createUser(['ROLE_DOCTOR']); $doctor = new Doctor($owner, 'دکتر'); $this->em->persist($doctor); $this->em->flush(); $patient = $this->createUser(['ROLE_USER']); $record = new PatientRecord('doctor', $doctor->getId(), $patient, 'doctor', $doctor->getId()); $this->em->persist($record); $this->em->flush(); return [$owner, $record, $patient]; } public function testListsPatientPayments(): void { [$owner, $record, $patient] = $this->recordFor(); $payment = new Payment($patient, 250000, 'mellat', 'appointment'); $payment->setStatus(Payment::STATUS_SUCCESS); $this->em->persist($payment); $this->em->flush(); $res = $this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/payments', $owner); self::assertSame(200, $this->responseCode()); self::assertCount(1, $res['data']); self::assertSame(250000, $res['data'][0]['amount_rials']); self::assertSame(1, $res['meta']['totalRecords']); } public function testWalletBalanceReflectsCreditMinusDebit(): void { [$owner, $record, $patient] = $this->recordFor(); $this->em->persist(new WalletTransaction($patient, 500000, 'credit', 500000)); $this->em->persist(new WalletTransaction($patient, 200000, 'debit', 300000)); $this->em->flush(); $res = $this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/wallet', $owner); self::assertSame(200, $this->responseCode()); self::assertSame(300000, $res['data']['balance_rials']); self::assertCount(2, $res['data']['recent_transactions']); } public function testListsWalletTransactionsPaginated(): void { [$owner, $record, $patient] = $this->recordFor(); $this->em->persist(new WalletTransaction($patient, 100000, 'credit', 100000)); $this->em->flush(); $res = $this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/wallet/transactions', $owner); self::assertSame(200, $this->responseCode()); self::assertCount(1, $res['data']); self::assertSame('credit', $res['data'][0]['type']); self::assertSame(1, $res['meta']['totalRecords']); } public function testFinancialsAreOwnershipScoped(): void { [, $record] = $this->recordFor(); [$other] = $this->recordFor(); // A different owner cannot read this record's finances. $this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/payments', $other); self::assertSame(404, $this->responseCode()); $this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/wallet', $other); self::assertSame(404, $this->responseCode()); $this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/wallet/transactions', $other); self::assertSame(404, $this->responseCode()); } }