userDetailsLoader_test.go 38 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178
  1. package loaders
  2. import (
  3. "context"
  4. "database/sql"
  5. "fmt"
  6. "math"
  7. "math/rand"
  8. "sort"
  9. "testing"
  10. "time"
  11. "perms-system-server/internal/consts"
  12. "perms-system-server/internal/model"
  13. deptModel "perms-system-server/internal/model/dept"
  14. permModel "perms-system-server/internal/model/perm"
  15. productModel "perms-system-server/internal/model/product"
  16. memberModel "perms-system-server/internal/model/productmember"
  17. roleModel "perms-system-server/internal/model/role"
  18. rolePermModel "perms-system-server/internal/model/roleperm"
  19. userModel "perms-system-server/internal/model/user"
  20. userPermModel "perms-system-server/internal/model/userperm"
  21. userRoleModel "perms-system-server/internal/model/userrole"
  22. "github.com/stretchr/testify/assert"
  23. "github.com/stretchr/testify/require"
  24. "github.com/zeromicro/go-zero/core/stores/cache"
  25. "github.com/zeromicro/go-zero/core/stores/redis"
  26. "github.com/zeromicro/go-zero/core/stores/sqlx"
  27. "golang.org/x/crypto/bcrypt"
  28. )
  29. // --------------- inline test config (avoid circular import with testutil) ---------------
  30. var testCacheConf = cache.CacheConf{
  31. {
  32. RedisConf: redis.RedisConf{Host: "127.0.0.1:6379", Pass: "NsDmWyM@312", Type: "node"},
  33. Weight: 100,
  34. },
  35. }
  36. var testKeyPrefix = "test_perms"
  37. var testDataSource = "root:NsDmWyM@312@tcp(127.0.0.1:3306)/perms_system?charset=utf8mb4&parseTime=true&loc=Asia%2FShanghai"
  38. func testConn() sqlx.SqlConn { return sqlx.NewMysql(testDataSource) }
  39. func testRedis() *redis.Redis { return redis.MustNewRedis(testCacheConf[0].RedisConf) }
  40. func testModels() *model.Models {
  41. conn := testConn()
  42. return model.NewModels(conn, testCacheConf, testKeyPrefix)
  43. }
  44. func uniqueId() string {
  45. return fmt.Sprintf("t_%d_%d", time.Now().UnixNano(), rand.Intn(100000))
  46. }
  47. func hashPwd(p string) string {
  48. h, _ := bcrypt.GenerateFromPassword([]byte(p), bcrypt.MinCost)
  49. return string(h)
  50. }
  51. func cleanTable(ctx context.Context, conn sqlx.SqlConn, table string, ids ...int64) {
  52. for _, id := range ids {
  53. conn.ExecCtx(ctx, fmt.Sprintf("DELETE FROM %s WHERE `id` = ?", table), id)
  54. }
  55. }
  56. func cleanTableByField(ctx context.Context, conn sqlx.SqlConn, table, field string, value interface{}) {
  57. conn.ExecCtx(ctx, fmt.Sprintf("DELETE FROM %s WHERE `%s` = ?", table, field), value)
  58. }
  59. func newTestLoader() *UserDetailsLoader {
  60. rds := testRedis()
  61. m := testModels()
  62. return NewUserDetailsLoader(rds, testKeyPrefix, m)
  63. }
  64. func now() int64 { return time.Now().Unix() }
  65. // --------------- helpers: insert test data ---------------
  66. func insertUser(ctx context.Context, t *testing.T, m *model.Models, u *userModel.SysUser) int64 {
  67. t.Helper()
  68. res, err := m.SysUserModel.Insert(ctx, u)
  69. require.NoError(t, err)
  70. id, _ := res.LastInsertId()
  71. return id
  72. }
  73. func insertDept(ctx context.Context, t *testing.T, m *model.Models, d *deptModel.SysDept) int64 {
  74. t.Helper()
  75. res, err := m.SysDeptModel.Insert(ctx, d)
  76. require.NoError(t, err)
  77. id, _ := res.LastInsertId()
  78. return id
  79. }
  80. func insertProduct(ctx context.Context, t *testing.T, m *model.Models, p *productModel.SysProduct) int64 {
  81. t.Helper()
  82. res, err := m.SysProductModel.Insert(ctx, p)
  83. require.NoError(t, err)
  84. id, _ := res.LastInsertId()
  85. return id
  86. }
  87. func insertMember(ctx context.Context, t *testing.T, m *model.Models, mb *memberModel.SysProductMember) int64 {
  88. t.Helper()
  89. res, err := m.SysProductMemberModel.Insert(ctx, mb)
  90. require.NoError(t, err)
  91. id, _ := res.LastInsertId()
  92. return id
  93. }
  94. func insertRole(ctx context.Context, t *testing.T, m *model.Models, r *roleModel.SysRole) int64 {
  95. t.Helper()
  96. res, err := m.SysRoleModel.Insert(ctx, r)
  97. require.NoError(t, err)
  98. id, _ := res.LastInsertId()
  99. return id
  100. }
  101. func insertPerm(ctx context.Context, t *testing.T, m *model.Models, p *permModel.SysPerm) int64 {
  102. t.Helper()
  103. res, err := m.SysPermModel.Insert(ctx, p)
  104. require.NoError(t, err)
  105. id, _ := res.LastInsertId()
  106. return id
  107. }
  108. func insertUserRole(ctx context.Context, t *testing.T, m *model.Models, ur *userRoleModel.SysUserRole) int64 {
  109. t.Helper()
  110. res, err := m.SysUserRoleModel.Insert(ctx, ur)
  111. require.NoError(t, err)
  112. id, _ := res.LastInsertId()
  113. return id
  114. }
  115. func insertRolePerm(ctx context.Context, t *testing.T, m *model.Models, rp *rolePermModel.SysRolePerm) int64 {
  116. t.Helper()
  117. res, err := m.SysRolePermModel.Insert(ctx, rp)
  118. require.NoError(t, err)
  119. id, _ := res.LastInsertId()
  120. return id
  121. }
  122. func insertUserPerm(ctx context.Context, t *testing.T, m *model.Models, up *userPermModel.SysUserPerm) int64 {
  123. t.Helper()
  124. res, err := m.SysUserPermModel.Insert(ctx, up)
  125. require.NoError(t, err)
  126. id, _ := res.LastInsertId()
