Add manual wallet withdrawal (debit) endpoint mirroring the offline app's
balance guard, and rebuild the patient کیف پول tab around a single
charge/withdraw toggle modal (quick amounts, تومان→ریال conversion,
transaction filters).
Backend:
- POST /api/v1/patient/{uuid}/wallet/withdraw — creates a debit
WalletTransaction; 422 ERR_WALLET_INSUFFICIENT when amount exceeds balance.
- ErrorCodes: ERR_WALLET_INSUFFICIENT ('موجودی کیف پول کافی نیست').
- docs/api/patient.md updated.
Frontend:
- usePatientWallet hook (balance + charge/withdraw mutations).
- WalletTransactionModal (toggle, quick amounts, UI-only payment fields).
- WalletTab: charge button, همه/واریزی/برداشت filters.
Tests: backend withdraw success/insufficient/non-positive/ownership;
frontend modal + wallet tab interactions.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
176 lines
7.4 KiB
PHP
176 lines
7.4 KiB
PHP
<?php
|
|
|
|
namespace App\Tests\Patient;
|
|
|
|
use App\Doctor\Entity\Doctor;
|
|
use App\Patient\Entity\PatientRecord;
|
|
use App\Payment\Entity\Payment;
|
|
use App\Settlement\Entity\WalletTransaction;
|
|
use App\Tests\ApiTestCase;
|
|
|
|
/**
|
|
* Record-owner-gated reads of the patient's finances:
|
|
* payments list, wallet balance, and wallet-transaction ledger.
|
|
*/
|
|
class PatientFinancialsTest extends ApiTestCase
|
|
{
|
|
/** @return array{0: \App\Auth\Entity\User, 1: PatientRecord, 2: \App\Auth\Entity\User} */
|
|
private function recordFor(): array
|
|
{
|
|
$owner = $this->createUser(['ROLE_DOCTOR']);
|
|
$doctor = new Doctor($owner, 'دکتر');
|
|
$this->em->persist($doctor);
|
|
$this->em->flush();
|
|
|
|
$patient = $this->createUser(['ROLE_USER']);
|
|
$record = new PatientRecord('doctor', $doctor->getId(), $patient, 'doctor', $doctor->getId());
|
|
$this->em->persist($record);
|
|
$this->em->flush();
|
|
|
|
return [$owner, $record, $patient];
|
|
}
|
|
|
|
public function testListsPatientPayments(): void
|
|
{
|
|
[$owner, $record, $patient] = $this->recordFor();
|
|
|
|
$payment = new Payment($patient, 250000, 'mellat', 'appointment');
|
|
$payment->setStatus(Payment::STATUS_SUCCESS);
|
|
$this->em->persist($payment);
|
|
$this->em->flush();
|
|
|
|
$res = $this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/payments', $owner);
|
|
self::assertSame(200, $this->responseCode());
|
|
self::assertCount(1, $res['data']);
|
|
self::assertSame(250000, $res['data'][0]['amount_rials']);
|
|
self::assertSame(1, $res['meta']['totalRecords']);
|
|
}
|
|
|
|
public function testWalletBalanceReflectsCreditMinusDebit(): void
|
|
{
|
|
[$owner, $record, $patient] = $this->recordFor();
|
|
|
|
$this->em->persist(new WalletTransaction($patient, 500000, 'credit', 500000));
|
|
$this->em->persist(new WalletTransaction($patient, 200000, 'debit', 300000));
|
|
$this->em->flush();
|
|
|
|
$res = $this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/wallet', $owner);
|
|
self::assertSame(200, $this->responseCode());
|
|
self::assertSame(300000, $res['data']['balance_rials']);
|
|
self::assertCount(2, $res['data']['recent_transactions']);
|
|
}
|
|
|
|
public function testListsWalletTransactionsPaginated(): void
|
|
{
|
|
[$owner, $record, $patient] = $this->recordFor();
|
|
|
|
$this->em->persist(new WalletTransaction($patient, 100000, 'credit', 100000));
|
|
$this->em->flush();
|
|
|
|
$res = $this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/wallet/transactions', $owner);
|
|
self::assertSame(200, $this->responseCode());
|
|
self::assertCount(1, $res['data']);
|
|
self::assertSame('credit', $res['data'][0]['type']);
|
|
self::assertSame(1, $res['meta']['totalRecords']);
|
|
}
|
|
|
|
public function testChargeWalletCreatesCreditAndReturnsBalance(): void
|
|
{
|
|
[$owner, $record, $patient] = $this->recordFor();
|
|
|
|
$this->em->persist(new WalletTransaction($patient, 200000, 'credit', 200000));
|
|
$this->em->flush();
|
|
|
|
$res = $this->authJson('POST', '/api/v1/patient/' . $record->getUuid() . '/wallet/charge', $owner, [
|
|
'amount_rials' => 300000, 'description' => 'بیعانه نوبت',
