutil.CleanTable(ctx, conn, m.TableName(), id) })
  1211. // 预热 cache:sysUser:username:<realUsername>(via FindOneByUsername 走 go-zero 的 WithCache)。
  1212. _, err = m.FindOneByUsername(ctx, realUsername)
  1213. require.NoError(t, err)
  1214. rds := redis.MustNewRedis(testutil.GetTestConfig().CacheRedis.Nodes[0].RedisConf)
  1215. // 直接往 Redis 里插一条 wrongUser 的桩缓存,供我们观察它是否被 UpdateStatus 失效。
  1216. // 注意:我们并不关心桩的内容,只关心 key 是否被 Del。
  1217. wrongKey := sysUserUsernameCacheKey(wrongUsername)
  1218. realKey := sysUserUsernameCacheKey(realUsername)
  1219. require.NoError(t, rds.Set(wrongKey, "stub"))
  1220. // 预热后确认 realKey 存在(如果环境脏,用下面的断言兜底;缓存可能是 */null/任意值)。
  1221. gotReal, err := rds.Get(realKey)
  1222. require.NoError(t, err)
  1223. require.NotEmpty(t, gotReal, "FindOneByUsername 未能把 realKey 写入缓存,前置条件失败")
  1224. // 推进 updateTime 以触发 CAS 可成功。sys_user.updateTime 精度到秒。
  1225. time.Sleep(1100 * time.Millisecond)
  1226. cur, err := m.FindOne(ctx, id)
  1227. require.NoError(t, err)
  1228. // 关键:传入故意错位的 username。若 Model 还在内部 FindOne,就会用 realUsername 作失效键,
  1229. // wrongKey 不会被删;若 Model 已按 的契约"透传即用",wrongKey 必被删。
  1230. require.NoError(t,
  1231. m.UpdateStatus(ctx, id, wrongUsername, 2, cur.UpdateTime),
  1232. "UpdateStatus 语义上只依赖 id+expectedUpdateTime 做 CAS,username 只用于构造缓存键,不应因错位而失败")
  1233. // 契约 1:wrongKey 必被删
  1234. gotWrong, _ := rds.Get(wrongKey)
  1235. assert.Empty(t, gotWrong,
  1236. "UpdateStatus 必须用调用方透传的 username 做 Del,wrongKey 必须消失")
  1237. // 契约 2:realKey 依然留存(Model 不知道真 username,不应当去动它)
  1238. gotRealAfter, err := rds.Get(realKey)
  1239. require.NoError(t, err)
  1240. assert.NotEmpty(t, gotRealAfter,
  1241. "Model 没有内部 FindOne 获取真 username,因此不应删除 realKey")
  1242. }
  1243. // TC-1045: IncrementTokenVersion 同样只删调用方透传的 username key
  1244. func TestSysUserModel_IncrementTokenVersion_UsesSuppliedUsername_NoInternalFindOne(t *testing.T) {
  1245. ctx := context.Background()
  1246. m, conn := newModel(t)
  1247. realUsername := "mr112i_real_" + testutil.UniqueId()
  1248. wrongUsername := "mr112i_wrong_" + testutil.UniqueId()
  1249. data := newTestSysUser(realUsername, 1)
  1250. res, err := m.Insert(ctx, data)
  1251. require.NoError(t, err)
  1252. id, err := res.LastInsertId()
  1253. require.NoError(t, err)
  1254. t.Cleanup(func() { testutil.CleanTable(ctx, conn, m.TableName(), id) })
  1255. _, err = m.FindOneByUsername(ctx, realUsername)
  1256. require.NoError(t, err)
  1257. rds := redis.MustNewRedis(testutil.GetTestConfig().CacheRedis.Nodes[0].RedisConf)
  1258. wrongKey := sysUserUsernameCacheKey(wrongUsername)
  1259. realKey := sysUserUsernameCacheKey(realUsername)
  1260. require.NoError(t, rds.Set(wrongKey, "stub"))
  1261. // IncrementTokenVersion 不依赖 expectedUpdateTime,直接按 id 更新即可。
  1262. newV, err := m.IncrementTokenVersion(ctx, id, wrongUsername)
  1263. require.NoError(t, err)
  1264. assert.Equal(t, int64(1), newV, "从 0 起递增到 1")
  1265. gotWrong, _ := rds.Get(wrongKey)
  1266. assert.Empty(t, gotWrong,
  1267. "IncrementTokenVersion 必须用透传的 username 做 Del,wrongKey 必须消失")
  1268. gotRealAfter, err := rds.Get(realKey)
  1269. require.NoError(t, err)
  1270. assert.NotEmpty(t, gotRealAfter,
  1271. "Model 没有内部 FindOne 取真 username,realKey 不应受影响")
  1272. }
  1273. // TC-1046: IncrementTokenVersion 用户已被并发删除,返回 ErrUpdateConflict
  1274. // 此契约由 引入, 下的签名改动不得削弱它:affected=0 仍要 ErrUpdateConflict。
  1275. func TestSysUserModel_IncrementTokenVersion_DeletedRow_StillConflicts(t *testing.T) {
  1276. ctx := context.Background()
  1277. m, conn := newModel(t)
  1278. username := "mr112i_del_" + testutil.UniqueId()
  1279. data := newTestSysUser(username, 1)
  1280. res, err := m.Insert(ctx, data)
  1281. require.NoError(t, err)
  1282. id, err := res.LastInsertId()
  1283. require.NoError(t, err)
  1284. testutil.CleanTable(ctx, conn, m.TableName(), id)
  1285. _, err = m.IncrementTokenVersion(ctx, id, username)
  1286. require.ErrorIs(t, err, user.ErrUpdateConflict,
  1287. "目标行已被并发删除,IncrementTokenVersion 不得静默返回 tokenVersion=0")
  1288. }
  1289. func TestSysUserModel_UpdatePassword_RowDeletedBetweenFindAndExec_ReturnsConflict(t *testing.T) {
