mirror of
https://github.com/mauriceboe/TREK.git
synced 2026-06-19 13:21:46 +00:00
3c040fab11
* fix(share): serve place thumbnails in shared trip links (#1100) Google-sourced place photos are stored as image_url pointing at the JWT-guarded /api/maps/place-photo/:placeId/bytes endpoint, so they 401 for an unauthenticated shared-trip viewer and render as broken images. Rewrite place image_url values in the shared payload to a public, token-scoped proxy (/api/shared/:token/place-photo/:placeId/bytes) and add an unguarded SharedController route that validates the token and that the place belongs to its trip before streaming the cached bytes. Mirrors the existing JourneyPublicController precedent. No client changes needed. * fix(atlas): replace Natural Earth with geoBoundaries for up-to-date regions (#1119) Atlas sourced country and sub-national boundaries from Natural Earth's GitHub `master` at runtime. That data is stale (e.g. it still shows Norway's pre-2020 counties such as Oppland/Hordaland) and depicts some contested territory in unwanted ways (nvkelso/natural-earth-vector#391), so Natural Earth is dropped entirely. - Country borders (admin0) now come from the geoBoundaries CGAZ composite; sub-national regions (admin1) from per-country gbOpen, which carries ISO 3166-2 codes. A new script (server/scripts/build-atlas-geo.mjs) normalizes and quantizes them into committed gzipped bundles under server/assets/atlas, read server-side at runtime (no network at boot, no GitHub CSP allowlist entry). - New GET /addons/atlas/countries/geo serves the country layer; the client fetches it from the API instead of GitHub. - A migration reconciles manually-marked visited_regions against the new bundle (valid code -> keep; region name still matches -> re-code; curated merge crosswalk for renamed reforms; else leave intact), with UNIQUE-safe dedup. bucket_list and visited_countries hold only invariant alpha-2 country codes, so they are untouched. - Attribution added (NOTICE.md + README) per geoBoundaries CC BY 4.0. Closes #1119 * fix(packing): make templates admin-only to create, usable by members Creating a packing-list template was gated only by trip access, so any trip member could create one from the Lists feature, while applying a template silently failed for non-admins because the apply dropdown was populated from the AdminGuard-protected /api/admin/packing-templates endpoint. - save-as-template now returns 403 for non-admins; the Save-as-Template button is hidden unless the user is an admin (both the TripPlanner toolbar and the inline packing header). - add member-accessible GET /api/trips/:tripId/packing/templates so the apply dropdown lists templates for any trip member; client fetches from it instead of the admin endpoint. Closes #1120 Closes #1121 * fix(packing): show bag tracking to non-admin members The global Bag Tracking toggle was only readable via the admin-gated GET /api/admin/bag-tracking, so non-admin trip members got 403 and the weight fields, bag circles, and BAGS sidebar never rendered (#1124). Surface the flag through the already-authenticated GET /api/addons (loaded into the client addon store on app start for every user); the packing hook reads it from the store instead of the admin endpoint. The admin write path stays admin-gated and unchanged.
527 lines
22 KiB
TypeScript
527 lines
22 KiB
TypeScript
/**
|
|
* Packing List integration tests.
|
|
* Covers PACK-001 to PACK-014.
