|
7 | 7 | - 幂等:重复通知仍 200(不重复入队不报错) |
8 | 8 | - 降级:查询失败 → 入队 pending,响应 200 |
9 | 9 | - 订单未支付(签名有效时)→ 正常拒绝不入队 |
| 10 | +- 自动绑定:携带 from_user → sold → bound + paid metadata;无用户标识 → 仅 sold |
10 | 11 | """ |
11 | 12 |
|
12 | 13 | import hashlib |
@@ -145,3 +146,77 @@ async def test_missing_order_id_rejected(self): |
145 | 146 |
|
146 | 147 | result = await _handle_webhook({}) |
147 | 148 | assert result["code"] == 400 |
| 149 | + |
| 150 | + |
| 151 | +class TestAutoBind: |
| 152 | + """webhook 自动绑定用户(支付→激活闭环)""" |
| 153 | + |
| 154 | + @pytest.mark.asyncio |
| 155 | + async def test_webhook_with_from_user_auto_binds(self): |
| 156 | + """携带 from_user 的 webhook 自动完成 sold → bound + paid metadata""" |
| 157 | + from routers.license_webhook import _handle_webhook |
| 158 | + from services import payment_adapter, supabase_adapter |
| 159 | + |
| 160 | + _seed_pool() |
| 161 | + payment_adapter._seed_mock_order("MB-2001", "ENTROPY-PRO-AAAA-BBBB", status="paid") |
| 162 | + |
| 163 | + result = await _handle_webhook({ |
| 164 | + "order_id": "MB-2001", |
| 165 | + "code": "ENTROPY-PRO-AAAA-BBBB", |
| 166 | + "from_user": "user-123", |
| 167 | + }) |
| 168 | + assert result["code"] == 200 |
| 169 | + assert result["message"] == "ok" |
| 170 | + |
| 171 | + # 自动绑定:sold → bound |
| 172 | + row = supabase_adapter._mock_pool["ENTROPY-PRO-AAAA-BBBB"] |
| 173 | + assert row["status"] == "bound" |
| 174 | + assert row["bound_user_id"] == "user-123" |
| 175 | + assert row["machine_id"] == "auto-webhook" |
| 176 | + |
| 177 | + # paid metadata 已更新(mock 模式直接存 paid dict:tier/expires_at/updated_at) |
| 178 | + meta = supabase_adapter._mock_metadata.get("user-123") |
| 179 | + assert meta is not None |
| 180 | + assert meta["tier"] == "pro" |
| 181 | + assert meta["expires_at"] is not None |
| 182 | + |
| 183 | + @pytest.mark.asyncio |
| 184 | + async def test_webhook_without_from_user_no_bind(self): |
| 185 | + """无用户标识的 webhook 仅标记 sold,不自动绑定(兼容手动激活码)""" |
| 186 | + from routers.license_webhook import _handle_webhook |
| 187 | + from services import payment_adapter, supabase_adapter |
| 188 | + |
| 189 | + _seed_pool() |
| 190 | + payment_adapter._seed_mock_order("MB-2002", "ENTROPY-PRO-AAAA-BBBB", status="paid") |
| 191 | + |
| 192 | + result = await _handle_webhook({ |
| 193 | + "order_id": "MB-2002", |
| 194 | + "code": "ENTROPY-PRO-AAAA-BBBB", |
| 195 | + }) |
| 196 | + assert result["code"] == 200 |
| 197 | + |
| 198 | + # 仅 sold,未绑定(mock 记录中 bound_user_id/machine_id 保持 None) |
| 199 | + row = supabase_adapter._mock_pool["ENTROPY-PRO-AAAA-BBBB"] |
| 200 | + assert row["status"] == "sold" |
| 201 | + assert row["bound_user_id"] is None |
| 202 | + assert row["machine_id"] is None |
| 203 | + |
| 204 | + @pytest.mark.asyncio |
| 205 | + async def test_webhook_with_unknown_email_no_bind(self): |
| 206 | + """携带 email 但未匹配到用户 → 跳过绑定不崩溃(回落手动激活)""" |
| 207 | + from routers.license_webhook import _handle_webhook |
| 208 | + from services import payment_adapter, supabase_adapter |
| 209 | + |
| 210 | + _seed_pool() |
| 211 | + payment_adapter._seed_mock_order("MB-2003", "ENTROPY-PRO-AAAA-BBBB", status="paid") |
| 212 | + |
| 213 | + result = await _handle_webhook({ |
| 214 | + "order_id": "MB-2003", |
| 215 | + "code": "ENTROPY-PRO-AAAA-BBBB", |
| 216 | + "buyer_email": "buyer@example.com", |
| 217 | + }) |
| 218 | + assert result["code"] == 200 |
| 219 | + |
| 220 | + row = supabase_adapter._mock_pool["ENTROPY-PRO-AAAA-BBBB"] |
| 221 | + assert row["status"] == "sold" |
| 222 | + assert row["bound_user_id"] is None |
0 commit comments