4 Commits

Author SHA1 Message Date
david ed50d2427e fix: return field-level validation errors on POST /habits
Previously all validation failures in CreateHabitHandler returned a
generic {"error":"invalid input"}, making it impossible to tell
whether type, frequency, specific_days or specific_dates was the
problem. Errors are now wrapped with field + i18n key and the HTTP
layer replies via respondValidationErrorI18n, matching the pattern
already used by auth endpoints.
2026-04-17 19:04:23 +02:00
david c20720f120 Add live docs URL to README and remove broken /docs shortcut 2026-03-27 01:09:14 +01:00
david a07d033e93 Add NoOp email service, /docs shortcut and fix streak timezone bug
Replace nil email service pattern with NoOpEmailService (Null Object)
to eliminate nil pointer panics across all handlers.

Add /docs route as a shortcut to Swagger UI.

Fix streak calculation returning 0 when server timezone differs from
UTC — CreatedAt was not converted to UTC before date extraction.
2026-03-27 00:32:10 +01:00
david 67fc508384 Fix import order 2026-03-27 00:04:15 +01:00
14 changed files with 134 additions and 32 deletions
+3 -1
View File
@@ -139,7 +139,9 @@ API runs on `http://localhost:8080`
## API Documentation
Access the interactive Swagger UI at `http://localhost:8080/api/v1/docs`
**Live:** [apocapoc.app/api/v1/docs](https://apocapoc.app/api/v1/docs)
**Local:** `http://localhost:8080/api/v1/docs`
Includes endpoint reference, schemas, authentication examples, and live testing.
+2 -2
View File
@@ -14,13 +14,13 @@ import (
"apocapoc-api/internal/application/commands"
"apocapoc-api/internal/application/queries"
"apocapoc-api/internal/domain/services"
"apocapoc-api/internal/i18n"
"apocapoc-api/internal/infrastructure/auth"
"apocapoc-api/internal/infrastructure/backup"
"apocapoc-api/internal/infrastructure/config"
"apocapoc-api/internal/infrastructure/crypto"
"apocapoc-api/internal/infrastructure/email"
"apocapoc-api/internal/domain/services"
httpInfra "apocapoc-api/internal/infrastructure/http"
"apocapoc-api/internal/infrastructure/logger"
"apocapoc-api/internal/infrastructure/persistence/sqlite"
@@ -95,7 +95,7 @@ func main() {
jwtService := auth.NewJWTService(cfg.JWTSecret, jwtExpiryHours)
passwordHasher := crypto.NewBcryptHasher()
var emailService services.EmailService
var emailService services.EmailService = &services.NoOpEmailService{}
if cfg.SMTPHost != "" {
smtpPort, err := strconv.Atoi(cfg.SMTPPort)
if err != nil {
@@ -2,6 +2,7 @@ package commands
import (
"context"
"fmt"
"apocapoc-api/internal/domain/entities"
"apocapoc-api/internal/domain/repositories"
@@ -32,19 +33,19 @@ func NewCreateHabitHandler(habitRepo repositories.HabitRepository) *CreateHabitH
func (h *CreateHabitHandler) Handle(ctx context.Context, cmd CreateHabitCommand) (string, error) {
if !cmd.Type.IsValid() {
return "", errors.ErrInvalidInput
return "", fmt.Errorf("%w: type: type_invalid", errors.ErrInvalidInput)
}
if !cmd.Frequency.IsValid() {
return "", errors.ErrInvalidInput
return "", fmt.Errorf("%w: frequency: frequency_invalid", errors.ErrInvalidInput)
}
if cmd.Frequency == value_objects.FrequencyWeekly && len(cmd.SpecificDays) == 0 {
return "", errors.ErrInvalidInput
return "", fmt.Errorf("%w: specific_days: specific_days_required", errors.ErrInvalidInput)
}
if cmd.Frequency == value_objects.FrequencyMonthly && len(cmd.SpecificDates) == 0 {
return "", errors.ErrInvalidInput
return "", fmt.Errorf("%w: specific_dates: specific_dates_required", errors.ErrInvalidInput)
}
habit := entities.NewHabit(cmd.UserID, cmd.Name, cmd.Type, cmd.Frequency, cmd.CarryOver, cmd.IsNegative)
@@ -4,6 +4,8 @@ import (
"apocapoc-api/internal/domain/repositories"
"apocapoc-api/internal/shared/pagination"
"context"
stderrors "errors"
"strings"
"testing"
"time"
@@ -110,8 +112,31 @@ func TestCreateHabitHandler_InvalidType(t *testing.T) {
_, err := handler.Handle(context.Background(), cmd)
if err != errors.ErrInvalidInput {
t.Errorf("Expected ErrInvalidInput, got %v", err)
if !stderrors.Is(err, errors.ErrInvalidInput) {
t.Fatalf("Expected ErrInvalidInput wrapper, got %v", err)
}
if !strings.Contains(err.Error(), "type: type_invalid") {
t.Errorf("Expected 'type: type_invalid' in error, got %q", err.Error())