|
|
*/
|
|
import { describe, it, expect, vi, beforeAll, beforeEach, afterAll } from 'vitest';
|
|
import request from 'supertest';
|
|
import type { Application } from 'express';
|
|
import type { INestApplication } from '@nestjs/common';
|
|
|
|
const { testDb, dbMock } = vi.hoisted(() => {
|
|
const Database = require('better-sqlite3');
|
|
const db = new Database(':memory:');
|
|
db.exec('PRAGMA journal_mode = WAL');
|
|
db.exec('PRAGMA foreign_keys = ON');
|
|
db.exec('PRAGMA busy_timeout = 5000');
|
|
const mock = {
|
|
db,
|
|
closeDb: () => {},
|
|
reinitialize: () => {},
|
|
getPlaceWithTags: (placeId: number) => {
|
|
const place: any = db.prepare(`SELECT p.*, c.name as category_name, c.color as category_color, c.icon as category_icon FROM places p LEFT JOIN categories c ON p.category_id = c.id WHERE p.id = ?`).get(placeId);
|
|
if (!place) return null;
|
|
const tags = db.prepare(`SELECT t.* FROM tags t JOIN place_tags pt ON t.id = pt.tag_id WHERE pt.place_id = ?`).all(placeId);
|
|
return { ...place, category: place.category_id ? { id: place.category_id, name: place.category_name, color: place.category_color, icon: place.category_icon } : null, tags };
|
|
},
|
|
canAccessTrip: (tripId: any, userId: number) =>
|
|
db.prepare(`SELECT t.id, t.user_id FROM trips t LEFT JOIN trip_members m ON m.trip_id = t.id AND m.user_id = ? WHERE t.id = ? AND (t.user_id = ? OR m.user_id IS NOT NULL)`).get(userId, tripId, userId),
|
|
isOwner: (tripId: any, userId: number) =>
|
|
!!db.prepare('SELECT id FROM trips WHERE id = ? AND user_id = ?').get(tripId, userId),
|
|
};
|
|
return { testDb: db, dbMock: mock };
|
|
});
|
|
|
|
vi.mock('../../src/db/database', () => dbMock);
|
|
vi.mock('../../src/config', () => ({
|
|
JWT_SECRET: 'test-jwt-secret-for-trek-testing-only',
|
|
ENCRYPTION_KEY: 'a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6a7b8c9d0e1f2a3b4c5d6a7b8c9d0e1f2',
|
|
updateJwtSecret: () => {},
|
|
SESSION_DURATION: '24h',
|
|
SESSION_DURATION_MS: 86400000,
|
|
SESSION_DURATION_SECONDS: 86400,
|
|
DEFAULT_LANGUAGE: 'en',
|
|
}));
|
|
vi.mock('../../src/websocket', () => ({ broadcast: vi.fn(), broadcastToUser: vi.fn() }));
|
|
|
|
import { buildApp } from '../../src/bootstrap';
|
|
import { createTables } from '../../src/db/schema';
|
|
import { runMigrations } from '../../src/db/migrations';
|
|
import { resetTestDb, resetRateLimits } from '../helpers/test-db';
|
|
import { createUser, createTrip, createPackingItem, addTripMember } from '../helpers/factories';
|
|
import { authCookie } from '../helpers/auth';
|
|
|
|
let nestApp: INestApplication;
|
|
let app: Application;
|
|
|
|
beforeAll(async () => {
|
|
createTables(testDb);
|
|
runMigrations(testDb);
|
|
nestApp = await buildApp();
|
|
app = nestApp.getHttpAdapter().getInstance();
|
|
});
|
|
|
|
beforeEach(() => {
|
|
resetTestDb(testDb);
|
|
resetRateLimits(nestApp);
|
|
});
|
|
|
|
afterAll(async () => {
|
|
await nestApp.close();
|
|
testDb.close();
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// Create packing item
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('Create packing item', () => {
|
|
it('PACK-001 — POST creates a packing item', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
|
|
const res = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ name: 'Passport', category: 'Documents' });
|
|
expect(res.status).toBe(201);
|
|
expect(res.body.item.name).toBe('Passport');
|
|
expect(res.body.item.category).toBe('Documents');
|
|
expect(res.body.item.checked).toBe(0);
|
|
});
|
|
|
|
it('PACK-001 — POST without name returns 400', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
|
|
const res = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ category: 'Clothing' });
|
|
expect(res.status).toBe(400);
|
|
});
|
|
|
|
it('PACK-014 — non-member cannot create packing item', async () => {
|
|
const { user: owner } = createUser(testDb);
|
|
const { user: other } = createUser(testDb);
|
|
const trip = createTrip(testDb, owner.id);
|
|
|
|
const res = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing`)
|
|
.set('Cookie', authCookie(other.id))
|
|
.send({ name: 'Sunscreen' });
|
|
expect(res.status).toBe(404);
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// List packing items
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('List packing items', () => {
|
|
it('PACK-002 — GET /api/trips/:tripId/packing returns all items', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
createPackingItem(testDb, trip.id, { name: 'Toothbrush', category: 'Toiletries' });
