The showcase was a Barcelona market: Catalan names, +34 numbers, euro rates and "Carrer Example 12" on every job. Presented to a Mexican client, all of that reads as somebody else's product. City comes from NEXT_PUBLIC_CITY_* as before, now Ciudad de México at 19.4326/-99.1332, with MAPBOX_COUNTRY=mx. The seed's fallbacks were Barcelona literals, so an unset env quietly seeded a different city than the app rendered — they now agree. Two db tests pinned the Barcelona centre as a hardcoded constant, which is why the deck returned zero cards on the first run here: every pro was a continent outside the radius. They read the same env as the seed now, so the trap cannot recur. Money: formatCents defaults to USD/en-US, and the nine hardcoded euro signs across the card, search rows, quote strip and forms are dollars. The rate NUMBERS are unchanged and still read high for CDMX — that is a pricing decision, not a currency one, and is left alone deliberately. Seed people are Mexican, addressed on real Roma/Condesa streets rotated by index rather than one placeholder repeated. Phones moved to +52 55, which moves the demo login to +525500000000 / 000000. Also in here, from the same session: - Sending a job now confirms. The mutation always succeeded; the sheet just closed with no receipt, which from the customer's side is indistinguishable from a dead button. Dismissing that receipt resolves as 'sent', so the card does not return to the deck. - Media moves to DigitalOcean Spaces, with the public origin derived from bucket and region instead of a second env var to keep in sync. - Managed-Postgres TLS: DATABASE_CA_CERT takes a path or inline PEM. - The client-facing project panel beside the running app. - Two profiles removed and four renamed to match their photos. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
174 lines
6.3 KiB
TypeScript
174 lines
6.3 KiB
TypeScript
/**
|
|
* Integration tests for the search surface, against the live seeded database.
|
|
*
|
|
* pnpm services:up && pnpm db:migrate && pnpm db:seed
|
|
*
|
|
* `pro.search` is the first procedure in this API that takes an unbounded string
|
|
* from a caller with no session, and `pro.publicProfile` is now the same. Most
|
|
* of what follows is about those two facts: the caps hold, and neither one is a
|
|
* way to read a pro who is not on the deck.
|
|
*/
|
|
import { config } from 'dotenv';
|
|
import { sql } from 'drizzle-orm';
|
|
import { afterAll, beforeAll, describe, expect, it } from 'vitest';
|
|
|
|
config({ path: '../../.env' });
|
|
|
|
const { closePool, db } = await import('@linkdr/db');
|
|
const { appRouter } = await import('../src/root');
|
|
const { createInnerContext } = await import('../src/context');
|
|
const { createCallerFactory } = await import('../src/trpc');
|
|
|
|
const createCaller = createCallerFactory(appRouter);
|
|
type Session = import('../src/context').Session;
|
|
|
|
function callerFor(session: Session | null) {
|
|
return createCaller(createInnerContext({ db, session }));
|
|
}
|
|
|
|
const clientSession = (userId: string): Session => ({
|
|
userId,
|
|
role: 'client',
|
|
name: 'Test Client',
|
|
email: 'client@test',
|
|
phone: null,
|
|
verificationStatus: null,
|
|
});
|
|
|
|
const RUN = Math.random().toString(36).slice(2, 8);
|
|
|
|
let client: string;
|
|
let verifiedPro: string;
|
|
let awayPro: string;
|
|
|
|
/**
|
|
* This file's own pro, parked far from the city with no trades.
|
|
*
|
|
* Test files run in parallel against one database: banning a seeded pro to prove
|
|
* a point would delete a card out from under deck.router.test.ts mid-run.
|
|
*/
|
|
let bannedPro: string;
|
|
|
|
beforeAll(async () => {
|
|
const [aClient] = await db.execute<{ id: string }>(
|
|
// A SEEDED client, not "the first client". Test files share one database
|
|
// and several insert their own client probes, so a bare role filter picks
|
|
// whichever uuid sorts first — which another file may delete in its
|
|
// afterAll, mid-run. Seeded accounts are on @linkder.test and are stable.
