Three related fixes, all rooted in the same flaw: authorization and scoping
decided by the caller's role instead of by the environment the data belongs to.
1. Single-appointment access (clinic operations were entirely broken)
AppointmentController::canView/canManage only knew the patient, the owning
doctor and admin -- appointment.clinic was never consulted. A clinic user could
create an appointment through /my/appointment but got 403 on detail, edit,
move, reserve transfer/replace and status change, so nearly every appointment
operation failed in clinic mode.
AppointmentAccessChecker now decides from appointment.clinic: clinic owner,
member doctor (via ClinicDoctorPermissionChecker) and assigned secretary (via
active context + DoctorSecretary) are recognised. Actions reuse the existing
permission vocabulary, so active=false remains the single source of truth for
"collaboration ended". Cancellation is gated separately and an inline status on
PATCH /appointment/{uuid} cannot bypass that gate. The patient is narrowed to
view + cancel.
Also fixed alongside: listByDoctor now serves a clinic manager but scoped to
that clinic; todayStats gained an admin branch and no longer passes an array of
doctor ids as the clinic parameter; PatientController::appointments filters on
appointment.clinic instead of current membership, so deactivating a doctor no
longer erases clinic appointment history from the case file.
The doctor-only active_slot_key was reviewed and deliberately left alone -- a
doctor is one physical person, so adding clinic to the key would permit
double-booking, not fix a bug. Reasoning recorded on the entity.
2. Appointment registration and confirmation
Panel-created appointments are born pending ("ثبت شده") instead of confirmed.
Confirming is now an explicit act: POST /appointment/{uuid}/confirm transitions
the status, files the case file for the appointment's environment (reusing an
existing record or creating one) and registers full or partial payments on the
resulting visit -- all in one transaction.
AppointmentExpiryService would have expired those pending appointments the
moment their slot time passed; findExpiredPending is now limited to online
gateway holds, which are the only pendings carrying a TTL. A pending
appointment still occupies its slot, so the time stays reserved.
The admin panel gets a "قطعی کردن نوبت" modal showing the visit fee, each
selected service, the total, and paid/remaining/status. It is wired inside
AppointmentStatusDropdown, so picking "confirmed" anywhere (timeline, detail,
reserve list, info modal) goes through it and confirmation can never silently
skip the case file and payment.
3. Clinic case-file access
PatientRecordScopeResolver replaces the single-destination role mapping: the
active context decides, so a doctor invited into a clinic finally sees their
patients' records there. A clinic record is per-patient and shared by design,
so "their own patients" is derived from appointments with that doctor in that
clinic rather than from a new column. Clinic secretaries are limited to their
assigned doctors. Read and write share one rule, and out-of-scope records
report 404 so other environments are never disclosed.
Tests: 29 new cases across the three areas (clinic appointment access, confirm
flow, clinic record access). Full suite 466 tests, 2 pre-existing failures
unchanged. API docs updated for all three.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
82 lines
3.2 KiB
PHP
82 lines
3.2 KiB
PHP
<?php
|
|
|
|
namespace App\Tests\Appointment;
|
|
|
|
use App\Appointment\Entity\Appointment;
|
|
use App\Appointment\Service\AppointmentExpiryService;
|
|
use App\Doctor\Entity\Doctor;
|
|
use App\Payment\Entity\Payment;
|
|
use App\Tests\ApiTestCase;
|
|
|
|
/**
|
|
* Covers AppointmentExpiryService: stale pending bookings are expired and their
|
|
* pending payments cancelled. Also guards the N+1 fix (batch payment fetch) by
|
|
* exercising several appointments at once.
|
|
*/
|
|
class AppointmentExpiryServiceTest extends ApiTestCase
|
|
{
|
|
public function testExpiresStaleAndCancelsPendingPayments(): void
|
|
{
|
|
$owner = $this->createUser(['ROLE_DOCTOR']);
|
|
$doctor = new Doctor($owner, 'دکتر تست');
|
|
$this->em->persist($doctor);
|
|
|
|
$past = time() - 3600;
|
|
$appointments = [];
|
|
for ($i = 0; $i < 5; $i++) {
|
|
$patient = $this->createUser(['ROLE_USER']);
|
|
// distinct past slots — one live booking per (doctor, slot)
|
|
$slotStart = $past - $i * 1000;
|
|
$appt = new Appointment($doctor, $patient, $slotStart, $slotStart + 900);
|
|
// مثل مسیر واقعیِ رزرو آنلاین: نگهداشتِ موقت تا پرداخت درگاه.
|
|
$appt->markPendingWithTtl(-1);
|
|
$this->em->persist($appt);
|
|
|
|
$payment = new Payment($patient, 100_000, 'mellat', 'appointment');
|
|
$payment->setAppointment($appt);
|
|
$this->em->persist($payment);
|
|
|
|
$appointments[] = [$appt, $payment];
|
|
}
|
|
$this->em->flush();
|
|
|
|
$service = static::getContainer()->get(AppointmentExpiryService::class);
|
|
$count = $service->expireStale();
|
|
|
|
// At least our 5 — db_test is shared and may hold other stale pendings
|
|
// from earlier tests/runs; the per-row checks below verify our own 5.
|
|
$this->assertGreaterThanOrEqual(5, $count);
|
|
|
|
$this->em->clear();
|
|
foreach ($appointments as [$appt, $payment]) {
|
|
$freshAppt = $this->em->getRepository(Appointment::class)->find($appt->getId());
|
|
$freshPay = $this->em->getRepository(Payment::class)->find($payment->getId());
|
|
$this->assertSame(Appointment::STATUS_EXPIRED, $freshAppt->getStatus());
|
|
$this->assertSame(Payment::STATUS_CANCELED, $freshPay->getStatus());
|
|
}
|
|
}
|
|
|
|
/**
|
|
* نوبت «ثبتشده»ی پنل TTL ندارد؛ گذشتنِ ساعتِ نوبت نباید خودبهخود منقضیاش کند —
|
|
* قطعی/لغو کردنش تصمیم اپراتور است.
|
|
*/
|
|
public function testPanelRegisteredPendingSurvivesExpiry(): void
|
|
{
|
|
$owner = $this->createUser(['ROLE_DOCTOR']);
|
|
$doctor = new Doctor($owner, 'دکتر پنل');
|
|
$this->em->persist($doctor);
|
|
|
|
$slotStart = time() - 7200;
|
|
$appt = new Appointment($doctor, $this->createUser(['ROLE_USER']), $slotStart, $slotStart + 900);
|
|
$this->em->persist($appt);
|
|
$this->em->flush();
|
|
|
|
static::getContainer()->get(AppointmentExpiryService::class)->expireStale();
|
|
|
|
$this->em->clear();
|
|
$fresh = $this->em->getRepository(Appointment::class)->find($appt->getId());
|
|
|
|
$this->assertSame(Appointment::STATUS_PENDING, $fresh->getStatus());
|
|
}
|
|
}
|