feat : also update
CI / Verify (push) Successful in 2m4s
CI / Build immutable images and deploy (push) Successful in 3m8s

This commit is contained in:
2026-10-01 19:47:02 +07:00 Unverified
parent 0022625edb
commit 2517982a27
18 changed files with 609 additions and 83 deletions
@@ -0,0 +1,67 @@
import { beforeEach, describe, expect, it, vi } from "vitest";
import { HttpError } from "@/lib/security/http";
const authorizeMobileSlip = vi.fn();
const consumeMobileSlipLink = vi.fn();
const recordMobileSlipError = vi.fn();
const verifyAndCreateTicket = vi.fn();
const limitRequest = vi.fn();
vi.mock("@/lib/commission/mobile-slip", () => ({
authorizeMobileSlip, consumeMobileSlipLink, recordMobileSlipError,
}));
vi.mock("@/lib/commission/slip-upload", () => ({ MAX_SLIP_BYTES: 6 * 1024 * 1024, verifyAndCreateTicket }));
vi.mock("@/lib/security/rate-limit", () => ({ limitRequest }));
const { GET, POST } = await import("./route");
const token = "x".repeat(43);
const checkout = { id: "checkout-1", userId: "customer-1", amountBaht: 150 };
function upload(origin = "https://guide.sudloh.com") {
const form = new FormData();
form.set("file", new File(["image"], "slip.png", { type: "image/png" }));
return new Request("https://guide.sudloh.com/api/commission/mobile-slip", {
method: "POST", headers: { Origin: origin, Authorization: `Bearer ${token}` }, body: form,
});
}
describe("commission phone slip upload", () => {
beforeEach(() => {
process.env.BETTER_AUTH_URL = "https://guide.sudloh.com";
vi.clearAllMocks();
authorizeMobileSlip.mockResolvedValue({ checkout, ticketId: null, digest: "digest-1" });
verifyAndCreateTicket.mockResolvedValue({ ticketId: "ticket-1", created: true });
consumeMobileSlipLink.mockResolvedValue(undefined);
recordMobileSlipError.mockResolvedValue(undefined);
});
it("checks the bearer link without requiring a login", async () => {
const response = await GET(new Request("https://guide.sudloh.com/api/commission/mobile-slip", {
headers: { Authorization: `Bearer ${token}` },
}));
expect(response.status).toBe(200);
expect(await response.json()).toEqual({ amountBaht: 150, complete: false });
expect(authorizeMobileSlip).toHaveBeenCalledWith(token);
});
it("verifies a phone slip and consumes the link", async () => {
const response = await POST(upload());
expect(response.status).toBe(201);
expect(verifyAndCreateTicket).toHaveBeenCalledWith(checkout, expect.any(File));
expect(consumeMobileSlipLink).toHaveBeenCalledWith("checkout-1", "digest-1");
});
it("rejects cross-origin uploads before using the link", async () => {
expect((await POST(upload("https://example.com"))).status).toBe(403);
expect(authorizeMobileSlip).not.toHaveBeenCalled();
});
it("reports verification failures for the desktop and permits retry", async () => {
const failure = new HttpError(422, "slip-rejected:200402");
verifyAndCreateTicket.mockRejectedValueOnce(failure);
const response = await POST(upload());
expect(response.status).toBe(422);
expect(recordMobileSlipError).toHaveBeenCalledWith("digest-1", "customer-1", failure);
expect(consumeMobileSlipLink).not.toHaveBeenCalled();
});
});
+42
View File
@@ -0,0 +1,42 @@
import { authorizeMobileSlip, consumeMobileSlipLink, recordMobileSlipError } from "@/lib/commission/mobile-slip";
import { MAX_SLIP_BYTES, verifyAndCreateTicket } from "@/lib/commission/slip-upload";
import { boundedBody, errorResponse, HttpError, requireSameOrigin, withUploadSlot } from "@/lib/security/http";
import { limitRequest } from "@/lib/security/rate-limit";
function bearerToken(request: Request) {
const value = request.headers.get("authorization") ?? "";
if (!value.startsWith("Bearer ")) throw new HttpError(401, "upload-link-required");
return value.slice(7);
}
export async function GET(request: Request) {
try {
const { checkout, ticketId } = await authorizeMobileSlip(bearerToken(request));
return Response.json({ amountBaht: checkout.amountBaht, complete: Boolean(ticketId) },
{ headers: { "Cache-Control": "no-store" } });
} catch (cause) { return errorResponse(cause); }
}
export async function POST(request: Request) {
let handoff: Awaited<ReturnType<typeof authorizeMobileSlip>> | undefined;
try {
requireSameOrigin(request);
handoff = await authorizeMobileSlip(bearerToken(request));
await limitRequest("commission-mobile-slip-token", handoff.digest, 10);
if (handoff.ticketId) return Response.json({ complete: true }, { headers: { "Cache-Control": "no-store" } });
if (!request.headers.get("content-type")?.startsWith("multipart/form-data;"))
throw new HttpError(415, "expected-multipart");
const { checkout, digest } = handoff;
const result = await withUploadSlot(async () => {
const form = await boundedBody(request, MAX_SLIP_BYTES + 64 * 1024).formData();
return verifyAndCreateTicket(checkout, form.get("file"));
});
await consumeMobileSlipLink(checkout.id, digest).catch(() => undefined);
return Response.json({ complete: true }, {
status: result.created ? 201 : 200, headers: { "Cache-Control": "no-store" },
});
} catch (cause) {
if (handoff) await recordMobileSlipError(handoff.digest, handoff.checkout.userId, cause).catch(() => undefined);
return errorResponse(cause);
}
}