trypost/tests/Feature/Mcp/OAuthRegistrationTest.php
Paulo Castellano a1fa897106
Activation checklist + MCP OAuth authorize UX (#239) (#250)
* Wire onboarding activation into Account, observers, and shared Inertia data

Add onboarding casts/hasFinishedOnboarding, AccessToken ObservedBy,
Platform::connectableOptions, Post/SocialAccount onboarding broadcast hooks,
and lazy onboardingResidual share + SharedData types.

* Register onboarding routes and post-checkout activation redirects.

Wire billing processing and the sidebar checklist so owners land on
activation after subscribe, with locale sidebar/uk onboarding strings.

* Align MCP grant usability with onboarding activation checks

Unbound MCP tokens fall back to the user's current workspace and require
createPost so viewer/unscoped grants neither unlock the checklist nor
broadcast onboarding status.

* Require bound MCP workspace for onboarding activation.

Drop current-workspace fallback from usable MCP grants so checklist
detection and broadcasts match Passport token scoping; viewers still
cannot unlock the MCP step.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Harden onboarding review findings and tighten locale strings.

Fix Welcome/Persona/TrackPost suites broken by the activation route reuse
and PostObserver analytics side effects, restore Echo poll fallbacks,
reject unbound MCP grants in tests, and drop unused onboarding.mcp keys.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Remove unused sidebar and MCP authorization locale keys.

Drop dead sidebar menu/theme strings (including the overwritten
workspace label and api_keys nav entry) and unused MCP authorize
app_title/approving copy across all locales.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix SetLocale crashing on Passport Symfony OAuth responses.

OAuth errors return a raw Symfony Response without withCookie(); attach
the default locale cookie via headers so authorize no longer 500s.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Prompt OAuth guests to log in before rejecting unknown clients.

MCP Inspector often reuses a stale client_id; validateAuthorizationRequest
was returning invalid_client JSON before the login redirect. Guests now
hit /login first, then client validation runs after authentication.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Render Inertia OAuth authorize errors for browser logins.

After login, Inertia follows the intended authorize URL; raw invalid_client
JSON broke that visit. HTML/Inertia requests now get mcp/AuthorizeError
while API JSON clients still receive the OAuth error payload.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Detect Inertia OAuth error pages via Request::inertia().

Use the framework helper so post-login authorize failures keep returning
an Inertia page instead of raw OAuth JSON.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify OAuth authorize error page detection to expectsJson.

Drop the X-Inertia header sniff; browser and Inertia visits already do
not expectsJson, while API clients still receive the OAuth JSON payload.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Share MCP authorize layout and drop the error close button.

Keep authorize and authorize-error on the same centered card shell instead of the auth split layout.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify onboarding activation for reviewability and safety.

Use an exists-based MCP check, keep GETs read-only, move sync into
syncAndNotify, clear MCP skips on connect, restrict complete to owners,
and share Echo/poll via one composable.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Move MCP OAuth authorize UX out of the onboarding PR.

Keep the activation checklist focused; OAuth guest/error-page work now
lives on fix/mcp-oauth-authorize-ux.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix corrupted French MCP locale after OAuth key cleanup.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Restore MCP OAuth authorize UX onto the onboarding branch.

Keep authorize error page, guest login-before-client validation, and
SetLocale Symfony cookie fix in #250.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix OAuth prompt=none redirects and harden onboarding tests.

Keep login_required/consent_required as redirects instead of Inertia,
add regression coverage for owner-only activation, require invite email
confirmation, and align MCP connected apps with the sessions list UI.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify onboarding guards and dedupe viewed analytics.

Introduce isOnboardingOpen / belongsToAccount helpers, collapse
duplicated sync/dispatch paths, and capture onboarding.viewed once
per account.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify onboarding event, observers, and status helpers.

Tighten Account onboarding predicates, drop nullable broadcast/dispatch
APIs, and collapse repeated observer/controller guards.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Treat in-app users as always having an account.

Add resolveAccount(), tighten belongsToAccount to string ids, and fold
guest residual handling into ResolveOnboardingStatus.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Rename onboarding residual share test to progress.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify onboarding status and rename residual to progress.

Use accountOrFail, extract MCP onboarding scope, auto-leave the ready
screen, and send non-onboarding checkout back to accounts.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Extract HasAccount and prefer data_get in onboarding flows.

Move account helpers off User, drop nullable sidebarProgress, and
read OAuth/onboarding payloads with data_get.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify onboarding checks and extract HasOnboarding.

Use Eloquent + policies for MCP/backfill paths, and move account
onboarding helpers into a dedicated trait.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add trait tests and tidy onboarding imports.

Cover HasAccount and HasOnboarding under Models/Traits, prefer filled() for checkout session ids, and import Throwable instead of FQCN.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify checkout session_id and OAuth error props.

Read session_id via request->string(), and take OAuth error details from the League exception instead of decoding the response body.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify PostObserver onboarding notify path.

Share one otherPosts check for first-create and last-delete instead of separate callbacks.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Use post author as onboarding sync actor.

Drop Auth::user() preference in PostObserver; checklist sync attributes to $post->user.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify SocialAccountObserver and OAuth authorize flow.

Share create/delete onboarding notify, drop Auth actor fallback to owner, and inline Passport Inertia error handling.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Use lazy Inertia props for onboarding partial reloads.

Drop partial-header branching; wrap page props in closures and always redirect completed/dismissed accounts to the calendar.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Defer sidebar onboarding progress and stamp completion as owner-only.