  1290. ctx := context.Background()
  1291. m, conn := newModel(t)
  1292. username := "m2_pw_del_" + testutil.UniqueId()
  1293. data := newTestSysUser(username, 1)
  1294. res, err := m.Insert(ctx, data)
  1295. require.NoError(t, err)
  1296. id, err := res.LastInsertId()
  1297. require.NoError(t, err)
  1298. t.Cleanup(func() { testutil.CleanTable(ctx, conn, m.TableName(), id) })
  1299. // 触发 FindOne 填充二级缓存 (id-key + username-key),模拟 Loader 刚读过用户的场景
  1300. _, err = m.FindOne(ctx, id)
  1301. require.NoError(t, err)
  1302. _, err = m.FindOneByUsername(ctx, username)
  1303. require.NoError(t, err)
  1304. // 直接走原始 SQL 删除行,**绕过** Model 的缓存失效钩子——此时 Redis 里仍保留用户快照
  1305. _, err = conn.ExecCtx(ctx, "DELETE FROM `sys_user` WHERE `id` = ?", id)
  1306. require.NoError(t, err)
  1307. // UpdatePassword 内部 WHERE id=? AND updateTime=?(外层透传 expectedUpdateTime, )。
  1308. // 行已被删除,affected=0。旧实现 `return nil` 被视为"改密成功";新实现必须回 ErrUpdateConflict。
  1309. // expectedUpdateTime 用 stale cache 的 UpdateTime,即"观测到的快照" —— DB 已无对应行,CAS 必失败。
  1310. stale, _ := m.FindOne(ctx, id)
  1311. var expectedUpdateTime int64
  1312. if stale != nil {
  1313. expectedUpdateTime = stale.UpdateTime
  1314. }
  1315. err = m.UpdatePassword(ctx, id, username, "new_hashed_pw", 1, expectedUpdateTime)
  1316. require.ErrorIs(t, err, user.ErrUpdateConflict,
  1317. "RowsAffected=0 必须升格为 ErrUpdateConflict,杜绝对已消失用户的静默改密")
  1318. }
  1319. // TC-0925: UpdateStatus 对已被并发删除(缓存仍在)的用户必须 fail-fast,禁止静默成功
  1320. func TestSysUserModel_UpdateStatus_RowDeletedBetweenFindAndExec_ReturnsConflict(t *testing.T) {
  1321. ctx := context.Background()
  1322. m, conn := newModel(t)
  1323. username := "m2_st_del_" + testutil.UniqueId()
  1324. data := newTestSysUser(username, 1)
  1325. res, err := m.Insert(ctx, data)
  1326. require.NoError(t, err)
  1327. id, err := res.LastInsertId()
  1328. require.NoError(t, err)
  1329. t.Cleanup(func() { testutil.CleanTable(ctx, conn, m.TableName(), id) })
  1330. _, err = m.FindOne(ctx, id)
  1331. require.NoError(t, err)
  1332. _, err = m.FindOneByUsername(ctx, username)
  1333. require.NoError(t, err)
  1334. _, err = conn.ExecCtx(ctx, "DELETE FROM `sys_user` WHERE `id` = ?", id)
  1335. require.NoError(t, err)
  1336. // UpdateStatus 内部:FindOne 命中 stale cache → UPDATE WHERE id=? AND updateTime=? 仍 affected=0。
  1337. // 旧实现返回 nil;新实现必须回 ErrUpdateConflict,让上层区分"冻结生效 / 用户已不存在"。
  1338. // 新签名:需要把 FindOne 拿到的 UpdateTime 作为 expectedUpdateTime 传入
  1339. staleUd, _ := m.FindOne(ctx, id)
  1340. var expectedUpdateTime int64
  1341. if staleUd != nil {
  1342. expectedUpdateTime = staleUd.UpdateTime
  1343. }
  1344. err = m.UpdateStatus(ctx, id, username, 2, expectedUpdateTime)
  1345. require.ErrorIs(t, err, user.ErrUpdateConflict,
  1346. "RowsAffected=0 必须升格为 ErrUpdateConflict,杜绝对已消失用户的静默封禁")
  1347. }
  1348. // TC-0926: UpdatePassword 正常路径仍然成功,且真实落盘(保证 的 fail-close 不误伤正常流)
  1349. func TestSysUserModel_UpdatePassword_HappyPath_PersistsAndBumpsTokenVersion(t *testing.T) {
  1350. ctx := context.Background()
  1351. m, conn := newModel(t)
  1352. username := "m2_pw_ok_" + testutil.UniqueId()
  1353. data := newTestSysUser(username, 1)
  1354. res, err := m.Insert(ctx, data)
  1355. require.NoError(t, err)
  1356. id, err := res.LastInsertId()
  1357. require.NoError(t, err)
  1358. t.Cleanup(func() { testutil.CleanTable(ctx, conn, m.TableName(), id) })
  1359. orig, err := m.FindOne(ctx, id)
  1360. require.NoError(t, err)
  1361. origTv := orig.TokenVersion
  1362. // 乐观锁依赖秒级 updateTime,必须让 UPDATE 的 time.Now().Unix() 严格 > orig.UpdateTime,
  1363. // 否则"空白更新"仍 affected=1 但 updateTime 值不变,容易掩盖后续断言
  1364. time.Sleep(1100 * time.Millisecond)
  1365. newPw := "new_hashed_password_xyz"
  1366. err = m.UpdatePassword(ctx, id, username, newPw, 1, orig.UpdateTime)
  1367. require.NoError(t, err)
  1368. got, err := m.FindOne(ctx, id)
  1369. require.NoError(t, err)
  1370. assert.Equal(t, newPw, got.Password)
  1371. assert.Equal(t, int64(1), got.MustChangePassword)
  1372. assert.Equal(t, origTv+1, got.TokenVersion, "改密必须递增 tokenVersion 以注销旧会话")
