feat: phase 1 — InsForge session auth, role gates, refresh middleware, auth test suites
This commit is contained in:
@@ -0,0 +1,109 @@
|
||||
<?php
|
||||
|
||||
namespace Tests\Feature\Auth;
|
||||
|
||||
use App\Models\User;
|
||||
use App\Services\InsForge\InsForgeAuthService;
|
||||
use Filament\Auth\Pages\Login;
|
||||
use Illuminate\Support\Facades\Session;
|
||||
use Livewire\Livewire;
|
||||
use Tests\Support\InsForgeFake;
|
||||
use Tests\TestCase;
|
||||
|
||||
class AuthenticationTest extends TestCase
|
||||
{
|
||||
private function adminProfile(array $overrides = []): array
|
||||
{
|
||||
return array_merge([
|
||||
'id' => '11111111-1111-1111-1111-111111111111',
|
||||
'name' => 'Admin BerasPro',
|
||||
'email' => 'admin@beraspro.test',
|
||||
'password' => '$2y$04$hash',
|
||||
'role' => 'admin',
|
||||
'is_active' => true,
|
||||
], $overrides);
|
||||
}
|
||||
|
||||
public function test_login_page_renders_for_guest(): void
|
||||
{
|
||||
$this->get('/admin/login')->assertOk();
|
||||
}
|
||||
|
||||
public function test_unauthenticated_user_is_redirected_to_login(): void
|
||||
{
|
||||
$this->get('/admin')->assertRedirect('/admin/login');
|
||||
}
|
||||
|
||||
public function test_user_can_login_with_valid_credentials(): void
|
||||
{
|
||||
InsForgeFake::fakeLoginSuccess($this->adminProfile());
|
||||
|
||||
Livewire::test(Login::class)
|
||||
->fillForm(['email' => 'admin@beraspro.test', 'password' => 'secret'])
|
||||
->call('authenticate')
|
||||
->assertHasNoErrors();
|
||||
|
||||
$this->assertAuthenticated();
|
||||
|
||||
$this->assertSame(
|
||||
InsForgeFake::$accessToken,
|
||||
Session::get(InsForgeAuthService::SESSION_ACCESS_TOKEN),
|
||||
);
|
||||
|
||||
$user = auth()->user();
|
||||
|
||||
$this->assertInstanceOf(User::class, $user);
|
||||
$this->assertTrue($user->isAdmin());
|
||||
}
|
||||
|
||||
public function test_mirror_profile_is_created_when_missing(): void
|
||||
{
|
||||
InsForgeFake::fakeLoginSuccess($this->adminProfile());
|
||||
unset(InsForgeFake::$profiles['admin@beraspro.test']);
|
||||
|
||||
Livewire::test(Login::class)
|
||||
->fillForm(['email' => 'admin@beraspro.test', 'password' => 'secret'])
|
||||
->call('authenticate');
|
||||
|
||||
$this->assertArrayHasKey('admin@beraspro.test', InsForgeFake::$profiles);
|
||||
$this->assertSame('operator', InsForgeFake::$profiles['admin@beraspro.test']['role']);
|
||||
}
|
||||
|
||||
public function test_invalid_credentials_do_not_authenticate(): void
|
||||
{
|
||||
InsForgeFake::fakeLoginFailure();
|
||||
|
||||
Livewire::test(Login::class)
|
||||
->fillForm(['email' => 'admin@beraspro.test', 'password' => 'wrong'])
|
||||
->call('authenticate')
|
||||
->assertHasErrors();
|
||||
|
||||
$this->assertGuest();
|
||||
}
|
||||
|
||||
public function test_inactive_user_cannot_access_panel(): void
|
||||
{
|
||||
InsForgeFake::fakeLoginSuccess($this->adminProfile(['is_active' => false]));
|
||||
|
||||
Livewire::test(Login::class)
|
||||
->fillForm(['email' => 'admin@beraspro.test', 'password' => 'secret'])
|
||||
->call('authenticate');
|
||||
|
||||
$this->get('/admin')->assertRedirect('/admin/login');
|
||||
$this->assertGuest();
|
||||
}
|
||||
|
||||
public function test_logout_clears_insforge_tokens(): void
|
||||
{
|
||||
InsForgeFake::fakeLoginSuccess($this->adminProfile());
|
||||
|
||||
Livewire::test(Login::class)
|
||||
->fillForm(['email' => 'admin@beraspro.test', 'password' => 'secret'])
|
||||
->call('authenticate');
|
||||
|
||||
$this->post('/admin/logout');
|
||||
|
||||
$this->assertGuest();
|
||||
$this->assertNull(Session::get(InsForgeAuthService::SESSION_ACCESS_TOKEN));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,66 @@
|
||||
<?php
|
||||
|
||||
namespace Tests\Feature\Auth;
|
||||
|
||||
use App\Models\User;
|
||||
use Illuminate\Support\Facades\Gate;
|
||||
use Tests\Support\InsForgeFake;
|
||||
use Tests\TestCase;
|
||||
|
||||
class AuthorizationTest extends TestCase
|
||||
{
|
||||
private const ADMIN_ONLY_ABILITIES = [
|
||||
'manage-products',
|
||||
'manage-stock',
|
||||
'manage-drivers',
|
||||
'manage-users',
|
||||
'view-reports',
|
||||
'view-activity-logs',
|
||||
];
|
||||
|
||||
private function loginUser(array $profile): User
|
||||
{
|
||||
InsForgeFake::fakeLoginSuccess($profile);
|
||||
|
||||
$user = new User;
|
||||
$user->forceFill([
|
||||
'id' => $profile['id'],
|
||||
'name' => $profile['name'],
|
||||
'email' => $profile['email'],
|
||||
'role' => $profile['role'],
|
||||
'is_active' => true,
|
||||
]);
|
||||
|
||||
$this->actingAs($user);
|
||||
|
||||
return $user;
|
||||
}
|
||||
|
||||
public function test_admin_is_granted_every_ability(): void
|
||||
{
|
||||
$this->loginUser([
|
||||
'id' => '22222222-2222-2222-2222-222222222222',
|
||||
'name' => 'Admin',
|
||||
'email' => 'admin@beraspro.test',
|
||||
'role' => 'admin',
|
||||
]);
|
||||
|
||||
foreach (self::ADMIN_ONLY_ABILITIES as $ability) {
|
||||
$this->assertTrue(Gate::allows($ability), "admin should be allowed {$ability}");
|
||||
}
|
||||
}
|
||||
|
||||
public function test_operator_is_denied_admin_only_abilities(): void
|
||||
{
|
||||
$this->loginUser([
|
||||
'id' => '33333333-3333-3333-3333-333333333333',
|
||||
'name' => 'Operator',
|
||||
'email' => 'operator@beraspro.test',
|
||||
'role' => 'operator',
|
||||
]);
|
||||
|
||||
foreach (self::ADMIN_ONLY_ABILITIES as $ability) {
|
||||
$this->assertTrue(Gate::denies($ability), "operator should be denied {$ability}");
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user