New-client onboarding: provision resources/services/owner login, drop EA (#24)
Test backoffice (smb-crm) / test (push) Has been cancelled

n8n/onboarding.json now provisions a default resource (with Mon-Sat 09:00-18:00
hours so the public booking page has slots immediately), a starter service, and
an owner-login user for every new client, recording the temp password via the
existing credentials CRM entity -- gated behind an If check so a failed user
creation can't leave a stale credentials row. The EA-provisioning chain
(service/provider creation against Easy!Appointments) is removed entirely.

Adds POST /api/resources, /api/services, /api/owner_users to the backoffice API
for n8n to call, backed by booking_db.py's existing tenancy-safe create_*
helpers. Also adds "slug" to db.py's clients column list -- it was already a DB
column (#17) but the generic /api/clients POST silently dropped it, so
onboarding could never actually set a client's public-facing slug.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-04 13:11:38 +02:00
parent a27ee59125
commit aabd1d56c4
4 changed files with 315 additions and 126 deletions
+124
View File
@@ -0,0 +1,124 @@
"""Flask test client / real-DB integration tests for the onboarding
provisioning endpoints (#24): POST /api/resources, /api/services, and
/api/owner_users, used by n8n/onboarding.json in place of the retired EA
provider-account chain.
"""
import pytest
import app as app_module
import booking_db as bdb
from app import app as flask_app
CLIENT_A = "C-TEST-PROV-A"
CLIENT_B = "C-TEST-PROV-B"
AUTH = {"X-CRM-Token": "test-crm-token"}
@pytest.fixture
def client(monkeypatch):
flask_app.config["TESTING"] = True
monkeypatch.setattr(app_module, "CRM_TOKEN", "test-crm-token")
return flask_app.test_client()
def _insert_client(client_id):
with bdb.db.connect() as conn, conn.cursor() as cur:
cur.execute(
"INSERT INTO clients (client_id, business_name) VALUES (%s, %s) "
"ON CONFLICT (client_id) DO NOTHING",
(client_id, "Café " + client_id))
conn.commit()
# ---- /api/clients slug (generic entity POST, #24) ----
def test_create_client_persists_slug(client):
resp = client.post("/api/clients", headers=AUTH, json={
"business_name": "Slug Test Client", "slug": "slug-test-abcd"})
assert resp.status_code == 201
client_id = resp.get_json()["added"]
assert bdb.get_client_by_slug("slug-test-abcd")["client_id"] == client_id
# ---- /api/resources ----
def test_create_resource_requires_crm_token(client):
resp = client.post("/api/resources", json={"client_id": CLIENT_A, "name": "Hauptressource"})
assert resp.status_code == 403
def test_create_resource_sets_hours(client):
_insert_client(CLIENT_A)
resp = client.post("/api/resources", headers=AUTH, json={
"client_id": CLIENT_A, "name": "Hauptressource",
"hours": [{"weekday": 0, "opens_at": "09:00", "closes_at": "18:00"}]})
assert resp.status_code == 201
resource_id = resp.get_json()["resource_id"]
hours = bdb.get_resource_hours(CLIENT_A, resource_id)
assert 0 in hours
def test_create_resource_requires_name(client):
_insert_client(CLIENT_A)
resp = client.post("/api/resources", headers=AUTH, json={"client_id": CLIENT_A})
assert resp.status_code == 400
# ---- /api/services ----
def test_create_service_requires_crm_token(client):
resp = client.post("/api/services", json={
"client_id": CLIENT_A, "name": "Termin", "duration_minutes": 30})
assert resp.status_code == 403
def test_create_service_creates_active_service(client):
_insert_client(CLIENT_A)
resp = client.post("/api/services", headers=AUTH, json={
"client_id": CLIENT_A, "name": "Termin", "duration_minutes": 30})
assert resp.status_code == 201
service_id = resp.get_json()["service_id"]
row = bdb.get_service(CLIENT_A, service_id)
assert row["active"] is True
assert row["duration_minutes"] == 30
def test_create_service_requires_duration(client):
_insert_client(CLIENT_A)
resp = client.post("/api/services", headers=AUTH,
json={"client_id": CLIENT_A, "name": "Termin"})
assert resp.status_code == 400
# ---- /api/owner_users ----
def test_create_owner_user_requires_crm_token(client):
resp = client.post("/api/owner_users", json={
"client_id": CLIENT_A, "email": "owner@example.com", "password": "pw12345"})
assert resp.status_code == 403
def test_create_owner_user_creates_login(client):
_insert_client(CLIENT_A)
resp = client.post("/api/owner_users", headers=AUTH, json={
"client_id": CLIENT_A, "email": "owner@example.com", "password": "pw12345"})
assert resp.status_code == 201
user = bdb.find_user_by_email("owner@example.com")
assert user["client_id"] == CLIENT_A
assert bdb.verify_password(user, "pw12345")
def test_create_owner_user_rejects_duplicate_email(client):
_insert_client(CLIENT_A)
_insert_client(CLIENT_B)
bdb.create_user(CLIENT_A, "owner@example.com", "pw12345")
resp = client.post("/api/owner_users", headers=AUTH, json={
"client_id": CLIENT_B, "email": "owner@example.com", "password": "pw67890"})
assert resp.status_code == 409
def test_create_owner_user_requires_password(client):
_insert_client(CLIENT_A)
resp = client.post("/api/owner_users", headers=AUTH,
json={"client_id": CLIENT_A, "email": "owner@example.com"})
assert resp.status_code == 400