  1373. assert.Greater(t, got.UpdateTime, orig.UpdateTime, "updateTime 必须推进,否则乐观锁无法生效")
  1374. }
  1375. // TC-0927: UpdateStatus 正常路径仍然成功且 tokenVersion 递增
  1376. func TestSysUserModel_UpdateStatus_HappyPath_PersistsAndBumpsTokenVersion(t *testing.T) {
  1377. ctx := context.Background()
  1378. m, conn := newModel(t)
  1379. username := "m2_st_ok_" + testutil.UniqueId()
  1380. data := newTestSysUser(username, 1)
  1381. res, err := m.Insert(ctx, data)
  1382. require.NoError(t, err)
  1383. id, err := res.LastInsertId()
  1384. require.NoError(t, err)
  1385. t.Cleanup(func() { testutil.CleanTable(ctx, conn, m.TableName(), id) })
  1386. orig, err := m.FindOne(ctx, id)
  1387. require.NoError(t, err)
  1388. origTv := orig.TokenVersion
  1389. require.Equal(t, int64(1), orig.Status)
  1390. // 乐观锁依赖秒级 updateTime,确保 UPDATE 的 time.Now().Unix() 严格 > orig.UpdateTime
  1391. time.Sleep(1100 * time.Millisecond)
  1392. err = m.UpdateStatus(ctx, id, username, 2, orig.UpdateTime)
  1393. require.NoError(t, err)
  1394. got, err := m.FindOne(ctx, id)
  1395. require.NoError(t, err)
  1396. assert.Equal(t, int64(2), got.Status)
  1397. assert.Equal(t, origTv+1, got.TokenVersion, "冻结 / 解冻必须递增 tokenVersion 使旧 token 全部失效")
  1398. assert.Greater(t, got.UpdateTime, orig.UpdateTime, "updateTime 必须推进,否则后续乐观锁失效")
  1399. }
  1400. // TC-0928(R11 重写):UpdatePassword 对不存在的 userId 必须回 ErrUpdateConflict
  1401. // ( 后,Model 不再内部 FindOne;不存在的 id + 任意 expectedUpdateTime → affected=0 → ErrUpdateConflict)
  1402. func TestSysUserModel_UpdatePassword_UserNotExist_ReturnsConflict(t *testing.T) {
  1403. ctx := context.Background()
  1404. m, _ := newModel(t)
  1405. err := m.UpdatePassword(ctx, 999999999999, "ghost_user", "irrelevant", 1, 1)
  1406. require.ErrorIs(t, err, user.ErrUpdateConflict,
  1407. "UpdatePassword 不再内部 FindOne,对不存在的 id 回 ErrUpdateConflict")
  1408. }
  1409. // TC-0929(R11 重写):UpdateStatus 对不存在的 userId 必须回 ErrUpdateConflict
  1410. func TestSysUserModel_UpdateStatus_UserNotExist_ReturnsConflict(t *testing.T) {
  1411. ctx := context.Background()
  1412. m, _ := newModel(t)
  1413. err := m.UpdateStatus(ctx, 999999999999, "ghost_user", 2, 1)
  1414. require.ErrorIs(t, err, user.ErrUpdateConflict,
  1415. "UpdateStatus 不再内部 FindOne,对不存在的 id 回 ErrUpdateConflict")
  1416. }
  1417. func TestSysUserModel_UpdatePassword_StaleExpectedUpdateTime_Conflict(t *testing.T) {
  1418. ctx := context.Background()
  1419. m, conn := newModel(t)
  1420. username := "hr111_stale_" + testutil.UniqueId()
  1421. data := newTestSysUser(username, 1)
  1422. res, err := m.Insert(ctx, data)
  1423. require.NoError(t, err)
  1424. id, err := res.LastInsertId()
  1425. require.NoError(t, err)
  1426. t.Cleanup(func() { testutil.CleanTable(ctx, conn, m.TableName(), id) })
  1427. // 外层 Session A 观测到的 updateTime(会校验旧密码时一起拿到)
  1428. snapshotA, err := m.FindOne(ctx, id)
  1429. require.NoError(t, err)
  1430. snapshotAUpdateTime := snapshotA.UpdateTime
  1431. // sys_user.updateTime 精度到秒,确保 Session B 提交的 UPDATE 严格推进 updateTime;
  1432. // 否则同秒写回值与 snapshotAUpdateTime 相同,CAS 仍然匹配,无法复现 TOCTOU。
  1433. time.Sleep(1100 * time.Millisecond)
  1434. // Session B("设备 B 紧急改密 P2")抢先基于 snapshotA 成功完成一次 CAS
  1435. require.NoError(t,
  1436. m.UpdatePassword(ctx, id, username, "H_P2", 1, snapshotAUpdateTime),
  1437. "Session B 基于快照 A 的 updateTime 抢先完成 CAS,应当成功")
  1438. // 现在 DB 的 updateTime 已经不是 snapshotAUpdateTime。
  1439. // Session A(持有旧密码 P0、已校验过旧密码)再用**同一份**旧 snapshot 的 updateTime
  1440. // 去改密 P1,CAS 必须失败,否则 P2 会被 P1 覆盖( TOCTOU)。
  1441. err = m.UpdatePassword(ctx, id, username, "H_P1_to_cover_P2", 1, snapshotAUpdateTime)
  1442. require.ErrorIs(t, err, user.ErrUpdateConflict,
  1443. "expectedUpdateTime 必须是外层快照;Session B 已推进时,Session A 的改密 CAS 必须失败")
  1444. // DB 终态保持为 Session B 的 _P2,不被 Session A 覆盖
  1445. got, err := m.FindOne(ctx, id)
  1446. require.NoError(t, err)
  1447. assert.Equal(t, "H_P2", got.Password,
  1448. "TOCTOU 被关闭后,DB 终态必须是后到而胜出的那一方,不得被旧快照覆盖")
  1449. }
  1450. // TC-1040: 正常路径 expectedUpdateTime 匹配时 UpdatePassword 落盘并递增 tokenVersion
  1451. func TestSysUserModel_UpdatePassword_HappyPath_ExplicitExpectedUpdateTime(t *testing.T) {
