0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-14 13:58:53 +08:00
discourse/plugins/discourse-subscriptions/test/javascripts/unit/controllers/subscriptions-test.js
Arpit Jalan ec3fbdb7ef
FIX: Use signed checkout user references in discourse-subscriptions (#40058)
Previously, `checkout.session.completed` selected the Discourse user
from Stripe's checkout email, which could record a subscription against
the wrong account.

This change sends a signed user reference through Stripe Pricing Tables
and uses it as the trusted webhook binding while preserving the existing
checkout email validation.

---------

Co-authored-by: discourse-patch-triage[bot] <272280883+discourse-patch-triage[bot]@users.noreply.github.com>
2026-05-28 22:19:56 +05:30

65 lines
2 KiB
JavaScript
Vendored

import { settled } from "@ember/test-helpers";
import { setupTest } from "ember-qunit";
import { module, test } from "qunit";
import { i18n } from "discourse-i18n";
module("Unit | Controller | subscriptions", function (hooks) {
setupTest(hooks);
hooks.beforeEach(function () {
const siteSettings = this.owner.lookup("service:site-settings");
siteSettings.discourse_subscriptions_pricing_table_enabled = true;
siteSettings.discourse_subscriptions_pricing_table_id = "prctbl_123";
siteSettings.discourse_subscriptions_public_key = "pk_test_123";
this.currentUser = {
checkEmail() {
return Promise.resolve();
},
};
this.owner.unregister("service:current-user");
this.owner.register("service:current-user", this.currentUser, {
instantiate: false,
});
});
test("returns empty content while current user data loads", async function (assert) {
this.currentUser.email = "user@example.com";
this.currentUser.discourse_subscriptions_checkout_session_user_reference =
"signed-reference";
const controller = this.owner.lookup("controller:subscriptions");
assert.strictEqual(controller.pricingTable, "");
await settled();
assert.true(
String(controller.pricingTable).includes(
'customer-email="user@example.com"'
)
);
});
test("returns empty content when current user reference is missing", async function (assert) {
this.currentUser.email = "user@example.com";
const controller = this.owner.lookup("controller:subscriptions");
await settled();
assert.strictEqual(controller.pricingTable, "");
});
test("returns no products when pricing table is not configured", function (assert) {
const siteSettings = this.owner.lookup("service:site-settings");
siteSettings.discourse_subscriptions_pricing_table_id = "";
const controller = this.owner.lookup("controller:subscriptions");
assert.strictEqual(
controller.pricingTable,
i18n("discourse_subscriptions.subscribe.no_products")
);
});
});