Adds POST /customer/orders/:id/pay-with-points (docs/prd-point-coin.md F9, PC-306) for the customer app and self-order. It uses the same payment path as the cashier, approved by the customer's PIN instead of a code: the session alone is not enough (K8), and a wrong PIN takes nothing and counts toward the lock. A customer can pay only their own order; any other order, and one that does not exist, answer 404 alike, so the endpoint does not reveal other customers' orders. The method is the organization's EnakPoint method, no cashier is recorded, and settling the order triggers earning through the same onOrderPaid hook as every other payment. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
52 lines
1.7 KiB
Go
52 lines
1.7 KiB
Go
package router
|
|
|
|
import (
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
|
|
"apskel-pos-be/config"
|
|
"apskel-pos-be/internal/middleware"
|
|
)
|
|
|
|
// Gin panics at startup when two routes disagree on a path parameter's name at the
|
|
// same position (say /outlets/:id/x next to /outlets/:outlet_id/y). Registering every
|
|
// route here catches that in a test instead of on deploy. Handlers are nil: nothing is
|
|
// served, only registered.
|
|
func TestAllRoutesRegister(t *testing.T) {
|
|
r := &Router{
|
|
config: &config.Config{},
|
|
authMiddleware: middleware.NewAuthMiddleware(nil),
|
|
customerAuthMiddleware: middleware.NewCustomerAuthMiddleware("test"),
|
|
}
|
|
engine := r.Init()
|
|
|
|
registered := map[string]bool{}
|
|
for _, route := range engine.Routes() {
|
|
registered[route.Method+" "+route.Path] = true
|
|
}
|
|
for _, want := range []string{
|
|
"GET /api/v1/customer/wallet",
|
|
"GET /api/v1/customer/wallet/transactions",
|
|
"GET /api/v1/marketing/customers/:id/wallet",
|
|
"POST /api/v1/marketing/customers/:id/wallet/adjust",
|
|
"GET /api/v1/outlets/:outlet_id/loyalty-settings",
|
|
"PUT /api/v1/outlets/:outlet_id/loyalty-settings",
|
|
"GET /api/v1/marketing/loyalty-settings",
|
|
"PUT /api/v1/marketing/loyalty-settings",
|
|
"GET /api/v1/marketing/loyalty-settings/history",
|
|
"POST /api/v1/customer/wallet/payment-code",
|
|
"GET /api/v1/orders/:id/point-payment/preview",
|
|
"POST /api/v1/customer/orders/:id/pay-with-points",
|
|
"GET /api/v1/customer/pin/status",
|
|
"POST /api/v1/customer/pin/otp",
|
|
"POST /api/v1/customer/pin",
|
|
"PUT /api/v1/customer/pin",
|
|
"POST /api/v1/customer/pin/reset",
|
|
"DELETE /api/v1/marketing/customers/:id/pin",
|
|
"GET /api/v1/marketing/customers/:id/security-events",
|
|
} {
|
|
assert.True(t, registered[want], want)
|
|
}
|
|
}
|