  1452. ctx := context.Background()
  1453. m, conn := newModel(t)
  1454. username := "hr111_ok_" + testutil.UniqueId()
  1455. data := newTestSysUser(username, 1)
  1456. res, err := m.Insert(ctx, data)
  1457. require.NoError(t, err)
  1458. id, err := res.LastInsertId()
  1459. require.NoError(t, err)
  1460. t.Cleanup(func() { testutil.CleanTable(ctx, conn, m.TableName(), id) })
  1461. orig, err := m.FindOne(ctx, id)
  1462. require.NoError(t, err)
  1463. origTV := orig.TokenVersion
  1464. time.Sleep(1100 * time.Millisecond)
  1465. require.NoError(t,
  1466. m.UpdatePassword(ctx, id, username, "H_NEW", 0, orig.UpdateTime),
  1467. "expectedUpdateTime 与 DB 当前 updateTime 一致时必须成功")
  1468. got, err := m.FindOne(ctx, id)
  1469. require.NoError(t, err)
  1470. assert.Equal(t, "H_NEW", got.Password)
  1471. assert.Equal(t, int64(0), got.MustChangePassword)
  1472. assert.Equal(t, origTV+1, got.TokenVersion,
  1473. "UpdatePassword 必须递增 tokenVersion 以注销旧会话")
  1474. assert.Greater(t, got.UpdateTime, orig.UpdateTime,
  1475. "updateTime 必须推进以支撑下一次 CAS")
  1476. }
  1477. // TC-1041: 同一行被并发修改(如 UpdateProfile 改了昵称)之后,UpdatePassword 的 CAS 必须失败
  1478. // 覆盖"任何修改 sys_user 行的并发写入都会触发 ErrUpdateConflict"这一更严的契约:
  1479. // 不仅是另一次改密可以"偷走"本次;改昵称/解冻/任何推进 updateTime 的操作也必须把本次改密拦住。
  1480. func TestSysUserModel_UpdatePassword_ConcurrentProfileWrite_BlocksPasswordUpdate(t *testing.T) {
  1481. ctx := context.Background()
  1482. m, conn := newModel(t)
  1483. username := "hr111_prof_" + testutil.UniqueId()
  1484. data := newTestSysUser(username, 1)
  1485. res, err := m.Insert(ctx, data)
  1486. require.NoError(t, err)
  1487. id, err := res.LastInsertId()
  1488. require.NoError(t, err)
  1489. t.Cleanup(func() { testutil.CleanTable(ctx, conn, m.TableName(), id) })
  1490. snapshot, err := m.FindOne(ctx, id)
  1491. require.NoError(t, err)
  1492. // sys_user.updateTime 秒级,sleep 以确保 UpdateProfile 的 UPDATE 真的推进
  1493. time.Sleep(1100 * time.Millisecond)
  1494. // Session B 改了昵称(完全合法的场景:管理员在用户"修改密码"弹窗打开的同一时刻修了昵称)
  1495. require.NoError(t,
  1496. m.UpdateProfile(ctx, id, username,
  1497. "new_nick", snapshot.Email, snapshot.Phone, snapshot.Remark,
  1498. snapshot.DeptId, snapshot.Status, false, snapshot.UpdateTime),
  1499. "UpdateProfile 旁路已成功执行")
  1500. // Session A 仍然基于 snapshot.UpdateTime 改密 —— 必须被 CAS 拦住
  1501. err = m.UpdatePassword(ctx, id, username, "H_LOST", 1, snapshot.UpdateTime)
  1502. require.ErrorIs(t, err, user.ErrUpdateConflict,
  1503. "任何改动(含改昵称)都推进 updateTime;基于旧快照的改密必须被 CAS 拦住")
  1504. got, err := m.FindOne(ctx, id)
  1505. require.NoError(t, err)
  1506. assert.Equal(t, snapshot.Password, got.Password, "Password 必须保持原值,未被 Session A 覆盖")
  1507. assert.Equal(t, "new_nick", got.Nickname, "Profile 写入必须成功落盘")
  1508. }
  1509. // ---------------------------------------------------------------------------
  1510. // 覆盖目标:UpdateProfileWithTx 的 pre-commit DelCache 窗口闭合。
  1511. //
  1512. // 修复前(交错):
  1513. // T0: UpdateProfileWithTx 调用 m.ExecCtx(fn, idKey, usernameKey)
  1514. // go-zero 的 CachedConn.Exec 在 fn 成功返回时**立即**走 DelCache 两把 key。
  1515. // T1: 事务还没 commit;并发 goroutine 的 FindOne 触发 cache-miss → 回 DB 读**旧行**
  1516. // (此时事务未提交,MVCC 仍给它看到旧值)→ 再灌回缓存 = stale 值。
  1517. // T2: 事务随后 commit;新值落库但缓存已是被"回灌的旧值",直到 TTL 到期前所有
  1518. // FindOne 都读到 stale 行。
  1519. //
  1520. // 修复后:
  1521. // * UpdateProfileWithTx 改走 session.ExecCtx 绕过 CachedConn 的 DelCache 语义,
  1522. // 事务成功与否都不去动 sysUser 的两把低层缓存。
  1523. // * 新增 InvalidateProfileCache(id, username) helper,由调用方**在 TransactCtx
  1524. // 返回(commit 成功)之后**显式调 DelCacheCtx 失效 id / username 两把 key。
  1525. //
  1526. // 本测试组把两个语义契约各自钉死:
  1527. // A) 事务内 UpdateProfileWithTx 自身不得碰缓存(即便事务 commit 成功,缓存仍持旧值)。
  1528. // B) InvalidateProfileCache 必须一次性失效 id / username 两把低层 key。
  1529. // ---------------------------------------------------------------------------
  1530. func seedUserForR12_1(t *testing.T, m user.SysUserModel) (*user.SysUser, func()) {
  1531. t.Helper()
  1532. ctx := context.Background()
  1533. now := time.Now().Unix()
  1534. username := "r12_1_" + testutil.UniqueId()