|
|
createPackingItem(testDb, trip.id, { name: 'Shirt', category: 'Clothing' });
|
|
|
|
const res = await request(app)
|
|
.get(`/api/trips/${trip.id}/packing`)
|
|
.set('Cookie', authCookie(user.id));
|
|
expect(res.status).toBe(200);
|
|
expect(res.body.items).toHaveLength(2);
|
|
});
|
|
|
|
it('PACK-002 — member can list packing items', async () => {
|
|
const { user: owner } = createUser(testDb);
|
|
const { user: member } = createUser(testDb);
|
|
const trip = createTrip(testDb, owner.id);
|
|
addTripMember(testDb, trip.id, member.id);
|
|
createPackingItem(testDb, trip.id, { name: 'Jacket' });
|
|
|
|
const res = await request(app)
|
|
.get(`/api/trips/${trip.id}/packing`)
|
|
.set('Cookie', authCookie(member.id));
|
|
expect(res.status).toBe(200);
|
|
expect(res.body.items).toHaveLength(1);
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// Update packing item
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('Update packing item', () => {
|
|
it('PACK-003 — PUT updates packing item (toggle checked)', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
const item = createPackingItem(testDb, trip.id, { name: 'Camera' });
|
|
|
|
const res = await request(app)
|
|
.put(`/api/trips/${trip.id}/packing/${item.id}`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ checked: true });
|
|
expect(res.status).toBe(200);
|
|
expect(res.body.item.checked).toBe(1);
|
|
});
|
|
|
|
it('PACK-003 — PUT returns 404 for non-existent item', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
|
|
const res = await request(app)
|
|
.put(`/api/trips/${trip.id}/packing/99999`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ name: 'Updated' });
|
|
expect(res.status).toBe(404);
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// Delete packing item
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('Delete packing item', () => {
|
|
it('PACK-004 — DELETE removes packing item', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
const item = createPackingItem(testDb, trip.id, { name: 'Sunglasses' });
|
|
|
|
const del = await request(app)
|
|
.delete(`/api/trips/${trip.id}/packing/${item.id}`)
|
|
.set('Cookie', authCookie(user.id));
|
|
expect(del.status).toBe(200);
|
|
expect(del.body.success).toBe(true);
|
|
|
|
const list = await request(app)
|
|
.get(`/api/trips/${trip.id}/packing`)
|
|
.set('Cookie', authCookie(user.id));
|
|
expect(list.body.items).toHaveLength(0);
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// Bulk import
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('Bulk import packing items', () => {
|
|
it('PACK-005 — POST /import creates multiple items at once', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
|
|
const res = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/import`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({
|
|
items: [
|
|
{ name: 'Toothbrush', category: 'Toiletries' },
|
|
{ name: 'Shampoo', category: 'Toiletries' },
|
|
{ name: 'Socks', category: 'Clothing' },
|
|
],
|
|
});
|
|
expect(res.status).toBe(201);
|
|
expect(res.body.items).toHaveLength(3);
|
|
expect(res.body.count).toBe(3);
|
|
});
|
|
|
|
it('PACK-005 — POST /import with empty array returns 400', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
|
|
const res = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/import`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ items: [] });
|
|
expect(res.status).toBe(400);
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// Reorder
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('Reorder packing items', () => {
|
|
it('PACK-006 — PUT /reorder reorders items', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
const i1 = createPackingItem(testDb, trip.id, { name: 'Item A' });
|
|
const i2 = createPackingItem(testDb, trip.id, { name: 'Item B' });
|
|
|
|
const res = await request(app)
|
|
.put(`/api/trips/${trip.id}/packing/reorder`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ orderedIds: [i2.id, i1.id] });
|
|
expect(res.status).toBe(200);
|
|
expect(res.body.success).toBe(true);
|
|
|
|
const rows = testDb
|
|
.prepare('SELECT id, sort_order FROM packing_items WHERE trip_id = ? ORDER BY sort_order')
|
|
.all(trip.id) as Array<{ id: number; sort_order: number }>;
|
|
expect(rows[0].id).toBe(i2.id);
|
|
expect(rows[1].id).toBe(i1.id);
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// Bags
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('Bags', () => {
|
|
it('PACK-008 — POST /bags creates a bag', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
