Files
smb-online/backoffice/app/tests/test_public_booking.py
T
mivanchenko 456ca3872f
Test backoffice (smb-crm) / test (push) Successful in 1m46s
Add locations (Filialen) as a grouping layer above resources
Enables multiple barbers/staff bookable at the same location and time
-- previously "resource" conflated "location" and "the thing that
can't double-book itself" into one row, so a Filiale could only ever
have exactly one bookable slot at once.

- New `locations` table; `resources.location_id` with a generic,
  idempotent backfill migration (any resource without a location gets
  one auto-created matching its name -- not a one-off for any single
  client, protects any future resource stuck in the old flat shape too)
- `resources`/`resource_hours`/services keep everything they already
  had (hours, min-notice, max-advance, buffer, the no-overlap
  constraint) scoped to resource_id, not location_id -- two barbers at
  one location must stay independently bookable at the same time
- booking_db.py: new locations CRUD mirroring the existing
  resources/services pattern; create_resource now requires a
  location_id, guarded the same way every other tenant check here is
  (get_location existence check, no real FK -- matches this schema's
  existing no-FK convention throughout)
- app.py: new POST /api/locations provisioning route; POST
  /api/resources now requires location_id
- owner_settings.py + settings.html: new self-service "add a Filiale"
  / "add a barber" UI -- there was previously no way to create a
  resource at all outside the CRM/n8n provisioning API
- public_booking.py + book.html: new Filiale picker (reuses the
  existing wireOptionGroup button-group pattern), filtering the
  Mitarbeiter picker to the selected location -- a single-location
  client sees no extra click, same as before Filialen existed
- owner_booking.py + agenda.html: the Filiale show/hide toggle and
  hide-cancelled toggle (shipped earlier this session) now key off
  location_id instead of resource_id, so hiding a Filiale hides every
  barber's bookings at it; manual-booking dropdown grouped by Filiale
- n8n/onboarding.json: default provisioning now creates a "Hauptfiliale"
  location before its resource (inert until re-imported into the live
  n8n instance)

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 03:02:56 +02:00

143 lines
5.5 KiB
Python

"""Flask test client / real-DB integration tests for the public booking page
and its honeypot abuse-protection (#17), per #14's testing decision: assert on
HTTP response + resulting DB state.
"""
from datetime import date, time, timedelta
import pytest
import booking_db as bdb
from app import app as flask_app
CLIENT_A = "C-TEST-PUBLIC-A"
CLIENT_B = "C-TEST-PUBLIC-B"
@pytest.fixture
def client():
flask_app.config["TESTING"] = True
return flask_app.test_client()
def _next_monday(after):
d = after + timedelta(days=1)
while d.weekday() != 0:
d += timedelta(days=1)
return d
def _make_client(client_id=CLIENT_A, slug="happynails", business_name="Happy Nails"):
with bdb.db.connect() as conn, conn.cursor() as cur:
cur.execute(
"INSERT INTO clients (client_id, business_name, slug, timezone, auto_confirm) "
"VALUES (%s, %s, %s, %s, %s) "
"ON CONFLICT (client_id) DO UPDATE SET business_name = EXCLUDED.business_name, "
"slug = EXCLUDED.slug, timezone = EXCLUDED.timezone, "
"auto_confirm = EXCLUDED.auto_confirm",
(client_id, business_name, slug, "Europe/Berlin", True))
conn.commit()
def _setup_bookable_client(client_id=CLIENT_A, slug="happynails"):
_make_client(client_id, slug)
location = bdb.create_location(client_id, "Main")
resource = bdb.create_resource(client_id, location["location_id"], "Chair 1",
min_notice_minutes=0, max_advance_days=365)
bdb.set_resource_hours(client_id, resource["resource_id"], 0, time(9, 0), time(17, 0))
service = bdb.create_service(client_id, "Haircut", 60, price=25)
return resource, service
def test_book_page_renders_for_known_slug_with_services_and_resources(client):
resource, service = _setup_bookable_client()
resp = client.get("/book/happynails")
assert resp.status_code == 200
body = resp.get_data(as_text=True)
assert "Happy Nails" in body
assert "Haircut" in body
assert resource["resource_id"] in body
def test_book_page_404s_for_unknown_slug(client):
resp = client.get("/book/does-not-exist")
assert resp.status_code == 404
def test_book_page_404s_when_client_has_no_active_service(client):
_make_client(CLIENT_B, slug="no-services-client")
bdb.create_resource(CLIENT_B, bdb.create_location(CLIENT_B, "Main")["location_id"], "Chair 1")
# No services created for this client.
resp = client.get("/book/no-services-client")
assert resp.status_code == 404
def test_book_page_404s_when_client_has_only_inactive_service(client):
_make_client(CLIENT_B, slug="inactive-service-client")
bdb.create_resource(CLIENT_B, bdb.create_location(CLIENT_B, "Main")["location_id"], "Chair 1")
bdb.create_service(CLIENT_B, "Haircut", 60, active=False)
resp = client.get("/book/inactive-service-client")
assert resp.status_code == 404
def test_book_page_includes_location_in_context(client):
resource, service = _setup_bookable_client()
resp = client.get("/book/happynails")
assert resp.status_code == 200
body = resp.get_data(as_text=True)
assert "LOCATIONS" in body
assert resource["location_id"] in body
def test_book_page_404s_when_only_location_is_inactive(client):
"""A resource whose Filiale was deactivated must not stay bookable even
though the resource row itself is still active."""
_make_client(CLIENT_B, slug="inactive-location-client")
location = bdb.create_location(CLIENT_B, "Main")
bdb.create_resource(CLIENT_B, location["location_id"], "Chair 1")
bdb.create_service(CLIENT_B, "Haircut", 60)
bdb.update_location(CLIENT_B, location["location_id"], active=False)
resp = client.get("/book/inactive-location-client")
assert resp.status_code == 404
def test_honeypot_filled_silently_rejects_booking(client):
resource, service = _setup_bookable_client()
day = _next_monday(date.today())
slot = client.get("/api/booking/slots", query_string={
"client_id": CLIENT_A, "resource_id": resource["resource_id"],
"service_id": service["service_id"],
"date_from": day.isoformat(), "date_to": day.isoformat()}).get_json()["slots"]
assert slot
resp = client.post("/api/booking", json={
"client_id": CLIENT_A, "resource_id": resource["resource_id"],
"service_id": service["service_id"], "start_time": slot[0],
"customer_name": "Bot", "customer_contact": "bot@example.com",
"website": "https://spam.example"})
# Looks like an ordinary success to the caller...
assert resp.status_code == 201
body = resp.get_json()
assert body["status"] == "confirmed"
assert "token" in body
# ...but no booking was actually created.
assert bdb.list_bookings(CLIENT_A) == []
def test_honeypot_empty_creates_a_real_booking(client):
resource, service = _setup_bookable_client()
day = _next_monday(date.today())
slot = client.get("/api/booking/slots", query_string={
"client_id": CLIENT_A, "resource_id": resource["resource_id"],
"service_id": service["service_id"],
"date_from": day.isoformat(), "date_to": day.isoformat()}).get_json()["slots"]
resp = client.post("/api/booking", json={
"client_id": CLIENT_A, "resource_id": resource["resource_id"],
"service_id": service["service_id"], "start_time": slot[0],
"customer_name": "Real Customer", "customer_contact": "real@example.com",
"website": ""})
assert resp.status_code == 201
assert len(bdb.list_bookings(CLIENT_A)) == 1