  1535. res, err := m.Insert(ctx, &user.SysUser{
  1536. Username: username,
  1537. Password: "pw",
  1538. Nickname: "orig",
  1539. Avatar: sql.NullString{},
  1540. Email: username + "@test.com",
  1541. Phone: "13800000000",
  1542. Remark: "orig_remark",
  1543. DeptId: 0,
  1544. IsSuperAdmin: 2,
  1545. MustChangePassword: 2,
  1546. Status: 1,
  1547. CreateTime: now,
  1548. UpdateTime: now,
  1549. })
  1550. require.NoError(t, err)
  1551. id, _ := res.LastInsertId()
  1552. u, err := m.FindOne(ctx, id)
  1553. require.NoError(t, err, "FindOne 预热 id 维度缓存")
  1554. _, err = m.FindOneByUsername(ctx, username)
  1555. require.NoError(t, err, "FindOneByUsername 预热 username 维度缓存")
  1556. return u, func() {
  1557. conn := testutil.GetTestSqlConn()
  1558. testutil.CleanTable(ctx, conn, "`sys_user`", id)
  1559. }
  1560. }
  1561. func userCacheKeys(id int64, username string) (idKey, usernameKey string) {
  1562. prefix := testutil.GetTestCachePrefix()
  1563. idKey = fmt.Sprintf("%s:cache:sysUser:id:%d", prefix, id)
  1564. usernameKey = fmt.Sprintf("%s:cache:sysUser:username:%s", prefix, username)
  1565. return
  1566. }
  1567. // TC-1080: UpdateProfileWithTx 成功提交后缓存仍持旧值(证明已绕过 pre-commit DelCache)
  1568. // 修复前该测试会失败:m.ExecCtx 会在 session.ExecCtx 返回时立刻清掉两把 key。
  1569. // 修复后 UpdateProfileWithTx 只走 session.ExecCtx,缓存必须保持不动,直到调用方显式 invalidate。
  1570. func TestUpdateProfileWithTx_DoesNotSelfInvalidateCache(t *testing.T) {
  1571. ctx := context.Background()
  1572. conn := testutil.GetTestSqlConn()
  1573. m := user.NewSysUserModel(conn, testutil.GetTestCacheConf(), testutil.GetTestCachePrefix())
  1574. rds := redis.MustNewRedis(testutil.GetTestConfig().CacheRedis.Nodes[0].RedisConf)
  1575. u, cleanup := seedUserForR12_1(t, m)
  1576. t.Cleanup(cleanup)
  1577. idKey, usernameKey := userCacheKeys(u.Id, u.Username)
  1578. gotId, err := rds.Get(idKey)
  1579. require.NoError(t, err)
  1580. require.NotEmpty(t, gotId, "预置断言:id 缓存已预热")
  1581. gotUn, err := rds.Get(usernameKey)
  1582. require.NoError(t, err)
  1583. require.NotEmpty(t, gotUn, "预置断言:username 缓存已预热")
  1584. require.NoError(t,
  1585. m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  1586. return m.UpdateProfileWithTx(
  1587. c, session,
  1588. u.Id, u.Username,
  1589. "new_nick", u.Email, u.Phone, "new_remark",
  1590. u.DeptId, u.Status, false, u.UpdateTime,
  1591. )
  1592. }))
  1593. // 事务已 commit,DB 里是新值;但 UpdateProfileWithTx 不得碰缓存。
  1594. // 严格契约:两把 key 必须仍存在且值为旧 payload(否则等价于 pre-commit DelCache 回归)。
  1595. gotIdAfter, err := rds.Get(idKey)
  1596. require.NoError(t, err)
  1597. assert.NotEmpty(t, gotIdAfter,
  1598. "UpdateProfileWithTx 内部不得失效 id 维度缓存 —— "+
  1599. "若缓存被清,证明又回到 m.ExecCtx 的 pre-commit DelCache 模式,"+
  1600. "并发 FindOne 会在事务 commit 前把旧值回灌成 stale")
  1601. assert.Equal(t, gotId, gotIdAfter,
  1602. "缓存值必须保持不变(仍为预热时的旧 payload),一旦变动代表 UpdateProfileWithTx "+
  1603. "自作主张动了缓存")
  1604. gotUnAfter, err := rds.Get(usernameKey)
  1605. require.NoError(t, err)
  1606. assert.NotEmpty(t, gotUnAfter,
  1607. "username 维度缓存同样不得被 UpdateProfileWithTx 失效")
  1608. assert.Equal(t, gotUn, gotUnAfter)
  1609. // DB 确为新值:证明 session.ExecCtx 确实跑了 UPDATE,不是空操作掩盖。
  1610. var nickFromDb string
  1611. require.NoError(t, conn.QueryRowCtx(ctx, &nickFromDb,
  1612. "SELECT `nickname` FROM `sys_user` WHERE `id` = ?", u.Id))
  1613. assert.Equal(t, "new_nick", nickFromDb,
  1614. "DB 必须已更新为新值,证明 UPDATE 真的通过 session.ExecCtx 落盘;"+
  1615. "这样缓存仍是旧值才真正构成 stale 风险场景")
  1616. }
  1617. // TC-1081: InvalidateProfileCache 必须同时失效 id 与 username 两把 key
  1618. // 对应 fix:post-commit 阶段由调用方显式调用,一次性清理 sysUser 低层缓存。
  1619. func TestInvalidateProfileCache_DelsBothKeys(t *testing.T) {
  1620. ctx := context.Background()
  1621. conn := testutil.GetTestSqlConn()
  1622. m := user.NewSysUserModel(conn, testutil.GetTestCacheConf(), testutil.GetTestCachePrefix())
  1623. rds := redis.MustNewRedis(testutil.GetTestConfig().CacheRedis.Nodes[0].RedisConf)
  1624. u, cleanup := seedUserForR12_1(t, m)
  1625. t.Cleanup(cleanup)
  1626. idKey, usernameKey := userCacheKeys(u.Id, u.Username)
