Repository navigation
test: add test suite for listMyTransactions (GET /api/transactions/me) - #1954
Merged
Merged
Conversation
listMyTransactions had no test coverage; every other controller does. Start route-level tests with supertest against the real app, mocking the DB pool, cache, and external services. First cases pin down the JWT gate: 401 without an Authorization header, 401 for an invalid token, and 200 with a valid JWT whose publicKey scopes the query. Refs LabsCrypt#1853
With no query params the endpoint should return the first 20 rows (DEFAULT_LIMIT) ordered newest-first, expose snake_case DB columns as camelCase fields, and report page_info with limit 20, count 20, a next_cursor for the following page, and has_next true because the controller deliberately probes limit + 1 rows. Refs LabsCrypt#1853
Walking GET /api/transactions/me with the returned next_cursor must yield every row exactly once in newest-first order. Each page carries has_previous/has_next flags and a next_cursor built from the last row's id; the SQL appends AND id < $3 with the cursor as the third parameter. Refs LabsCrypt#1853
Non-numeric, zero, negative, and empty cursor values are all treated as absent: the query gets no cursor clause, page_info reports has_previous=false and next_cursor=null, and the response is the full first page rather than an error or a partial leak. Refs LabsCrypt#1853
A client-supplied limit of 10000 must not translate into an unbounded fetch: page_info reports the clamped limit 500, only 500 rows come back, and the SQL probe parameter shows limit + 1 (501) proving the clamp happened before the query was built. Refs LabsCrypt#1853
…rams Non-numeric, zero, and negative limit values fall back to the DEFAULT_LIMIT of 20 instead of erroring or producing a zero-row page. Refs LabsCrypt#1853
The endpoint must filter on the authenticated wallet's publicKey. Another user's rows are seeded with higher ids so they would surface first under newest-first ordering if the ownership filter were dropped; the response contains only the caller's rows and the SQL binds the authenticated wallet as the $1 ownership parameter. Refs LabsCrypt#1853
Cursor-filtered requests must retain the submitted_by ownership clause alongside the AND id < $3 predicate, so paging cannot widen the result set beyond the authenticated wallet's own transactions. Refs LabsCrypt#1853
test: add coverage for GET /api/transactions/me
Contributor
Author
|
The failing RemitLend CI / backend check is due to 8 pre-existing lint errors already on main (in auditLogService.ts, auditLogService.pagination.test.ts, and idempotency.namespace.test.ts) — unrelated to this PR's change. My changed file (transactionRoutes.test.ts) has 0 lint errors/warnings. Flagging in case these should be cleaned up separately. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #1853
listMyTransactions(GET/api/transactions/me) was the only controller insrc/controllerswith zero test coverage — no test file referencedtransactionController,transactionRoutes, orlistMyTransactions. This PR adds route-level coverage following the existing conventions inremittanceRoutes.test.ts: supertest against the real Express app,requireJwtAuthexercised with real JWTs, andjest.unstable_mockModulefor the DB pool, cache, and external services. The mock DB is an in-memory simulation oftransaction_submissionshonoring the controller's exact query shape ($1= owner,$2= limit + 1, optional$3= cursor), so tests assert both HTTP responses and the emitted SQL parameters.Acceptance criteria
Authorizationheader and invalid tokenpage_infoshape,WHERE submitted_by = $1+limit + 1probe asserted in SQLnext_cursor/has_previous/has_nexttransitions, exact params ([wallet, limit+1, cursor]), no duplicate or skipped rowsabc,0,-1,""treated as absent: no cursor clause, first-page semantics, no errorlimit=10000→page_info.limit500, 500 rows,501probe param; plus default-limit fallback forabc/0/-5submitted_bynever returned — other-user rows seeded with higher IDs (would surface first if the filter were dropped) asserted absent, on both the first page and cursor pages, with the SQL ownership clause assertedTest plan
npm test(targeted suite): 13/13 passingnpx eslint src/__tests__/transactionRoutes.test.ts: cleanstsc --noEmit: no new errors for this file (pre-existing errors in unrelated files unchanged)