  127. return id
  128. }
  129. // --------------- TC-0458: Load-DB加载(缓存miss) ---------------
  130. func TestLoad_DBMiss(t *testing.T) {
  131. ctx := context.Background()
  132. conn := testConn()
  133. m := testModels()
  134. loader := newTestLoader()
  135. uid := uniqueId()
  136. ts := now()
  137. pcode := "p_" + uid
  138. deptId := insertDept(ctx, t, m, &deptModel.SysDept{
  139. ParentId: 0, Name: "dept_" + uid, Path: "/1/", Sort: 1,
  140. DeptType: consts.DeptTypeNormal, Status: consts.StatusEnabled,
  141. CreateTime: ts, UpdateTime: ts,
  142. })
  143. userId := insertUser(ctx, t, m, &userModel.SysUser{
  144. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  145. Avatar: sql.NullString{}, Email: uid + "@test.com", Phone: "13800000001",
  146. Remark: "remark", DeptId: deptId, IsSuperAdmin: consts.IsSuperAdminNo,
  147. MustChangePassword: consts.MustChangePasswordNo, Status: consts.StatusEnabled,
  148. CreateTime: ts, UpdateTime: ts,
  149. })
  150. productId := insertProduct(ctx, t, m, &productModel.SysProduct{
  151. Code: pcode, Name: "prod_" + uid, AppKey: "ak_" + uid, AppSecret: "as_" + uid,
  152. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  153. })
  154. memberId := insertMember(ctx, t, m, &memberModel.SysProductMember{
  155. ProductCode: pcode, UserId: userId, MemberType: consts.MemberTypeMember,
  156. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  157. })
  158. roleId := insertRole(ctx, t, m, &roleModel.SysRole{
  159. ProductCode: pcode, Name: "role_" + uid, Remark: "test",
  160. Status: consts.StatusEnabled, PermsLevel: 10, CreateTime: ts, UpdateTime: ts,
  161. })
  162. permId := insertPerm(ctx, t, m, &permModel.SysPerm{
  163. ProductCode: pcode, Name: "perm_" + uid, Code: "perm:" + uid,
  164. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  165. })
  166. urId := insertUserRole(ctx, t, m, &userRoleModel.SysUserRole{
  167. UserId: userId, RoleId: roleId, CreateTime: ts, UpdateTime: ts,
  168. })
  169. rpId := insertRolePerm(ctx, t, m, &rolePermModel.SysRolePerm{
  170. RoleId: roleId, PermId: permId, CreateTime: ts, UpdateTime: ts,
  171. })
  172. t.Cleanup(func() {
  173. loader.Del(ctx, userId, pcode)
  174. cleanTable(ctx, conn, "`sys_role_perm`", rpId)
  175. cleanTable(ctx, conn, "`sys_user_role`", urId)
  176. cleanTable(ctx, conn, "`sys_perm`", permId)
  177. cleanTable(ctx, conn, "`sys_role`", roleId)
  178. cleanTable(ctx, conn, "`sys_product_member`", memberId)
  179. cleanTable(ctx, conn, "`sys_product`", productId)
  180. cleanTable(ctx, conn, "`sys_user`", userId)
  181. cleanTable(ctx, conn, "`sys_dept`", deptId)
  182. })
  183. // clear any leftover cache
  184. loader.Del(ctx, userId, pcode)
  185. ud := loader.Load(ctx, userId, pcode)
  186. require.NotNil(t, ud)
  187. assert.Equal(t, userId, ud.UserId)
  188. assert.Equal(t, uid, ud.Username)
  189. assert.Equal(t, "nick_"+uid, ud.Nickname)
  190. assert.Equal(t, uid+"@test.com", ud.Email)
  191. assert.Equal(t, int64(consts.StatusEnabled), ud.Status)
  192. assert.Equal(t, deptId, ud.DeptId)
  193. assert.Equal(t, "dept_"+uid, ud.DeptName)
  194. assert.Equal(t, pcode, ud.ProductCode)
  195. assert.Equal(t, "prod_"+uid, ud.ProductName)
  196. assert.Equal(t, consts.MemberTypeMember, ud.MemberType)
  197. assert.Len(t, ud.Roles, 1)
  198. assert.Equal(t, roleId, ud.Roles[0].Id)
  199. assert.Equal(t, int64(10), ud.MinPermsLevel)
  200. assert.Contains(t, ud.Perms, "perm:"+uid)
  201. }
  202. // --------------- TC-0459: Load-缓存命中 ---------------
  203. func TestLoad_CacheHit(t *testing.T) {
  204. ctx := context.Background()
  205. conn := testConn()
  206. m := testModels()
  207. loader := newTestLoader()
  208. uid := uniqueId()
  209. ts := now()
  210. pcode := "p_" + uid
  211. userId := insertUser(ctx, t, m, &userModel.SysUser{
  212. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  213. Email: uid + "@test.com", Phone: "13800000002", DeptId: 0,
  214. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  215. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  216. })
  217. productId := insertProduct(ctx, t, m, &productModel.SysProduct{
  218. Code: pcode, Name: "prod_" + uid, AppKey: "ak_" + uid, AppSecret: "as_" + uid,
  219. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  220. })
  221. t.Cleanup(func() {
  222. loader.Del(ctx, userId, pcode)
  223. cleanTable(ctx, conn, "`sys_product`", productId)
  224. cleanTable(ctx, conn, "`sys_user`", userId)
  225. })
  226. loader.Del(ctx, userId, pcode)
  227. ud1 := loader.Load(ctx, userId, pcode)
  228. require.NotNil(t, ud1)
  229. ud2 := loader.Load(ctx, userId, pcode)
  230. require.NotNil(t, ud2)
  231. assert.Equal(t, ud1.UserId, ud2.UserId)
  232. assert.Equal(t, ud1.Username, ud2.Username)
  233. assert.Equal(t, ud1.ProductName, ud2.ProductName)
  234. }
  235. // --------------- TC-0460: Load-用户不存在 ---------------
  236. func TestLoad_UserNotExist(t *testing.T) {
  237. ctx := context.Background()
  238. loader := newTestLoader()
  239. nonExistId := int64(999999999)
  240. loader.Del(ctx, nonExistId, "nonexist_product")
  241. ud := loader.Load(ctx, nonExistId, "nonexist_product")
  242. require.NotNil(t, ud)
  243. assert.Equal(t, int64(0), ud.Status)
  244. assert.Empty(t, ud.Username)
