Files
sure/test/controllers/family_exports_controller_test.rb
Guillem Arias Fauste 5105752bbd feat(sync): family-facing cancellation for syncs, imports, and exports (#2685)
* feat(sync): family-facing cancellation for syncs, imports, and exports

Users had no way to stop or recover any background operation: a
mistaken "Sync all" runs to completion, and an import or export whose
job died (hard worker kills lose in-flight Sidekiq jobs) wedges with a
spinner forever.

Sync cancellation (cooperative — nothing is ever killed):

- New syncs.cancel_requested_at column. Only the cancelled sync
  carries the flag: pending descendants are marked stale immediately
  (their queued jobs no-op via the existing may_start? guard), while
  descendants whose jobs are already executing finish their work
  honestly.
- Family::Syncer stops fanning out child syncs once the flag is set
  (fresh read per iteration — the flag comes from the web process).
- Finalization resolves a cancel-requested sync to stale instead of
  completed, which also skips post-sync (transfer matching, rules,
  broadcasts) via the existing stale gate.
- The `visible` scope excludes cancel-requested syncs, so spinners
  clear immediately and — fixing a latent bug this feature would have
  amplified — sync_later no longer piggybacks a new sync request onto
  a dying sync it would silently swallow.
- Cancel button appears next to "Sync all" on the accounts page while
  a family sync is visible. SyncsController#cancel scopes through
  Sync.for_family with resource_owner, so cross-family ids 404 and
  account-level syncs respect per-user account access.

Stuck import/export self-service:

- Import#force_fail! / FamilyExport#force_fail!: allowed only once the
  record has been idle past PRESUMED_LOST_AFTER (1 hour — dwarfs any
  legitimate run), and applied inside with_lock with a status
  re-check, so a job finishing between page render and button click
  wins. Imports fail into the existing retry path (reverting ->
  revert_failed keeps the revert retryable); PdfImports release their
  processing claim back to pending; exports fail so a new one can be
  created.
- "Mark as failed" buttons appear on the imports/exports index rows
  only when a record is presumed lost, behind the pages' existing
  permission gates (statement-import permission for imports, admin
  for exports).

* fix(sync-cancel): cascade pending cancels, guard late finalizers, scope provider syncs

Review feedback on #2685 (CodeRabbit, Codex):

- request_cancel! now cascades finalization for pending syncs too: a
  pending child resolved to stale never runs its job, so nothing else
  would ever call finalize_if_all_children_finalized — its waiting
  parent hung in syncing until the 24h sweep (CodeRabbit critical)
- SimplefinItem::Syncer#mark_completed re-reads the sync under a row
  lock and skips finalization once cancellation was requested or the
  row went terminal — its in-memory copy predates the cancel, and the
  unguarded complete! (plus the raw status fallback) resurrected a
  cancelled sync and re-ran post-sync (Codex)
- Cancelling provider-item syncs now requires admin: for_family's
  resource_owner only scopes the Account branch, so a restricted member
  could cancel admin-managed provider syncs spanning accounts they
  cannot see. Family- and account-level syncs stay member-cancellable,
  matching the buttons the UI shows (Codex)
- Lost-import error copy moved behind i18n
  (imports.errors.presumed_lost), resolved at call time (CodeRabbit)
- Tests: pending-child cancel finalizes the parent; late provider
  complete! cannot resurrect a cancelled sync; provider-sync
  cancellation is admin-only

* fix(sync-cancel): capture the skipped-finalization case via DebugLogEntry

CodeRabbit round-2: the mark_completed skip (cancelled/terminal sync)
is support-relevant — record it in the super-admin debug UI with the
family and provider attached instead of a raw Rails.logger line.
category: provider_sync, matching the other provider syncers.
2026-07-17 06:57:54 +02:00