  1627. idBefore, err := rds.Get(idKey)
  1628. require.NoError(t, err)
  1629. require.NotEmpty(t, idBefore, "预置:id 缓存已存在")
  1630. unBefore, err := rds.Get(usernameKey)
  1631. require.NoError(t, err)
  1632. require.NotEmpty(t, unBefore, "预置:username 缓存已存在")
  1633. m.InvalidateProfileCache(ctx, u.Id, u.Username)
  1634. idAfter, err := rds.Get(idKey)
  1635. require.NoError(t, err)
  1636. assert.Empty(t, idAfter,
  1637. "InvalidateProfileCache 必须失效 sysUser:id 缓存 key %q", idKey)
  1638. unAfter, err := rds.Get(usernameKey)
  1639. require.NoError(t, err)
  1640. assert.Empty(t, unAfter,
  1641. "InvalidateProfileCache 必须同时失效 sysUser:username 缓存 key %q", usernameKey)
  1642. }
  1643. // TC-1082: 完整两段式闭环:UpdateProfileWithTx(不碰缓存) + InvalidateProfileCache(清缓存) → 下一轮 FindOne 取到新值
  1644. // 本 TC 是修复后的正向契约:只有两步都按顺序做到,才保证业务最终从缓存读到新值。
  1645. // 若未来有人回滚到只做第一步不调 invalidate,FindOne 会返回旧值 → 本 TC 直接炸掉,不给静默回归机会。
  1646. func TestUpdateProfileWithTx_PlusInvalidateProfileCache_E2E(t *testing.T) {
  1647. ctx := context.Background()
  1648. conn := testutil.GetTestSqlConn()
  1649. m := user.NewSysUserModel(conn, testutil.GetTestCacheConf(), testutil.GetTestCachePrefix())
  1650. u, cleanup := seedUserForR12_1(t, m)
  1651. t.Cleanup(cleanup)
  1652. require.NoError(t,
  1653. m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  1654. return m.UpdateProfileWithTx(
  1655. c, session,
  1656. u.Id, u.Username,
  1657. "e2e_nick", u.Email, u.Phone, "e2e_remark",
  1658. u.DeptId, u.Status, false, u.UpdateTime,
  1659. )
  1660. }))
  1661. // Step A: 仅事务成功,缓存仍旧 → FindOne 命中缓存返回旧值
  1662. afterUpdOnly, err := m.FindOne(ctx, u.Id)
  1663. require.NoError(t, err)
  1664. assert.Equal(t, "orig", afterUpdOnly.Nickname,
  1665. "未 invalidate 前 FindOne 必须命中缓存返回旧值,证明 UpdateProfileWithTx "+
  1666. "确实绕过了 pre-commit DelCache(否则缓存已被清,这里应当已回灌新值)")
  1667. // Step B: post-commit 显式 invalidate → 下一轮 FindOne miss 后回源 DB 取新值
  1668. m.InvalidateProfileCache(ctx, u.Id, u.Username)
  1669. afterInvalidate, err := m.FindOne(ctx, u.Id)
  1670. require.NoError(t, err)
  1671. assert.Equal(t, "e2e_nick", afterInvalidate.Nickname,
  1672. "InvalidateProfileCache 后 FindOne 必须回源 DB 并得到新值;"+
  1673. "两步共同保证'事务提交 → 缓存权威'的正确顺序")
  1674. assert.Equal(t, "e2e_remark", afterInvalidate.Remark,
  1675. "non-status 字段也必须与 DB 一致,确保 DelCache 清到的是完整缓存行而不是部分失效")
  1676. }
  1677. // TC-1117: InvalidateProfileCache 在 ctx 已取消 / 已超时下仍不得 panic、不得阻塞主流程。
  1678. // 这条契约是 L-R13-5 方案 B 的核心:post-commit 缓存清理是 best-effort,ctx 异常分类
  1679. // 走 audit tag 日志,但绝不能把异常向上抛给业务流程(DB 事务已 commit,业务已成功)。
  1680. func TestInvalidateProfileCache_CanceledCtxDoesNotPanicOrBlock(t *testing.T) {
  1681. conn := testutil.GetTestSqlConn()
  1682. m := user.NewSysUserModel(conn, testutil.GetTestCacheConf(), testutil.GetTestCachePrefix())
  1683. u, cleanup := seedUserForR12_1(t, m)
  1684. t.Cleanup(cleanup)
  1685. cases := []struct {
  1686. name string
  1687. makeCtx func() (context.Context, context.CancelFunc)
  1688. }{
  1689. {
  1690. name: "already_canceled",
  1691. makeCtx: func() (context.Context, context.CancelFunc) {
  1692. ctx, cancel := context.WithCancel(context.Background())
  1693. cancel()
  1694. return ctx, func() {}
  1695. },
  1696. },
  1697. {
  1698. name: "already_deadline_exceeded",
  1699. makeCtx: func() (context.Context, context.CancelFunc) {
  1700. ctx, cancel := context.WithDeadline(context.Background(), time.Now().Add(-time.Second))
  1701. return ctx, cancel
  1702. },
  1703. },
  1704. }
  1705. for _, tc := range cases {
  1706. tc := tc
  1707. t.Run(tc.name, func(t *testing.T) {
  1708. ctx, cancel := tc.makeCtx()
  1709. defer cancel()
  1710. done := make(chan struct{})
  1711. go func() {
  1712. defer close(done)
  1713. assert.NotPanics(t, func() {
  1714. m.InvalidateProfileCache(ctx, u.Id, u.Username)
  1715. }, "ctx 异常下 InvalidateProfileCache 必须吞错不 panic")
  1716. }()
  1717. select {
  1718. case <-done:
  1719. case <-time.After(500 * time.Millisecond):
  1720. t.Fatal("InvalidateProfileCache 在 canceled ctx 下必须立即返回,不得阻塞 post-commit 路径")
  1721. }
  1722. })
  1723. }
  1724. }
