Files
rakuten-api/tests/test_trading_api.py
T
q792602257andClaude Opus 5 63c41b61e7 自动登录接口 + 有状态端容器化部署 + 三服务合并 openapi 导出
自动登录(此前只能人工跑 scripts/login.py 再 /api/auth/reload):
- 新增 POST /api/auth/login:动作顺序与下单前的 require_logged_in 一致(探测 →
  未登录则按 account.yaml 登一次 → 再探测),已登录直接跳过不白起浏览器。
  刻意**不抛 5001**:失败以 logged_in=false + 各站 detail 正常返回,调用方自己
  决定是人工接管还是换账号。
- 新增 RAKUTEN_AUTO_LOGIN_ON_START(默认 false):启动即准备登录态,为容器部署
  而存在(镜像里没有落盘的 storage_state)。做成后台任务而非启动阻塞——登录最长
  等 relogin_timeout_seconds(默认 300s,撞验证码时在等人工),阻塞会让 /health
  在这段时间里连端口都不通;关服务时 cancel 掉在途的那次。
- 自动登录不绕过站点校验:凭据是用户自己配在 account.yaml 里的,代填进站点自己的
  登录表单,撞 reCAPTCHA / 设备验证会停在有头浏览器等人工,等不到就超时失败。

容器化部署(新增 Dockerfile.trading + docker-compose.yml):
- 有状态端单独出镜像不是为了整洁:下单/结算必须用**有头** Chromium(headless 会让
  结算 SPA 失灵),镜像要带 Xvfb + 日文字体 + 给人工接管用的可选 x11vnc,抓取镜像
  没有这些。网关复用同一镜像只换 command。
- Jenkinsfile 一条流水线产出两个镜像,BUILD_SCRAPING / BUILD_TRADING 两个开关控制。
- .dockerignore 补上 account.yaml / .auth/ / .browser-data/ / data/:明文密码+卡号、
  可直接冒充账号的 cookie、带登录态的浏览器 profile、含真实 PII 的证据快照,都不该
  进镜像也不该进 build context,运行时一律走挂载。
- .env.example 里 RAKUTEN_AUTO_LOGIN_ON_START 刻意留成注释:compose 的变量插值与
  env_file 读的是同一个 ./.env,这里写成显式值会让 compose 的 `${...:-true}` 失效,
  按 compose 文件头「cp .env.example .env」走反而不会自动登录。

openapi 导出(scripts/export_openapi.py):三服务合并成一份可直接导入 Apifox /
Postman 的文档,每条接口带 operation 级 servers(不必手动切端口)。鉴权标注是遍历
FastAPI 依赖树认出真的挂了 require_bearer_token 的接口,不按路径猜。

openapi.json 本身仍是 gitignore 的本地生成物,因此 tests/test_openapi_export.py
只在内存里校验合并逻辑(三服务覆盖、operation 级 servers、除 /health 外全部标鉴权、
operationId 唯一、$ref 可解析),不断言「文件内容 == 当前导出结果」——CI 的全新
clone 里没有这个文件,那种断言必然失败。代价是「改了接口忘了重新导出」没有自动
兜底,得手动跑 --check,已在 README 里点明。

398 测试全绿;另单独验证过缺 openapi.json 时该文件 5 个用例仍通过(CI 场景)。
compose 的变量插值行为只按文档核对,本机没有 docker 未能实测。