  245. assert.Empty(t, ud.Perms)
  246. assert.Empty(t, ud.Roles)
  247. loader.Del(ctx, nonExistId, "nonexist_product")
  248. }
  249. // --------------- TC-0461: Load-productCode为空 ---------------
  250. func TestLoad_EmptyProductCode(t *testing.T) {
  251. ctx := context.Background()
  252. conn := testConn()
  253. m := testModels()
  254. loader := newTestLoader()
  255. uid := uniqueId()
  256. ts := now()
  257. userId := insertUser(ctx, t, m, &userModel.SysUser{
  258. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  259. Email: uid + "@test.com", Phone: "13800000003", DeptId: 0,
  260. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  261. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  262. })
  263. t.Cleanup(func() {
  264. loader.Del(ctx, userId, "")
  265. cleanTable(ctx, conn, "`sys_user`", userId)
  266. })
  267. loader.Del(ctx, userId, "")
  268. ud := loader.Load(ctx, userId, "")
  269. require.NotNil(t, ud)
  270. assert.Equal(t, uid, ud.Username)
  271. assert.Equal(t, int64(consts.StatusEnabled), ud.Status)
  272. assert.Empty(t, ud.ProductCode)
  273. assert.Empty(t, ud.ProductName)
  274. assert.Empty(t, ud.MemberType)
  275. assert.Empty(t, ud.Roles)
  276. assert.Empty(t, ud.Perms)
  277. }
  278. // --------------- TC-0462: Del删除指定缓存 ---------------
  279. func TestDel(t *testing.T) {
  280. ctx := context.Background()
  281. conn := testConn()
  282. m := testModels()
  283. loader := newTestLoader()
  284. uid := uniqueId()
  285. ts := now()
  286. pcode := "p_" + uid
  287. userId := insertUser(ctx, t, m, &userModel.SysUser{
  288. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  289. Email: uid + "@test.com", Phone: "13800000004", DeptId: 0,
  290. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  291. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  292. })
  293. productId := insertProduct(ctx, t, m, &productModel.SysProduct{
  294. Code: pcode, Name: "prod_" + uid, AppKey: "ak_" + uid, AppSecret: "as_" + uid,
  295. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  296. })
  297. t.Cleanup(func() {
  298. loader.Del(ctx, userId, pcode)
  299. cleanTable(ctx, conn, "`sys_product`", productId)
  300. cleanTable(ctx, conn, "`sys_user`", userId)
  301. })
  302. loader.Del(ctx, userId, pcode)
  303. ud1 := loader.Load(ctx, userId, pcode)
  304. require.NotNil(t, ud1)
  305. assert.Equal(t, uid, ud1.Username)
  306. loader.Del(ctx, userId, pcode)
  307. ud2 := loader.Load(ctx, userId, pcode)
  308. require.NotNil(t, ud2)
  309. assert.Equal(t, uid, ud2.Username)
  310. }
  311. // --------------- TC-0463: Clean清除用户所有产品缓存 ---------------
  312. func TestClean(t *testing.T) {
  313. ctx := context.Background()
  314. conn := testConn()
  315. m := testModels()
  316. loader := newTestLoader()
  317. uid := uniqueId()
  318. ts := now()
  319. pcode1 := "p1_" + uid
  320. pcode2 := "p2_" + uid
  321. userId := insertUser(ctx, t, m, &userModel.SysUser{
  322. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  323. Email: uid + "@test.com", Phone: "13800000005", DeptId: 0,
  324. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  325. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  326. })
  327. pid1 := insertProduct(ctx, t, m, &productModel.SysProduct{
  328. Code: pcode1, Name: "prod1_" + uid, AppKey: "ak1_" + uid, AppSecret: "as1_" + uid,
  329. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  330. })
  331. pid2 := insertProduct(ctx, t, m, &productModel.SysProduct{
  332. Code: pcode2, Name: "prod2_" + uid, AppKey: "ak2_" + uid, AppSecret: "as2_" + uid,
  333. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  334. })
  335. t.Cleanup(func() {
  336. loader.Del(ctx, userId, pcode1)
  337. loader.Del(ctx, userId, pcode2)
  338. cleanTable(ctx, conn, "`sys_product`", pid1, pid2)
  339. cleanTable(ctx, conn, "`sys_user`", userId)
  340. })
  341. loader.Del(ctx, userId, pcode1)
  342. loader.Del(ctx, userId, pcode2)
  343. ud1 := loader.Load(ctx, userId, pcode1)
  344. ud2 := loader.Load(ctx, userId, pcode2)
  345. require.NotNil(t, ud1)
  346. require.NotNil(t, ud2)
  347. rds := testRedis()
  348. key1 := loader.cacheKey(userId, pcode1)
  349. key2 := loader.cacheKey(userId, pcode2)
  350. v1, _ := rds.GetCtx(ctx, key1)
  351. v2, _ := rds.GetCtx(ctx, key2)
  352. assert.NotEmpty(t, v1)
  353. assert.NotEmpty(t, v2)
  354. loader.Clean(ctx, userId)
  355. v1After, _ := rds.GetCtx(ctx, key1)
  356. v2After, _ := rds.GetCtx(ctx, key2)
  357. assert.Empty(t, v1After)
  358. assert.Empty(t, v2After)
  359. }
  360. // --------------- TC-0464: CleanByProduct清除产品所有用户 ---------------
  361. func TestCleanByProduct(t *testing.T) {
  362. ctx := context.Background()
  363. conn := testConn()
  364. m := testModels()
  365. loader := newTestLoader()
  366. uid1 := uniqueId()
  367. uid2 := uniqueId()
  368. ts := now()
  369. pcode := "p_" + uid1
  370. userId1 := insertUser(ctx, t, m, &userModel.SysUser{
  371. Username: uid1, Password: hashPwd("pass123"), Nickname: "nick_" + uid1,
  372. Email: uid1 + "@test.com", Phone: "13800000006", DeptId: 0,
  373. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  374. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  375. })
  376. userId2 := insertUser(ctx, t, m, &userModel.SysUser{
