TorbatYar/docs/development/testing-strategy.md
Mortezakoohjani e41ecfad4c Sync platform docs, infra, and module services with Accounting integration.
Include Loyalty/Communication/Sports Center backends and registry updates alongside production nginx and compose wiring.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-25 22:35:23 +03:30

1.4 KiB

Testing Strategy

Required Layers

Layer Purpose
Unit Pure domain logic, validators, mappers
Service Business rules with DB/fakes
Repository Query correctness, tenant filters
API HTTP contracts, authz, status codes
Integration Multi-component flows (onboarding, OTP, SSO handoff)
Migration Upgrade/downgrade smoke on clean DB
Tenant Cross-tenant isolation negatives
Performance Hot entitlement/resolve paths as needed
Security Auth bypass attempts, token scope checks
Architecture Boundary rules (optional lint/CI later)
Documentation validation Links, registry completeness for the phase

Rules

  1. New behavior ships with tests in the same phase.
  2. Tenant tests must include at least one cross-tenant denial case for new tenant-scoped APIs.
  3. Do not rely on production data for assertions.
  4. Prefer deterministic time/OTP fakes.
  5. Phase is incomplete if tests fail or are absent for claimed deliverables.

Commands (current)

cd backend/core-service
pytest -q

cd backend/services/identity-access
pytest -q