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-14 14:27:38 +08:00

452 lines
14 KiB
Python

"""交易服务 API 测试:健康检查、登录态查询与重载、购物车接口、鉴权
登录态会话与站点交互器都被替换为桩,不触达真实站点、不需要真实账号、不起 Playwright。
AuthSession 自身的行为(cookie 加载、探测判据)在 tests/test_auth_session.py。
SiteInteractor 的 DOM 解析纯函数在 tests/test_site_interact.py。
"""
from __future__ import annotations
import pytest
from fastapi.testclient import TestClient
from app.shared.config import get_settings
from app.shared.errors import CartOperationError, NotLoggedInError
from app.trading.main import create_app
from app.trading.services.auth_session import AuthStatus
TOKEN = get_settings().bearer_token
AUTH = {"Authorization": f"Bearer {TOKEN}"}
class StubAuthSession:
"""记录调用并返回固定登录态的桩"""
def __init__(self) -> None:
self.checked: list[str] = []
self.reloaded: list[str] = []
self.relogin_calls: list[str] = []
self.logged_in = True
# try_relogin 的结果;None 表示「登录成功并转为登录态」
self.relogin_result: bool | None = None
@property
def sites(self) -> tuple[str, ...]:
return ("rakuten",)
def _status(self, site: str) -> AuthStatus:
return AuthStatus(
site=site,
state_file_exists=True,
logged_in=self.logged_in,
checked_at=None,
detail="stub",
)
async def check(self, site: str) -> AuthStatus:
self.checked.append(site)
return self._status(site)
def status(self, site: str) -> AuthStatus:
return self._status(site)
def status_all(self) -> dict[str, dict]:
return {site: self._status(site).to_dict() for site in self.sites}
def reload(self, site: str) -> int:
self.reloaded.append(site)
return 3
async def try_relogin(self, site: str) -> bool:
"""默认「登录成功」:翻成登录态并返回 True;relogin_result 可注入失败"""
self.relogin_calls.append(site)
if self.relogin_result is None:
self.logged_in = True
return True
return self.relogin_result
async def require_logged_in(self, site: str) -> None:
if not self.logged_in:
raise NotLoggedInError(site=site, detail="stub")
async def close(self) -> None:
"""lifespan 收尾会调用;桩没有真实客户端要关"""
class StubSiteInteractor:
"""记录调用并返回固定结果的 SiteInteractor 桩
真实 SiteInteractor 起 Playwright,本桩不打外网、不开浏览器。
通过 fail_with 注入异常可测错误路径(5001/5002)。
"""
def __init__(self) -> None:
self.add_calls: list[dict] = []
self.status_calls = 0
self.clear_calls = 0
self.remove_calls: list[str] = []
self.fail_with: Exception | None = None
async def add_to_cart_payload(
self,
*,
item_url: str,
quantity: int = 1,
variant_id: str | None = None,
choice: str | list[str] | None = None,
) -> dict:
self.add_calls.append(
{
"item_url": item_url,
"quantity": quantity,
"variant_id": variant_id,
"choice": choice,
}
)
if self.fail_with:
raise self.fail_with
return {
"item_id": "10000382",
"shop_bid": "284609",
"basket_domain": "https://sp.basket.step.rakuten.co.jp/rms/mall/bss/cartadd/set",
"cart_count": 1,
}
async def cart_status(self) -> dict:
self.status_calls += 1
if self.fail_with:
raise self.fail_with
return {"logged_in": True, "count": 1, "raw_status": "100"}
async def clear_cart(self) -> dict:
self.clear_calls += 1
if self.fail_with:
raise self.fail_with
return {"removed_count": 1, "cart_count": 0}
async def remove_item(self, item_id: str) -> dict:
self.remove_calls.append(item_id)
if self.fail_with:
raise self.fail_with
return {"removed": True, "item_id": item_id}
async def close(self) -> None:
"""lifespan 收尾会调用;桩没有真实浏览器要关"""
@pytest.fixture
def client_and_stubs():
app = create_app()
with TestClient(app) as client:
stub = StubAuthSession()
stub_site = StubSiteInteractor()
app.state.container.auth_session = stub
app.state.container.site = stub_site
yield client, stub, stub_site
@pytest.fixture
def client(client_and_stubs):
return client_and_stubs[0]
@pytest.fixture
def stub(client_and_stubs):
return client_and_stubs[1]
@pytest.fixture
def stub_site(client_and_stubs):
return client_and_stubs[2]
# ---- 健康检查 ----
def test_health_needs_no_token(client):
response = client.get("/health")
assert response.status_code == 200
body = response.json()
assert body["data"]["status"] == "ok"
assert set(body["data"]["auth"]) == {"rakuten"}
def test_health_does_not_probe_the_site(client, stub):