  1725. // ---------------------------------------------------------------------------
  1726. // M-R15-1 / L-R15-3:IncrementTokenVersionWithTx / BatchIncrementTokenVersionWithTx
  1727. //
  1728. // 接口契约:
  1729. // - 必须在调用方提供的事务里执行(session=nil 直接 error);
  1730. // - 不得自身触发 sqlc 缓存失效(与 UpdateProfileWithTx 同家族——失效由 post-commit 的
  1731. // InvalidateProfileCache 单独走);
  1732. // - 事务未提交时外部 FindOne 仍看到旧 tokenVersion;rollback 必须让 DB 保持初值。
  1733. // ---------------------------------------------------------------------------
  1734. // TC-1143: IncrementTokenVersionWithTx 正常路径——事务内 UPDATE,返回 DB 递增后的值。
  1735. func TestIncrementTokenVersionWithTx_ReturnsNewVersion(t *testing.T) {
  1736. m, conn := newModel(t)
  1737. ctx := context.Background()
  1738. now := time.Now().Unix()
  1739. username := "itv_tx_ok_" + testutil.UniqueId()
  1740. res, err := m.Insert(ctx, &user.SysUser{
  1741. Username: username, Password: "x", Nickname: "n",
  1742. Avatar: sql.NullString{}, IsSuperAdmin: 2, MustChangePassword: 2,
  1743. Status: 1, TokenVersion: 3, CreateTime: now, UpdateTime: now,
  1744. })
  1745. require.NoError(t, err)
  1746. id, _ := res.LastInsertId()
  1747. t.Cleanup(func() { testutil.CleanTable(ctx, conn, "`sys_user`", id) })
  1748. var newVersion int64
  1749. require.NoError(t,
  1750. m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  1751. v, e := m.IncrementTokenVersionWithTx(c, session, id)
  1752. if e != nil {
  1753. return e
  1754. }
  1755. newVersion = v
  1756. return nil
  1757. }))
  1758. assert.Equal(t, int64(4), newVersion,
  1759. "LAST_INSERT_ID(tokenVersion+1) 必须返回 DB 真实递增后的值(4=3+1)")
  1760. // 事务 commit 后再从 DB 读,确认值被持久化
  1761. fresh, err := m.FindOne(ctx, id)
  1762. require.NoError(t, err)
  1763. assert.Equal(t, int64(4), fresh.TokenVersion, "DB 必须持久化递增后的 tokenVersion")
  1764. }
  1765. // TC-1144: IncrementTokenVersionWithTx 目标行在事务内被并发删除 → affected=0 → ErrUpdateConflict。
  1766. // 与 IncrementTokenVersion 的 L-R10-3 契约对齐:不得静默返回 tokenVersion=0。
  1767. func TestIncrementTokenVersionWithTx_NotFound_ReturnsUpdateConflict(t *testing.T) {
  1768. m, _ := newModel(t)
  1769. ctx := context.Background()
  1770. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  1771. _, e := m.IncrementTokenVersionWithTx(c, session, 999999999999)
  1772. require.ErrorIs(t, e, user.ErrUpdateConflict,
  1773. "目标行不存在时必须返回 ErrUpdateConflict,让上层事务 rollback")
  1774. return nil
  1775. })
  1776. require.NoError(t, err)
  1777. }
  1778. // TC-1145: IncrementTokenVersionWithTx session==nil → 必须返回错误(防御性编程)。
  1779. // 此契约保证调用方无法"忘了开事务"就误用——直接 nil session 等同于退化为非事务递增,
  1780. // 会打破"降权吊销" = "业务 UPDATE" 的原子性语义。
  1781. func TestIncrementTokenVersionWithTx_NilSession_ReturnsError(t *testing.T) {
  1782. m, _ := newModel(t)
  1783. _, err := m.IncrementTokenVersionWithTx(context.Background(), nil, 1)
  1784. require.Error(t, err,
  1785. "nil session 必须 fail-fast,防止调用方脱离事务误用")
  1786. assert.Contains(t, err.Error(), "non-nil session")
  1787. }
  1788. // TC-1146: 事务 rollback 时 tokenVersion 不得落盘。
  1789. // 这是"降权吊销与业务 UPDATE 原子绑定"的正向证据:UpdateMember 的 last-admin 校验
  1790. // 失败 rollback 也会把 IncrementTokenVersionWithTx 的副作用一并回滚。
  1791. func TestIncrementTokenVersionWithTx_Rollback_NoPersistence(t *testing.T) {
  1792. m, conn := newModel(t)
  1793. ctx := context.Background()
  1794. now := time.Now().Unix()
  1795. username := "itv_tx_rb_" + testutil.UniqueId()
  1796. res, err := m.Insert(ctx, &user.SysUser{
  1797. Username: username, Password: "x", Nickname: "n",
  1798. Avatar: sql.NullString{}, IsSuperAdmin: 2, MustChangePassword: 2,
  1799. Status: 1, TokenVersion: 7, CreateTime: now, UpdateTime: now,
  1800. })
  1801. require.NoError(t, err)
  1802. id, _ := res.LastInsertId()
  1803. t.Cleanup(func() { testutil.CleanTable(ctx, conn, "`sys_user`", id) })
  1804. err = m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  1805. _, e := m.IncrementTokenVersionWithTx(c, session, id)
  1806. require.NoError(t, e)
  1807. return errors.New("force rollback")
  1808. })
  1809. require.Error(t, err)
  1810. // 直读 DB 确认 rollback 后 tokenVersion 仍是 7(绕过缓存读法:FindOne 也能测到,因为
