Files
opensourcepos/tests
jekkosandobjecttothis f90adab493 fix(taxes): reject invalid characters in tax code, category, and jurisdiction names (#4733)
* fix(taxes): reject invalid characters in tax code, category, and jurisdiction names

Apply the same unicode_alpha_numeric_punct validation already used for
item tax names to the three tax save endpoints, so stored-XSS payloads
(<, >) are rejected with a validation error instead of being saved.

Mirrors the Items fix and adds a TaxesControllerTest regression suite.

* fix(taxes): permit slash and CJK in tax names, add regression tests

The unicode_alpha_numeric_punct guard rejected '/' (char type Po), which
blocks legitimate slash-separated tax names such as 'GST/HST' and 'VAT/GST'
from being saved. Add '/' to the allowed punctuation set and document it.

Also add regression tests proving acceptance of a slash name (GST/HST) and a
CJK name (消費税) across the tax save endpoints. Addresses CodeRabbit review
on #4679.

* test(4679): adopt test{Method}_{Purpose} naming convention

Align test method names with the convention from #4730
(testPostSaveTaxCodes_RejectsMaliciousName, etc.), per review.

* fix(taxes): allow parentheses in names, make name optional

Address CodeRabbit review on #4733:
- Permit parentheses in tax names (e.g. "VAT (20%)"); slash was
  already allowed, so both "GST/HST" and "VAT (20%)" now pass while
  < and > are still rejected.
- Drop the  rule from tax_code_name, jurisdiction_name and
  tax_category so a code with a blank name can be saved, matching the
  form (the form does not require the name).
- Add regression tests for the parentheses and blank-name cases.

---------

Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-10-07 23:14:48 +02:00
..
2024-06-15 17:19:15 +02:00

Running Application Tests

This is the quick-start to CodeIgniter testing. Its intent is to describe what it takes to set up your application and get it ready to run unit tests. It is not intended to be a full description of the test features that you can use to test your application. Those details can be found in the documentation.

Resources

Requirements

It is recommended to use the latest version of PHPUnit. At the time of this writing, we are running version 9.x. Support for this has been built into the composer.json file that ships with CodeIgniter and can easily be installed via Composer if you don't already have it installed globally.

> composer install

If running under macOS or Linux, you can create a symbolic link to make running tests a touch nicer.

> ln -s ./vendor/bin/phpunit ./phpunit

You also need to install XDebug in order for code coverage to be calculated successfully. After installing XDebug, you must add xdebug.mode=coverage in the php.ini file to enable code coverage.

Setting Up

A number of the tests use a running database. In order to set up the database edit the details for the tests group in app/Config/Database.php or .env. Make sure that you provide a database engine that is currently running on your machine. More details on a test database setup are in the Testing Your Database section of the documentation.

Running the tests

The entire test suite can be run by simply typing one command-line command from the main directory.

> ./phpunit

If you are using Windows, use the following command.

> vendor\bin\phpunit

You can limit tests to those within a single test directory by specifying the directory name after phpunit.

> ./phpunit app/Models

Generating Code Coverage

To generate coverage information, including HTML reports you can view in your browser, you can use the following command:

> ./phpunit --colors --coverage-text=tests/coverage.txt --coverage-html=tests/coverage/ -d memory_limit=1024m

This runs all of the tests again collecting information about how many lines, functions, and files are tested. It also reports the percentage of the code that is covered by tests. It is collected in two formats: a simple text file that provides an overview as well as a comprehensive collection of HTML files that show the status of every line of code in the project.

The text file can be found at tests/coverage.txt. The HTML files can be viewed by opening tests/coverage/index.html in your favorite browser.

PHPUnit XML Configuration

The repository has a phpunit.xml.dist file in the project root that's used for PHPUnit configuration. This is used to provide a default configuration if you do not have your own configuration file in the project root.

The normal practice would be to copy phpunit.xml.dist to phpunit.xml (which is git ignored), and to tailor it as you see fit. For instance, you might wish to exclude database tests, or automatically generate HTML code coverage reports.

Test Cases

Every test needs a test case, or class that your tests extend. CodeIgniter 4 provides one class that you may use directly:

  • CodeIgniter\Test\CIUnitTestCase

Most of the time you will want to write your own test cases that extend CIUnitTestCase to hold functions and services common to your test suites.

Creating Tests

All tests go in the tests/ directory. Each test file is a class that extends a Test Case (see above) and contains methods for the individual tests. These method names must start with the word "test" and should have descriptive names for precisely what they are testing: testUserCanModifyFile() testOutputColorMatchesInput() testIsLoggedInFailsWithInvalidUser()

Writing tests is an art, and there are many resources available to help learn how. Review the links above and always pay attention to your code coverage.

Database Tests

Tests can include migrating, seeding, and testing against a mock or live database. Be sure to modify the test case (or create your own) to point to your seed and migrations and include any additional steps to be run before tests in the setUp() method. See Testing Your Database for details.