  377. Username: uid2, Password: hashPwd("pass123"), Nickname: "nick_" + uid2,
  378. Email: uid2 + "@test.com", Phone: "13800000007", DeptId: 0,
  379. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  380. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  381. })
  382. pid := insertProduct(ctx, t, m, &productModel.SysProduct{
  383. Code: pcode, Name: "prod_" + uid1, AppKey: "ak_" + uid1, AppSecret: "as_" + uid1,
  384. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  385. })
  386. t.Cleanup(func() {
  387. loader.Del(ctx, userId1, pcode)
  388. loader.Del(ctx, userId2, pcode)
  389. cleanTable(ctx, conn, "`sys_product`", pid)
  390. cleanTable(ctx, conn, "`sys_user`", userId1, userId2)
  391. })
  392. loader.Del(ctx, userId1, pcode)
  393. loader.Del(ctx, userId2, pcode)
  394. loader.Load(ctx, userId1, pcode)
  395. loader.Load(ctx, userId2, pcode)
  396. rds := testRedis()
  397. k1 := loader.cacheKey(userId1, pcode)
  398. k2 := loader.cacheKey(userId2, pcode)
  399. v1, _ := rds.GetCtx(ctx, k1)
  400. v2, _ := rds.GetCtx(ctx, k2)
  401. assert.NotEmpty(t, v1)
  402. assert.NotEmpty(t, v2)
  403. loader.CleanByProduct(ctx, pcode)
  404. v1After, _ := rds.GetCtx(ctx, k1)
  405. v2After, _ := rds.GetCtx(ctx, k2)
  406. assert.Empty(t, v1After)
  407. assert.Empty(t, v2After)
  408. }
  409. // --------------- TC-0465: BatchDel批量删除 ---------------
  410. func TestBatchDel(t *testing.T) {
  411. ctx := context.Background()
  412. conn := testConn()
  413. m := testModels()
  414. loader := newTestLoader()
  415. uid1 := uniqueId()
  416. uid2 := uniqueId()
  417. ts := now()
  418. pcode := "p_" + uid1
  419. userId1 := insertUser(ctx, t, m, &userModel.SysUser{
  420. Username: uid1, Password: hashPwd("pass123"), Nickname: "nick_" + uid1,
  421. Email: uid1 + "@test.com", Phone: "13800000008", DeptId: 0,
  422. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  423. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  424. })
  425. userId2 := insertUser(ctx, t, m, &userModel.SysUser{
  426. Username: uid2, Password: hashPwd("pass123"), Nickname: "nick_" + uid2,
  427. Email: uid2 + "@test.com", Phone: "13800000009", DeptId: 0,
  428. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  429. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  430. })
  431. pid := insertProduct(ctx, t, m, &productModel.SysProduct{
  432. Code: pcode, Name: "prod_" + uid1, AppKey: "ak_" + uid1, AppSecret: "as_" + uid1,
  433. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  434. })
  435. t.Cleanup(func() {
  436. loader.Del(ctx, userId1, pcode)
  437. loader.Del(ctx, userId2, pcode)
  438. cleanTable(ctx, conn, "`sys_product`", pid)
  439. cleanTable(ctx, conn, "`sys_user`", userId1, userId2)
  440. })
  441. loader.Del(ctx, userId1, pcode)
  442. loader.Del(ctx, userId2, pcode)
  443. loader.Load(ctx, userId1, pcode)
  444. loader.Load(ctx, userId2, pcode)
  445. rds := testRedis()
  446. k1 := loader.cacheKey(userId1, pcode)
  447. k2 := loader.cacheKey(userId2, pcode)
  448. v1, _ := rds.GetCtx(ctx, k1)
  449. v2, _ := rds.GetCtx(ctx, k2)
  450. assert.NotEmpty(t, v1)
  451. assert.NotEmpty(t, v2)
  452. loader.BatchDel(ctx, []int64{userId1, userId2}, pcode)
  453. v1After, _ := rds.GetCtx(ctx, k1)
  454. v2After, _ := rds.GetCtx(ctx, k2)
  455. assert.Empty(t, v1After)
  456. assert.Empty(t, v2After)
  457. }
  458. // --------------- TC-0466: BatchDel空数组 ---------------
  459. func TestBatchDel_EmptySlice(t *testing.T) {
  460. ctx := context.Background()
  461. loader := newTestLoader()
  462. loader.BatchDel(ctx, []int64{}, "some_code")
  463. }
  464. // --------------- TC-0467: loadPerms-超管拥有全部权限 ---------------
  465. func TestLoadPerms_SuperAdmin(t *testing.T) {
  466. ctx := context.Background()
  467. conn := testConn()
  468. m := testModels()
  469. loader := newTestLoader()
  470. uid := uniqueId()
  471. ts := now()
  472. pcode := "p_" + uid
  473. userId := insertUser(ctx, t, m, &userModel.SysUser{
  474. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  475. Email: uid + "@test.com", Phone: "13800000010", DeptId: 0,
  476. IsSuperAdmin: consts.IsSuperAdminYes, MustChangePassword: consts.MustChangePasswordNo,
  477. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  478. })
  479. pid := insertProduct(ctx, t, m, &productModel.SysProduct{
  480. Code: pcode, Name: "prod_" + uid, AppKey: "ak_" + uid, AppSecret: "as_" + uid,
  481. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  482. })
  483. permCode1 := "perm1:" + uid
  484. permCode2 := "perm2:" + uid
  485. permId1 := insertPerm(ctx, t, m, &permModel.SysPerm{
  486. ProductCode: pcode, Name: "p1_" + uid, Code: permCode1,
  487. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  488. })
  489. permId2 := insertPerm(ctx, t, m, &permModel.SysPerm{
  490. ProductCode: pcode, Name: "p2_" + uid, Code: permCode2,
  491. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  492. })
  493. t.Cleanup(func() {
  494. loader.Del(ctx, userId, pcode)
  495. cleanTable(ctx, conn, "`sys_perm`", permId1, permId2)
  496. cleanTable(ctx, conn, "`sys_product`", pid)
  497. cleanTable(ctx, conn, "`sys_user`", userId)
  498. })
  499. loader.Del(ctx, userId, pcode)
  500. ud := loader.Load(ctx, userId, pcode)
