package web import ( "net/http" "net/http/httptest" "net/url" "strings" "testing" ) // R-415 / R-138 option B: every customer has their own domain (`01` §7). The CONSEQUENCE asserted: a refused create // stores nothing; an allowed one is stored; an edit keeping its own domain is allowed. // RED-PROOF: delete the domainConflictMessage block in handleConfigCreate → „b" with „example.hu" is created → FAILS. func TestR415_CreateAndEditRefuseConflictingDomain(t *testing.T) { s, st := newTestServer(t) post := func(id, domain string) *httptest.ResponseRecorder { form := url.Values{"customer_id": {id}, "customer_name": {"T " + id}, "email": {"t@example.org"}, "domain": {domain}} req := httptest.NewRequest(http.MethodPost, "/configs/new", strings.NewReader(form.Encode())) req.Header.Set("Content-Type", "application/x-www-form-urlencoded") rr := httptest.NewRecorder() s.handleConfigCreate(rr, req) return rr } if rr := post("a", "example.hu"); rr.Code != http.StatusSeeOther { t.Fatalf("create a: %d %s", rr.Code, rr.Body.String()) } for _, c := range []struct{ id, domain string }{{"b1", "example.hu"}, {"b2", "x.EXAMPLE.hu."}, {"b3", "hu"}, {"b4", "t1.felhom.eu"}, {"b5", "felhom.eu"}} { rr := post(c.id, c.domain) if rr.Code == http.StatusSeeOther { t.Errorf("%s with %q was created — it must be refused", c.id, c.domain) } if !strings.Contains(rr.Body.String(), "Nothing was saved") { t.Errorf("%s with %q: the refusal must say nothing was saved; got %d", c.id, c.domain, rr.Code) } if got, _ := st.GetCustomerConfig(c.id); got != nil { t.Errorf("%s with %q: a config was stored", c.id, c.domain) } } for _, c := range []struct{ id, domain string }{{"c1", "example2.hu"}, {"c2", "notexample.hu"}} { if rr := post(c.id, c.domain); rr.Code != http.StatusSeeOther { t.Errorf("%s with %q must be allowed; got %d %s", c.id, c.domain, rr.Code, rr.Body.String()) } } // Edit: „a" keeping its own domain is allowed; „c1" moving under „a"'s is refused and keeps its old domain. edit := func(id, domain string) *httptest.ResponseRecorder { form := url.Values{"customer_name": {"T " + id}, "email": {"t@example.org"}, "domain": {domain}} req := httptest.NewRequest(http.MethodPost, "/configs/"+id, strings.NewReader(form.Encode())) req.Header.Set("Content-Type", "application/x-www-form-urlencoded") rr := httptest.NewRecorder() s.handleConfigUpdate(rr, req, id) return rr } if rr := edit("a", "example.hu"); strings.Contains(rr.Body.String(), "Nothing was saved") { t.Errorf("editing a with its own domain must not conflict with itself: %s", rr.Body.String()) } if rr := edit("c1", "shop.example.hu"); !strings.Contains(rr.Body.String(), "Nothing was saved") { t.Errorf("moving c1 under a's domain must be refused; got %d", rr.Code) } if got, _ := st.GetCustomerConfig("c1"); got == nil || got.Domain != "example2.hu" { t.Errorf("c1's domain must stay example2.hu after a refused edit; got %+v", got) } }