|
|
const res = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/bags`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ name: 'Carry-on', color: '#3b82f6' });
|
|
expect(res.status).toBe(201);
|
|
expect(res.body.bag.name).toBe('Carry-on');
|
|
});
|
|
|
|
it('PACK-008 — POST /bags without name returns 400', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
|
|
const res = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/bags`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ color: '#ff0000' });
|
|
expect(res.status).toBe(400);
|
|
});
|
|
|
|
it('PACK-011 — GET /bags returns bags list', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
// Create a bag
|
|
await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/bags`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ name: 'Main Bag' });
|
|
|
|
const res = await request(app)
|
|
.get(`/api/trips/${trip.id}/packing/bags`)
|
|
.set('Cookie', authCookie(user.id));
|
|
expect(res.status).toBe(200);
|
|
expect(res.body.bags).toHaveLength(1);
|
|
});
|
|
|
|
it('PACK-009 — PUT /bags/:bagId updates bag', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
const createRes = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/bags`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ name: 'Old Name' });
|
|
const bagId = createRes.body.bag.id;
|
|
|
|
const res = await request(app)
|
|
.put(`/api/trips/${trip.id}/packing/bags/${bagId}`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ name: 'New Name' });
|
|
expect(res.status).toBe(200);
|
|
expect(res.body.bag.name).toBe('New Name');
|
|
});
|
|
|
|
it('PACK-010 — DELETE /bags/:bagId removes bag', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
const createRes = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/bags`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ name: 'Temp Bag' });
|
|
const bagId = createRes.body.bag.id;
|
|
|
|
const del = await request(app)
|
|
.delete(`/api/trips/${trip.id}/packing/bags/${bagId}`)
|
|
.set('Cookie', authCookie(user.id));
|
|
expect(del.status).toBe(200);
|
|
expect(del.body.success).toBe(true);
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// Category assignees
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('Category assignees', () => {
|
|
it('PACK-012 — PUT /category-assignees/:category sets assignees', async () => {
|
|
const { user } = createUser(testDb);
|
|
const { user: member } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
addTripMember(testDb, trip.id, member.id);
|
|
|
|
const res = await request(app)
|
|
.put(`/api/trips/${trip.id}/packing/category-assignees/Clothing`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ user_ids: [user.id, member.id] });
|
|
expect(res.status).toBe(200);
|
|
expect(res.body.assignees).toBeDefined();
|
|
});
|
|
|
|
it('PACK-013 — GET /category-assignees returns all category assignments', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
// Set an assignee first
|
|
await request(app)
|
|
.put(`/api/trips/${trip.id}/packing/category-assignees/Electronics`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ user_ids: [user.id] });
|
|
|
|
const res = await request(app)
|
|
.get(`/api/trips/${trip.id}/packing/category-assignees`)
|
|
.set('Cookie', authCookie(user.id));
|
|
expect(res.status).toBe(200);
|
|
expect(res.body.assignees).toBeDefined();
|
|
});
|
|
});
|
|
|
|
describe('Packing — apply-template, bag members, save-as-template', () => {
|
|
it('PACK-015 — POST /apply-template/:templateId applies template items to trip', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
|
|
const tpl = testDb.prepare("INSERT INTO packing_templates (name, created_by) VALUES ('Beach', ?)").run(user.id);
|
|
const cat = testDb.prepare("INSERT INTO packing_template_categories (template_id, name, sort_order) VALUES (?, 'Essentials', 0)").run(tpl.lastInsertRowid);
|
|
testDb.prepare("INSERT INTO packing_template_items (category_id, name, sort_order) VALUES (?, 'Sunscreen', 0)").run(cat.lastInsertRowid);
|
|
const templateId = tpl.lastInsertRowid;
|
|
|
|
const res = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/apply-template/${templateId}`)
|
|
.set('Cookie', authCookie(user.id));
|
|
|
|
expect(res.status).toBe(200);
|
|
expect(Array.isArray(res.body.items)).toBe(true);
|
|
expect(res.body.items.length).toBeGreaterThan(0);
|
|
expect(res.body.count).toBeGreaterThan(0);
|
|
});
|
|
|
|
it('PACK-015b — POST /apply-template/:id for empty template returns 404', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
|
|