  1811. // IncrementTokenVersionWithTx 不自身失效缓存,事务 rollback 后缓存依旧是入口时写入的 7)
  1812. var tv int64
  1813. require.NoError(t,
  1814. conn.QueryRowCtx(ctx, &tv,
  1815. "SELECT `tokenVersion` FROM `sys_user` WHERE `id` = ?", id))
  1816. assert.Equal(t, int64(7), tv,
  1817. "事务 rollback 后 tokenVersion 必须保持初值,否则业务失败会把合法用户莫名踢下线")
  1818. }
  1819. // TC-1147: BatchIncrementTokenVersionWithTx 正常路径——多用户同时 +1。
  1820. func TestBatchIncrementTokenVersionWithTx_BumpsAll(t *testing.T) {
  1821. m, conn := newModel(t)
  1822. ctx := context.Background()
  1823. now := time.Now().Unix()
  1824. var ids []int64
  1825. for i := 0; i < 3; i++ {
  1826. res, err := m.Insert(ctx, &user.SysUser{
  1827. Username: fmt.Sprintf("bitv_ok_%d_%s", i, testutil.UniqueId()),
  1828. Password: "x", Nickname: "n",
  1829. Avatar: sql.NullString{}, IsSuperAdmin: 2, MustChangePassword: 2,
  1830. Status: 1, TokenVersion: int64(10 + i), CreateTime: now, UpdateTime: now,
  1831. })
  1832. require.NoError(t, err)
  1833. id, _ := res.LastInsertId()
  1834. ids = append(ids, id)
  1835. }
  1836. t.Cleanup(func() { testutil.CleanTable(ctx, conn, "`sys_user`", ids...) })
  1837. require.NoError(t,
  1838. m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  1839. return m.BatchIncrementTokenVersionWithTx(c, session, ids)
  1840. }))
  1841. for i, id := range ids {
  1842. var tv int64
  1843. require.NoError(t,
  1844. conn.QueryRowCtx(ctx, &tv,
  1845. "SELECT `tokenVersion` FROM `sys_user` WHERE `id` = ?", id))
  1846. assert.Equal(t, int64(10+i+1), tv,
  1847. "id=%d tokenVersion 必须 +1(初值=%d)", id, 10+i)
  1848. }
  1849. }
  1850. // TC-1148: BatchIncrementTokenVersionWithTx 空 ids 不得报错,也不得触达 DB。
  1851. // 对应 UpdateProduct 空活跃成员场景:若此方法对 []int64{} 误抛错,会让禁用产品事务整体 rollback。
  1852. func TestBatchIncrementTokenVersionWithTx_EmptyIds_NoOp(t *testing.T) {
  1853. m, _ := newModel(t)
  1854. ctx := context.Background()
  1855. require.NoError(t,
  1856. m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  1857. require.NoError(t, m.BatchIncrementTokenVersionWithTx(c, session, nil))
  1858. require.NoError(t, m.BatchIncrementTokenVersionWithTx(c, session, []int64{}))
  1859. return nil
  1860. }))
  1861. }
  1862. // TC-1149: BatchIncrementTokenVersionWithTx nil session → error。
  1863. func TestBatchIncrementTokenVersionWithTx_NilSession_ReturnsError(t *testing.T) {
  1864. m, _ := newModel(t)
  1865. err := m.BatchIncrementTokenVersionWithTx(context.Background(), nil, []int64{1, 2})
  1866. require.Error(t, err)
  1867. assert.Contains(t, err.Error(), "non-nil session")
  1868. }
  1869. // TC-1150: BatchIncrementTokenVersionWithTx rollback 后 tokenVersion 全部回滚。
  1870. // 覆盖"产品禁用事务中途失败必须整体回滚"的原子性边界——
  1871. // 若 Batch UPDATE 走独立连接(而不是 session),事务 rollback 无法撤销,则本用例直接炸。
  1872. func TestBatchIncrementTokenVersionWithTx_Rollback_NoPersistence(t *testing.T) {
  1873. m, conn := newModel(t)
  1874. ctx := context.Background()
  1875. now := time.Now().Unix()
  1876. var ids []int64
  1877. for i := 0; i < 2; i++ {
  1878. res, err := m.Insert(ctx, &user.SysUser{
  1879. Username: fmt.Sprintf("bitv_rb_%d_%s", i, testutil.UniqueId()),
  1880. Password: "x", Nickname: "n",
  1881. Avatar: sql.NullString{}, IsSuperAdmin: 2, MustChangePassword: 2,
  1882. Status: 1, TokenVersion: 50, CreateTime: now, UpdateTime: now,
  1883. })
  1884. require.NoError(t, err)
  1885. id, _ := res.LastInsertId()
  1886. ids = append(ids, id)
  1887. }
  1888. t.Cleanup(func() { testutil.CleanTable(ctx, conn, "`sys_user`", ids...) })
  1889. err := m.TransactCtx(ctx, func(c context.Context, session sqlx.Session) error {
  1890. if e := m.BatchIncrementTokenVersionWithTx(c, session, ids); e != nil {
  1891. return e
  1892. }
  1893. return errors.New("force rollback after batch update")
  1894. })
  1895. require.Error(t, err)
  1896. for _, id := range ids {
  1897. var tv int64
  1898. require.NoError(t,
  1899. conn.QueryRowCtx(ctx, &tv,
  1900. "SELECT `tokenVersion` FROM `sys_user` WHERE `id` = ?", id))
  1901. assert.Equal(t, int64(50), tv,
  1902. "id=%d rollback 后 tokenVersion 必须保持初值", id)
  1903. }
  1904. }