"""健康检查只读缓存:它会被高频轮询,不能每次都去打站点"""
client.get("/health")
assert stub.checked == []
# ---- 鉴权 ----
@pytest.mark.parametrize(
"path", ["/api/auth/status", "/api/auth/login", "/api/auth/reload"]
)
def test_auth_endpoints_reject_missing_token(client, path):
response = client.post(path, json={})
assert response.status_code == 401
assert response.json()["code"] == 1001
def test_auth_endpoints_reject_wrong_token(client):
response = client.post(
"/api/auth/status", json={}, headers={"Authorization": "Bearer wrong-token"}
)
assert response.status_code == 401
# ---- 登录态查询 ----
def test_status_probes_site_by_default(client, stub):
response = client.post("/api/auth/status", json={}, headers=AUTH)
assert response.status_code == 200
body = response.json()
assert [item["site"] for item in body["data"]["sites"]] == ["rakuten"]
assert stub.checked == ["rakuten"]
def test_status_can_skip_the_probe(client, stub):
"""refresh=false 时读缓存,不打站点"""
response = client.post("/api/auth/status", json={"refresh": False}, headers=AUTH)
assert response.status_code == 200
assert stub.checked == []
def test_status_accepts_a_single_site(client, stub):
response = client.post("/api/auth/status", json={"site": "rakuten"}, headers=AUTH)
assert response.status_code == 200
assert stub.checked == ["rakuten"]
def test_status_rejects_unknown_site(client):
"""站点名是枚举,未知值应在校验层就被挡下"""
response = client.post("/api/auth/status", json={"site": "mercari"}, headers=AUTH)
assert response.status_code == 422
assert response.json()["code"] == 1002
# ---- 自动登录 ----
def test_login_skips_when_already_logged_in(client, stub):
"""已登录时不该白起一次登录流程(起浏览器 + 打站点,代价不小)"""
response = client.post("/api/auth/login", json={}, headers=AUTH)
assert response.status_code == 200
body = response.json()
assert body["data"]["logged_in"] is True
assert body["data"]["relogin_attempted"] == {"rakuten": False}
assert stub.relogin_calls == []
# 结论必须来自真实探测,不能只看缓存
assert stub.checked == ["rakuten"]
def test_login_triggers_relogin_when_logged_out(client, stub):
stub.logged_in = False
response = client.post("/api/auth/login", json={"site": "rakuten"}, headers=AUTH)
assert response.status_code == 200
body = response.json()
assert body["data"]["logged_in"] is True
assert body["data"]["relogin_attempted"] == {"rakuten": True}
assert stub.relogin_calls == ["rakuten"]
# 登录后必须再探测一次确认,不能拿登录流程的自述当结论
assert stub.checked == ["rakuten", "rakuten"]
def test_login_reports_failure_without_raising(client, stub):
"""登录失败按 logged_in=false 正常返回,不是 5001
调用方要据此决定人工接管还是换账号;抛错会把「为什么失败」压成一个错误码。
"""
stub.logged_in = False
stub.relogin_result = False
response = client.post("/api/auth/login", json={}, headers=AUTH)
assert response.status_code == 200
body = response.json()
assert body["success"] is True
assert body["data"]["logged_in"] is False
assert body["data"]["relogin_attempted"] == {"rakuten": True}
def test_login_rejects_unknown_site(client):
response = client.post("/api/auth/login", json={"site": "mercari"}, headers=AUTH)
assert response.status_code == 422
assert response.json()["code"] == 1002
# ---- 启动时自动登录(RAKUTEN_AUTO_LOGIN_ON_START)----
class _FakeContainer:
def __init__(self, auth_session) -> None:
self.auth_session = auth_session
async def test_auto_login_on_start_skips_when_logged_in():
from app.trading.main import auto_login_on_start
stub = StubAuthSession()
await auto_login_on_start(_FakeContainer(stub))
assert stub.relogin_calls == []
async def test_auto_login_on_start_logs_in_when_logged_out():
from app.trading.main import auto_login_on_start
stub = StubAuthSession()
stub.logged_in = False
await auto_login_on_start(_FakeContainer(stub))
assert stub.relogin_calls == ["rakuten"]
async def test_auto_login_on_start_swallows_errors():
"""探测抛错也不能把启动流程带崩——服务要能起来报「未登录」"""
from app.trading.main import auto_login_on_start
class Boom(StubAuthSession):
async def check(self, site: str):
raise RuntimeError("站点不可达")
stub = Boom()
await auto_login_on_start(_FakeContainer(stub))
assert stub.relogin_calls == []
# ---- 登录态重载 ----
def test_reload_reloads_then_probes(client, stub):
