Add gardens CRUD + service-layer conventions (#7)
Establishes the patterns every later backend issue copies: the actor parameter, centralized role checks, and the version-guard/409 sync protocol. The service layer is the seam both REST handlers and future agent tools call, so permissions live here, not in handlers. - service/gardens.go: Service methods take (ctx, actorID, args). requireGardenRole(ctx, actor, gardenID, min) is THE authorization point — owner is implicit via owner_id now; #16 extends it to consult garden_shares. A user with no role gets ErrNotFound (existence masked), not ErrForbidden. Create/Get/List/Update/Delete with input validation (name required, 0 dims default to 10 m on create / rejected on update, negatives always rejected, unit metric|imperial, 100 m cap). - store/gardens.go: version-guarded UPDATE ... WHERE id=? AND version=? RETURNING; a no-match re-reads to return (current row, ErrVersionConflict) vs ErrNotFound. ListGardensForOwner returns a non-nil slice. - api/gardens.go: GET,POST /gardens and GET,PATCH,DELETE /gardens/:id behind requireAuth. writeVersionConflict documents the 409 envelope ({error:{code,message}, current:{...}}) — the contract for every mutable resource. writeResourceError maps ErrNotFound/Forbidden/ InvalidInput/VersionConflict; parseIDParam guards path ids. Tests: service (defaults, validation, owned-only list, version conflict returns current + retry, cross-user ErrNotFound, delete) and api (full CRUD flow, 409 envelope shape, cross-user 404, auth required, create validation). Verified against the running binary: create stores imperial 122x244 cm and list returns it. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01JdQpdYYsTgtkJBxbcpAszi
This commit is contained in:
@@ -0,0 +1,167 @@
|
||||
package api
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
"strconv"
|
||||
"testing"
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
// registerAndCookie creates a user via the API and returns its session cookie.
|
||||
func registerAndCookie(t *testing.T, r *gin.Engine, email string) *http.Cookie {
|
||||
t.Helper()
|
||||
w := doJSON(t, r, http.MethodPost, "/api/v1/auth/register",
|
||||
map[string]string{"email": email, "displayName": email, "password": "password123"}, nil)
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("register %s: status %d, body %s", email, w.Code, w.Body.String())
|
||||
}
|
||||
return sessionCookieFrom(t, w)
|
||||
}
|
||||
|
||||
func decodeGarden(t *testing.T, body []byte) map[string]any {
|
||||
t.Helper()
|
||||
var g map[string]any
|
||||
if err := json.Unmarshal(body, &g); err != nil {
|
||||
t.Fatalf("decode garden: %v (body %s)", err, body)
|
||||
}
|
||||
return g
|
||||
}
|
||||
|
||||
func TestGardenCRUDFlow(t *testing.T) {
|
||||
r := authEngine(t, localCfg())
|
||||
cookie := registerAndCookie(t, r, "[email protected]")
|
||||
|
||||
// Create (defaults applied) → 201.
|
||||
w := doJSON(t, r, http.MethodPost, "/api/v1/gardens", map[string]any{"name": "Backyard"}, cookie)
|
||||
if w.Code != http.StatusCreated {
|
||||
t.Fatalf("create status = %d, body %s", w.Code, w.Body.String())
|
||||
}
|
||||
created := decodeGarden(t, w.Body.Bytes())
|
||||
id := int64(created["id"].(float64))
|
||||
if created["widthCm"].(float64) != 1000 || created["unitPref"].(string) != "metric" {
|
||||
t.Errorf("defaults not applied: %+v", created)
|
||||
}
|
||||
|
||||
// List → array with one garden.
|
||||
w = doJSON(t, r, http.MethodGet, "/api/v1/gardens", nil, cookie)
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("list status = %d", w.Code)
|
||||
}
|
||||
var list []map[string]any
|
||||
if err := json.Unmarshal(w.Body.Bytes(), &list); err != nil {
|
||||
t.Fatalf("decode list: %v (body %s)", err, w.Body.String())
|
||||
}
|
||||
if len(list) != 1 {
|
||||
t.Errorf("list len = %d, want 1", len(list))
|
||||
}
|
||||
|
||||
// Get → 200.
|
||||
w = doJSON(t, r, http.MethodGet, gardenPath(id), nil, cookie)
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("get status = %d", w.Code)
|
||||
}
|
||||
|
||||
// Patch with the current version → 200, version bumped.
|
||||
w = doJSON(t, r, http.MethodPatch, gardenPath(id),
|
||||
map[string]any{"name": "Front", "widthCm": 200, "heightCm": 400, "unitPref": "imperial", "version": 1}, cookie)
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("patch status = %d, body %s", w.Code, w.Body.String())
|
||||
}
|
||||
patched := decodeGarden(t, w.Body.Bytes())
|
||||
if patched["name"].(string) != "Front" || patched["version"].(float64) != 2 {
|
||||
t.Errorf("patch didn't persist/bump: %+v", patched)
|
||||
}
|
||||
|
||||
// Delete → 204, then get → 404.
