fix: review 修复——meta 覆盖、重复支付、卸载守卫、测试补全

- EditPost 保存时合并表单中的部分 meta 键,防止插件注入字段覆盖 unlocked_user_ids 等其他键(单篇解锁用户会失去权限的 bug)
- unlockPost:已有阅读权限(会员/作者/已解锁)直接跳文章,不重复支付
- subscribe:已有该套餐有效订阅直接跳我的订阅页
- uninstall:存在已启用的依赖者时拒绝卸载(与 disable 一致)
- .gitignore 排除 storage/media-library/temp 测试残留
- 测试:AdminPagesTest 补 /admin/plugins /admin/payments;新增 Livewire 保存验证 meta 保留、解锁/订阅防重复支付、卸载守卫
This commit is contained in:
ak
2026-08-12 00:53:46 +08:00
parent ec087fe2a8
commit 6a7daa79da
8 changed files with 124 additions and 3 deletions
+2
View File
@@ -22,3 +22,5 @@
Homestead.json
Homestead.yaml
Thumbs.db
/storage/media-library/temp/
+6
View File
@@ -178,6 +178,12 @@ class PluginManager
public function uninstall(string $plugin): void
{
$dependents = $this->dependents($plugin);
if ($dependents) {
throw new RuntimeException('无法卸载 '.$plugin.':以下已启用插件依赖它:'.implode('、', $dependents).'。请先停用这些插件。');
}
[$vendor, $name] = array_pad(explode('.', $plugin), 2, $plugin);
PluginRecord::query()->where('vendor', $vendor)->where('name', $name)->delete();
}
@@ -19,4 +19,14 @@ class EditPost extends EditRecord
DeleteAction::make(),
];
}
protected function mutateFormDataBeforeSave(array $data): array
{
// 表单只包含部分 meta 键(插件注入的价格/会员标记等),合并保留其他插件写入的键(如解锁用户)
if (array_key_exists('meta', $data)) {
$data['meta'] = array_merge($this->record->meta ?? [], $data['meta'] ?? []);
}
return $data;
}
}
@@ -37,6 +37,19 @@ class MembershipController
}
$user = $request->user();
// 已有该套餐的有效订阅:直接返回我的订阅页,避免重复支付
$active = Subscription::query()
->where('user_id', $user->id)
->where('membership_plan_id', $plan->id)
->where('status', 'active')
->where('ends_at', '>', now())
->exists();
if ($active) {
return redirect()->route('membership.mine');
}
$channel = $request->input('channel', 'alipay');
$payment = $this->payment->createOrder(
@@ -63,6 +76,13 @@ class MembershipController
public function unlockPost(Request $request, Post $post)
{
$user = $request->user();
// 已有阅读权限(会员 / 作者 / 已解锁):直接查看文章,避免重复支付
if ($this->service->canReadPost($user, $post)) {
return redirect()->route('posts.show', $post->slug ?? $post->id);
}
// 单篇付费解锁:创建一笔定向支付
$price = (int) ($post->meta['price'] ?? 0);
@@ -70,7 +90,6 @@ class MembershipController
abort(404);
}
$user = $request->user();
$channel = $request->input('channel', 'alipay');
$payment = $this->payment->createOrder(
+6
View File
@@ -50,6 +50,12 @@ class AdminPagesTest extends TestCase
$this->actingAs($this->admin)->get('/admin/media')->assertOk();
}
public function test_plugin_and_payment_pages_load(): void
{
$this->actingAs($this->admin)->get('/admin/plugins')->assertOk();
$this->actingAs($this->admin)->get('/admin/payments')->assertOk();
}
public function test_guest_is_redirected_to_login(): void
{
$this->get('/admin')->assertRedirect('/admin/login');
+38 -1
View File
@@ -112,7 +112,8 @@ class MembershipFlowTest extends TestCase
'content_format' => 'markdown',
'status' => 'published',
'published_at' => now(),
'meta' => ['price' => 500],
// members_only:非会员被拦截,可单篇支付解锁
'meta' => ['price' => 500, 'members_only' => true],
]);
$this->actingAs($this->user)
@@ -147,4 +148,40 @@ class MembershipFlowTest extends TestCase