196 lines
5.7 KiB
Ruby

require "test_helper"
class FamilyExportsControllerTest < ActionDispatch::IntegrationTest
setup do
@admin = users(:family_admin)
@non_admin = users(:family_member)
@family = @admin.family
sign_in @admin
end
test "non-admin cannot access exports" do
sign_in @non_admin
get new_family_export_path
assert_redirected_to root_path
post family_exports_path
assert_redirected_to root_path
get family_exports_path
assert_redirected_to root_path
end
test "admin can view export modal" do
get new_family_export_path
assert_response :success
assert_select "h2", text: "Export your data"
end
test "admin can mark a lost export as failed" do
export = @family.family_exports.create!
export.update_columns(status: "processing", updated_at: 2.hours.ago)
post cancel_family_export_path(export)
assert_redirected_to family_exports_path
assert_equal "failed", export.reload.status
end
test "cancel refuses an export that is not presumed lost" do
export = @family.family_exports.create!
export.update_columns(status: "processing", updated_at: 5.minutes.ago)
post cancel_family_export_path(export)
assert_equal I18n.t("family_exports.cancel.not_cancellable"), flash[:alert]
assert_equal "processing", export.reload.status
end
test "non-admin cannot cancel an export" do
export = @family.family_exports.create!
export.update_columns(status: "processing", updated_at: 2.hours.ago)
sign_in @non_admin
post cancel_family_export_path(export)
assert_redirected_to root_path
assert_equal "processing", export.reload.status
end
test "admin can create export" do
assert_enqueued_with(job: FamilyDataExportJob) do
post family_exports_path
end
assert_redirected_to family_exports_path
assert_equal "Export started. You'll be able to download it shortly.", flash[:notice]
export = @family.family_exports.last
assert_equal "pending", export.status
end
test "admin can view export list" do
export1 = @family.family_exports.create!(status: "completed")
export2 = @family.family_exports.create!(status: "processing")
get family_exports_path
assert_response :success
assert_match export1.filename, response.body
assert_match "Exporting...", response.body
end
test "admin can download completed export" do
export = @family.family_exports.create!(status: "completed")
export.export_file.attach(
io: StringIO.new("test zip content"),
filename: "test.zip",
content_type: "application/zip"
)
get download_family_export_path(export)
assert_redirected_to(/rails\/active_storage/)
end
test "cannot download incomplete export" do
export = @family.family_exports.create!(status: "processing")
get download_family_export_path(export)
assert_redirected_to family_exports_path
assert_equal "Export not ready for download", flash[:alert]
end
test "admin can delete export" do
export = @family.family_exports.create!(status: "completed")
assert_difference "@family.family_exports.count", -1 do
delete family_export_path(export)
end
assert_redirected_to family_exports_path
assert_equal "Export deleted successfully", flash[:notice]
end
test "admin can delete export with attached file" do
export = @family.family_exports.create!(status: "completed")
export.export_file.attach(
io: StringIO.new("test zip content"),
filename: "test.zip",
content_type: "application/zip"
)
assert export.export_file.attached?
assert_difference "@family.family_exports.count", -1 do
delete family_export_path(export)
end
assert_redirected_to family_exports_path
assert_equal "Export deleted successfully", flash[:notice]
end
test "admin can delete failed export with attached file" do
export = @family.family_exports.create!(status: "failed")
export.export_file.attach(
io: StringIO.new("failed export content"),
filename: "failed.zip",
content_type: "application/zip"
)
assert export.export_file.attached?
assert_difference "@family.family_exports.count", -1 do
delete family_export_path(export)
end
assert_redirected_to family_exports_path
assert_equal "Export deleted successfully", flash[:notice]
end
test "export file is purged when export is deleted" do
export = @family.family_exports.create!(status: "completed")
export.export_file.attach(
io: StringIO.new("test zip content"),
filename: "test.zip",
content_type: "application/zip"
)
# Verify file is attached
assert export.export_file.attached?
file_id = export.export_file.id
# Delete the export
delete family_export_path(export)
# Verify the export record is gone
assert_not FamilyExport.exists?(export.id)
# Verify the Active Storage attachment is also gone
# Note: Active Storage purges files asynchronously with `dependent: :purge_later`
# In tests, we can check that the attachment record is gone
assert_not ActiveStorage::Attachment.exists?(file_id)
end
test "index responds to html with settings layout" do
get family_exports_path
assert_response :success
assert_select "title" # rendered with layout
end
test "index responds to turbo_stream without raising MissingTemplate" do
get family_exports_path, headers: { "Accept" => "text/vnd.turbo-stream.html" }
assert_redirected_to family_exports_path
end
test "non-admin cannot delete export" do
export = @family.family_exports.create!(status: "completed")
sign_in @non_admin
assert_no_difference "@family.family_exports.count" do
delete family_export_path(export)
end
assert_redirected_to root_path
end
end