|
|
]);
|
|
self::assertSame(201, $this->responseCode());
|
|
self::assertSame(500000, $res['data']['balance_rials']);
|
|
self::assertSame('credit', $res['data']['transaction']['type']);
|
|
self::assertSame('بیعانه نوبت', $res['data']['transaction']['description']);
|
|
|
|
$wallet = $this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/wallet', $owner);
|
|
self::assertSame(500000, $wallet['data']['balance_rials']);
|
|
}
|
|
|
|
public function testChargeWalletRejectsNonPositiveAmount(): void
|
|
{
|
|
[$owner, $record] = $this->recordFor();
|
|
$this->authJson('POST', '/api/v1/patient/' . $record->getUuid() . '/wallet/charge', $owner, ['amount_rials' => 0]);
|
|
self::assertSame(422, $this->responseCode());
|
|
}
|
|
|
|
public function testWithdrawWalletCreatesDebitAndReducesBalance(): void
|
|
{
|
|
[$owner, $record, $patient] = $this->recordFor();
|
|
|
|
$this->em->persist(new WalletTransaction($patient, 500000, 'credit', 500000));
|
|
$this->em->flush();
|
|
|
|
$res = $this->authJson('POST', '/api/v1/patient/' . $record->getUuid() . '/wallet/withdraw', $owner, [
|
|
'amount_rials' => 200000, 'description' => 'عودت وجه',
|
|
]);
|
|
self::assertSame(201, $this->responseCode());
|
|
self::assertSame(300000, $res['data']['balance_rials']);
|
|
self::assertSame('debit', $res['data']['transaction']['type']);
|
|
self::assertSame('عودت وجه', $res['data']['transaction']['description']);
|
|
|
|
$wallet = $this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/wallet', $owner);
|
|
self::assertSame(300000, $wallet['data']['balance_rials']);
|
|
}
|
|
|
|
public function testWithdrawWalletDefaultsDescription(): void
|
|
{
|
|
[$owner, $record, $patient] = $this->recordFor();
|
|
|
|
$this->em->persist(new WalletTransaction($patient, 400000, 'credit', 400000));
|
|
$this->em->flush();
|
|
|
|
$res = $this->authJson('POST', '/api/v1/patient/' . $record->getUuid() . '/wallet/withdraw', $owner, [
|
|
'amount_rials' => 400000,
|
|
]);
|
|
self::assertSame(201, $this->responseCode());
|
|
self::assertSame(0, $res['data']['balance_rials']);
|
|
self::assertSame('برداشت از کیف پول', $res['data']['transaction']['description']);
|
|
}
|
|
|
|
public function testWithdrawWalletRejectsAmountAboveBalance(): void
|
|
{
|
|
[$owner, $record, $patient] = $this->recordFor();
|
|
|
|
$this->em->persist(new WalletTransaction($patient, 100000, 'credit', 100000));
|
|
$this->em->flush();
|
|
|
|
$res = $this->authJson('POST', '/api/v1/patient/' . $record->getUuid() . '/wallet/withdraw', $owner, [
|
|
'amount_rials' => 150000,
|
|
]);
|
|
self::assertSame(422, $this->responseCode());
|
|
self::assertSame('ERR_WALLET_INSUFFICIENT', $res['errors'][0]['code']);
|
|
}
|
|
|
|
public function testWithdrawWalletRejectsNonPositiveAmount(): void
|
|
{
|
|
[$owner, $record] = $this->recordFor();
|
|
$this->authJson('POST', '/api/v1/patient/' . $record->getUuid() . '/wallet/withdraw', $owner, ['amount_rials' => 0]);
|
|
self::assertSame(422, $this->responseCode());
|
|
}
|
|
|
|
public function testFinancialsAreOwnershipScoped(): void
|
|
{
|
|
[, $record] = $this->recordFor();
|
|
[$other] = $this->recordFor();
|
|
|
|
// A different owner cannot read this record's finances (or charge them).
|
|
$this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/payments', $other);
|
|
self::assertSame(404, $this->responseCode());
|
|
$this->authJson('POST', '/api/v1/patient/' . $record->getUuid() . '/wallet/charge', $other, ['amount_rials' => 1000]);
|
|
self::assertSame(404, $this->responseCode());
|
|
$this->authJson('POST', '/api/v1/patient/' . $record->getUuid() . '/wallet/withdraw', $other, ['amount_rials' => 1000]);
|
|
self::assertSame(404, $this->responseCode());
|
|
$this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/wallet', $other);
|
|
self::assertSame(404, $this->responseCode());
|
|
$this->authJson('GET', '/api/v1/patient/' . $record->getUuid() . '/wallet/transactions', $other);
|
|
self::assertSame(404, $this->responseCode());
|
|
}
|
|
}
|