const axios = require('axios'); const BASE_URL = 'http://localhost:9000'; async function runTests() { console.log('=== STARTING INTEGRATION TESTS FOR MENTOR TASK MANAGEMENT ===\n'); let adminToken = ''; let mentorToken = ''; let otherMentorToken = ''; let createdProjectId = null; let otherProjectId = null; let taskId = null; const mentorEmail = `mentor_task_${Date.now()}@internify.com`; const otherMentorEmail = `other_mentor_task_${Date.now()}@internify.com`; const mentorPassword = 'Password123'; // Helper config generator const getHeader = (token) => ({ headers: { Authorization: `Bearer ${token}` } }); try { // 1. Login as Admin console.log('1. Logging in as Admin (admin1@internify.com)...'); const loginRes = await axios.post(`${BASE_URL}/auth-api/login`, { email: 'admin1@internify.com', password: 'password123' }); adminToken = loginRes.data.data.token; console.log(' Admin logged in successfully!\n'); // 2. Create Mentor Accounts via Admin API console.log(`2. Creating mentor accounts...`); await axios.post(`${BASE_URL}/admin-api/add`, { nama_depan: 'John', nama_belakang: 'MentorTask', email: mentorEmail, password: mentorPassword, role: 'mentor' }, getHeader(adminToken)); await axios.post(`${BASE_URL}/admin-api/add`, { nama_depan: 'Jane', nama_belakang: 'OtherMentorTask', email: otherMentorEmail, password: mentorPassword, role: 'mentor' }, getHeader(adminToken)); console.log(' Mentor accounts created successfully!\n'); // 3. Login as Mentors console.log('3. Logging in as mentors...'); const mentorLoginRes = await axios.post(`${BASE_URL}/auth-api/login`, { email: mentorEmail, password: mentorPassword }); mentorToken = mentorLoginRes.data.data.token; const otherMentorLoginRes = await axios.post(`${BASE_URL}/auth-api/login`, { email: otherMentorEmail, password: mentorPassword }); otherMentorToken = otherMentorLoginRes.data.data.token; console.log(' Mentors logged in successfully!\n'); // 4. Mentors create projects console.log('4. Creating projects for mentors...'); const createProjectRes = await axios.post(`${BASE_URL}/project-api/add`, { project_icon: 'code', project_name: `Mentor's Project - ${Date.now()}`, description: 'Project to test mentor task permissions.', start_date: '2026-07-01', end_date: '2026-10-01', member_emails: [] }, getHeader(mentorToken)); createdProjectId = createProjectRes.data.data.id; const otherProjectRes = await axios.post(`${BASE_URL}/project-api/add`, { project_icon: 'shield', project_name: `Other Mentor's Project - ${Date.now()}`, description: 'Project owned by another mentor.', start_date: '2026-07-01', end_date: '2026-10-01', member_emails: [] }, getHeader(otherMentorToken)); otherProjectId = otherProjectRes.data.data.id; console.log(` Projects created: Mentor Project ID = ${createdProjectId}, Other Project ID = ${otherProjectId}\n`); // 5. Mentor creates a task in their project console.log(`5. Mentor creating task in project ID ${createdProjectId}...`); const createTaskRes = await axios.post(`${BASE_URL}/task-api/projects/${createdProjectId}/tasks`, { title: 'Task 1', description: 'First task created by mentor.', deadline_date: '2026-08-01', specific_time: '23:59', submission_type: 'url_link' }, getHeader(mentorToken)); taskId = createTaskRes.data.data.id; console.log(` Task created successfully! ID: ${taskId}\n`); // 6. Mentor tries to create task in project they do not own console.log(`6. Testing isolation: Mentor trying to create task in project ID ${otherProjectId} (owned by other mentor)...`); try { await axios.post(`${BASE_URL}/task-api/projects/${otherProjectId}/tasks`, { title: 'Task in other project', description: 'Should fail.', deadline_date: '2026-08-01', specific_time: '23:59', submission_type: 'url_link' }, getHeader(mentorToken)); throw new Error('TEST FAILED: Mentor created a task in a project they do not own!'); } catch (err) { if (err.response && err.response.status === 403) { console.log(' PASSED: Access denied with 403 Forbidden as expected.