Files
summercms/modules/cabana/relation_child_smoke_test.go
Jakub Zych afb05b6ee4 feat(12.2-03): add parent-scoped child show, update, delete and pivot routes
- loadChild finds a child with one query carrying the parent predicate; a foreign child is 404
- GET/PUT .../records/{child} and POST .../delete (all or nothing) per relation kind
- hasMany link adopts NULL-key rows and unlink clears the key; pending created children are never candidates
- link accepts pivot values for one id through the pivot.form whitelist; GET/PUT .../pivot/{child}
- Link and Unlink share linkRelated/unlinkRelated for the deferred commit
2026-10-02 18:44:34 +02:00

234 lines
12 KiB
Go

package cabana_test
import (
"encoding/json"
"fmt"
"net/http"
"net/http/httptest"
"slices"
"strings"
"testing"
)
// linkedIDs lists the ids of a gadget relation's linked rows.
func (e *conformEnv) linkedIDs(t *testing.T, gadget uint, relation string, headers map[string]string) []uint {
t.Helper()
rec := e.sendWith(t, http.MethodGet, fmt.Sprintf("/acme/conform/gadgets/%d/relations/%s", gadget, relation), nil, "", headers)
if rec.Code != http.StatusOK {
t.Fatalf("linked %s status=%d body=%s", relation, rec.Code, rec.Body.String())
}
var body struct {
Data []struct {
ID uint `json:"id"`
} `json:"data"`
}
if err := json.Unmarshal(rec.Body.Bytes(), &body); err != nil {
t.Fatal(err)
}
out := make([]uint, 0, len(body.Data))
for _, row := range body.Data {
out = append(out, row.ID)
}
return out
}
// partOwner reads a part's gadget_id straight from the table.
func (e *conformEnv) partOwner(t *testing.T, id uint) *uint {
t.Helper()
var part conformPart
if err := e.db.First(&part, id).Error; err != nil {
t.Fatal(err)
}
return part.GadgetID
}
// TestRelationChildSmokeCreate creates a hasMany child of a saved gadget
// through the relation manager: the server sets the foreign key from the
// scoped parent, the child lists under that parent only, and a body naming
// the foreign key cannot move it.
func TestRelationChildSmokeCreate(t *testing.T) {
env := newConformEnv(t)
env.loginAs(t, env.login)
a := env.createGadget(t, "a-"+env.stamp, "")
b := env.createGadget(t, "b-"+env.stamp, "")
rec := env.send(t, http.MethodPost, fmt.Sprintf("/acme/conform/gadgets/%d/relations/parts/records", a), map[string]any{"label": "wheel", "gadget_id": b}, true)
if rec.Code != http.StatusCreated {
t.Fatalf("create part status=%d body=%s", rec.Code, rec.Body.String())
}
part := dataID(t, rec.Body.Bytes())
if owner := env.partOwner(t, part); owner == nil || *owner != a {
t.Fatalf("part gadget_id = %v, want %d", owner, a)
}
if got := env.linkedIDs(t, a, "parts", nil); !slices.Contains(got, part) {
t.Fatalf("gadget A parts = %v, want %d", got, part)
}
if got := env.linkedIDs(t, b, "parts", nil); slices.Contains(got, part) {
t.Fatalf("gadget B lists A's part: %v", got)
}
invalid := env.send(t, http.MethodPost, fmt.Sprintf("/acme/conform/gadgets/%d/relations/parts/records", a), map[string]any{"label": ""}, true)
if invalid.Code != http.StatusUnprocessableEntity {
t.Fatalf("empty label status=%d body=%s", invalid.Code, invalid.Body.String())
}
undeclared := env.send(t, http.MethodPost, fmt.Sprintf("/acme/conform/gadgets/%d/relations/members/records", a), map[string]any{"email": "x@example.test"}, true)
if undeclared.Code != http.StatusForbidden {
t.Fatalf("create on a relation without the create button status=%d body=%s", undeclared.Code, undeclared.Body.String())
}
missing := env.send(t, http.MethodPost, fmt.Sprintf("/acme/conform/gadgets/%d/relations/parts/records", b+1000), map[string]any{"label": "x"}, true)
if missing.Code != http.StatusNotFound {
t.Fatalf("create under a missing parent status=%d body=%s", missing.Code, missing.Body.String())
}
}
// relationPath is the admin API path of a gadget relation route.
func relationPath(gadget uint, relation, rest string) string {
return fmt.Sprintf("/acme/conform/gadgets/%d/relations/%s%s", gadget, relation, rest)
}
// expectStatus fails the test unless rec has the status.
func expectStatus(t *testing.T, what string, rec *httptest.ResponseRecorder, status int) {
t.Helper()
if rec.Code != status {
t.Fatalf("%s status=%d want %d body=%s", what, rec.Code, status, rec.Body.String())
}
}
// createPart creates a part under a gadget through the relation manager.
