userDetailLogic_test.go 6.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180
  1. package user
  2. import (
  3. "context"
  4. "database/sql"
  5. "errors"
  6. "github.com/stretchr/testify/assert"
  7. "github.com/stretchr/testify/require"
  8. "perms-system-server/internal/consts"
  9. "perms-system-server/internal/loaders"
  10. "perms-system-server/internal/middleware"
  11. memberModel "perms-system-server/internal/model/productmember"
  12. userModel "perms-system-server/internal/model/user"
  13. "perms-system-server/internal/model/userrole"
  14. "perms-system-server/internal/response"
  15. "perms-system-server/internal/svc"
  16. "perms-system-server/internal/testutil"
  17. "perms-system-server/internal/testutil/ctxhelper"
  18. "perms-system-server/internal/types"
  19. "testing"
  20. "time"
  21. )
  22. func TestUserDetail_Success(t *testing.T) {
  23. ctx := ctxhelper.SuperAdminCtx()
  24. svcCtx := svc.NewServiceContext(testutil.GetTestConfig())
  25. conn := testutil.GetTestSqlConn()
  26. username := testutil.UniqueId()
  27. userId := insertTestUser(t, ctx, username, testutil.HashPassword("pass"))
  28. // 插入两条"当前产品"下的真实 sys_role 以及一条属于其它产品的 sys_role,
  29. // 用户同时绑定这三个角色。超管在 test_product 上下文下应当只看到前两个。
  30. roleInCurrent1 := insertTestRole(t, svcCtx, "test_product", 1)
  31. roleInCurrent2 := insertTestRole(t, svcCtx, "test_product", 1)
  32. roleInOther := insertTestRole(t, svcCtx, "other_product", 1)
  33. now := time.Now().Unix()
  34. var roleRecordIds []int64
  35. for _, roleId := range []int64{roleInCurrent1, roleInCurrent2, roleInOther} {
  36. res, err := svcCtx.SysUserRoleModel.Insert(ctx, &userrole.SysUserRole{
  37. UserId: userId,
  38. RoleId: roleId,
  39. CreateTime: now,
  40. UpdateTime: now,
  41. })
  42. require.NoError(t, err)
  43. id, _ := res.LastInsertId()
  44. roleRecordIds = append(roleRecordIds, id)
  45. }
  46. t.Cleanup(func() {
  47. testutil.CleanTable(ctx, conn, "`sys_user_role`", roleRecordIds...)
  48. testutil.CleanTable(ctx, conn, "`sys_role`", roleInCurrent1, roleInCurrent2, roleInOther)
  49. testutil.CleanTable(ctx, conn, "`sys_user`", userId)
  50. })
  51. logic := NewUserDetailLogic(ctx, svcCtx)
  52. resp, err := logic.UserDetail(&types.UserDetailReq{Id: userId})
  53. require.NoError(t, err)
  54. require.NotNil(t, resp)
  55. assert.Equal(t, userId, resp.Id)
  56. assert.Equal(t, username, resp.Username)
  57. // 修复后:超管在产品上下文里只看到 test_product 的角色;other_product 的角色不应返回
  58. assert.ElementsMatch(t, []int64{roleInCurrent1, roleInCurrent2}, resp.RoleIds)
  59. assert.NotContains(t, resp.RoleIds, roleInOther, "超管在具体产品上下文不应返回其它产品的 roleIds")
  60. }
  61. // TC-0182: 正常查询-含Avatar
  62. func TestUserDetail_WithAvatar(t *testing.T) {
  63. ctx := ctxhelper.SuperAdminCtx()
  64. svcCtx := svc.NewServiceContext(testutil.GetTestConfig())
  65. conn := testutil.GetTestSqlConn()
  66. userId := insertTestUserFull(t, ctx, &userModel.SysUser{
  67. Username: testutil.UniqueId(),
  68. Password: testutil.HashPassword("pass"),
  69. Nickname: "avatar_user",
  70. Avatar: sql.NullString{String: "https://example.com/avatar.png", Valid: true},
  71. IsSuperAdmin: 2,
  72. MustChangePassword: 2,
  73. Status: 1,
  74. })
  75. t.Cleanup(func() { testutil.CleanTable(ctx, conn, "`sys_user`", userId) })
  76. logic := NewUserDetailLogic(ctx, svcCtx)
  77. resp, err := logic.UserDetail(&types.UserDetailReq{Id: userId})
  78. require.NoError(t, err)
  79. require.NotNil(t, resp)
  80. assert.Equal(t, "https://example.com/avatar.png", resp.Avatar)
  81. }
  82. // TC-0183: 不存在
  83. func TestUserDetail_NotFound(t *testing.T) {
