"""交易服务 API 测试:健康检查、登录态查询与重载、购物车接口、鉴权 登录态会话与站点交互器都被替换为桩,不触达真实站点、不需要真实账号、不起 Playwright。 AuthSession 自身的行为(cookie 加载、探测判据)在 tests/test_auth_session.py。 SiteInteractor 的 DOM 解析纯函数在 tests/test_site_interact.py。 """ from __future__ import annotations import pytest from fastapi.testclient import TestClient from app.shared.config import get_settings from app.shared.errors import CartOperationError, NotLoggedInError from app.trading.main import create_app from app.trading.services.auth_session import AuthStatus TOKEN = get_settings().bearer_token AUTH = {"Authorization": f"Bearer {TOKEN}"} class StubAuthSession: """记录调用并返回固定登录态的桩""" def __init__(self) -> None: self.checked: list[str] = [] self.reloaded: list[str] = [] self.relogin_calls: list[str] = [] self.logged_in = True # try_relogin 的结果;None 表示「登录成功并转为登录态」 self.relogin_result: bool | None = None @property def sites(self) -> tuple[str, ...]: return ("rakuten",) def _status(self, site: str) -> AuthStatus: return AuthStatus( site=site, state_file_exists=True, logged_in=self.logged_in, checked_at=None, detail="stub", ) async def check(self, site: str) -> AuthStatus: self.checked.append(site) return self._status(site) def status(self, site: str) -> AuthStatus: return self._status(site) def status_all(self) -> dict[str, dict]: return {site: self._status(site).to_dict() for site in self.sites} def reload(self, site: str) -> int: self.reloaded.append(site) return 3 async def try_relogin(self, site: str) -> bool: """默认「登录成功」:翻成登录态并返回 True;relogin_result 可注入失败""" self.relogin_calls.append(site) if self.relogin_result is None: self.logged_in = True return True return self.relogin_result async def require_logged_in(self, site: str) -> None: if not self.logged_in: raise NotLoggedInError(site=site, detail="stub") async def close(self) -> None: """lifespan 收尾会调用;桩没有真实客户端要关""" class StubSiteInteractor: """记录调用并返回固定结果的 SiteInteractor 桩 真实 SiteInteractor 起 Playwright,本桩不打外网、不开浏览器。 通过 fail_with 注入异常可测错误路径(5001/5002)。 """ def __init__(self) -> None: self.add_calls: list[dict] = [] self.status_calls = 0 self.clear_calls = 0 self.remove_calls: list[str] = [] self.fail_with: Exception | None = None async def add_to_cart_payload( self, *, item_url: str, quantity: int = 1, variant_id: str | None = None, choice: str | list[str] | None = None, ) -> dict: self.add_calls.append( { "item_url": item_url, "quantity": quantity, "variant_id": variant_id, "choice": choice, } ) if self.fail_with: raise self.fail_with return { "item_id": "10000382", "shop_bid": "284609", "basket_domain": "https://sp.basket.step.rakuten.co.jp/rms/mall/bss/cartadd/set", "cart_count": 1, } async def cart_status(self) -> dict: self.status_calls += 1 if self.fail_with: raise self.fail_with return {"logged_in": True, "count": 1, "raw_status": "100"} async def clear_cart(self) -> dict: self.clear_calls += 1 if self.fail_with: raise self.fail_with return {"removed_count": 1, "cart_count": 0} async def remove_item(self, item_id: str) -> dict: self.remove_calls.append(item_id) if self.fail_with: raise self.fail_with return {"removed": True, "item_id": item_id} async def close(self) -> None: """lifespan 收尾会调用;桩没有真实浏览器要关""" @pytest.fixture def client_and_stubs(): app = create_app() with TestClient(app) as client: stub = StubAuthSession() stub_site = StubSiteInteractor() app.state.container.auth_session = stub app.state.container.site = stub_site yield client, stub, stub_site @pytest.fixture def client(client_and_stubs): return client_and_stubs[0] @pytest.fixture def stub(client_and_stubs): return client_and_stubs[1] @pytest.fixture def stub_site(client_and_stubs): return client_and_stubs[2] # ---- 健康检查 ---- def test_health_needs_no_token(client): response = client.get("/health") assert response.status_code == 200 body = response.json() assert body["data"]["status"] == "ok" assert set(body["data"]["auth"]) == {"rakuten"} def test_health_does_not_probe_the_site(client, stub): """健康检查只读缓存:它会被高频轮询,不能每次都去打站点""" client.get("/health") assert