  501. require.NotNil(t, ud)
  502. assert.True(t, ud.IsSuperAdmin)
  503. assert.Equal(t, consts.MemberTypeSuperAdmin, ud.MemberType)
  504. sort.Strings(ud.Perms)
  505. expected := []string{permCode1, permCode2}
  506. sort.Strings(expected)
  507. assert.Equal(t, expected, ud.Perms)
  508. }
  509. // --------------- TC-0468: loadPerms-ADMIN成员拥有全部权限 ---------------
  510. func TestLoadPerms_AdminMember(t *testing.T) {
  511. ctx := context.Background()
  512. conn := testConn()
  513. m := testModels()
  514. loader := newTestLoader()
  515. uid := uniqueId()
  516. ts := now()
  517. pcode := "p_" + uid
  518. userId := insertUser(ctx, t, m, &userModel.SysUser{
  519. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  520. Email: uid + "@test.com", Phone: "13800000011", DeptId: 0,
  521. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  522. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  523. })
  524. pid := insertProduct(ctx, t, m, &productModel.SysProduct{
  525. Code: pcode, Name: "prod_" + uid, AppKey: "ak_" + uid, AppSecret: "as_" + uid,
  526. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  527. })
  528. memberId := insertMember(ctx, t, m, &memberModel.SysProductMember{
  529. ProductCode: pcode, UserId: userId, MemberType: consts.MemberTypeAdmin,
  530. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  531. })
  532. permCode := "perm:" + uid
  533. permId := insertPerm(ctx, t, m, &permModel.SysPerm{
  534. ProductCode: pcode, Name: "p_" + uid, Code: permCode,
  535. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  536. })
  537. t.Cleanup(func() {
  538. loader.Del(ctx, userId, pcode)
  539. cleanTable(ctx, conn, "`sys_perm`", permId)
  540. cleanTable(ctx, conn, "`sys_product_member`", memberId)
  541. cleanTable(ctx, conn, "`sys_product`", pid)
  542. cleanTable(ctx, conn, "`sys_user`", userId)
  543. })
  544. loader.Del(ctx, userId, pcode)
  545. ud := loader.Load(ctx, userId, pcode)
  546. require.NotNil(t, ud)
  547. assert.Equal(t, consts.MemberTypeAdmin, ud.MemberType)
  548. assert.Contains(t, ud.Perms, permCode)
  549. }
  550. // --------------- TC-0469: loadPerms-DEVELOPER成员拥有全部权限 ---------------
  551. func TestLoadPerms_DeveloperMember(t *testing.T) {
  552. ctx := context.Background()
  553. conn := testConn()
  554. m := testModels()
  555. loader := newTestLoader()
  556. uid := uniqueId()
  557. ts := now()
  558. pcode := "p_" + uid
  559. userId := insertUser(ctx, t, m, &userModel.SysUser{
  560. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  561. Email: uid + "@test.com", Phone: "13800000012", DeptId: 0,
  562. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  563. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  564. })
  565. pid := insertProduct(ctx, t, m, &productModel.SysProduct{
  566. Code: pcode, Name: "prod_" + uid, AppKey: "ak_" + uid, AppSecret: "as_" + uid,
  567. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  568. })
  569. memberId := insertMember(ctx, t, m, &memberModel.SysProductMember{
  570. ProductCode: pcode, UserId: userId, MemberType: consts.MemberTypeDeveloper,
  571. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  572. })
  573. permCode := "perm:" + uid
  574. permId := insertPerm(ctx, t, m, &permModel.SysPerm{
  575. ProductCode: pcode, Name: "p_" + uid, Code: permCode,
  576. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  577. })
  578. t.Cleanup(func() {
  579. loader.Del(ctx, userId, pcode)
  580. cleanTable(ctx, conn, "`sys_perm`", permId)
  581. cleanTable(ctx, conn, "`sys_product_member`", memberId)
  582. cleanTable(ctx, conn, "`sys_product`", pid)
  583. cleanTable(ctx, conn, "`sys_user`", userId)
  584. })
  585. loader.Del(ctx, userId, pcode)
  586. ud := loader.Load(ctx, userId, pcode)
  587. require.NotNil(t, ud)
  588. assert.Equal(t, consts.MemberTypeDeveloper, ud.MemberType)
  589. assert.Contains(t, ud.Perms, permCode)
  590. }
  591. // --------------- TC-0470: loadPerms-DEV部门成员拥有全部权限 ---------------
  592. func TestLoadPerms_DevDept(t *testing.T) {
  593. ctx := context.Background()
  594. conn := testConn()
  595. m := testModels()
  596. loader := newTestLoader()
  597. uid := uniqueId()
  598. ts := now()
  599. pcode := "p_" + uid
  600. deptId := insertDept(ctx, t, m, &deptModel.SysDept{
  601. ParentId: 0, Name: "devdept_" + uid, Path: "/1/", Sort: 1,
  602. DeptType: consts.DeptTypeDev, Status: consts.StatusEnabled,
  603. CreateTime: ts, UpdateTime: ts,
  604. })
  605. userId := insertUser(ctx, t, m, &userModel.SysUser{
  606. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  607. Email: uid + "@test.com", Phone: "13800000013", DeptId: deptId,
  608. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  609. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  610. })
  611. pid := insertProduct(ctx, t, m, &productModel.SysProduct{
  612. Code: pcode, Name: "prod_" + uid, AppKey: "ak_" + uid, AppSecret: "as_" + uid,
  613. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  614. })
  615. memberId := insertMember(ctx, t, m, &memberModel.SysProductMember{
  616. ProductCode: pcode, UserId: userId, MemberType: consts.MemberTypeMember,
  617. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  618. })
  619. permCode := "perm:" + uid