$this->assertSame('—', $payment->payable_label);
$this->assertNull($payment->payable_url);
}
public function test_unlock_post_skips_payment_when_already_unlocked(): void
{
$post = Post::create([
'title' => '已解锁',
'slug' => 'already-unlocked',
'content' => '内容',
'content_format' => 'markdown',
'status' => 'published',
'published_at' => now(),
'meta' => ['price' => 500, 'unlocked_user_ids' => [$this->user->id]],
]);
$this->actingAs($this->user)
->post('/posts/'.$post->id.'/unlock')
->assertRedirect('/posts/already-unlocked.shtml');
$this->assertSame(0, Payment::query()->count());
}
public function test_subscribe_skips_payment_when_plan_already_active(): void
{
Subscription::create([
'user_id' => $this->user->id,
'membership_plan_id' => $this->plan->id,
'status' => 'active',
'starts_at' => now(),
'ends_at' => now()->addDays(30),
]);
$this->actingAs($this->user)
->post('/membership/'.$this->plan->id.'/subscribe')
->assertRedirect(route('membership.mine'));
$this->assertSame(0, Payment::query()->count());
}
}
+15
View File
@@ -83,6 +83,21 @@ class PluginDependencyTest extends TestCase
$this->assertSame(['neatstudio.payment'], $plugins['neatstudio.membership']['dependency_errors']);
}
public function test_uninstall_plugin_with_enabled_dependent_throws(): void
{
$manager = $this->manager();
try {
$manager->uninstall('neatstudio.payment');
$this->fail('存在已启用的依赖者时应抛出异常');
} catch (RuntimeException $e) {
$this->assertStringContainsString('neatstudio.membership', $e->getMessage());
}
// 卸载失败,记录仍在
$this->assertTrue($manager->isEnabled('neatstudio.payment'));
}
public function test_dependency_problems_for_missing_plugin(): void
{
$manager = $this->manager();
+27 -1
View File
@@ -4,10 +4,13 @@ declare(strict_types=1);
namespace Tests\Feature;
use App\Filament\Resources\Posts\Pages\EditPost;
use App\Filament\Resources\Posts\PostResource;
use App\Models\Post;
use Filament\Schemas\Schema;
use Filament\Tables\Table;
use Illuminate\Foundation\Testing\RefreshDatabase;
use Livewire\Livewire;
use ReflectionClass;
use Tests\TestCase;
@@ -55,7 +58,7 @@ class PostFormInjectionTest extends TestCase
public function test_meta_price_maps_to_post_meta_json(): void
{
$post = \App\Models\Post::create([
$post = Post::create([
'title' => '付费文章',
'content' => '内容',
'content_format' => 'markdown',
@@ -67,4 +70,27 @@ class PostFormInjectionTest extends TestCase
$this->assertSame(9900, $post->meta['price']);
$this->assertTrue($post->meta['members_only']);
}
public function test_edit_post_save_preserves_other_meta_keys(): void
{
$post = Post::create([
'title' => '已解锁文章',
'slug' => 'unlocked-post',
'content' => '内容',
'content_format' => 'markdown',
'status' => 'published',
'published_at' => now(),
'meta' => ['price' => 9900, 'members_only' => true, 'unlocked_user_ids' => [1, 2]],
]);
Livewire::test(EditPost::class, ['record' => $post->getRouteKey()])
->call('save')
->assertHasNoFormErrors();
$post->refresh();
// 表单只含 price/members_only,保存时不得覆盖解锁用户等其他 meta 键
$this->assertSame([1, 2], $post->meta['unlocked_user_ids']);
$this->assertSame(9900, $post->meta['price']);
$this->assertTrue($post->meta['members_only']);
}
}