// Template with no items
|
|
const tpl = testDb.prepare("INSERT INTO packing_templates (name, created_by) VALUES ('Empty', ?)").run(user.id);
|
|
const emptyTemplateId = tpl.lastInsertRowid;
|
|
|
|
const res = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/apply-template/${emptyTemplateId}`)
|
|
.set('Cookie', authCookie(user.id));
|
|
|
|
expect(res.status).toBe(404);
|
|
expect(res.body.error).toBeDefined();
|
|
});
|
|
|
|
it('PACK-016 — PUT /bags/:bagId/members sets bag members', async () => {
|
|
const { user } = createUser(testDb);
|
|
const { user: member } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
addTripMember(testDb, trip.id, member.id);
|
|
|
|
// Create a bag first
|
|
const bagRes = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/bags`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ name: 'Carry-on' });
|
|
expect(bagRes.status).toBe(201);
|
|
const bagId = bagRes.body.bag.id;
|
|
|
|
const res = await request(app)
|
|
.put(`/api/trips/${trip.id}/packing/bags/${bagId}/members`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ user_ids: [user.id, member.id] });
|
|
|
|
expect(res.status).toBe(200);
|
|
expect(Array.isArray(res.body.members)).toBe(true);
|
|
expect(res.body.members.length).toBe(2);
|
|
});
|
|
|
|
it('PACK-016b — PUT /bags/:bagId/members for non-existent bag returns 404', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
|
|
const res = await request(app)
|
|
.put(`/api/trips/${trip.id}/packing/bags/999999/members`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ user_ids: [user.id] });
|
|
|
|
expect(res.status).toBe(404);
|
|
expect(res.body.error).toBeDefined();
|
|
});
|
|
|
|
it('PACK-017 — POST /save-as-template saves packing list as a template (admin)', async () => {
|
|
const { user } = createUser(testDb, { role: 'admin' });
|
|
const trip = createTrip(testDb, user.id);
|
|
|
|
// Add an item so the trip has something to save
|
|
createPackingItem(testDb, trip.id);
|
|
|
|
const res = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/save-as-template`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ name: 'My Summer Template' });
|
|
|
|
expect(res.status).toBe(201);
|
|
expect(res.body.template).toBeDefined();
|
|
expect(res.body.template.name).toBe('My Summer Template');
|
|
});
|
|
|
|
it('PACK-017b — POST /save-as-template without name returns 400 (admin)', async () => {
|
|
const { user } = createUser(testDb, { role: 'admin' });
|
|
const trip = createTrip(testDb, user.id);
|
|
|
|
const res = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/save-as-template`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({});
|
|
|
|
expect(res.status).toBe(400);
|
|
expect(res.body.error).toBeDefined();
|
|
});
|
|
|
|
it('PACK-017c — POST /save-as-template when trip has no items returns 400 (admin)', async () => {
|
|
const { user } = createUser(testDb, { role: 'admin' });
|
|
const trip = createTrip(testDb, user.id);
|
|
|
|
const res = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/save-as-template`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ name: 'Empty Trip Template' });
|
|
|
|
expect(res.status).toBe(400);
|
|
expect(res.body.error).toBeDefined();
|
|
});
|
|
|
|
it('PACK-017d — POST /save-as-template is forbidden for non-admins (403)', async () => {
|
|
const { user } = createUser(testDb);
|
|
const trip = createTrip(testDb, user.id);
|
|
createPackingItem(testDb, trip.id);
|
|
|
|
const res = await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/save-as-template`)
|
|
.set('Cookie', authCookie(user.id))
|
|
.send({ name: 'My Summer Template' });
|
|
|
|
expect(res.status).toBe(403);
|
|
expect(res.body.error).toBe('Admin access required');
|
|
});
|
|
|
|
it('PACK-017e — GET /packing/templates lists templates for a trip member', async () => {
|
|
const { user: admin } = createUser(testDb, { role: 'admin' });
|
|
const trip = createTrip(testDb, admin.id);
|
|
createPackingItem(testDb, trip.id);
|
|
await request(app)
|
|
.post(`/api/trips/${trip.id}/packing/save-as-template`)
|
|
.set('Cookie', authCookie(admin.id))
|
|
.send({ name: 'Shared Template' });
|
|
|
|
const res = await request(app)
|
|
.get(`/api/trips/${trip.id}/packing/templates`)
|
|
.set('Cookie', authCookie(admin.id));
|
|
|
|
expect(res.status).toBe(200);
|
|
expect(Array.isArray(res.body.templates)).toBe(true);
|
|
expect(res.body.templates.some((t: { name: string }) => t.name === 'Shared Template')).toBe(true);
|
|
expect(res.body.templates[0]).toHaveProperty('item_count');
|
|
});
|
|
});
|