seed(RolePermissionSeeder::class); } public function test_tenant_owner_can_create_update_reset_and_disable_user(): void { [$tenant, $owner] = $this->tenantWithOwner('tenant-a'); $this->actingAs($owner)->post(route('administration.users.store', $tenant), [ 'name' => 'NOC Operator', 'email' => 'noc@example.test', 'password' => 'Strong!Password123', 'password_confirmation' => 'Strong!Password123', ])->assertRedirect(route('administration.users.index', $tenant)); $user = User::withoutGlobalScope('tenant')->where('email', 'noc@example.test')->firstOrFail(); $this->assertSame($tenant->id, $user->tenant_id); setPermissionsTeamId($tenant->id); $this->assertTrue($user->hasRole('TENANT USER')); $this->actingAs($owner)->put(route('administration.users.password', [$tenant, $user]), [ 'password' => 'Changed!Password123', 'password_confirmation' => 'Changed!Password123', ])->assertRedirect(); $this->assertTrue(Hash::check('Changed!Password123', $user->fresh()->password)); $this->actingAs($owner)->patch(route('administration.users.toggle-active', [$tenant, $user]))->assertRedirect(); $this->assertFalse($user->fresh()->is_active); } public function test_tenant_owner_cannot_access_other_tenant_administration(): void { [, $ownerA] = $this->tenantWithOwner('tenant-a'); [$tenantB] = $this->tenantWithOwner('tenant-b'); $this->actingAs($ownerA)->get(route('administration.users.index', $tenantB))->assertForbidden(); } public function test_tenant_admin_is_protected_from_deletion(): void { [$tenant, $owner] = $this->tenantWithOwner('tenant-a'); $this->actingAs(User::factory()->create(['is_platform_admin' => true])) ->delete(route('administration.users.destroy', [$tenant, $owner])) ->assertStatus(422); } public function test_tenant_admin_cannot_manage_another_tenant_admin(): void { [$tenant, $admin] = $this->tenantWithOwner('tenant-a'); $this->actingAs($admin) ->get(route('administration.users.edit', [$tenant, $admin])) ->assertForbidden(); } /** @return array{Tenant, User} */ private function tenantWithOwner(string $slug): array { $tenant = app(TenantProvisioningService::class)->createWithOwner([ 'name' => strtoupper($slug), 'slug' => $slug, 'owner_name' => 'Owner '.$slug, 'owner_email' => $slug.'@example.test', 'owner_password' => 'Strong!Password123', ]); return [$tenant, User::withoutGlobalScope('tenant')->where('tenant_id', $tenant->id)->firstOrFail()]; } }