Acme ships rockets fast.
user = User::factory()->create([]); $this->workspace = Workspace::factory()->create(['user_id' => $this->user->id]); $this->workspace->members()->attach($this->user->id, ['role' => Role::Member->value]); $this->user->update(['current_workspace_id' => $this->workspace->id]); }); // Index tests test('workspaces index requires authentication', function () { $response = $this->get(route('app.workspaces.index')); $response->assertRedirect(route('login')); }); test('workspaces index shows all workspaces for user', function () { $workspaces = Workspace::factory()->count(2)->create(['user_id' => $this->user->id]); foreach ($workspaces as $workspace) { $workspace->members()->attach($this->user->id, ['role' => Role::Member->value]); } $response = $this->actingAs($this->user)->get(route('app.workspaces.index')); $response->assertOk(); $response->assertInertia(fn ($page) => $page ->component('workspaces/Index', false) ->has('workspaces', 3) ->has('currentWorkspaceId') ); }); // Create tests test('create workspace requires authentication', function () { $response = $this->get(route('app.workspaces.create')); $response->assertRedirect(route('login')); }); test('create workspace shows form for user with no workspaces', function () { // Delete existing workspace so user has none $this->user->update(['current_workspace_id' => null]); $this->workspace->delete(); $response = $this->actingAs($this->user)->get(route('app.workspaces.create')); $response->assertOk(); $response->assertInertia(fn ($page) => $page ->component('workspaces/Create', false) ->has('availableContentLanguages', count(ContentLanguage::cases())) ->where('availableContentLanguages.0', ['value' => 'en', 'label' => 'English', 'englishName' => 'English']) ); }); test('create workspace shows form when user already has workspace in self-hosted mode', function () { config(['trypost.self_hosted' => true]); $response = $this->actingAs($this->user)->get(route('app.workspaces.create')); $response->assertOk(); $response->assertInertia(fn ($page) => $page ->component('workspaces/Create', false) ); }); // Store tests test('store workspace requires authentication', function () { $response = $this->post(route('app.workspaces.store'), ['name' => 'Test Workspace']); $response->assertRedirect(route('login')); }); test('store workspace creates first workspace', function () { // Delete existing workspace so user has none $this->user->update(['current_workspace_id' => null]); $this->workspace->delete(); $response = $this->actingAs($this->user)->post(route('app.workspaces.store'), [ 'name' => 'New Workspace', ]); $response->assertRedirect(route('app.accounts')); $this->assertDatabaseHas('workspaces', [ 'name' => 'New Workspace', 'user_id' => $this->user->id, ]); }); test('store workspace creates second workspace in self-hosted mode', function () { config(['trypost.self_hosted' => true]); $response = $this->actingAs($this->user)->post(route('app.workspaces.store'), [ 'name' => 'Second Workspace', ]); $response->assertRedirect(route('app.accounts')); $this->assertDatabaseHas('workspaces', [ 'name' => 'Second Workspace', 'user_id' => $this->user->id, ]); }); test('store workspace validates name is required', function () { $response = $this->actingAs($this->user)->post(route('app.workspaces.store'), [ 'name' => '', ]); $response->assertSessionHasErrors('name'); }); test('store workspace sets new workspace as current', function () { // Delete existing workspace so user has none $this->user->update(['current_workspace_id' => null]); $this->workspace->delete(); $this->actingAs($this->user)->post(route('app.workspaces.store'), [ 'name' => 'New Workspace', ]); $this->user->refresh(); $newWorkspace = Workspace::where('name', 'New Workspace')->first(); expect($this->user->current_workspace_id)->toBe($newWorkspace->id); }); // Switch tests test('switch workspace requires authentication', function () { $response = $this->post(route('app.workspaces.switch', $this->workspace)); $response->assertRedirect(route('login')); }); test('switch workspace changes current workspace', function () { $otherWorkspace = Workspace::factory()->create(['user_id' => $this->user->id]); $otherWorkspace->members()->attach($this->user->id, ['role' => Role::Member->value]); $response = $this->actingAs($this->user)->post(route('app.workspaces.switch', $otherWorkspace)); $response->assertRedirect(route('app.calendar')); $this->user->refresh(); expect($this->user->current_workspace_id)->toBe($otherWorkspace->id); }); test('switch workspace returns 403 for workspace user does not belong to', function () { $otherUser = User::factory()->create([]); $otherWorkspace = Workspace::factory()->create(['user_id' => $otherUser->id]); $response = $this->actingAs($this->user)->post(route('app.workspaces.switch', $otherWorkspace)); $response->assertForbidden(); }); // Settings tests test('workspace settings requires authentication', function () { $response = $this->get(route('app.workspace.settings')); $response->assertRedirect(route('login')); }); test('workspace settings shows the workspace settings page', function () { $response = $this->actingAs($this->user)->get(route('app.workspace.settings')); $response->assertOk(); $response->assertInertia(fn ($page) => $page ->component('settings/workspace/Workspace', false) ->has('workspace') ); }); test('brand settings shows the brand settings page', function () { $response = $this->actingAs($this->user)->get(route('app.workspace.brand')); $response->assertOk(); $response->assertInertia(fn ($page) => $page ->component('settings/workspace/Brand', false) ->has('workspace') ->has('availableContentLanguages', count(ContentLanguage::cases())) ); }); test('workspace settings redirects to create if no workspace', function () { $this->user->update(['current_workspace_id' => null]); $response = $this->actingAs($this->user)->get(route('app.workspace.settings')); $response->assertRedirect(route('app.workspaces.create')); }); // Update settings tests test('update workspace settings requires authentication', function () { $response = $this->put(route('app.workspace.settings.update'), [ 'name' => 'Updated Name', ]); $response->assertRedirect(route('login')); }); test('update workspace settings updates workspace and redirects back', function () { $response = $this->actingAs($this->user) ->from(route('app.workspace.brand')) ->put(route('app.workspace.settings.update'), [ 'name' => 'Updated Name', 'brand_font' => 'Inter', 'image_style' => 'cinematic', ]); $response->assertRedirect(route('app.workspace.brand')); $this->workspace->refresh(); expect($this->workspace->name)->toBe('Updated Name'); }); test('update workspace settings persists brand voice traits', function () { $this->actingAs($this->user) ->from(route('app.workspace.brand')) ->put(route('app.workspace.settings.update'), [ 'name' => $this->workspace->name, 'brand_font' => 'Inter', 'image_style' => 'cinematic', 'brand_voice_traits' => ['third_person', 'no_hype', 'data_driven'], ])->assertRedirect(route('app.workspace.brand')); expect($this->workspace->refresh()->brand_voice_traits)->toBe(['third_person', 'no_hype', 'data_driven']); }); test('update workspace settings rejects an unknown brand voice trait', function () { $this->actingAs($this->user) ->from(route('app.workspace.brand')) ->put(route('app.workspace.settings.update'), [ 'name' => $this->workspace->name, 'brand_font' => 'Inter', 'image_style' => 'cinematic', 'brand_voice_traits' => ['third_person', 'not_a_real_trait'], ])->assertSessionHasErrors('brand_voice_traits.1'); }); test('update workspace settings persists the image_style choice', function () { $this->actingAs($this->user) ->from(route('app.workspace.brand')) ->put(route('app.workspace.settings.update'), [ 'name' => $this->workspace->name, 'brand_font' => 'Inter', 'image_style' => 'minimalist', ])->assertRedirect(route('app.workspace.brand')); expect($this->workspace->refresh()->image_style->value)->toBe('minimalist'); }); test('update workspace settings updates the name when only the name is submitted', function () { $this->actingAs($this->user) ->from(route('app.workspace.settings')) ->put(route('app.workspace.settings.update'), [ 'name' => 'Name Only Update', ]) ->assertRedirect(route('app.workspace.settings')) ->assertSessionHasNoErrors(); expect($this->workspace->refresh()->name)->toBe('Name Only Update'); }); test('update workspace settings still requires brand_font and