  620. permId := insertPerm(ctx, t, m, &permModel.SysPerm{
  621. ProductCode: pcode, Name: "p_" + uid, Code: permCode,
  622. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  623. })
  624. t.Cleanup(func() {
  625. loader.Del(ctx, userId, pcode)
  626. cleanTable(ctx, conn, "`sys_perm`", permId)
  627. cleanTable(ctx, conn, "`sys_product_member`", memberId)
  628. cleanTable(ctx, conn, "`sys_product`", pid)
  629. cleanTable(ctx, conn, "`sys_user`", userId)
  630. cleanTable(ctx, conn, "`sys_dept`", deptId)
  631. })
  632. loader.Del(ctx, userId, pcode)
  633. ud := loader.Load(ctx, userId, pcode)
  634. require.NotNil(t, ud)
  635. assert.Equal(t, consts.DeptTypeDev, ud.DeptType)
  636. assert.Contains(t, ud.Perms, permCode)
  637. }
  638. // --------------- TC-0471: MEMBER角色权限+ALLOW-DENY ---------------
  639. func TestLoadPerms_MemberRolePermWithAllowDeny(t *testing.T) {
  640. ctx := context.Background()
  641. conn := testConn()
  642. m := testModels()
  643. loader := newTestLoader()
  644. uid := uniqueId()
  645. ts := now()
  646. pcode := "p_" + uid
  647. userId := insertUser(ctx, t, m, &userModel.SysUser{
  648. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  649. Email: uid + "@test.com", Phone: "13800000014", DeptId: 0,
  650. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  651. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  652. })
  653. pid := insertProduct(ctx, t, m, &productModel.SysProduct{
  654. Code: pcode, Name: "prod_" + uid, AppKey: "ak_" + uid, AppSecret: "as_" + uid,
  655. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  656. })
  657. memberId := insertMember(ctx, t, m, &memberModel.SysProductMember{
  658. ProductCode: pcode, UserId: userId, MemberType: consts.MemberTypeMember,
  659. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  660. })
  661. roleId := insertRole(ctx, t, m, &roleModel.SysRole{
  662. ProductCode: pcode, Name: "role_" + uid, Remark: "test",
  663. Status: consts.StatusEnabled, PermsLevel: 10, CreateTime: ts, UpdateTime: ts,
  664. })
  665. urId := insertUserRole(ctx, t, m, &userRoleModel.SysUserRole{
  666. UserId: userId, RoleId: roleId, CreateTime: ts, UpdateTime: ts,
  667. })
  668. // role perm: permA, permB
  669. permIdA := insertPerm(ctx, t, m, &permModel.SysPerm{
  670. ProductCode: pcode, Name: "permA_" + uid, Code: "permA:" + uid,
  671. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  672. })
  673. permIdB := insertPerm(ctx, t, m, &permModel.SysPerm{
  674. ProductCode: pcode, Name: "permB_" + uid, Code: "permB:" + uid,
  675. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  676. })
  677. // user ALLOW perm: permC
  678. permIdC := insertPerm(ctx, t, m, &permModel.SysPerm{
  679. ProductCode: pcode, Name: "permC_" + uid, Code: "permC:" + uid,
  680. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  681. })
  682. // user DENY perm: permB (should remove permB from result)
  683. rpIdA := insertRolePerm(ctx, t, m, &rolePermModel.SysRolePerm{
  684. RoleId: roleId, PermId: permIdA, CreateTime: ts, UpdateTime: ts,
  685. })
  686. rpIdB := insertRolePerm(ctx, t, m, &rolePermModel.SysRolePerm{
  687. RoleId: roleId, PermId: permIdB, CreateTime: ts, UpdateTime: ts,
  688. })
  689. upAllow := insertUserPerm(ctx, t, m, &userPermModel.SysUserPerm{
  690. UserId: userId, PermId: permIdC, Effect: consts.PermEffectAllow,
  691. CreateTime: ts, UpdateTime: ts,
  692. })
  693. upDeny := insertUserPerm(ctx, t, m, &userPermModel.SysUserPerm{
  694. UserId: userId, PermId: permIdB, Effect: consts.PermEffectDeny,
  695. CreateTime: ts, UpdateTime: ts,
  696. })
  697. t.Cleanup(func() {
  698. loader.Del(ctx, userId, pcode)
  699. cleanTable(ctx, conn, "`sys_user_perm`", upAllow, upDeny)
  700. cleanTable(ctx, conn, "`sys_role_perm`", rpIdA, rpIdB)
  701. cleanTable(ctx, conn, "`sys_perm`", permIdA, permIdB, permIdC)
  702. cleanTable(ctx, conn, "`sys_user_role`", urId)
  703. cleanTable(ctx, conn, "`sys_role`", roleId)
  704. cleanTable(ctx, conn, "`sys_product_member`", memberId)
  705. cleanTable(ctx, conn, "`sys_product`", pid)
  706. cleanTable(ctx, conn, "`sys_user`", userId)
  707. })
  708. loader.Del(ctx, userId, pcode)
  709. ud := loader.Load(ctx, userId, pcode)
  710. require.NotNil(t, ud)
  711. // permA (from role) + permC (from ALLOW) should be present
  712. // permB (denied) should NOT be present
  713. assert.Contains(t, ud.Perms, "permA:"+uid)
  714. assert.Contains(t, ud.Perms, "permC:"+uid)
  715. assert.NotContains(t, ud.Perms, "permB:"+uid)
  716. }
  717. // --------------- TC-0472: loadRoles-多角色取最小permsLevel ---------------
  718. func TestLoadRoles_MinPermsLevel(t *testing.T) {
  719. ctx := context.Background()
  720. conn := testConn()
  721. m := testModels()
  722. loader := newTestLoader()
  723. uid := uniqueId()
  724. ts := now()
  725. pcode := "p_" + uid
  726. userId := insertUser(ctx, t, m, &userModel.SysUser{
  727. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  728. Email: uid + "@test.com", Phone: "13800000015", DeptId: 0,
  729. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  730. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  731. })
  732. pid := insertProduct(ctx, t, m, &productModel.SysProduct{
  733. Code: pcode, Name: "prod_" + uid, AppKey: "ak_" + uid, AppSecret: "as_" + uid,
