mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 10:43:13 +00:00
* refactor(api): enforce service and data-service boundaries * refactor(api): complete feature service boundaries * refactor(identity): enforce service and data boundaries * refactor(vendors): enforce service and data boundaries * refactor(workorders): enforce service and data boundaries * refactor(backend): enforce architecture and optimize dispatch * style(backend): format changed architecture files * fix(architecture): address backend review follow-ups * fix(backend): sanitize exception disclosure in changed API endpoints Replace raw exception-message disclosure (ex.Message) returned to API callers with a stable sanitized public message plus correlated structured internal logging, across the endpoints changed in this PR. - Add SanitizedErrors helper: logs the original exception at Error with a generated correlation id and returns a stable public message referencing it so support can trace without exposing internals. - Inject ILogger<T> into the 14 changed controllers and route every ex.Message/dbex.Message disclosure through the helper, preserving status codes, response shapes, and business data (e.g. OpenWorkOrders). - Leave FluentValidation (vex.Errors) and existing fixed-message catches untouched; out-of-scope controllers (Account/Contact/Employee/Asset/ PMSchedule) are unchanged. - Add focused tests proving internal exception text is not returned and that Error logging carrying the original exception is invoked. * fix(architecture): abstract job run state access * style: format board update service * test: use collection assertion idiom
171 lines
7.9 KiB
C#
171 lines
7.9 KiB
C#
using Data.SeaHavenIndustries;
|
|
using FluentAssertions;
|
|
using Microsoft.AspNetCore.Identity;
|
|
using Microsoft.Extensions.Options;
|
|
using Moq;
|
|
using SeaHaven.DataServices.Interfaces;
|
|
using SeaHaven.Services.Configuration;
|
|
using SeaHaven.Services.DTOs;
|
|
using SeaHaven.Services.Implementation;
|
|
using SeaHaven.Services.Interfaces;
|
|
using System.Security.Claims;
|
|
using Xunit;
|
|
|
|
namespace Api.SeaHavenIndustries.Tests;
|
|
|
|
public class AuthenticationServiceTests
|
|
{
|
|
private static AuthenticationService NewService(
|
|
Mock<IUserDataService> userData,
|
|
Mock<IForgetPasswordDataService> forget,
|
|
Mock<IEmailSender> email,
|
|
out Mock<IUserRoleStore<ApplicationUser>> store,
|
|
out Mock<IPasswordHasher<ApplicationUser>> hasher)
|
|
{
|
|
var (manager, s, h) = IdentityTestHelpers.CreateUserManager();
|
|
store = s;
|
|
hasher = h;
|
|
return new AuthenticationService(manager, Microsoft.Extensions.Options.Options.Create(JwtOptions), userData.Object, forget.Object, email.Object);
|
|
}
|
|
|
|
private static JwtOptions JwtOptions => new()
|
|
{
|
|
Secret = new string('x', 64),
|
|
ValidIssuer = "issuer",
|
|
ValidAudience = "audience"
|
|
};
|
|
|
|
[Fact]
|
|
public async Task Login_UnknownUser_ReturnsNull()
|
|
{
|
|
var service = NewService(new Mock<IUserDataService>(), new Mock<IForgetPasswordDataService>(), new Mock<IEmailSender>(), out var store, out _);
|
|