image_style when submitted empty', function () { $this->actingAs($this->user) ->put(route('app.workspace.settings.update'), [ 'name' => $this->workspace->name, 'brand_font' => '', 'image_style' => '', ])->assertSessionHasErrors(['brand_font', 'image_style']); }); test('update workspace settings rejects unknown image_style values', function () { $this->actingAs($this->user) ->put(route('app.workspace.settings.update'), [ 'name' => $this->workspace->name, 'brand_font' => 'Inter', 'image_style' => 'pixel-art', ])->assertSessionHasErrors(['image_style']); }); test('update workspace settings persists a newly supported content language', function () { $this->actingAs($this->user) ->from(route('app.workspace.brand')) ->put(route('app.workspace.settings.update'), [ 'name' => $this->workspace->name, 'content_language' => 'fr', ])->assertRedirect(route('app.workspace.brand')) ->assertSessionHasNoErrors(); expect($this->workspace->refresh()->content_language)->toBe('fr'); }); test('update workspace settings rejects an unsupported content language', function () { $this->actingAs($this->user) ->put(route('app.workspace.settings.update'), [ 'name' => $this->workspace->name, 'content_language' => 'sv', ])->assertSessionHasErrors(['content_language']); }); test('update workspace settings validates required fields', function () { $response = $this->actingAs($this->user)->put(route('app.workspace.settings.update'), [ 'name' => '', ]); $response->assertSessionHasErrors(['name']); }); // Logo upload tests test('upload workspace logo requires authentication', function () { $response = $this->post(route('app.workspace.upload-logo'), [ 'photo' => UploadedFile::fake()->image('logo.jpg'), ]); $response->assertRedirect(route('login')); }); test('upload workspace logo succeeds with valid image', function () { $response = $this->actingAs($this->user)->post(route('app.workspace.upload-logo'), [ 'photo' => UploadedFile::fake()->image('logo.jpg', 200, 200), ]); $response->assertRedirect(); $this->workspace->refresh(); expect($this->workspace->has_logo)->toBeTrue(); expect($this->workspace->logo_url)->not->toBeNull(); }); test('upload workspace logo validates file is an image', function () { $response = $this->actingAs($this->user)->post(route('app.workspace.upload-logo'), [ 'photo' => UploadedFile::fake()->create('document.pdf', 100), ]); $response->assertSessionHasErrors('photo'); }); test('upload workspace logo validates max size', function () { $response = $this->actingAs($this->user)->post(route('app.workspace.upload-logo'), [ 'photo' => UploadedFile::fake()->image('logo.jpg')->size(3000), ]); $response->assertSessionHasErrors('photo'); }); test('upload workspace logo requires authorization', function () { $otherUser = User::factory()->create([]); $otherWorkspace = Workspace::factory()->create(['user_id' => $otherUser->id]); $otherWorkspace->members()->attach($otherUser->id, ['role' => Role::Member->value]); $otherUser->update(['current_workspace_id' => $otherWorkspace->id]); $otherUser->account->subscriptions()->create([ 'type' => Account::SUBSCRIPTION_NAME, 'stripe_id' => 'sub_test_'.fake()->uuid(), 'stripe_status' => 'active', 'stripe_price' => 'price_123', ]); // otherUser is account owner of their own account/workspace, so policy 'update' passes for their own workspace. // Switch their current workspace to the original $this->workspace (which they don't own) to trigger forbidden. $otherUser->update(['current_workspace_id' => $this->workspace->id]); $response = $this->actingAs($otherUser)->post(route('app.workspace.upload-logo'), [ 'photo' => UploadedFile::fake()->image('logo.jpg'), ]); $response->assertForbidden(); }); test('delete workspace logo requires authentication', function () { $response = $this->delete(route('app.workspace.delete-logo')); $response->assertRedirect(route('login')); }); test('delete workspace logo succeeds', function () { // Upload first $this->actingAs($this->user)->post(route('app.workspace.upload-logo'), [ 'photo' => UploadedFile::fake()->image('logo.jpg', 200, 200), ]); $this->workspace->refresh(); expect($this->workspace->has_logo)->toBeTrue(); // Delete $response = $this->actingAs($this->user)->delete(route('app.workspace.delete-logo')); $response->assertRedirect(); $this->workspace->refresh(); expect($this->workspace->has_logo)->toBeFalse(); }); test('delete workspace logo requires authorization', function () { $otherUser = User::factory()->create([]); $otherWorkspace = Workspace::factory()->create(['user_id' => $otherUser->id]); $otherWorkspace->members()->attach($otherUser->id, ['role' => Role::Member->value]); $otherUser->update(['current_workspace_id' => $otherWorkspace->id]); $otherUser->account->subscriptions()->create([ 'type' => Account::SUBSCRIPTION_NAME, 'stripe_id' => 'sub_test_'.fake()->uuid(), 'stripe_status' => 'active', 'stripe_price' => 'price_123', ]); $otherUser->update(['current_workspace_id' => $this->workspace->id]); $response = $this->actingAs($otherUser)->delete(route('app.workspace.delete-logo')); $response->assertForbidden(); }); // Destroy tests test('destroy workspace requires authentication', function () { $response = $this->delete(route('app.workspaces.destroy', $this->workspace)); $response->assertRedirect(route('login')); }); test('destroy workspace deletes the workspace', function () { Workspace::factory()->create([ 'account_id' => $this->user->account_id, 'user_id' => $this->user->id, ]); $workspaceId = $this->workspace->id; $response = $this->actingAs($this->user)->delete(route('app.workspaces.destroy', $this->workspace)); $response->assertRedirect(route('app.workspaces.index')); expect(Workspace::find($workspaceId))->toBeNull(); }); test('destroy workspace clears current workspace if deleting current', function () { Workspace::factory()->create([ 'account_id' => $this->user->account_id, 'user_id' => $this->user->id, ]); $this->actingAs($this->user)->delete(route('app.workspaces.destroy', $this->workspace)); $this->user->refresh(); expect($this->user->current_workspace_id)->toBeNull(); }); test('destroy workspace reassigns current to another joined workspace', function () { $other = Workspace::factory()->create(['user_id' => $this->user->id]); $other->members()->attach($this->user->id, ['role' => Role::Member->value]); $this->actingAs($this->user)->delete(route('app.workspaces.destroy', $this->workspace)); $this->user->refresh(); expect($this->user->current_workspace_id)->toBe($other->id); }); test('destroy workspace is blocked when it is the only workspace', function () { config(['trypost.self_hosted' => false]); $this->user->account->subscriptions()->create([ 'type' => Account::SUBSCRIPTION_NAME, 'stripe_id' => 'sub_test_'.fake()->uuid(), 'stripe_status' => 'active', 'stripe_price' => 'price_123', ]); $workspaceId = $this->workspace->id; $response = $this->actingAs($this->user)->delete(route('app.workspaces.destroy', $this->workspace)); $response->assertSessionHas('flash.error', __('workspaces.cannot_delete_last')); expect(Workspace::find($workspaceId))->not->toBeNull(); }); test('destroy workspace allows deleting the only workspace in self-hosted mode', function () { config(['trypost.self_hosted' => true]); $workspaceId = $this->workspace->id; $response = $this->actingAs($this->user)->delete(route('app.workspaces.destroy', $this->workspace)); $response->assertRedirect(route('app.workspaces.index')); expect(Workspace::find($workspaceId))->toBeNull(); }); test('destroy workspace returns 403 for non-owner', function () { $otherUser = User::factory()->create([]); $otherWorkspace = Workspace::factory()->create(['user_id' => $otherUser->id]); $otherWorkspace->members()->attach($otherUser->id, ['role' => Role::Member->value]); $otherUser->update(['current_workspace_id' => $otherWorkspace->id]); $otherUser->account->subscriptions()->create([ 'type' => Account::SUBSCRIPTION_NAME, 'stripe_id' => 'sub_test_'.fake()->uuid(), 'stripe_status' => 'active', 'stripe_price' => 'price_123', ]); $response = $this->actingAs($otherUser)->delete(route('app.workspaces.destroy', $this->workspace)); $response->assertForbidden(); }); // Autofill brand tests test('autofillBrand returns metadata without persisting anything', function () { $account = Account::factory()->create(); $user = User::factory()->create(['account_id' => $account->id]); $account->update(['owner_id' => $user->id]); Http::fake([ 'example.com/*' => Http::response( '
Acme ships rockets fast.