Initial build: WishNinja self-hosted gift wishlist manager
ASP.NET Core Blazor (.NET 10) + EF Core/SQLite + Identity. Features: - Wishlists & items with local image storage (upload, clipboard paste, or URL fetched and stored locally) - Owner-hidden claims (enforced at the query layer) to preserve surprises - Admin-invite-only onboarding with email-based password resets - All state under /data; ships as a single Docker image Includes Dockerfile, docker-compose, Gitea Actions CI (test + push image), Unraid template, and xUnit tests (claim privacy, invite lifecycle, image validation). Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
@@ -0,0 +1,89 @@
|
||||
using System.Security.Cryptography;
|
||||
using System.Text;
|
||||
using Microsoft.Extensions.Logging.Abstractions;
|
||||
using Microsoft.Extensions.Options;
|
||||
using WishNinja.Configuration;
|
||||
using WishNinja.Data;
|
||||
using WishNinja.Data.Entities;
|
||||
using WishNinja.Services;
|
||||
using Xunit;
|
||||
|
||||
namespace WishNinja.Tests;
|
||||
|
||||
/// <summary>
|
||||
/// Covers the token-validation half of the invite lifecycle (expiry + single-use). Account
|
||||
/// creation in AcceptInviteAsync requires the full Identity stack and is exercised manually /
|
||||
/// in integration, not here.
|
||||
/// </summary>
|
||||
public class InviteServiceTests : IDisposable
|
||||
{
|
||||
private readonly TestDb _db = new();
|
||||
private readonly InviteService _svc;
|
||||
private const string AdminId = "admin-1";
|
||||
|
||||
public InviteServiceTests()
|
||||
{
|
||||
using (var ctx = _db.CreateDbContext())
|
||||
{
|
||||
ctx.Users.Add(new ApplicationUser { Id = AdminId, UserName = "admin@x", DisplayName = "Admin" });
|
||||
ctx.SaveChanges();
|
||||
}
|
||||
_svc = new InviteService(
|
||||
_db,
|
||||
userManager: null!, // unused by GetValidInviteAsync
|
||||
emailSender: null!, // unused by GetValidInviteAsync
|
||||
options: Options.Create(new WishNinjaOptions()),
|
||||
logger: NullLogger<InviteService>.Instance);
|
||||
}
|
||||
|
||||
private static string Hash(string raw) =>
|
||||
Convert.ToBase64String(SHA256.HashData(Encoding.UTF8.GetBytes(raw)));
|
||||
|
||||
private void SeedInvite(string rawToken, DateTimeOffset expiresAt, DateTimeOffset? acceptedAt = null)
|
||||
{
|
||||
using var ctx = _db.CreateDbContext();
|
||||
ctx.Invites.Add(new Invite
|
||||
{
|
||||
Email = "invitee@x",
|
||||
TokenHash = Hash(rawToken),
|
||||
Role = "User",
|
||||
InvitedByUserId = AdminId,
|
||||
ExpiresAt = expiresAt,
|
||||
AcceptedAt = acceptedAt,
|
||||
});
|
||||
ctx.SaveChanges();
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Valid_token_returns_invite()
|
||||
{
|
||||
SeedInvite("good-token", DateTimeOffset.UtcNow.AddHours(1));
|
||||
var invite = await _svc.GetValidInviteAsync("good-token");
|
||||
Assert.NotNull(invite);
|
||||
Assert.Equal("invitee@x", invite!.Email);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Expired_token_returns_null()
|
||||
{
|
||||
SeedInvite("old-token", DateTimeOffset.UtcNow.AddHours(-1));
|
||||
Assert.Null(await _svc.GetValidInviteAsync("old-token"));
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Accepted_token_returns_null()
|
||||
{
|
||||
SeedInvite("used-token", DateTimeOffset.UtcNow.AddHours(1), acceptedAt: DateTimeOffset.UtcNow.AddMinutes(-5));
|
||||
Assert.Null(await _svc.GetValidInviteAsync("used-token"));
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Unknown_token_returns_null()
|
||||
{
|
||||
SeedInvite("real-token", DateTimeOffset.UtcNow.AddHours(1));
|
||||
Assert.Null(await _svc.GetValidInviteAsync("wrong-token"));
|
||||
Assert.Null(await _svc.GetValidInviteAsync(""));
|
||||
}
|
||||
|
||||
public void Dispose() => _db.Dispose();
|
||||
}
|
||||
Reference in New Issue
Block a user