\n'); } else { throw err; } } // 7. Mentor retrieves task list of their project console.log(`7. Mentor retrieving task list for project ID ${createdProjectId}...`); const getTasksRes = await axios.get(`${BASE_URL}/task-api/projects/${createdProjectId}/tasks`, getHeader(mentorToken)); const tasks = getTasksRes.data.data; console.log(` Tasks found: ${tasks.length}`); if (tasks.length !== 1 || tasks[0].id !== taskId) { throw new Error('TEST FAILED: Task list not retrieved correctly by mentor!'); } console.log(' PASSED: Task list retrieved successfully.\n'); // 8. Mentor retrieves details of their task console.log(`8. Mentor retrieving details of task ID ${taskId}...`); const getTaskDetailRes = await axios.get(`${BASE_URL}/task-api/tasks/${taskId}`, getHeader(mentorToken)); const taskDetail = getTaskDetailRes.data.data; // Mentor should get admin-like details including the submission_summary and submissions list. // Let's verify if submission_summary exists in response. console.log(' Retrieved detail data fields:', Object.keys(taskDetail)); if (!taskDetail.submission_summary) { throw new Error('TEST FAILED: Mentor retrieved detail as an intern (missing submission_summary)!'); } console.log(' PASSED: Mentor successfully retrieved detailed view of the task with submission summary.\n'); // 9. Mentor updates their task console.log(`9. Mentor updating task ID ${taskId}...`); await axios.patch(`${BASE_URL}/task-api/tasks/${taskId}`, { title: 'Task 1 Updated', description: 'Updated description by mentor.' }, getHeader(mentorToken)); console.log(' PASSED: Task updated successfully.\n'); // 10. Mentor tries to update task they do not own // Let's create a task in the other project first const otherTaskRes = await axios.post(`${BASE_URL}/task-api/projects/${otherProjectId}/tasks`, { title: 'Other Task', description: 'Task by other mentor.', deadline_date: '2026-08-01', specific_time: '23:59', submission_type: 'url_link' }, getHeader(otherMentorToken)); const otherTaskId = otherTaskRes.data.data.id; console.log(`10. Testing isolation: Mentor trying to update task ID ${otherTaskId}...`); try { await axios.patch(`${BASE_URL}/task-api/tasks/${otherTaskId}`, { title: 'Unauthorized Update' }, getHeader(mentorToken)); throw new Error('TEST FAILED: Mentor updated a task they do not own!'); } catch (err) { if (err.response && err.response.status === 403) { console.log(' PASSED: Access denied with 403 Forbidden as expected.\n'); } else { throw err; } } // 11. Mentor deletes their task console.log(`11. Mentor deleting task ID ${taskId}...`); await axios.delete(`${BASE_URL}/task-api/tasks/${taskId}`, getHeader(mentorToken)); console.log(' PASSED: Task deleted successfully.\n'); // 12. Mentor tries to delete task they do not own console.log(`12. Testing isolation: Mentor trying to delete task ID ${otherTaskId}...`); try { await axios.delete(`${BASE_URL}/task-api/tasks/${otherTaskId}`, getHeader(mentorToken)); throw new Error('TEST FAILED: Mentor deleted a task they do not own!'); } catch (err) { if (err.response && err.response.status === 403) { console.log(' PASSED: Access denied with 403 Forbidden as expected.\n'); } else { throw err; } } console.log('=== ALL INTEGRATION TESTS PASSED SUCCESSFULLY! ==='); } catch (err) { console.error('=== TEST EXECUTION ENCOUNTERED AN ERROR ==='); if (err.response) { console.error(`Status: ${err.response.status}`); console.error('Response Data:', JSON.stringify(err.response.data, null, 2)); } else { console.error(err); } process.exit(1); } } runTests();