}
}
func TestCreateHabitHandler_EmptyType(t *testing.T) {
mock := &mockHabitRepo{}
handler := NewCreateHabitHandler(mock)
cmd := CreateHabitCommand{
UserID: "user-123",
Name: "Exercise",
Frequency: "DAILY",
}
_, err := handler.Handle(context.Background(), cmd)
if !stderrors.Is(err, errors.ErrInvalidInput) {
t.Fatalf("Expected ErrInvalidInput wrapper, got %v", err)
}
if !strings.Contains(err.Error(), "type: type_invalid") {
t.Errorf("Expected 'type: type_invalid' in error, got %q", err.Error())
}
}
@@ -128,8 +153,11 @@ func TestCreateHabitHandler_InvalidFrequency(t *testing.T) {
_, err := handler.Handle(context.Background(), cmd)
if err != errors.ErrInvalidInput {
t.Errorf("Expected ErrInvalidInput, got %v", err)
if !stderrors.Is(err, errors.ErrInvalidInput) {
t.Fatalf("Expected ErrInvalidInput wrapper, got %v", err)
}
if !strings.Contains(err.Error(), "frequency: frequency_invalid") {
t.Errorf("Expected 'frequency: frequency_invalid' in error, got %q", err.Error())
}
}
@@ -147,8 +175,11 @@ func TestCreateHabitHandler_WeeklyWithoutSpecificDays(t *testing.T) {
_, err := handler.Handle(context.Background(), cmd)
if err != errors.ErrInvalidInput {
t.Errorf("Expected ErrInvalidInput, got %v", err)
if !stderrors.Is(err, errors.ErrInvalidInput) {
t.Fatalf("Expected ErrInvalidInput wrapper, got %v", err)
}
if !strings.Contains(err.Error(), "specific_days: specific_days_required") {
t.Errorf("Expected 'specific_days: specific_days_required' in error, got %q", err.Error())
}
}
@@ -166,8 +197,11 @@ func TestCreateHabitHandler_MonthlyWithoutSpecificDates(t *testing.T) {
_, err := handler.Handle(context.Background(), cmd)
if err != errors.ErrInvalidInput {
t.Errorf("Expected ErrInvalidInput, got %v", err)
if !stderrors.Is(err, errors.ErrInvalidInput) {
t.Fatalf("Expected ErrInvalidInput wrapper, got %v", err)
}
if !strings.Contains(err.Error(), "specific_dates: specific_dates_required") {
t.Errorf("Expected 'specific_dates: specific_dates_required' in error, got %q", err.Error())
}
}
@@ -73,7 +73,7 @@ func (h *RegisterUserHandler) Handle(ctx context.Context, cmd RegisterUserComman
user := entities.NewUser(cmd.Email, hashedPassword)
emailVerificationRequired := false
if h.emailService != nil {
if h.emailService.IsEnabled() {
token, err := h.generateVerificationToken()
if err != nil {
return nil, fmt.Errorf("failed to generate verification token: %w", err)
@@ -2,6 +2,7 @@ package commands
import (
"apocapoc-api/internal/domain/repositories"
"apocapoc-api/internal/domain/services"
"apocapoc-api/internal/shared/pagination"
"context"
"errors"
@@ -71,7 +72,7 @@ func TestRegisterUserHandler_Success(t *testing.T) {
},
}
hasher := &mockPasswordHasher{}
handler := NewRegisterUserHandler(repo, hasher, nil, "", "open", false)
handler := NewRegisterUserHandler(repo, hasher, &services.NoOpEmailService{}, "", "open", false)
cmd := RegisterUserCommand{
Email: "test@example.com",
@@ -88,7 +89,7 @@ func TestRegisterUserHandler_Success(t *testing.T) {
}
if result.EmailVerificationRequired {
t.Error("expected email verification to not be required when emailService is nil")
t.Error("expected email verification to not be required when email is disabled")
}
if createdUser == nil {
@@ -103,7 +104,7 @@ func TestRegisterUserHandler_Success(t *testing.T) {
func TestRegisterUserHandler_InvalidEmail(t *testing.T) {
repo := &mockUserRepo{}
hasher := &mockPasswordHasher{}
handler := NewRegisterUserHandler(repo, hasher, nil, "", "open", false)
handler := NewRegisterUserHandler(repo, hasher, &services.NoOpEmailService{}, "", "open", false)
tests := []struct {
name string
@@ -135,7 +136,7 @@ func TestRegisterUserHandler_InvalidEmail(t *testing.T) {
func TestRegisterUserHandler_InvalidPassword(t *testing.T) {
repo := &mockUserRepo{}
hasher := &mockPasswordHasher{}
handler := NewRegisterUserHandler(repo, hasher, nil, "", "open", false)
handler := NewRegisterUserHandler(repo, hasher, &services.NoOpEmailService{}, "", "open", false)
tests := []struct {
name string
@@ -174,7 +175,7 @@ func TestRegisterUserHandler_EmailAlreadyExists(t *testing.T) {
},
}
hasher := &mockPasswordHasher{}
handler := NewRegisterUserHandler(repo, hasher, nil, "", "open", false)
