import { INestApplication } from '@nestjs/common'; import { Test, TestingModule } from '@nestjs/testing'; import { eq } from 'drizzle-orm'; import request from 'supertest'; import { App } from 'supertest/types'; import { AppModule } from '../src/app.module'; import { configureApp } from '../src/common/configure-app'; import { DRIZZLE, type DrizzleDB } from '../src/database/database.module'; import { privilegeDetails, privilegeKeys, privileges, users, } from '../src/database/schema'; import { PRIVILEGE_ACTIONS } from '../src/modules/privileges/privilege-action'; describe('Sales payments (e2e)', () => { let app: INestApplication; let db: DrizzleDB; let token: string; let otherToken: string; let invoiceId: string; const password = 'password123'; const suffix = Date.now().toString().slice(-6); beforeAll(async () => { const moduleFixture: TestingModule = await Test.createTestingModule({ imports: [AppModule], }).compile(); app = moduleFixture.createNestApplication(); configureApp(app, { NODE_ENV: 'test', SWAGGER_ENABLED: 'false' }); await app.init(); db = app.get(DRIZZLE); const adminReg = await request(app.getHttpServer()) .post('/auth/register') .send({ username: `sp_admin_${suffix}`, password }) .expect(201); token = (adminReg.body as { accessToken: string }).accessToken; const adminMe = await request(app.getHttpServer()) .get('/auth/me') .set('Authorization', `Bearer ${token}`) .expect(200); const adminUserId = (adminMe.body as { id: string }).id; const otherReg = await request(app.getHttpServer()) .post('/auth/register') .send({ username: `sp_other_${suffix}`, password }) .expect(201); otherToken = (otherReg.body as { accessToken: string }).accessToken; const now = Date.now(); const [priv] = await db .insert(privileges) .values({ name: 'Payment Admin', code: `SP_ADMIN_${now}`, status: 'active', createdAt: now, updatedAt: now, createdBy: adminUserId, updatedBy: adminUserId, }) .returning(); const keys = await db.select().from(privilegeKeys); await db.insert(privilegeDetails).values( keys.flatMap((key) => PRIVILEGE_ACTIONS.map((action) => ({ privilegeId: priv.id, privilegeKeyId: key.id, action, value: true, })), ), ); await db .update(users) .set({ privilegeId: priv.id, updatedAt: Date.now() }) .where(eq(users.id, adminUserId)); const auth = { Authorization: `Bearer ${token}` }; const division = await request(app.getHttpServer()) .post('/divisions') .set(auth) .send({ code: `D_${suffix}`, name: 'Sales Division' }) .expect(201); const branch = await request(app.getHttpServer()) .post('/branches') .set(auth) .send({ code: `B_${suffix}`, name: 'Jakarta Pusat', phone: '+6281234567890', address: 'Jl Sudirman 1', workingDaysStart: 'monday', workingDaysEnd: 'friday', workingHoursStart: '08:00', workingHoursEnd: '17:00', divisionId: (division.body as { id: string }).id, }) .expect(201); const employee = await request(app.getHttpServer()) .post('/employees') .set(auth) .send({ code: `E_${suffix}`, name: 'Ada Lovelace', phone: '+6281234567890', position: 'sales', }) .expect(201); const customer = await request(app.getHttpServer()) .post('/customers') .set(auth) .send({ code: `C_${suffix}`, name: 'Acme Corp', phone: '+6281234567890', address: 'Jl Sudirman 1', }) .expect(201); const product = await request(app.getHttpServer()) .post('/products') .set(auth) .send({ code: `P_${suffix}`, name: 'Fuel 95', price: '12500.0000', }) .expect(201); const invoice = await request(app.getHttpServer()) .post('/sales-invoices') .set(auth) .send({ date: '2026-08-24T10:00:00+07:00', salesPersonId: (employee.body as { id: string }).id, branchId: (branch.body as { id: string }).id, divisionId: (division.body as { id: string }).id, customerId: (customer.body as { id: string }).id, products: [ { productId: (product.body as { id: string }).id, quantity: '2', }, ], }) .expect(201); invoiceId = (invoice.body as { id: string }).id; }); afterAll(async () => { await app.close(); }); it('rejects unauthenticated access', async () => { await request(app.getHttpServer()).get('/sales-payments').expect(401); }); it('forbids list without permission', async () => { await request(app.getHttpServer()) .get('/sales-payments') .set('Authorization', `Bearer ${otherToken}`) .expect(403); }); it('creates a payment and marks the invoice partial when approved', async () => { const created = await request(app.getHttpServer()) .post('/sales-payments') .set('Authorization', `Bearer ${token}`) .send({ date: '2026-08-24T10:00:00+07:00', invoices: [{ invoiceId, amount: '10000.0000' }], }) .expect(201); expect((created.body as { code: string }).code).toMatch(/^SP-/); const id = (created.body as { id: string }).id; await request(app.getHttpServer()) .patch(`/sales-payments/${id}`) .set('Authorization', `Bearer ${token}`) .send({ status: 'approved' }) .expect(400); await request(app.getHttpServer()) .patch(`/sales-payments/${id}/status`) .set('Authorization', `Bearer ${token}`) .send({ status: 'approved' }) .expect(200); const invoice = await request(app.getHttpServer()) .get(`/sales-invoices/${invoiceId}`) .set('Authorization', `Bearer ${token}`) .expect(200); expect(invoice.body).toMatchObject({ status: 'partial', balance: '15000.0000', }); }); });