Sign-in compared `admin@nearle.in` / `nearle123` — a compile-time const — after a 600ms delay standing in for a network call that was never made. Two things followed, and the second was the serious one. Every install of a build shared one password, and changing it meant a rebuild. Worse: because nothing was checked with the back office, the *outlet* could not come from the sign-in. It came from a store id typed into Settings, so the till asserted which shop it belonged to and the server took its word. One field on one screen moved a terminal into another tenant's books. Now a person signs in with their own back-office account and the outlet arrives as a consequence — sealed in a signed token, checked server-side on every request, and not editable from this device. `DemoCredentials` is gone, along with the prefilled fields and the "Demo account" hint that printed the password on the login screen. The pieces: - `PosSession` — what the back office answers with. The token is opaque on purpose: the till must not parse it or reason about what it appears to say. - `SessionStore` — the whole session to the platform keystore, not SQLite. The token is a bearer credential and SQLite here is a file behind a shop counter. An expired session reads back as absent, so no caller has to remember to check. - `SyncConfig.bearerToken` — one accessor rather than the same `??` at each call site, because the request that forgot it would be the one silently sending no credentials. The session beats a static API key: the key says the request came from our fleet, the session says which outlet it came from, and only the second can stop a till reaching another tenant's books. - Restore runs in `syncBootstrapProvider` *before* the engine starts. A drain that began first would upload the day's bills unauthenticated. A till trades all day; a reboot mid-shift must not put a login screen in front of a queue. - An outlet picker, shown only when the account genuinely reaches several. Not dismissable — defaulting silently to the first outlet is how a day's takings end up filed against the wrong shop. Store name, address, GSTIN and phone now come down with the session and are written on sign-in. They were compile-time constants, and on a GST invoice those fields are a legal requirement rather than decoration. The smoke test signs in through a fake client and inside `runAsync`: sign-in reaches SQLite now, and real disk I/O cannot complete on a widget test's fake clock — pumping alone leaves it suspended for ever. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
259 lines
9.3 KiB
Dart
259 lines
9.3 KiB
Dart
import 'package:flutter/material.dart';
|
|
import 'package:flutter_riverpod/flutter_riverpod.dart';
|
|
import 'package:flutter_test/flutter_test.dart';
|
|
import 'package:google_fonts/google_fonts.dart';
|
|
import 'package:nearle_pos/app/app.dart';
|
|
import 'package:nearle_pos/data/datasources/local_store.dart';
|
|
import 'package:nearle_pos/data/datasources/seed_data.dart';
|
|
import 'package:nearle_pos/data/remote/pos_auth_api.dart';
|
|
import 'package:nearle_pos/domain/entities/pos_session.dart';
|
|
import 'package:nearle_pos/app/providers.dart';
|
|
import 'package:nearle_pos/domain/entities/shift_report.dart';
|
|
import 'package:nearle_pos/domain/entities/store_account.dart';
|
|
import 'package:nearle_pos/presentation/pos/providers/cart_controller.dart';
|
|
import 'package:nearle_pos/presentation/pos/screens/pos_dashboard_screen.dart';
|
|
import 'package:nearle_pos/presentation/sync/providers/sync_controller.dart';
|
|
|
|
/// Boots the real application widget.
|
|
///
|
|
/// The unit suite proves the money is right; this proves the thing actually
|
|
/// assembles — router guard, provider graph, theme and shell — which type
|
|
/// checking alone cannot tell you.
|
|
void main() {
|
|
setUpAll(() {
|
|
// Tests have no network, and an attempted font fetch throws.
|
|
GoogleFonts.config.allowRuntimeFetching = false;
|
|
LocalStore.registerSeed(
|
|
products: SeedData.products,
|
|
customers: SeedData.customers,
|
|
);
|
|
});
|
|
|
|
setUp(() async {
|
|
await LocalStore.instance.reset(withCatalogue: true);
|
|
});
|
|
|
|
const testStore = StoreAccount(
|
|
id: 'store-001',
|
|
name: 'Nearle Daily',
|
|
email: 'manager@ragulstores.test',
|
|
address: '1 Test Street',
|
|
gstin: '33AABCU9603R1ZM',
|
|
phone: '9840000000',
|
|
staff: [
|
|
StaffUser(id: 'u1', name: 'Suriya', role: StaffRole.admin),
|
|
],
|
|
);
|
|
|
|
ShiftReport blankReport() => ShiftReport.blank(
|
|
businessDate: DateTime(2026, 7, 31),
|
|
terminalId: 'TERM-01',
|
|
cashierName: 'Suriya',
|
|
);
|
|
|
|
Future<void> bootApp(WidgetTester tester) async {
|
|
await tester.pumpWidget(
|
|
ProviderScope(
|
|
overrides: [
|
|
// The background drain would open a broker connection and hit the
|
|
// disk on a clock this test controls. Neither is what these tests
|
|
// measure, and a half-driven timer would leak into the next one.