func (e *conformEnv) createPart(t *testing.T, gadget uint, label string) uint {
t.Helper()
rec := e.send(t, http.MethodPost, relationPath(gadget, "parts", "/records"), map[string]any{"label": label}, true)
expectStatus(t, "create part", rec, http.StatusCreated)
return dataID(t, rec.Body.Bytes())
}
// TestRelationChildSmokeScope checks D-15 on every child route: a child of
// another parent, a member linked to another parent and a parent hidden by
// FormExtendQuery all answer 404, and a delete naming one foreign child
// deletes nothing. It also walks hasMany link, unlink and delete.
func TestRelationChildSmokeScope(t *testing.T) {
env := newConformEnv(t)
env.loginAs(t, env.login)
a := env.createGadget(t, "a-"+env.stamp, "")
b := env.createGadget(t, "b-"+env.stamp, "")
pa := env.createPart(t, a, "pa")
pb := env.createPart(t, b, "pb")
expectStatus(t, "show foreign child", env.send(t, http.MethodGet, relationPath(a, "parts", fmt.Sprintf("/records/%d", pb)), nil, true), http.StatusNotFound)
expectStatus(t, "update foreign child", env.send(t, http.MethodPut, relationPath(a, "parts", fmt.Sprintf("/records/%d", pb)), map[string]any{"label": "stolen"}, true), http.StatusNotFound)
expectStatus(t, "delete foreign child", env.send(t, http.MethodPost, relationPath(a, "parts", "/delete"), map[string]any{"ids": []uint{pa, pb}}, true), http.StatusNotFound)
for _, id := range []uint{pa, pb} {
var n int64
if err := env.db.Model(&conformPart{}).Where("id = ?", id).Count(&n).Error; err != nil || n != 1 {
t.Fatalf("part %d count=%d err=%v after a refused delete", id, n, err)
}
}
shown := env.send(t, http.MethodGet, relationPath(a, "parts", fmt.Sprintf("/records/%d", pa)), nil, true)
expectStatus(t, "show own child", shown, http.StatusOK)
updated := env.send(t, http.MethodPut, relationPath(a, "parts", fmt.Sprintf("/records/%d", pa)), map[string]any{"label": "pa-renamed", "gadget_id": b}, true)
expectStatus(t, "update own child", updated, http.StatusOK)
if owner := env.partOwner(t, pa); owner == nil || *owner != a {
t.Fatalf("update moved the part to %v", owner)
}
// A member linked to B has no pivot row under A.
expectStatus(t, "link member to B", env.send(t, http.MethodPost, relationPath(b, "members", "/link"), map[string]any{"ids": []uint{env.memberID}}, true), http.StatusOK)
expectStatus(t, "pivot of B's member through A", env.send(t, http.MethodGet, relationPath(a, "members", fmt.Sprintf("/pivot/%d", env.memberID)), nil, true), http.StatusNotFound)
expectStatus(t, "pivot update of B's member through A", env.send(t, http.MethodPut, relationPath(a, "members", fmt.Sprintf("/pivot/%d", env.memberID)), map[string]any{"note": "x"}, true), http.StatusNotFound)
// A parent FormExtendQuery hides is 404 on every child route.
hidden := conformGadget{Name: "hidden-" + env.stamp}
if err := env.db.Create(&hidden).Error; err != nil {
t.Fatal(err)
}
ph := conformPart{GadgetID: &hidden.ID, Label: "ph"}
if err := env.db.Create(&ph).Error; err != nil {
t.Fatal(err)
}
expectStatus(t, "hidden parent linked list", env.send(t, http.MethodGet, relationPath(hidden.ID, "parts", ""), nil, true), http.StatusNotFound)
expectStatus(t, "hidden parent child", env.send(t, http.MethodGet, relationPath(hidden.ID, "parts", fmt.Sprintf("/records/%d", ph.ID)), nil, true), http.StatusNotFound)
expectStatus(t, "hidden parent create", env.send(t, http.MethodPost, relationPath(hidden.ID, "parts", "/records"), map[string]any{"label": "x"}, true), http.StatusNotFound)
// hasMany link adopts a free part, unlink frees it, delete removes it.