|
|
sql`SELECT id FROM users
|
|
WHERE role = 'client' AND email LIKE '%@linkder.test'
|
|
ORDER BY id LIMIT 1`,
|
|
);
|
|
client = aClient!.id;
|
|
|
|
const [marc] = await db.execute<{ id: string }>(
|
|
sql`SELECT id FROM users WHERE name = 'Sergio Fabela' LIMIT 1`,
|
|
);
|
|
verifiedPro = marc!.id;
|
|
|
|
const [arnau] = await db.execute<{ id: string }>(
|
|
sql`SELECT id FROM users WHERE name = 'Away Arturo' LIMIT 1`,
|
|
);
|
|
awayPro = arnau!.id;
|
|
|
|
const [created] = await db.execute<{ id: string }>(sql`
|
|
INSERT INTO users (name, email, role, banned)
|
|
VALUES ('Search Probe', ${`search-probe-${RUN}@example.com`}, 'pro', true)
|
|
RETURNING id
|
|
`);
|
|
bannedPro = created!.id;
|
|
await db.execute(sql`
|
|
INSERT INTO pro_profiles (
|
|
user_id, headline, bio, hourly_rate_cents, base_location, service_radius_m,
|
|
verification_status, verified_at
|
|
)
|
|
VALUES (
|
|
${bannedPro}, 'Search probe', 'Exists only for the search router tests.', 3000,
|
|
ST_SetSRID(ST_MakePoint(0.5, 0.5), 4326)::geography, 15000, 'verified', now()
|
|
)
|
|
`);
|
|
});
|
|
|
|
afterAll(async () => {
|
|
await db.execute(sql`DELETE FROM users WHERE id = ${bannedPro}`);
|
|
await db.execute(
|
|
sql`UPDATE users SET location = NULL, search_radius_m = 15000 WHERE id = ${client}`,
|
|
);
|
|
await closePool();
|
|
});
|
|
|
|
describe('pro.search', () => {
|
|
it('is reachable without a session — a shop window behind a login is not one', async () => {
|
|
const result = await callerFor(null).pro.search({ sort: 'best' });
|
|
expect(result.results.length).toBeGreaterThan(0);
|
|
expect(result.centredOnYou).toBe(false);
|
|
});
|
|
|
|
it('reports its own total', async () => {
|
|
const result = await callerFor(null).pro.search({ q: 'plumber', sort: 'best' });
|
|
expect(result.total).toBe(result.results.length);
|
|
});
|
|
|
|
it('rejects an over-long query and an over-large page', async () => {
|
|
const caller = callerFor(null);
|
|
await expect(caller.pro.search({ q: 'x'.repeat(81), sort: 'best' })).rejects.toThrow();
|
|
await expect(caller.pro.search({ limit: 500, sort: 'best' })).rejects.toThrow();
|
|
await expect(caller.pro.search({ maxDistanceM: 5_000_000, sort: 'best' })).rejects.toThrow();
|
|
});
|
|
|
|
it('never returns an unverified, away or banned pro', async () => {
|
|
const { results } = await callerFor(null).pro.search({ limit: 50, sort: 'best' });
|
|
const ids = results.map((p) => p.proId);
|
|
const names = results.map((p) => p.name);
|
|
|
|
expect(names).not.toContain('Unverified Ulises');
|
|
expect(ids).not.toContain(awayPro);
|
|
expect(ids).not.toContain(bannedPro);
|
|
});
|
|
|
|
it('centres on the caller when they have saved a location', async () => {
|
|
// Put this client 20 km north of the centre and give them a tight radius:
|
|
// the pros next to the city centre must fall out of range.
|
|
await db.execute(sql`
|
|
UPDATE users
|
|
SET location = ST_SetSRID(ST_MakePoint(-99.1332, 19.6126), 4326)::geography,
|
|
search_radius_m = 2000
|
|
WHERE id = ${client}
|
|
`);
|
|
|
|
const mine = await callerFor(clientSession(client)).pro.search({ sort: 'best' });
|
|
expect(mine.centredOnYou).toBe(true);
|
|
expect(mine.results.map((p) => p.proId)).not.toContain(verifiedPro);
|
|
|
|
// An explicit filter still wins over the saved radius.
|
|
const wide = await callerFor(clientSession(client)).pro.search({
|
|
maxDistanceM: 50_000,
|
|
sort: 'best',
|
|
});
|
|
expect(wide.results.length).toBeGreaterThan(mine.results.length);
|
|
});
|
|
});
|
|
|
|
describe('pro.publicProfile', () => {
|
|
it('is readable without a session', async () => {
|
|
const profile = await callerFor(null).pro.publicProfile({ proId: verifiedPro });
|
|
expect(profile.proId).toBe(verifiedPro);
|
|
// Search needs these two; the old shape returned neither.
|
|
expect(Array.isArray(profile.categories)).toBe(true);
|
|
expect(Array.isArray(profile.skills)).toBe(true);
|
|
});
|
|
|
|
it('refuses a banned pro and a pro on holiday', async () => {
|
|
// A direct link used to be the one way to read a suspended pro.
|
|
await expect(callerFor(null).pro.publicProfile({ proId: bannedPro })).rejects.toThrow();
|
|
await expect(callerFor(null).pro.publicProfile({ proId: awayPro })).rejects.toThrow();
|
|
});
|
|
|
|
it('refuses a pro who was never verified', async () => {
|
|
const [ulla] = await db.execute<{ id: string }>(
|
|
sql`SELECT id FROM users WHERE name = 'Unverified Ulises' LIMIT 1`,
|
|
);
|
|
await expect(callerFor(null).pro.publicProfile({ proId: ulla!.id })).rejects.toThrow();
|
|
});
|
|
});
|