|
|
syncBootstrapProvider.overrideWith((ref) async {}),
|
|
|
|
// Sign-in now reads staff and store details from SQLite. Real disk
|
|
// I/O cannot complete inside a fixed number of pumps on a fake
|
|
// clock, so the sign-in would hang and every later assertion would
|
|
// fail on a screen that never arrived.
|
|
storeAccountProvider.overrideWith((ref) async => testStore),
|
|
|
|
// Sign-in is a network call now — a person's own back-office account
|
|
// rather than two constants compiled into the build. A widget test
|
|
// must not depend on a live endpoint, so the client is swapped for
|
|
// one that answers with a fixed session.
|
|
posAuthApiProvider.overrideWithValue(_FakePosAuthApi()),
|
|
|
|
// Catalogue reads come from the in-memory cache and resolve on the
|
|
// spot, but these four go to SQLite. Real disk I/O cannot be driven
|
|
// by the fake clock a widget test runs on: sqflite's own lock-warning
|
|
// timer is left pending and trips the binding's leak check. Stubbed
|
|
// so this test measures rendering, which is what it is for.
|
|
unsyncedCountProvider.overrideWith((ref) async => 0),
|
|
promosProvider.overrideWith((ref) async => []),
|
|
activePromosProvider.overrideWith((ref) async => []),
|
|
parkedBillsProvider.overrideWith((ref) async => []),
|
|
orderSyncRowsProvider.overrideWith((ref) async => []),
|
|
todayReportProvider.overrideWith((ref) async => blankReport()),
|
|
myShiftReportProvider.overrideWith((ref) async => blankReport()),
|
|
],
|
|
child: const NearlePosApp(),
|
|
),
|
|
);
|
|
await tester.pumpAndSettle();
|
|
}
|
|
|
|
/// Pumps a fixed number of frames instead of settling.
|
|
///
|
|
/// Once past login the header subscribes to a periodic clock, so there is
|
|
/// always another frame pending and `pumpAndSettle` never returns.
|
|
Future<void> settle(WidgetTester tester, {int frames = 15}) async {
|
|
for (var i = 0; i < frames; i++) {
|
|
await tester.pump(const Duration(milliseconds: 100));
|
|
}
|
|
}
|
|
|
|
Future<void> signIn(WidgetTester tester) async {
|
|
final fields = find.byType(TextFormField);
|
|
await tester.enterText(fields.first, _testEmail);
|
|
await tester.enterText(fields.at(1), _testPassword);
|
|
await tester.pump();
|
|
|
|
// Sign-in reaches SQLite now: it writes the outlet the back office named
|
|
// and the store details a receipt is legally required to carry, before the
|
|
// shell opens. Real disk I/O cannot complete on a widget test's fake clock,
|
|
// so the tap runs inside runAsync — pumping alone leaves the sign-in
|
|
// suspended for ever and every later assertion fails on a screen that never
|
|
// arrived.
|
|
await tester.runAsync(() async {
|
|
await tester.tap(find.text('Sign in').last);
|
|
await Future<void>.delayed(const Duration(milliseconds: 200));
|
|
});
|
|
await settle(tester);
|
|
}
|
|
|
|
testWidgets('the terminal starts on the login screen', (tester) async {
|
|
await bootApp(tester);
|
|
|
|
expect(find.byType(TextFormField), findsWidgets);
|
|
expect(find.text('Sign in'), findsWidgets);
|
|
expect(tester.takeException(), isNull);
|
|
});
|
|
|
|
testWidgets('the auth guard keeps an unauthenticated terminal out',
|
|
(tester) async {
|
|
await bootApp(tester);
|
|
|
|
expect(find.byType(PosDashboardScreen), findsNothing);
|
|
});
|
|
|
|
testWidgets('signing in reaches the billing terminal', (tester) async {
|
|
await bootApp(tester);
|
|
await signIn(tester);
|
|
|
|
expect(find.byType(PosDashboardScreen), findsOneWidget);
|
|
expect(tester.takeException(), isNull);
|
|
});
|
|
|
|
testWidgets('the shell renders every module without throwing',
|
|
(tester) async {
|
|
// Wide enough that the sidebar shows labels and the bill stays docked —
|
|
// the layout where a button label and its total compete for width.