stub.checked == [] # ---- 鉴权 ---- @pytest.mark.parametrize( "path", ["/api/auth/status", "/api/auth/login", "/api/auth/reload"] ) def test_auth_endpoints_reject_missing_token(client, path): response = client.post(path, json={}) assert response.status_code == 401 assert response.json()["code"] == 1001 def test_auth_endpoints_reject_wrong_token(client): response = client.post( "/api/auth/status", json={}, headers={"Authorization": "Bearer wrong-token"} ) assert response.status_code == 401 # ---- 登录态查询 ---- def test_status_probes_site_by_default(client, stub): response = client.post("/api/auth/status", json={}, headers=AUTH) assert response.status_code == 200 body = response.json() assert [item["site"] for item in body["data"]["sites"]] == ["rakuten"] assert stub.checked == ["rakuten"] def test_status_can_skip_the_probe(client, stub): """refresh=false 时读缓存,不打站点""" response = client.post("/api/auth/status", json={"refresh": False}, headers=AUTH) assert response.status_code == 200 assert stub.checked == [] def test_status_accepts_a_single_site(client, stub): response = client.post("/api/auth/status", json={"site": "rakuten"}, headers=AUTH) assert response.status_code == 200 assert stub.checked == ["rakuten"] def test_status_rejects_unknown_site(client): """站点名是枚举,未知值应在校验层就被挡下""" response = client.post("/api/auth/status", json={"site": "mercari"}, headers=AUTH) assert response.status_code == 422 assert response.json()["code"] == 1002 # ---- 自动登录 ---- def test_login_skips_when_already_logged_in(client, stub): """已登录时不该白起一次登录流程(起浏览器 + 打站点,代价不小)""" response = client.post("/api/auth/login", json={}, headers=AUTH) assert response.status_code == 200 body = response.json() assert body["data"]["logged_in"] is True assert body["data"]["relogin_attempted"] == {"rakuten": False} assert stub.relogin_calls == [] # 结论必须来自真实探测,不能只看缓存 assert stub.checked == ["rakuten"] def test_login_triggers_relogin_when_logged_out(client, stub): stub.logged_in = False response = client.post("/api/auth/login", json={"site": "rakuten"}, headers=AUTH) assert response.status_code == 200 body = response.json() assert body["data"]["logged_in"] is True assert body["data"]["relogin_attempted"] == {"rakuten": True} assert stub.relogin_calls == ["rakuten"] # 登录后必须再探测一次确认,不能拿登录流程的自述当结论 assert stub.checked == ["rakuten", "rakuten"] def test_login_reports_failure_without_raising(client, stub): """登录失败按 logged_in=false 正常返回,不是 5001 调用方要据此决定人工接管还是换账号;抛错会把「为什么失败」压成一个错误码。 """ stub.logged_in = False stub.relogin_result = False response = client.post("/api/auth/login", json={}, headers=AUTH) assert response.status_code == 200 body = response.json() assert body["success"] is True assert body["data"]["logged_in"] is False assert body["data"]["relogin_attempted"] == {"rakuten": True} def test_login_rejects_unknown_site(client): response = client.post("/api/auth/login", json={"site": "mercari"}, headers=AUTH) assert response.status_code == 422 assert response.json()["code"] == 1002 # ---- 启动时自动登录(RAKUTEN_AUTO_LOGIN_ON_START)---- class _FakeContainer: def __init__(self, auth_session) -> None: self.auth_session = auth_session async def test_auto_login_on_start_skips_when_logged_in(): from app.trading.main import auto_login_on_start stub = StubAuthSession() await auto_login_on_start(_FakeContainer(stub)) assert stub.relogin_calls == [] async def test_auto_login_on_start_logs_in_when_logged_out(): from app.trading.main import auto_login_on_start stub = StubAuthSession() stub.logged_in = False await auto_login_on_start(_FakeContainer(stub)) assert stub.relogin_calls == ["rakuten"] async def test_auto_login_on_start_swallows_errors(): """探测抛错也不能把启动流程带崩——服务要能起来报「未登录」""" from app.trading.main import auto_login_on_start class Boom(StubAuthSession): async def check(self, site: str): raise RuntimeError("站点不可达") stub = Boom() await auto_login_on_start(_FakeContainer(stub)) assert stub.relogin_calls == [] # ---- 登录态重载 ---- def test_reload_reloads_then_probes(client, stub): response = client.post("/api/auth/reload", json={"site": "rakuten"}, headers=AUTH) assert response.status_code == 200 body = response.json() assert body["data"]["reloaded"] == {"rakuten": 3} # 重载后必须立刻探测一次,否则调用方拿不到「这次登录到底成没成」 assert stub.reloaded == ["rakuten"] assert stub.checked == ["rakuten"] # ---- 购物车接口 ---- @pytest.mark.parametrize( "path", ["/api/cart/add", "/api/cart/status", "/api/cart/clear", "/api/cart/remove"], ) def test_cart_endpoints_reject_missing_token(client, path): """所有 cart 接口都要 Bearer token""" response = client.post(path, json={}) assert response.status_code == 401 assert response.json()["code"] == 1001 def test_cart_add_happy_path(client, stub_site): """加购成功:返回 added=true 与 cart_count""" response = client.post( "/api/cart/add", json={"item_url": "https://item.rakuten.co.jp/shop/x/", "quantity": 2}, headers=AUTH, ) assert response.status_code == 200 body = response.json() assert body["data"]["added"] is True assert body["data"]["item_id"] == "10000382" assert body["data"]["shop_bid"] == "284609" assert body["data"]["cart_count"] == 1 # 桩记下了入参 assert stub_site.add_calls == [ { "item_url": "https://item.rakuten.co.jp/shop/x/", "quantity": 2, "variant_id": None, "choice": None, } ] def test_cart_add_missing_item_url(client): """item_url 必填,缺失时 Pydantic 在校验层挡下(422)""" response = client.post("/api/cart/add", json={"quantity": 1}, headers=AUTH) assert response.status_code == 422 assert response.json()["code"] == 1002 def test_cart_add_propagates_not_logged_in(client, stub_site): """SiteInteractor 抛 NotLoggedInError(5001)→ HTTP 401""" stub_site.fail_with = NotLoggedInError(site="rakuten", detail="stub") response = client.post( "/api/cart/add", json={"item_url": "https://item.rakuten.co.jp/shop/x/"}, headers=AUTH, ) assert response.status_code == 401 assert response.json()["code"] == 5001 def test_cart_add_propagates_cart_error(client, stub_site): """SiteInteractor 抛 CartOperationError(5002)→ HTTP 400""" stub_site.fail_with = CartOperationError("商品不可购买:purchaseCondition=disabled") response = client.post( "/api/cart/add", json={"item_url": "https://item.rakuten.co.jp/shop/x/"}, headers=AUTH, ) assert response.status_code == 400 assert response.json()["code"] == 5002 def test_cart_status_happy_path(client, stub_site): response = client.post("/api/cart/status", json={}, headers=AUTH) assert response.status_code == 200 body = response.json() assert body["data"]["logged_in"] is True assert body["data"]["count"] == 1 assert body["data"]["raw_status"] == "100" assert stub_site.status_calls == 1 def test_cart_clear_happy_path(client, stub_site): response = client.post("/api/cart/clear", json={}, headers=AUTH) assert response.status_code == 200 body = response.json() assert body["data"]["removed_count"] == 1 assert body["data"]["cart_count"] == 0 assert stub_site.clear_calls == 1 def test_cart_remove_happy_path(client, stub_site): response = client.post( "/api/cart/remove", json={"item_id": "10000382"}, headers=AUTH ) assert response.status_code == 200 body = response.json() assert body["data"]["removed"] is True assert body["data"]["item_id"] == "10000382" assert stub_site.remove_calls == ["10000382"] def test_cart_remove_missing_item_id(client): response = client.post("/api/cart/remove", json={}, headers=AUTH) assert response.status_code == 422 assert response.json()["code"] == 1002 def test_cart_remove_propagates_cart_error(client, stub_site): """指定 item_id 不在购物车里 → 5002""" stub_site.fail_with = CartOperationError("购物车里没有 item_id=99999") response = client.post( "/api/cart/remove", json={"item_id": "99999"}, headers=AUTH ) assert response.status_code == 400 assert response.json()["code"] == 5002 def test_cart_endpoints_unavailable_when_site_is_none(client): """SiteInteractor 未就绪(container.site 为 None)→ UpstreamRequestError 3001 生产环境 lifespan 一定构造了 site;本测试模拟异常启动路径。 """ client.app.state.container.site = None response = client.post("/api/cart/status", json={}, headers=AUTH) assert response.status_code == 400 assert response.json()["code"] == 3001