free := conformPart{Label: "free"}
if err := env.db.Create(&free).Error; err != nil {
t.Fatal(err)
}
candidates := env.send(t, http.MethodGet, relationPath(a, "parts", "/candidates"), nil, true)
expectStatus(t, "candidates", candidates, http.StatusOK)
if !strings.Contains(candidates.Body.String(), `"label":"free"`) || strings.Contains(candidates.Body.String(), `"label":"pb"`) {
t.Fatalf("hasMany candidates = %s", candidates.Body.String())
}
expectStatus(t, "link owned part of B", env.send(t, http.MethodPost, relationPath(a, "parts", "/link"), map[string]any{"ids": []uint{pb}}, true), http.StatusUnprocessableEntity)
expectStatus(t, "link free part", env.send(t, http.MethodPost, relationPath(a, "parts", "/link"), map[string]any{"ids": []uint{free.ID}}, true), http.StatusOK)
if owner := env.partOwner(t, free.ID); owner == nil || *owner != a {
t.Fatalf("linked part owner = %v, want %d", owner, a)
}
expectStatus(t, "unlink part", env.send(t, http.MethodPost, relationPath(a, "parts", "/unlink"), map[string]any{"ids": []uint{free.ID, pb}}, true), http.StatusOK)
if owner := env.partOwner(t, free.ID); owner != nil {
t.Fatalf("unlinked part owner = %d", *owner)
}
if owner := env.partOwner(t, pb); owner == nil || *owner != b {
t.Fatalf("unlink through A freed B's part: %v", owner)
}
expectStatus(t, "delete own child", env.send(t, http.MethodPost, relationPath(a, "parts", "/delete"), map[string]any{"ids": []uint{pa}}, true), http.StatusOK)
var n int64
if err := env.db.Model(&conformPart{}).Where("id = ?", pa).Count(&n).Error; err != nil || n != 0 {
t.Fatalf("deleted part count=%d err=%v", n, err)
}
}
// TestRelationChildSmokePivot links a member with a pivot note (D-14): the
// note is stored, RelationBeforeLink still stamps its hook column, and pivot
// keys outside the pivot form are refused on link and on the pivot route.
func TestRelationChildSmokePivot(t *testing.T) {
env := newConformEnv(t)
env.loginAs(t, env.login)
g := env.createGadget(t, "g-"+env.stamp, "")
second := conformMember{Email: "second-" + env.stamp + "@example.test"}
if err := env.db.Create(&second).Error; err != nil {
t.Fatal(err)
}
for name, body := range map[string]map[string]any{
"foreign key": {"ids": []uint{env.memberID}, "pivot": map[string]any{"gadget_id": 99}},
"hook column": {"ids": []uint{env.memberID}, "pivot": map[string]any{"stamp": "forged"}},
"two ids": {"ids": []uint{env.memberID, second.ID}, "pivot": map[string]any{"note": "x"}},
"hasMany link": nil,
} {
if body == nil {
rec := env.send(t, http.MethodPost, relationPath(g, "parts", "/link"), map[string]any{"ids": []uint{1}, "pivot": map[string]any{"note": "x"}}, true)
expectStatus(t, name, rec, http.StatusUnprocessableEntity)
continue
}
expectStatus(t, name, env.send(t, http.MethodPost, relationPath(g, "members", "/link"), body, true), http.StatusUnprocessableEntity)
}
var count int64
if err := env.db.Model(&conformGadgetMember{}).Where("gadget_id = ?", g).Count(&count).Error; err != nil || count != 0 {
t.Fatalf("refused links wrote %d pivot rows (%v)", count, err)
}
expectStatus(t, "link with note", env.send(t, http.MethodPost, relationPath(g, "members", "/link"), map[string]any{"ids": []uint{env.memberID}, "pivot": map[string]any{"note": "hello"}}, true), http.StatusOK)
var row conformGadgetMember
if err := env.db.Where("gadget_id = ? AND member_id = ?", g, env.memberID).Take(&row).Error; err != nil {
t.Fatal(err)
}
if row.Note != "hello" || row.Stamp != "linked" {
t.Fatalf("pivot row = %+v, want note hello and stamp linked", row)
}
shown := env.send(t, http.MethodGet, relationPath(g, "members", fmt.Sprintf("/pivot/%d", env.memberID)), nil, true)
expectStatus(t, "pivot show", shown, http.StatusOK)
if !strings.Contains(shown.Body.String(), `"note":"hello"`) || strings.Contains(shown.Body.String(), "stamp") {
t.Fatalf("pivot show = %s", shown.Body.String())
}
expectStatus(t, "pivot update with a foreign key", env.send(t, http.MethodPut, relationPath(g, "members", fmt.Sprintf("/pivot/%d", env.memberID)), map[string]any{"member_id": second.ID}, true), http.StatusUnprocessableEntity)
expectStatus(t, "pivot update", env.send(t, http.MethodPut, relationPath(g, "members", fmt.Sprintf("/pivot/%d", env.memberID)), map[string]any{"note": "changed"}, true), http.StatusOK)
if err := env.db.Where("gadget_id = ? AND member_id = ?", g, env.memberID).Take(&row).Error; err != nil {
t.Fatal(err)
}
if row.Note != "changed" || row.Stamp != "linked" || row.MemberID != env.memberID {
t.Fatalf("pivot row after update = %+v", row)
}
}