handler := NewRegisterUserHandler(repo, hasher, &services.NoOpEmailService{}, "", "open", false)
cmd := RegisterUserCommand{
Email: "test@example.com",
@@ -195,7 +196,7 @@ func TestRegisterUserHandler_PasswordHashingError(t *testing.T) {
return "", expectedErr
},
}
handler := NewRegisterUserHandler(repo, hasher, nil, "", "open", false)
handler := NewRegisterUserHandler(repo, hasher, &services.NoOpEmailService{}, "", "open", false)
cmd := RegisterUserCommand{
Email: "test@example.com",
@@ -216,7 +217,7 @@ func TestRegisterUserHandler_RepositoryError(t *testing.T) {
},
}
hasher := &mockPasswordHasher{}
handler := NewRegisterUserHandler(repo, hasher, nil, "", "open", false)
handler := NewRegisterUserHandler(repo, hasher, &services.NoOpEmailService{}, "", "open", false)
cmd := RegisterUserCommand{
Email: "test@example.com",
@@ -232,7 +233,7 @@ func TestRegisterUserHandler_RepositoryError(t *testing.T) {
func TestRegisterUserHandler_EdgeCases(t *testing.T) {
repo := &mockUserRepo{}
hasher := &mockPasswordHasher{}
handler := NewRegisterUserHandler(repo, hasher, nil, "", "open", false)
handler := NewRegisterUserHandler(repo, hasher, &services.NoOpEmailService{}, "", "open", false)
tests := []struct {
name string
@@ -285,7 +286,7 @@ func TestRegisterUserHandler_EdgeCases(t *testing.T) {
func TestRegisterUserHandler_ClosedRegistration(t *testing.T) {
repo := &mockUserRepo{}
hasher := &mockPasswordHasher{}
handler := NewRegisterUserHandler(repo, hasher, nil, "", "closed", false)
handler := NewRegisterUserHandler(repo, hasher, &services.NoOpEmailService{}, "", "closed", false)
cmd := RegisterUserCommand{
Email: "test@example.com",
@@ -89,6 +89,10 @@ func (m *mockRequestResetEmailService) HealthCheck() error {
return nil
}
func (m *mockRequestResetEmailService) IsEnabled() bool {
return true
}
func TestRequestPasswordResetHandler_Success(t *testing.T) {
user := entities.NewUser("test@example.com", "hash")
user.ID = "user-123"
@@ -69,6 +69,10 @@ func (m *mockEmailService) HealthCheck() error {
return nil
}
func (m *mockEmailService) IsEnabled() bool {
return true
}
func TestVerifyEmailHandler_Success(t *testing.T) {
token := "valid-token"
expiry := time.Now().Add(24 * time.Hour)
@@ -10,4 +10,11 @@ type EmailMessage struct {
type EmailService interface {
Send(message EmailMessage) error
HealthCheck() error
IsEnabled() bool
}
type NoOpEmailService struct{}
func (n *NoOpEmailService) Send(_ EmailMessage) error { return nil }
func (n *NoOpEmailService) HealthCheck() error { return nil }
func (n *NoOpEmailService) IsEnabled() bool { return false }
+2 -1
View File
@@ -49,7 +49,8 @@ func buildEntryMap(entries []*entities.HabitEntry) map[string]*entities.HabitEnt
}
func allScheduledDates(habit *entities.Habit, now time.Time) []time.Time {
start := time.Date(habit.CreatedAt.Year(), habit.CreatedAt.Month(), habit.CreatedAt.Day(), 0, 0, 0, 0, time.UTC)
createdUTC := habit.CreatedAt.UTC()
start := time.Date(createdUTC.Year(), createdUTC.Month(), createdUTC.Day(), 0, 0, 0, 0, time.UTC)
today := time.Date(now.Year(), now.Month(), now.Day(), 0, 0, 0, 0, time.UTC)
freq := string(habit.Frequency)
@@ -107,6 +107,10 @@ func (s *SMTPService) GetConfig() SMTPConfig {
return s.config
}
func (s *SMTPService) IsEnabled() bool {
return true
}
func (s *SMTPService) HealthCheck() error {
dialer := mail.NewDialer(s.config.Host, s.config.Port, s.config.Username, s.config.Password)
dialer.TLSConfig = &tls.Config{
@@ -2,6 +2,7 @@ package http
import (
"encoding/json"
stderrors "errors"
"net/http"
"strconv"
"strings"
@@ -97,8 +98,8 @@ func (h *HabitHandlers) CreateHabit(w http.ResponseWriter, r *http.Request) {
habitID, err := h.createHandler.Handle(r.Context(), cmd)
if err != nil {
if err == errors.ErrInvalidInput {
respondError(w, http.StatusBadRequest, err.Error())
if stderrors.Is(err, errors.ErrInvalidInput) {
respondValidationErrorI18n(w, r, h.translator, err)
return
}
respondErrorI18n(w, r, h.translator, http.StatusInternalServerError, "failed_create_habit")
@@ -123,6 +123,47 @@ func TestHabitCRUDFlow(t *testing.T) {
}
})
t.Run("Create habit with missing type returns field-level error", func(t *testing.T) {
token := registerAndLogin(t, *ts.Router, "validationuser@example.com", "Password123!")