|
||||
w = doJSON(t, r, http.MethodDelete, gardenPath(id), nil, cookie)
|
||||
if w.Code != http.StatusNoContent {
|
||||
t.Fatalf("delete status = %d", w.Code)
|
||||
}
|
||||
w = doJSON(t, r, http.MethodGet, gardenPath(id), nil, cookie)
|
||||
if w.Code != http.StatusNotFound {
|
||||
t.Errorf("get after delete = %d, want 404", w.Code)
|
||||
}
|
||||
}
|
||||
|
||||
func TestGardenVersionConflictEnvelope(t *testing.T) {
|
||||
r := authEngine(t, localCfg())
|
||||
cookie := registerAndCookie(t, r, "[email protected]")
|
||||
|
||||
w := doJSON(t, r, http.MethodPost, "/api/v1/gardens", map[string]any{"name": "Yard"}, cookie)
|
||||
id := int64(decodeGarden(t, w.Body.Bytes())["id"].(float64))
|
||||
|
||||
body := map[string]any{"name": "Yard2", "widthCm": 1000, "heightCm": 1000, "unitPref": "metric", "version": 1}
|
||||
// First patch at version 1 succeeds (→ version 2).
|
||||
if w := doJSON(t, r, http.MethodPatch, gardenPath(id), body, cookie); w.Code != http.StatusOK {
|
||||
t.Fatalf("first patch status = %d", w.Code)
|
||||
}
|
||||
// Second patch still at version 1 conflicts.
|
||||
w = doJSON(t, r, http.MethodPatch, gardenPath(id), body, cookie)
|
||||
if w.Code != http.StatusConflict {
|
||||
t.Fatalf("stale patch status = %d, want 409", w.Code)
|
||||
}
|
||||
var env struct {
|
||||
Error struct{ Code string } `json:"error"`
|
||||
Current map[string]any `json:"current"`
|
||||
}
|
||||
if err := json.Unmarshal(w.Body.Bytes(), &env); err != nil {
|
||||
t.Fatalf("decode conflict envelope: %v (body %s)", err, w.Body.String())
|
||||
}
|
||||
if env.Error.Code != "VERSION_CONFLICT" {
|
||||
t.Errorf("error code = %q, want VERSION_CONFLICT", env.Error.Code)
|
||||
}
|
||||
if env.Current == nil || env.Current["version"].(float64) != 2 {
|
||||
t.Errorf("conflict body missing current row at version 2: %+v", env.Current)
|
||||
}
|
||||
}
|
||||
|
||||
func TestGardenCrossUserIsNotFound(t *testing.T) {
|
||||
r := authEngine(t, localCfg())
|
||||
alice := registerAndCookie(t, r, "[email protected]")
|
||||
bob := registerAndCookie(t, r, "[email protected]")
|
||||
|
||||
w := doJSON(t, r, http.MethodPost, "/api/v1/gardens", map[string]any{"name": "Alice's"}, alice)
|
||||
id := int64(decodeGarden(t, w.Body.Bytes())["id"].(float64))
|
||||
|
||||
// Bob sees a 404 (existence masked), not a 403.
|
||||
if w := doJSON(t, r, http.MethodGet, gardenPath(id), nil, bob); w.Code != http.StatusNotFound {
|
||||
t.Errorf("bob get = %d, want 404", w.Code)
|
||||
}
|
||||
if w := doJSON(t, r, http.MethodDelete, gardenPath(id), nil, bob); w.Code != http.StatusNotFound {
|
||||
t.Errorf("bob delete = %d, want 404", w.Code)
|
||||
}
|
||||
// Bob's own list is empty.
|
||||
w = doJSON(t, r, http.MethodGet, "/api/v1/gardens", nil, bob)
|
||||
if w.Body.String() != "[]" {
|
||||
t.Errorf("bob list = %s, want []", w.Body.String())
|
||||
}
|
||||
}
|
||||
|
||||
func TestGardenRequiresAuth(t *testing.T) {
|
||||
r := authEngine(t, localCfg())
|
||||
if w := doJSON(t, r, http.MethodGet, "/api/v1/gardens", nil, nil); w.Code != http.StatusUnauthorized {
|
||||
t.Errorf("unauthenticated list = %d, want 401", w.Code)
|
||||
}
|
||||
if w := doJSON(t, r, http.MethodPost, "/api/v1/gardens", map[string]any{"name": "X"}, nil); w.Code != http.StatusUnauthorized {
|
||||
t.Errorf("unauthenticated create = %d, want 401", w.Code)
|
||||
}
|
||||
}
|
||||
|
||||
func TestGardenCreateValidation(t *testing.T) {
|
||||
r := authEngine(t, localCfg())
|
||||
cookie := registerAndCookie(t, r, "[email protected]")
|
||||
// Missing name → 400.
|
||||
if w := doJSON(t, r, http.MethodPost, "/api/v1/gardens", map[string]any{"widthCm": 100}, cookie); w.Code != http.StatusBadRequest {
|
||||
t.Errorf("no-name create = %d, want 400", w.Code)
|
||||
}
|
||||
// Bad id path → 400.
|
||||
if w := doJSON(t, r, http.MethodGet, "/api/v1/gardens/not-a-number", nil, cookie); w.Code != http.StatusBadRequest {
|
||||
t.Errorf("bad id get = %d, want 400", w.Code)
|
||||
}
|
||||
}
|
||||
|
||||
func gardenPath(id int64) string {
|
||||
return "/api/v1/gardens/" + strconv.FormatInt(id, 10)
|
||||
}
|
||||
Reference in New Issue
Block a user