store.Setup(s => s.FindByNameAsync(It.IsAny<string>(), It.IsAny<CancellationToken>())).ReturnsAsync((ApplicationUser?)null);
|
|
|
|
var result = await service.LoginAsync("nobody", "pw", CancellationToken.None);
|
|
|
|
result.Should().BeNull();
|
|
}
|
|
|
|
[Fact]
|
|
public async Task Login_DeletedUser_RejectedBeforePasswordCheck()
|
|
{
|
|
var deletedUser = IdentityTestHelpers.User(isDeleted: true);
|
|
var service = NewService(new Mock<IUserDataService>(), new Mock<IForgetPasswordDataService>(), new Mock<IEmailSender>(), out var store, out var hasher);
|
|
store.Setup(s => s.FindByNameAsync(It.IsAny<string>(), It.IsAny<CancellationToken>())).ReturnsAsync(deletedUser);
|
|
store.Setup(s => s.GetRolesAsync(deletedUser, It.IsAny<CancellationToken>())).ReturnsAsync(new List<string>());
|
|
|
|
var result = await service.LoginAsync("alice", "pw", CancellationToken.None);
|
|
|
|
result.Should().BeNull();
|
|
hasher.Verify(h => h.VerifyHashedPassword(It.IsAny<ApplicationUser>(), It.IsAny<string>(), It.IsAny<string>()), Times.Never);
|
|
}
|
|
|
|
[Fact]
|
|
public async Task Login_ValidUser_ReturnsTokenFirstRoleAndIdentity()
|
|
{
|
|
var user = IdentityTestHelpers.User();
|
|
var service = NewService(new Mock<IUserDataService>(), new Mock<IForgetPasswordDataService>(), new Mock<IEmailSender>(), out var store, out var hasher);
|
|
store.Setup(s => s.FindByNameAsync(It.IsAny<string>(), It.IsAny<CancellationToken>())).ReturnsAsync(user);
|
|
store.Setup(s => s.GetRolesAsync(user, It.IsAny<CancellationToken>())).ReturnsAsync(new List<string> { "Admin", "Manager" });
|
|
store.As<Microsoft.AspNetCore.Identity.IUserPasswordStore<ApplicationUser>>()
|
|
.Setup(s => s.GetPasswordHashAsync(user, It.IsAny<CancellationToken>())).ReturnsAsync("hash");
|
|
hasher.Setup(h => h.VerifyHashedPassword(user, "hash", "pw")).Returns(Microsoft.AspNetCore.Identity.PasswordVerificationResult.Success);
|
|
|
|
var result = await service.LoginAsync("alice", "pw", CancellationToken.None);
|
|
|
|
result.Should().NotBeNull();
|
|
result!.Id.Should().Be(user.Id);
|
|
result.Email.Should().Be(user.Email);
|
|
result.PhoneNumber.Should().Be(user.PhoneNumber);
|
|
result.Fullname.Should().Be("Alice Q");
|
|
result.UserRole.Should().Be("Admin");
|
|
result.Token.Should().NotBeNullOrEmpty();
|
|
result.Expiration.Should().BeAfter(DateTime.Now.AddDays(9));
|
|
}
|
|
|
|
[Fact]
|
|
public async Task Login_BadPassword_ReturnsNull()
|
|
{
|
|
var user = IdentityTestHelpers.User();
|
|
var service = NewService(new Mock<IUserDataService>(), new Mock<IForgetPasswordDataService>(), new Mock<IEmailSender>(), out var store, out var hasher);
|
|
store.Setup(s => s.FindByNameAsync(It.IsAny<string>(), It.IsAny<CancellationToken>())).ReturnsAsync(user);
|
|
store.As<Microsoft.AspNetCore.Identity.IUserPasswordStore<ApplicationUser>>()
|
|
.Setup(s => s.GetPasswordHashAsync(user, It.IsAny<CancellationToken>())).ReturnsAsync("hash");
|
|
hasher.Setup(h => h.VerifyHashedPassword(user, "hash", "wrong")).Returns(Microsoft.AspNetCore.Identity.PasswordVerificationResult.Failed);
|
|
|
|
var result = await service.LoginAsync("alice", "wrong", CancellationToken.None);
|
|
|
|
result.Should().BeNull();
|
|
}
|
|
|
