Files
opensourcepos/tests/Models/ItemTest.php
objecttothis 29a9b1a7e7 Bugfix: Resolve Race Condition in Rewards and Gift Card Spending (#4640)
* Implement atomic updates for gift card and reward point decrements, enhance error handling for insufficient balances, and add regression tests for concurrency safety.

* Add translations for insufficient gift card balance and reward points error messages across all supported languages.

* Reorder `clear_suspended_sale_detail` call to ensure transactional consistency.

* Reorder `clear_all` call to align with success and error handling logic.

* Ensure soft-deleted gift cards are excluded in balance updates.

* Refactor change_quantity logic with atomic upserts, improve error handling for insufficient stock, and update related tests and constants.

* Added check for NEW_ENTRY

* Added unit tests to test changes.

* Fix class name casing in ItemQuantityTest for consistency.

* Fix Bulgarian translations for insufficient balance error messages in Sales module.

* Fix Greek translations for insufficient balance error messages in Sales module.

* Fix Armenian translations for insufficient balance error messages in Sales module.

* Fix Tamil translations for insufficient balance error messages in Sales module.

* Implement race condition testing for database methods with concurrent process support.

* Fix class name casing in ItemTest for consistency.

* Improve concurrent process handling in race condition tests; add readiness and synchronization barriers.

* Improve handling of process I/O streams and timeout management in race condition tests.

* Add test for decrementing gift card value when marked as deleted

* Add `finally` block to ensure proper cleanup in async database race condition tests

* Improve error handling and timeout management in async database race condition tests.

* Refactor test utilities to use shared `EmployeeFixtureTrait` and `ItemFixtureTrait`.

* Track process exit codes explicitly in race condition tests for improved error detection and debugging.

* Improve error handling in `ConcurrentDbRaceTrait` by adding exceptions for `mysqli_poll` and `mysqli_reap_async_query`.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

---------

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-20 02:24:23 +04:00

58 lines
2.1 KiB
PHP

<?php
namespace Tests\Models;
use CodeIgniter\Test\CIUnitTestCase;
use App\Models\Item;
class ItemTest extends CIUnitTestCase
{
public function testSuggestionsColumnValidationRejectsSQLInjection(): void
{
// These malicious values should not be in the allowed columns list
$malicious_columns = [
'name, SLEEP(5)',
'name; DROP TABLE items',
"name' OR '1'='1",
'name UNION SELECT * FROM users',
'name--comment'
];
foreach ($malicious_columns as $malicious) {
$this->assertNotContains($malicious, Item::ALLOWED_SUGGESTIONS_COLUMNS,
"Malicious input should not be in allowed columns: $malicious");
}
}
public function testSuggestionsColumnValidationAcceptsValidColumns(): void
{
// Valid columns should be preserved
$valid_columns = ['name', 'item_number', 'description', 'cost_price', 'unit_price'];
foreach ($valid_columns as $column) {
$this->assertContains($column, Item::ALLOWED_SUGGESTIONS_COLUMNS,
"Valid column should be in allowed list: $column");
}
}
public function testSuggestionsColumnValidationHandlesEmptyString(): void
{
// Empty string should only be allowed for second and third columns
$this->assertContains('', Item::ALLOWED_SUGGESTIONS_COLUMNS_WITH_EMPTY,
'Empty string should be allowed for optional columns');
}
public function testSuggestionsColumnValidationConstantsAreConsistent(): void
{
// Ensure the constants are properly defined
$this->assertCount(5, Item::ALLOWED_SUGGESTIONS_COLUMNS,
'Should have exactly 5 allowed columns');
$this->assertCount(6, Item::ALLOWED_SUGGESTIONS_COLUMNS_WITH_EMPTY,
'Should have exactly 6 allowed columns including empty');
// Ensure empty string is only in WITH_EMPTY variant
$this->assertNotContains('', Item::ALLOWED_SUGGESTIONS_COLUMNS,
'Empty string should not be in required columns list');
}
}