  84. ctx := ctxhelper.SuperAdminCtx()
  85. svcCtx := svc.NewServiceContext(testutil.GetTestConfig())
  86. logic := NewUserDetailLogic(ctx, svcCtx)
  87. _, err := logic.UserDetail(&types.UserDetailReq{Id: 999999999})
  88. require.Error(t, err)
  89. var codeErr *response.CodeError
  90. require.True(t, errors.As(err, &codeErr))
  91. assert.Equal(t, 404, codeErr.Code())
  92. assert.Equal(t, "用户不存在", codeErr.Error())
  93. }
  94. func insertH1Member(t *testing.T, ctx context.Context, svcCtx *svc.ServiceContext, productCode string, u *userModel.SysUser) (int64, int64) {
  95. t.Helper()
  96. id := insertTestUserFull(t, ctx, u)
  97. now := time.Now().Unix()
  98. res, err := svcCtx.SysProductMemberModel.Insert(ctx, &memberModel.SysProductMember{
  99. ProductCode: productCode, UserId: id, MemberType: consts.MemberTypeMember,
  100. Status: 1, CreateTime: now, UpdateTime: now,
  101. })
  102. require.NoError(t, err)
  103. mId, _ := res.LastInsertId()
  104. return id, mId
  105. }
  106. // TC-0991: 业务契约——看自己时 Email/Phone/Remark 原样返回。
  107. // 背景:PII 契约已由业务侧固定为"所有调用者(含同产品 MEMBER)原样返回联系信息",
  108. // 故不存在脱敏短路;本用例作为回归守卫,防止未来有人误加"同级脱敏"把 self-view 一起打了。
  109. func TestUserDetail_H1_ViewSelf_KeepsPII(t *testing.T) {
  110. ctx := context.Background()
  111. svcCtx := svc.NewServiceContext(testutil.GetTestConfig())
  112. conn := testutil.GetTestSqlConn()
  113. productCode := "h1_self_" + testutil.UniqueId()
  114. selfId, mSelf := insertH1Member(t, ctx, svcCtx, productCode, &userModel.SysUser{
  115. Username: "self_" + testutil.UniqueId(),
  116. Password: testutil.HashPassword("pw"),
  117. Nickname: "self",
  118. Email: "[email protected]",
  119. Phone: "13900002222",
  120. Remark: "self-only note",
  121. IsSuperAdmin: 2,
  122. MustChangePassword: 2,
  123. Status: 1,
  124. DeptId: 1,
  125. })
  126. t.Cleanup(func() {
  127. testutil.CleanTable(ctx, conn, "`sys_product_member`", mSelf)
  128. testutil.CleanTable(ctx, conn, "`sys_user`", selfId)
  129. })
  130. selfCtx := middleware.WithUserDetails(context.Background(), &loaders.UserDetails{
  131. UserId: selfId, Username: "self", MemberType: consts.MemberTypeMember,
  132. Status: 1, ProductCode: productCode, DeptId: 1, DeptPath: "/1/", MinPermsLevel: 100,
  133. })
  134. resp, err := NewUserDetailLogic(selfCtx, svcCtx).UserDetail(&types.UserDetailReq{Id: selfId})
  135. require.NoError(t, err)
  136. assert.Equal(t, "[email protected]", resp.Email, "看自己必须返回 Email 原值")
  137. assert.Equal(t, "13900002222", resp.Phone, "看自己必须返回 Phone 原值")
  138. assert.Equal(t, "self-only note", resp.Remark, "看自己必须返回 Remark 原值")
  139. }
  140. // TC-0992: 超管分支 —— SuperAdmin 看任何用户必须拿到 Email/Phone/Remark 原值。
  141. // 若未来有人加脱敏逻辑却漏写 IsSuperAdmin 豁免,本用例立刻炸。
  142. func TestUserDetail_H1_SuperAdmin_KeepsPII(t *testing.T) {
  143. ctx := ctxhelper.SuperAdminCtx()
  144. svcCtx := svc.NewServiceContext(testutil.GetTestConfig())
  145. conn := testutil.GetTestSqlConn()
  146. userId := insertTestUserFull(t, ctx, &userModel.SysUser{
  147. Username: "sa_view_" + testutil.UniqueId(), Password: testutil.HashPassword("pw"),
  148. Nickname: "n", Email: "[email protected]", Phone: "13700000000", Remark: "nb",
  149. IsSuperAdmin: 2, MustChangePassword: 2, Status: 1,
  150. })
  151. t.Cleanup(func() { testutil.CleanTable(ctx, conn, "`sys_user`", userId) })
  152. resp, err := NewUserDetailLogic(ctx, svcCtx).UserDetail(&types.UserDetailReq{Id: userId})
  153. require.NoError(t, err)
  154. assert.Equal(t, "[email protected]", resp.Email)
  155. assert.Equal(t, "13700000000", resp.Phone)
  156. assert.Equal(t, "nb", resp.Remark)
  157. }