|
[Fact]
|
|
public async Task ForgetPassword_RegisteredEmail_ReplacesCodeAndSendsEmail()
|
|
{
|
|
var user = IdentityTestHelpers.User();
|
|
var userData = new Mock<IUserDataService>();
|
|
userData.Setup(u => u.GetByEmailNormalizedAsync("alice@example.com", It.IsAny<CancellationToken>())).ReturnsAsync(user);
|
|
var forget = new Mock<IForgetPasswordDataService>();
|
|
var email = new Mock<IEmailSender>();
|
|
|
|
var service = NewService(userData, forget, email, out _, out _);
|
|
|
|
var found = await service.ForgetPasswordAsync("alice@example.com", CancellationToken.None);
|
|
|
|
found.Should().BeTrue();
|
|
forget.Verify(
|
|
f => f.ReplaceCodeAsync(
|
|
user.Email!,
|
|
user.Id,
|
|
It.Is<string>(code => code.Length == 6 && code.All(char.IsDigit)),
|
|
It.IsAny<CancellationToken>()),
|
|
Times.Once);
|
|
email.Verify(e => e.SendEmailAsync(user.Email!, "Forget Password Request.", It.Is<string>(b => b.Contains("Your Password Reset Code is:"))), Times.Once);
|
|
}
|
|
|
|
[Fact]
|
|
public async Task ForgetPassword_UnknownEmail_DoesNotEmailOrStoreCode()
|
|
{
|
|
var userData = new Mock<IUserDataService>();
|
|
userData.Setup(u => u.GetByEmailNormalizedAsync(It.IsAny<string>(), It.IsAny<CancellationToken>())).ReturnsAsync((ApplicationUser?)null);
|
|
var forget = new Mock<IForgetPasswordDataService>();
|
|
var email = new Mock<IEmailSender>();
|
|
|
|
var service = NewService(userData, forget, email, out _, out _);
|
|
|
|
var found = await service.ForgetPasswordAsync("nope@example.com", CancellationToken.None);
|
|
|
|
found.Should().BeFalse();
|
|
forget.Verify(f => f.ReplaceCodeAsync(It.IsAny<string>(), It.IsAny<string>(), It.IsAny<string>(), It.IsAny<CancellationToken>()), Times.Never);
|
|
email.Verify(e => e.SendEmailAsync(It.IsAny<string>(), It.IsAny<string>(), It.IsAny<string>()), Times.Never);
|
|
}
|
|
|
|
[Theory]
|
|
[InlineData(true)]
|
|
[InlineData(false)]
|
|
public async Task VerifyCode_ForwardsDataServiceResult(bool exists)
|
|
{
|
|
var forget = new Mock<IForgetPasswordDataService>();
|
|
forget.Setup(f => f.CodeExistsAsync("abc", It.IsAny<CancellationToken>())).ReturnsAsync(exists);
|
|
|
|
var service = NewService(new Mock<IUserDataService>(), forget, new Mock<IEmailSender>(), out _, out _);
|
|
|
|
var result = await service.VerifyCodeAsync("abc", CancellationToken.None);
|
|
|
|
result.Should().Be(exists);
|
|
}
|
|
|
|
[Fact]
|
|
public async Task ResetPassword_NoMatchingCode_ReturnsFalseWithoutReset()
|
|
{
|
|
var forget = new Mock<IForgetPasswordDataService>();
|
|
forget.Setup(f => f.ExistsByEmailAndCodeAsync(It.IsAny<string>(), It.IsAny<string>(), It.IsAny<CancellationToken>())).ReturnsAsync(false);
|
|
|
|
var service = NewService(new Mock<IUserDataService>(), forget, new Mock<IEmailSender>(), out var store, out _);
|
|
|
|
var result = await service.ResetPasswordAsync("a@b.com", "999", "new", CancellationToken.None);
|
|
|
|
result.Should().BeFalse();
|
|
store.Verify(s => s.FindByIdAsync(It.IsAny<string>(), It.IsAny<CancellationToken>()), Times.Never);
|
|
forget.Verify(f => f.RemoveByEmailAsync(It.IsAny<string>(), It.IsAny<CancellationToken>()), Times.Never);
|
|
}
|
|
}
|