Test: guard site subscriptions index back param no nesting

This commit is contained in:
萝卜
2026-03-13 18:09:06 +00:00
parent f6c11660ea
commit f9db5ecf46

View File

@@ -0,0 +1,90 @@
<?php
namespace Tests\Feature;
use App\Models\Merchant;
use App\Models\Plan;
use App\Models\PlatformOrder;
use App\Models\SiteSubscription;
use Illuminate\Foundation\Testing\RefreshDatabase;
use Tests\TestCase;
class AdminSiteSubscriptionIndexBackParamDoesNotNestTest extends TestCase
{
use RefreshDatabase;
protected function loginAsPlatformAdmin(): void
{
$this->seed();
$this->post('/admin/login', [
'email' => 'platform.admin@demo.local',
'password' => 'Platform@123456',
])->assertRedirect('/admin');
}
public function test_subscription_index_back_param_should_not_nest_back(): void
{
$this->loginAsPlatformAdmin();
$merchant = Merchant::query()->firstOrFail();
$plan = Plan::query()->create([
'code' => 'sub_index_back_no_nest_plan',
'name' => '订阅列表 back 防嵌套测试套餐',
'billing_cycle' => 'monthly',
'price' => 10,
'list_price' => 10,
'status' => 'active',
'sort' => 10,
'published_at' => now(),
]);
$sub = SiteSubscription::query()->create([
'merchant_id' => $merchant->id,
'plan_id' => $plan->id,
'status' => 'activated',
'source' => 'manual',
'subscription_no' => 'SUB_INDEX_BACK_NO_NEST_0001',
'plan_name' => $plan->name,
'billing_cycle' => $plan->billing_cycle,
'period_months' => 1,
'amount' => 10,
'starts_at' => now()->subDay(),
'ends_at' => now()->addMonth(),
'activated_at' => now()->subDay(),
]);
PlatformOrder::query()->create([
'merchant_id' => $merchant->id,
'plan_id' => $plan->id,
'site_subscription_id' => $sub->id,
'order_no' => 'PO_SUB_INDEX_BACK_NO_NEST_0001',
'order_type' => 'renewal',
'status' => 'activated',
'payment_status' => 'paid',
'plan_name' => $plan->name,
'billing_cycle' => $plan->billing_cycle,
'period_months' => 1,
'quantity' => 1,
'payable_amount' => 10,
'paid_amount' => 10,
'placed_at' => now(),
'paid_at' => now(),
'activated_at' => now(),
]);
$incomingBack = '/admin/platform-orders?status=pending';
$res = $this->get('/admin/site-subscriptions?status=activated&back=' . urlencode($incomingBack));
$res->assertOk();
// 期望:订阅列表页生成的 back 只应指向“当前列表(去掉 back 参数)”,不应无限嵌套 back
$expectedBack = urlencode('/admin/site-subscriptions?status=activated');
$res->assertSee('/admin/site-subscriptions/' . $sub->id . '?back=' . $expectedBack, false);
$res->assertSee('/admin/platform-orders?site_subscription_id=' . $sub->id . '&back=' . $expectedBack, false);
// 若发生 back 嵌套,通常会出现 back=...back%3D... 这样的结构
$res->assertDontSee('back%3D', false);
}
}