fix: harden week-two ordering, artwork and operations

This commit is contained in:
Cauê Faleiros
2026-09-23 10:40:18 -03:00
parent ccc25a2d5d
commit 24013458c9
43 changed files with 1064 additions and 228 deletions

View File

@@ -12,7 +12,7 @@ from urllib.error import HTTPError
from urllib.request import Request, urlopen
from uuid import uuid4
from tests.smoke_test import BASE, Client, upload_bytes, with_host
from tests.smoke_test import BASE, Client, upload_bytes, item_spec, with_host
SECRET = os.environ.get('PAYMENT_WEBHOOK_SECRET', 'local-webhook-secret').encode()
@@ -37,7 +37,7 @@ def reviewed_quote():
customer = Client()
customer.call('/session')
uid = upload_bytes(customer, b'PAYMENT WEBHOOK TEST')
item = {'mode': 'file', 'metres': '1.01', 'grade': 0, 'uploads': [uid]}
item = item_spec('file', '1.01', 0, uid)
profile = {'cnpj': '11222333000181', 'zap': '11999999999',
'mail': 'payment-' + uuid4().hex[:8] + '@example.test'}
quote = customer.call('/quotes', {'request_key': str(uuid4()), 'customer': profile,
@@ -62,7 +62,13 @@ def run():
deliver({'event_id': 'short-' + uuid4().hex, 'reference': quote_id,
'status': 'approved', 'amount_cents': total - 100})
assert not customer.call('/quotes/' + quote_id)['order'], 'underpayment created an order'
print('PASS: an amount that disagrees with the reviewed quote is refused')
deliver({'event_id': 'missing-amount-' + uuid4().hex, 'reference': quote_id,
'status': 'approved'})
assert not customer.call('/quotes/' + quote_id)['order'], 'missing paid amount created an order'
deliver({'event_id': 'invalid-amount-' + uuid4().hex, 'reference': quote_id,
'status': 'approved', 'amount_cents': str(total)})
assert not customer.call('/quotes/' + quote_id)['order'], 'non-integer paid amount created an order'
print('PASS: a missing, invalid or mismatched paid amount is refused')
# The real thing, then the same delivery again, and a second event for the
# same quote: a provider does all three.
@@ -81,6 +87,12 @@ def run():
assert customer.call('/quotes/' + quote_id)['order']['id'] == order['id'], 'a second order appeared'
print('PASS: one order from a repeated and re-sent approval')
assert customer.call('/orders/dev-paid', {'quote_id': quote_id})['id'] == order['id']
other = Client()
other.call('/session')
other.call('/orders/dev-paid', {'quote_id': quote_id}, expected=404)
print('PASS: another customer cannot retrieve the paid order by quote id')
# The customer is told once, not once per delivery.
board = Client()
events = board.call('/operator/board', operator=True)['events']