51 lines
2.0 KiB
TypeScript
51 lines
2.0 KiB
TypeScript
import { beforeEach, describe, expect, it, vi } from "vitest";
|
|
import { HttpError } from "@/lib/security/http";
|
|
|
|
const requireAdmin = vi.fn();
|
|
const notifyCommission = vi.fn();
|
|
const returning = vi.fn();
|
|
const where = vi.fn(() => ({ returning }));
|
|
const set = vi.fn(() => ({ where }));
|
|
|
|
vi.mock("@/lib/auth/server", () => ({ requireAdmin }));
|
|
vi.mock("@/lib/commission/server", () => ({ notifyCommission }));
|
|
vi.mock("@/db", () => ({ getDb: () => ({ update: () => ({ set }) }) }));
|
|
|
|
const { PATCH } = await import("./route");
|
|
const ticketId = "11111111-1111-4111-8111-111111111111";
|
|
|
|
function statusRequest(status: string, origin = "https://guide.sudloh.com") {
|
|
return new Request(`https://guide.sudloh.com/api/commission/tickets/${ticketId}/status`, {
|
|
method: "PATCH", headers: { Origin: origin, "Content-Type": "application/json" },
|
|
body: JSON.stringify({ status }),
|
|
});
|
|
}
|
|
|
|
function context() {
|
|
return { params: Promise.resolve({ id: ticketId }) } as RouteContext<"/api/commission/tickets/[id]/status">;
|
|
}
|
|
|
|
describe("commission ticket status", () => {
|
|
beforeEach(() => {
|
|
process.env.BETTER_AUTH_URL = "https://guide.sudloh.com";
|
|
vi.clearAllMocks();
|
|
requireAdmin.mockResolvedValue({ user: { id: "admin-1" } });
|
|
returning.mockResolvedValue([{ userId: "customer-1" }]);
|
|
});
|
|
|
|
it("publishes a distinct closure event for the customer", async () => {
|
|
const response = await PATCH(statusRequest("closed"), context());
|
|
expect(response.status).toBe(200);
|
|
expect(await response.json()).toEqual({ status: "closed" });
|
|
expect(notifyCommission).toHaveBeenCalledWith(ticketId, "customer-1", "status:closed");
|
|
});
|
|
|
|
it("rejects non-admin and cross-origin attempts", async () => {
|
|
expect((await PATCH(statusRequest("closed", "https://elsewhere.test"), context())).status).toBe(403);
|
|
expect(requireAdmin).not.toHaveBeenCalled();
|
|
requireAdmin.mockRejectedValueOnce(new HttpError(401, "unauthorized"));
|
|
expect((await PATCH(statusRequest("closed"), context())).status).toBe(401);
|
|
expect(notifyCommission).not.toHaveBeenCalled();
|
|
});
|
|
});
|