67 lines
1.7 KiB
PHP
67 lines
1.7 KiB
PHP
<?php
|
|
|
|
namespace Tests\Feature\Auth;
|
|
|
|
use App\Models\User;
|
|
use Illuminate\Support\Facades\Gate;
|
|
use Tests\Support\InsForgeFake;
|
|
use Tests\TestCase;
|
|
|
|
class AuthorizationTest extends TestCase
|
|
{
|
|
private const ADMIN_ONLY_ABILITIES = [
|
|
'manage-products',
|
|
'manage-stock',
|
|
'manage-drivers',
|
|
'manage-users',
|
|
'view-reports',
|
|
'view-activity-logs',
|
|
];
|
|
|
|
private function loginUser(array $profile): User
|
|
{
|
|
InsForgeFake::fakeLoginSuccess($profile);
|
|
|
|
$user = new User;
|
|
$user->forceFill([
|
|
'id' => $profile['id'],
|
|
'name' => $profile['name'],
|
|
'email' => $profile['email'],
|
|
'role' => $profile['role'],
|
|
'is_active' => true,
|
|
]);
|
|
|
|
$this->actingAs($user);
|
|
|
|
return $user;
|
|
}
|
|
|
|
public function test_admin_is_granted_every_ability(): void
|
|
{
|
|
$this->loginUser([
|
|
'id' => '22222222-2222-2222-2222-222222222222',
|
|
'name' => 'Admin',
|
|
'email' => 'admin@beraspro.test',
|
|
'role' => 'admin',
|
|
]);
|
|
|
|
foreach (self::ADMIN_ONLY_ABILITIES as $ability) {
|
|
$this->assertTrue(Gate::allows($ability), "admin should be allowed {$ability}");
|
|
}
|
|
}
|
|
|
|
public function test_operator_is_denied_admin_only_abilities(): void
|
|
{
|
|
$this->loginUser([
|
|
'id' => '33333333-3333-3333-3333-333333333333',
|
|
'name' => 'Operator',
|
|
'email' => 'operator@beraspro.test',
|
|
'role' => 'operator',
|
|
]);
|
|
|
|
foreach (self::ADMIN_ONLY_ABILITIES as $ability) {
|
|
$this->assertTrue(Gate::denies($ability), "operator should be denied {$ability}");
|
|
}
|
|
}
|
|
}
|