  734. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  735. })
  736. memberId := insertMember(ctx, t, m, &memberModel.SysProductMember{
  737. ProductCode: pcode, UserId: userId, MemberType: consts.MemberTypeMember,
  738. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  739. })
  740. roleId1 := insertRole(ctx, t, m, &roleModel.SysRole{
  741. ProductCode: pcode, Name: "roleH_" + uid, Remark: "high",
  742. Status: consts.StatusEnabled, PermsLevel: 10, CreateTime: ts, UpdateTime: ts,
  743. })
  744. roleId2 := insertRole(ctx, t, m, &roleModel.SysRole{
  745. ProductCode: pcode, Name: "roleL_" + uid, Remark: "low",
  746. Status: consts.StatusEnabled, PermsLevel: 5, CreateTime: ts, UpdateTime: ts,
  747. })
  748. urId1 := insertUserRole(ctx, t, m, &userRoleModel.SysUserRole{
  749. UserId: userId, RoleId: roleId1, CreateTime: ts, UpdateTime: ts,
  750. })
  751. urId2 := insertUserRole(ctx, t, m, &userRoleModel.SysUserRole{
  752. UserId: userId, RoleId: roleId2, CreateTime: ts, UpdateTime: ts,
  753. })
  754. t.Cleanup(func() {
  755. loader.Del(ctx, userId, pcode)
  756. cleanTable(ctx, conn, "`sys_user_role`", urId1, urId2)
  757. cleanTable(ctx, conn, "`sys_role`", roleId1, roleId2)
  758. cleanTable(ctx, conn, "`sys_product_member`", memberId)
  759. cleanTable(ctx, conn, "`sys_product`", pid)
  760. cleanTable(ctx, conn, "`sys_user`", userId)
  761. })
  762. loader.Del(ctx, userId, pcode)
  763. ud := loader.Load(ctx, userId, pcode)
  764. require.NotNil(t, ud)
  765. assert.Len(t, ud.Roles, 2)
  766. assert.Equal(t, int64(5), ud.MinPermsLevel)
  767. }
  768. // --------------- TC-0473: loadRoles-无角色 ---------------
  769. func TestLoadRoles_NoRoles(t *testing.T) {
  770. ctx := context.Background()
  771. conn := testConn()
  772. m := testModels()
  773. loader := newTestLoader()
  774. uid := uniqueId()
  775. ts := now()
  776. pcode := "p_" + uid
  777. userId := insertUser(ctx, t, m, &userModel.SysUser{
  778. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  779. Email: uid + "@test.com", Phone: "13800000016", DeptId: 0,
  780. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  781. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  782. })
  783. pid := insertProduct(ctx, t, m, &productModel.SysProduct{
  784. Code: pcode, Name: "prod_" + uid, AppKey: "ak_" + uid, AppSecret: "as_" + uid,
  785. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  786. })
  787. t.Cleanup(func() {
  788. loader.Del(ctx, userId, pcode)
  789. cleanTable(ctx, conn, "`sys_product`", pid)
  790. cleanTable(ctx, conn, "`sys_user`", userId)
  791. })
  792. loader.Del(ctx, userId, pcode)
  793. ud := loader.Load(ctx, userId, pcode)
  794. require.NotNil(t, ud)
  795. assert.Equal(t, int64(math.MaxInt64), ud.MinPermsLevel)
  796. }
  797. // --------------- TC-0474: loadRoles-角色跨产品过滤 ---------------
  798. func TestLoadRoles_CrossProductFilter(t *testing.T) {
  799. ctx := context.Background()
  800. conn := testConn()
  801. m := testModels()
  802. loader := newTestLoader()
  803. uid := uniqueId()
  804. ts := now()
  805. pcodeA := "pA_" + uid
  806. pcodeB := "pB_" + uid
  807. userId := insertUser(ctx, t, m, &userModel.SysUser{
  808. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  809. Email: uid + "@test.com", Phone: "13800000017", DeptId: 0,
  810. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  811. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  812. })
  813. pidA := insertProduct(ctx, t, m, &productModel.SysProduct{
  814. Code: pcodeA, Name: "prodA_" + uid, AppKey: "akA_" + uid, AppSecret: "asA_" + uid,
  815. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  816. })
  817. pidB := insertProduct(ctx, t, m, &productModel.SysProduct{
  818. Code: pcodeB, Name: "prodB_" + uid, AppKey: "akB_" + uid, AppSecret: "asB_" + uid,
  819. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  820. })
  821. memA := insertMember(ctx, t, m, &memberModel.SysProductMember{
  822. ProductCode: pcodeA, UserId: userId, MemberType: consts.MemberTypeMember,
  823. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  824. })
  825. roleA := insertRole(ctx, t, m, &roleModel.SysRole{
  826. ProductCode: pcodeA, Name: "roleA_" + uid, Remark: "A",
  827. Status: consts.StatusEnabled, PermsLevel: 10, CreateTime: ts, UpdateTime: ts,
  828. })
  829. roleB := insertRole(ctx, t, m, &roleModel.SysRole{
  830. ProductCode: pcodeB, Name: "roleB_" + uid, Remark: "B",
  831. Status: consts.StatusEnabled, PermsLevel: 20, CreateTime: ts, UpdateTime: ts,
  832. })
  833. urA := insertUserRole(ctx, t, m, &userRoleModel.SysUserRole{
  834. UserId: userId, RoleId: roleA, CreateTime: ts, UpdateTime: ts,
  835. })
  836. urB := insertUserRole(ctx, t, m, &userRoleModel.SysUserRole{
  837. UserId: userId, RoleId: roleB, CreateTime: ts, UpdateTime: ts,
  838. })
  839. t.Cleanup(func() {
  840. loader.Del(ctx, userId, pcodeA)
  841. loader.Del(ctx, userId, pcodeB)
  842. cleanTable(ctx, conn, "`sys_user_role`", urA, urB)
  843. cleanTable(ctx, conn, "`sys_role`", roleA, roleB)
  844. cleanTable(ctx, conn, "`sys_product_member`", memA)
  845. cleanTable(ctx, conn, "`sys_product`", pidA, pidB)
  846. cleanTable(ctx, conn, "`sys_user`", userId)
  847. })
  848. loader.Del(ctx, userId, pcodeA)