|
|
tester.view.physicalSize = const Size(1800, 1200);
|
|
tester.view.devicePixelRatio = 1;
|
|
addTearDown(tester.view.reset);
|
|
|
|
await bootApp(tester);
|
|
await signIn(tester);
|
|
|
|
for (final label in [
|
|
'Customers',
|
|
'Product Import',
|
|
'Promo',
|
|
'Events',
|
|
'Settings',
|
|
'POS',
|
|
]) {
|
|
final target = find.text(label);
|
|
expect(target, findsWidgets, reason: 'no sidebar entry for "$label"');
|
|
|
|
await tester.tap(target.first);
|
|
await settle(tester);
|
|
expect(tester.takeException(), isNull, reason: 'opening "$label" threw');
|
|
}
|
|
});
|
|
|
|
testWidgets('the back office connection dialog opens and validates',
|
|
(tester) async {
|
|
// The only way a shop can point a till at a broker. Until it existed a
|
|
// store was wired up by editing a provider and rebuilding.
|
|
tester.view.physicalSize = const Size(1800, 1200);
|
|
tester.view.devicePixelRatio = 1;
|
|
addTearDown(tester.view.reset);
|
|
|
|
await bootApp(tester);
|
|
await signIn(tester);
|
|
|
|
await tester.tap(find.text('Settings').first);
|
|
await settle(tester);
|
|
|
|
await tester.tap(find.text('Configure').first);
|
|
await settle(tester);
|
|
|
|
// "Back office connection" is both the dialog title and the About card's
|
|
// button, so match the dialog itself.
|
|
expect(find.byType(AlertDialog), findsOneWidget);
|
|
expect(find.text('MQTT'), findsOneWidget);
|
|
|
|
// Switching to MQTT and saving with no host must be refused, not silently
|
|
// accepted — a terminal pointed at nothing looks identical to one that is
|
|
// simply offline.
|
|
await tester.tap(find.text('MQTT'));
|
|
await settle(tester);
|
|
await tester.tap(find.text('Save'));
|
|
await settle(tester);
|
|
|
|
expect(find.text('A broker host is required'), findsOneWidget);
|
|
expect(find.byType(AlertDialog), findsOneWidget,
|
|
reason: 'the dialog must stay open on a validation failure',);
|
|
expect(tester.takeException(), isNull);
|
|
});
|
|
}
|
|
|
|
const _testEmail = 'manager@ragulstores.test';
|
|
const _testPassword = 'correct-horse';
|
|
|
|
/// A back office that accepts one account and refuses everything else.
|
|
///
|
|
/// Subclasses rather than reimplements an interface because the real client is
|
|
/// concrete — and answering a wrong password correctly matters here: the login
|
|
/// screen's failure path is part of what these tests cover.
|
|
class _FakePosAuthApi extends PosAuthApi {
|
|
_FakePosAuthApi() : super(baseUrl: 'https://example.invalid/pos');
|
|
|
|
@override
|
|
Future<PosSession> login({
|
|
required String authname,
|
|
required String password,
|
|
String? terminalId,
|
|
String? deviceId,
|
|
int? locationId,
|
|
int? configId,
|
|
}) async {
|
|
if (authname.trim() != _testEmail || password != _testPassword) {
|
|
throw const PosAuthException(
|
|
'those sign-in details were not recognised',
|
|
isCredentialFailure: true,
|
|
);
|
|
}
|
|
|
|
return PosSession(
|
|
token: 'test-session-token',
|
|
expiresAt: DateTime.now().add(const Duration(days: 30)),
|
|
userId: 1229,
|
|
fullName: 'Test Manager',
|
|
email: _testEmail,
|
|
roleId: 0,
|
|
tenantId: 1087,
|
|
tenantName: 'Ragul Stores',
|
|
storeId: '1135',
|
|
locationId: 1135,
|
|
locationName: 'Ragul stores Selvapuram',
|
|
outlets: const [
|
|
PosOutlet(locationId: 1135, locationName: 'Ragul stores Selvapuram'),
|
|
],
|
|
);
|
|
}
|
|
|
|
@override
|
|
void dispose() {}
|
|
}
|