response = client.post("/api/auth/reload", json={"site": "rakuten"}, headers=AUTH)
assert response.status_code == 200
body = response.json()
assert body["data"]["reloaded"] == {"rakuten": 3}
# 重载后必须立刻探测一次,否则调用方拿不到「这次登录到底成没成」
assert stub.reloaded == ["rakuten"]
assert stub.checked == ["rakuten"]
# ---- 购物车接口 ----
@pytest.mark.parametrize(
"path",
["/api/cart/add", "/api/cart/status", "/api/cart/clear", "/api/cart/remove"],
)
def test_cart_endpoints_reject_missing_token(client, path):
"""所有 cart 接口都要 Bearer token"""
response = client.post(path, json={})
assert response.status_code == 401
assert response.json()["code"] == 1001
def test_cart_add_happy_path(client, stub_site):
"""加购成功:返回 added=true 与 cart_count"""
response = client.post(
"/api/cart/add",
json={"item_url": "https://item.rakuten.co.jp/shop/x/", "quantity": 2},
headers=AUTH,
)
assert response.status_code == 200
body = response.json()
assert body["data"]["added"] is True
assert body["data"]["item_id"] == "10000382"
assert body["data"]["shop_bid"] == "284609"
assert body["data"]["cart_count"] == 1
# 桩记下了入参
assert stub_site.add_calls == [
{
"item_url": "https://item.rakuten.co.jp/shop/x/",
"quantity": 2,
"variant_id": None,
"choice": None,
}
]
def test_cart_add_missing_item_url(client):
"""item_url 必填,缺失时 Pydantic 在校验层挡下(422)"""
response = client.post("/api/cart/add", json={"quantity": 1}, headers=AUTH)
assert response.status_code == 422
assert response.json()["code"] == 1002
def test_cart_add_propagates_not_logged_in(client, stub_site):
"""SiteInteractor 抛 NotLoggedInError(5001)→ HTTP 401"""
stub_site.fail_with = NotLoggedInError(site="rakuten", detail="stub")
response = client.post(
"/api/cart/add",
json={"item_url": "https://item.rakuten.co.jp/shop/x/"},
headers=AUTH,
)
assert response.status_code == 401
assert response.json()["code"] == 5001
def test_cart_add_propagates_cart_error(client, stub_site):
"""SiteInteractor 抛 CartOperationError(5002)→ HTTP 400"""
stub_site.fail_with = CartOperationError("商品不可购买:purchaseCondition=disabled")
response = client.post(
"/api/cart/add",
json={"item_url": "https://item.rakuten.co.jp/shop/x/"},
headers=AUTH,
)
assert response.status_code == 400
assert response.json()["code"] == 5002
def test_cart_status_happy_path(client, stub_site):
response = client.post("/api/cart/status", json={}, headers=AUTH)
assert response.status_code == 200
body = response.json()
assert body["data"]["logged_in"] is True
assert body["data"]["count"] == 1
assert body["data"]["raw_status"] == "100"
assert stub_site.status_calls == 1
def test_cart_clear_happy_path(client, stub_site):
response = client.post("/api/cart/clear", json={}, headers=AUTH)
assert response.status_code == 200
body = response.json()
assert body["data"]["removed_count"] == 1
assert body["data"]["cart_count"] == 0
assert stub_site.clear_calls == 1
def test_cart_remove_happy_path(client, stub_site):
response = client.post(
"/api/cart/remove", json={"item_id": "10000382"}, headers=AUTH
)
assert response.status_code == 200
body = response.json()
assert body["data"]["removed"] is True
assert body["data"]["item_id"] == "10000382"
assert stub_site.remove_calls == ["10000382"]
def test_cart_remove_missing_item_id(client):
response = client.post("/api/cart/remove", json={}, headers=AUTH)
assert response.status_code == 422
assert response.json()["code"] == 1002
def test_cart_remove_propagates_cart_error(client, stub_site):
"""指定 item_id 不在购物车里 → 5002"""
stub_site.fail_with = CartOperationError("购物车里没有 item_id=99999")
response = client.post(
"/api/cart/remove", json={"item_id": "99999"}, headers=AUTH
)
assert response.status_code == 400
assert response.json()["code"] == 5002
def test_cart_endpoints_unavailable_when_site_is_none(client):
"""SiteInteractor 未就绪(container.site 为 None)→ UpstreamRequestError 3001
生产环境 lifespan 一定构造了 site;本测试模拟异常启动路径。
"""
client.app.state.container.site = None
response = client.post("/api/cart/status", json={}, headers=AUTH)
assert response.status_code == 400
assert response.json()["code"] == 3001