reqBody := map[string]any{"name": "No Type"}
rr := makeRequest(t, *ts.Router, "POST", "/api/v1/habits", reqBody, token)
if rr.Code != http.StatusBadRequest {
t.Fatalf("Expected 400, got %d. Body: %s", rr.Code, rr.Body.String())
}
var resp ValidationErrorResponse
decodeResponse(t, rr, &resp)
if resp.Field != "type" {
t.Errorf("Expected field 'type', got %q. Body: %s", resp.Field, rr.Body.String())
}
if resp.Error == "" {
t.Errorf("Expected non-empty translated error message. Body: %s", rr.Body.String())
}
})
t.Run("Create weekly habit without specific_days returns field-level error", func(t *testing.T) {
token := registerAndLogin(t, *ts.Router, "weeklyuser@example.com", "Password123!")
reqBody := CreateHabitRequest{
Name: "Cut nails",
Type: "BOOLEAN",
Frequency: "WEEKLY",
}
rr := makeRequest(t, *ts.Router, "POST", "/api/v1/habits", reqBody, token)
if rr.Code != http.StatusBadRequest {
t.Fatalf("Expected 400, got %d. Body: %s", rr.Code, rr.Body.String())
}
var resp ValidationErrorResponse
decodeResponse(t, rr, &resp)
if resp.Field != "specific_days" {
t.Errorf("Expected field 'specific_days', got %q. Body: %s", resp.Field, rr.Body.String())
}
})
t.Run("Access other user's habit", func(t *testing.T) {
otherToken := registerAndLogin(t, *ts.Router, "otheruser@example.com", "Password123!")
@@ -11,6 +11,7 @@ import (
"apocapoc-api/internal/application/commands"
"apocapoc-api/internal/application/queries"
"apocapoc-api/internal/domain/services"
"apocapoc-api/internal/i18n"
"apocapoc-api/internal/infrastructure/auth"
"apocapoc-api/internal/infrastructure/crypto"
@@ -43,14 +44,15 @@ func setupTestServer(t *testing.T) *TestServer {
refreshTokenRepo := sqlite.NewRefreshTokenRepository(db)
passwordResetTokenRepo := sqlite.NewPasswordResetTokenRepository(db)
registerHandler := commands.NewRegisterUserHandler(userRepo, passwordHasher, nil, "", "open", false)
noOpEmail := &services.NoOpEmailService{}
registerHandler := commands.NewRegisterUserHandler(userRepo, passwordHasher, noOpEmail, "", "open", false)
loginHandler := queries.NewLoginUserHandler(userRepo, passwordHasher)
refreshTokenHandler := queries.NewRefreshTokenHandler(refreshTokenRepo, userRepo)
revokeTokenHandler := commands.NewRevokeTokenHandler(refreshTokenRepo)
revokeAllTokensHandler := commands.NewRevokeAllTokensHandler(refreshTokenRepo)
verifyEmailHandler := commands.NewVerifyEmailHandler(userRepo, nil, false)
resendVerificationEmailHandler := commands.NewResendVerificationEmailHandler(userRepo, nil, "")
requestPasswordResetHandler := commands.NewRequestPasswordResetHandler(userRepo, passwordResetTokenRepo, nil, "")
verifyEmailHandler := commands.NewVerifyEmailHandler(userRepo, noOpEmail, false)
resendVerificationEmailHandler := commands.NewResendVerificationEmailHandler(userRepo, noOpEmail, "")
requestPasswordResetHandler := commands.NewRequestPasswordResetHandler(userRepo, passwordResetTokenRepo, noOpEmail, "")
resetPasswordHandler := commands.NewResetPasswordHandler(userRepo, passwordResetTokenRepo, passwordHasher)
createHandler := commands.NewCreateHabitHandler(habitRepo)
getTodaysHandler := queries.NewGetTodaysHabitsHandler(habitRepo, entryRepo)