  849. ud := loader.Load(ctx, userId, pcodeA)
  850. require.NotNil(t, ud)
  851. assert.Len(t, ud.Roles, 1)
  852. assert.Equal(t, roleA, ud.Roles[0].Id)
  853. assert.Equal(t, int64(10), ud.MinPermsLevel)
  854. }
  855. // --------------- TC-0475: loadRoles-禁用角色不计入 ---------------
  856. func TestLoadRoles_DisabledRoleExcluded(t *testing.T) {
  857. ctx := context.Background()
  858. conn := testConn()
  859. m := testModels()
  860. loader := newTestLoader()
  861. uid := uniqueId()
  862. ts := now()
  863. pcode := "p_" + uid
  864. userId := insertUser(ctx, t, m, &userModel.SysUser{
  865. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  866. Email: uid + "@test.com", Phone: "13800000018", DeptId: 0,
  867. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  868. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  869. })
  870. pid := insertProduct(ctx, t, m, &productModel.SysProduct{
  871. Code: pcode, Name: "prod_" + uid, AppKey: "ak_" + uid, AppSecret: "as_" + uid,
  872. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  873. })
  874. memberId := insertMember(ctx, t, m, &memberModel.SysProductMember{
  875. ProductCode: pcode, UserId: userId, MemberType: consts.MemberTypeMember,
  876. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  877. })
  878. enabledRole := insertRole(ctx, t, m, &roleModel.SysRole{
  879. ProductCode: pcode, Name: "rEnabled_" + uid, Remark: "enabled",
  880. Status: consts.StatusEnabled, PermsLevel: 5, CreateTime: ts, UpdateTime: ts,
  881. })
  882. disabledRole := insertRole(ctx, t, m, &roleModel.SysRole{
  883. ProductCode: pcode, Name: "rDisabled_" + uid, Remark: "disabled",
  884. Status: consts.StatusDisabled, PermsLevel: 1, CreateTime: ts, UpdateTime: ts,
  885. })
  886. ur1 := insertUserRole(ctx, t, m, &userRoleModel.SysUserRole{
  887. UserId: userId, RoleId: enabledRole, CreateTime: ts, UpdateTime: ts,
  888. })
  889. ur2 := insertUserRole(ctx, t, m, &userRoleModel.SysUserRole{
  890. UserId: userId, RoleId: disabledRole, CreateTime: ts, UpdateTime: ts,
  891. })
  892. t.Cleanup(func() {
  893. loader.Del(ctx, userId, pcode)
  894. cleanTable(ctx, conn, "`sys_user_role`", ur1, ur2)
  895. cleanTable(ctx, conn, "`sys_role`", enabledRole, disabledRole)
  896. cleanTable(ctx, conn, "`sys_product_member`", memberId)
  897. cleanTable(ctx, conn, "`sys_product`", pid)
  898. cleanTable(ctx, conn, "`sys_user`", userId)
  899. })
  900. loader.Del(ctx, userId, pcode)
  901. ud := loader.Load(ctx, userId, pcode)
  902. require.NotNil(t, ud)
  903. assert.Len(t, ud.Roles, 1)
  904. assert.Equal(t, enabledRole, ud.Roles[0].Id)
  905. assert.Equal(t, int64(5), ud.MinPermsLevel)
  906. }
  907. // --------------- TC-0476: loadMembership-超管自动SUPER_ADMIN ---------------
  908. func TestLoadMembership_SuperAdminAuto(t *testing.T) {
  909. ctx := context.Background()
  910. conn := testConn()
  911. m := testModels()
  912. loader := newTestLoader()
  913. uid := uniqueId()
  914. ts := now()
  915. pcode := "p_" + uid
  916. userId := insertUser(ctx, t, m, &userModel.SysUser{
  917. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  918. Email: uid + "@test.com", Phone: "13800000019", DeptId: 0,
  919. IsSuperAdmin: consts.IsSuperAdminYes, MustChangePassword: consts.MustChangePasswordNo,
  920. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  921. })
  922. pid := insertProduct(ctx, t, m, &productModel.SysProduct{
  923. Code: pcode, Name: "prod_" + uid, AppKey: "ak_" + uid, AppSecret: "as_" + uid,
  924. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  925. })
  926. t.Cleanup(func() {
  927. loader.Del(ctx, userId, pcode)
  928. cleanTable(ctx, conn, "`sys_product`", pid)
  929. cleanTable(ctx, conn, "`sys_user`", userId)
  930. })
  931. loader.Del(ctx, userId, pcode)
  932. ud := loader.Load(ctx, userId, pcode)
  933. require.NotNil(t, ud)
  934. assert.True(t, ud.IsSuperAdmin)
  935. assert.Equal(t, consts.MemberTypeSuperAdmin, ud.MemberType)
  936. }
  937. // --------------- TC-0477: loadMembership-非成员MemberType为空 ---------------
  938. func TestLoadMembership_NonMemberEmpty(t *testing.T) {
  939. ctx := context.Background()
  940. conn := testConn()
  941. m := testModels()
  942. loader := newTestLoader()
  943. uid := uniqueId()
  944. ts := now()
  945. pcode := "p_" + uid
  946. userId := insertUser(ctx, t, m, &userModel.SysUser{
  947. Username: uid, Password: hashPwd("pass123"), Nickname: "nick_" + uid,
  948. Email: uid + "@test.com", Phone: "13800000020", DeptId: 0,
  949. IsSuperAdmin: consts.IsSuperAdminNo, MustChangePassword: consts.MustChangePasswordNo,
  950. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  951. })
  952. pid := insertProduct(ctx, t, m, &productModel.SysProduct{
  953. Code: pcode, Name: "prod_" + uid, AppKey: "ak_" + uid, AppSecret: "as_" + uid,
  954. Status: consts.StatusEnabled, CreateTime: ts, UpdateTime: ts,
  955. })
  956. t.Cleanup(func() {
  957. loader.Del(ctx, userId, pcode)
  958. cleanTable(ctx, conn, "`sys_product`", pid)
  959. cleanTable(ctx, conn, "`sys_user`", userId)
  960. })
  961. loader.Del(ctx, userId, pcode)
  962. ud := loader.Load(ctx, userId, pcode)
  963. require.NotNil(t, ud)
  964. assert.False(t, ud.IsSuperAdmin)
  965. assert.Empty(t, ud.MemberType)
  966. }