Skip the MCP checklist work on full Inertia visits via deferred shared props,
early-exit token scans, and keep account completion stamps owner-gated.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify deferred onboarding progress share via canShowProgress.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add User firstName for shared auth and simplify onboarding page.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Move User firstName coverage into UserTest.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Use first_name directly without empty-name fallbacks.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Resolve onboarding sample prompt on the frontend via i18n.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Stamp onboarding completion via the account owner after teammate unlocks.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Count only the account owner MCP grant toward onboarding activation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix OAuth consent auth-token mismatch for mid-activation owners.

Skip deferred onboardingProgress on Passport authorize so Inertia does not
rotate the session authToken, cover happy and stale-token paths in tests,
and polish MCP setup copy plus sidebar/onboarding layout.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Keep users on onboarding after activation completes.

Stamp completion and re-render the finished checklist instead of
redirecting to the calendar so owners can review the done state.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Clarify Passport consent-view opt-out and guard app-route deferral.

Rename the authorize-only route check and assert onboardingProgress still
defers on calendar, onboarding, and MCP settings.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Harden onboarding completion and MCP consent workspace binding.

Reject OAuth approve without a workspace, retry auto-complete until
stamped, send dismissed complete straight to calendar, and cover the
device consent defer opt-out.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Enable activation checklist for self-hosted installs.

Remove the self-hosted onboarding redirects, keep the SaaS-only dismiss backfill, and cover subscription-less owners plus skip/complete destinations.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add GitHub, Hacker News, and directories referral sources.

Expand the welcome referral step with open-source and directory discovery channels.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Refine welcome referral sources and labels.

Split Instagram/Threads, add Founder, and shorten Google, GitHub, AI, and blog option labels.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Sort accounts platforms alphabetically and drop connect hover plus.

Reuse connectableOptions for the accounts index and remove the unused plus badge on disconnected cards.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Centralize PostHog once-capture so disabled installs don't burn dedupe keys.

Move isEnabled + Cache::add into PostHogService::captureOnce and route onboarding viewed/step events through it.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify onboarding backfill to complete every existing open account.

Drop self-hosted and subscription filters; down clears completed_at again.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Drop PostHog captureOnce and use plain capture for onboarding.

Remove cache-based event dedupe; callers rely on PostHogService::capture gating.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-07 20:34:43 -03:00

269 lines
10 KiB
PHP

<?php
declare(strict_types=1);
use App\Enums\UserWorkspace\Role;
use App\Http\Middleware\App\EnsureCanAuthorizeMcp;
use App\Models\Account;
use App\Models\User;
use App\Models\Workspace;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Str;
test('dynamic oauth client registration is rate limited', function () {
$payload = [
'client_name' => 'MCP Client',
'redirect_uris' => ['https://client.example/callback'],
'grant_types' => ['authorization_code'],
'response_types' => ['code'],
'token_endpoint_auth_method' => 'none',
];
for ($attempt = 0; $attempt < 30; $attempt++) {
$this->postJson('/oauth/register', $payload)->assertSuccessful();
}
$this->postJson('/oauth/register', $payload)->assertTooManyRequests();
});
test('dynamic oauth registration rejects custom callback schemes', function (string $redirectUri) {
$this->postJson('/oauth/register', [
'client_name' => 'Native MCP Client',
'redirect_uris' => [$redirectUri],
'grant_types' => ['authorization_code'],
'response_types' => ['code'],
'token_endpoint_auth_method' => 'none',
])->assertBadRequest();
})->with([
'cursor' => 'cursor://oauth/callback',
'vscode' => 'vscode://oauth/callback',
]);
test('mcp oauth consent page is available for workspace viewers', function () {
$account = Account::factory()->create();
$owner = User::factory()->create(['account_id' => $account->id]);
$account->update(['owner_id' => $owner->id]);
$workspace = Workspace::factory()->create([
'account_id' => $account->id,
'user_id' => $owner->id,
'name' => 'Viewer Workspace',
]);
$workspace->members()->attach($owner->id, ['role' => Role::Admin->value]);
$viewer = User::factory()->create(['account_id' => $account->id]);
$workspace->members()->attach($viewer->id, ['role' => Role::Viewer->value]);
$viewer->update(['current_workspace_id' => $workspace->id]);
$clientId = mcpOauthClient('Viewer Agent');
DB::table('oauth_clients')->where('id', $clientId)->update([
'redirect_uris' => json_encode(['https://client.example/callback']),
]);
$this->actingAs($viewer)
->get(route('passport.authorizations.authorize', oauthAuthorizeQuery($clientId)))
->assertOk()
->assertInertia(fn ($page) => $page
->component('mcp/Authorize')
->where('client.name', 'Viewer Agent')
->where('user.email', $viewer->email)
->where('selectedWorkspaceId', (string) $workspace->id)
->has('workspaces', 1)
->where('workspaces.0.id', (string) $workspace->id)
->where('workspaces.0.name', 'Viewer Workspace')
->has('scopes', 1)
->where('scopes.0.id', 'mcp:use')
->has('authToken')
->where('state', 'test-state'));
expect(view()->exists('mcp.authorize-denied'))->toBeFalse()
->and(class_exists(EnsureCanAuthorizeMcp::class))->toBeFalse();
});
test('mcp oauth consent page uses the active locale', function () {
app()->setLocale('pt-BR');
expect(__('mcp.authorize.heading', ['client' => 'Claude']))->toBe('Autorizar Claude')
->and(__('mcp.authorize.logged_in_as'))->toBe('Conectado como:')
->and(__('mcp.authorize.workspace_scope'))->toBe('Esta conexão terá acesso somente ao workspace selecionado.')
->and(__('mcp.authorize.approve'))->toBe('Autorizar')
->and(__('mcp.authorize.cancel'))->toBe('Cancelar');
});
test('mcp oauth consent page lists every workspace the user can access', function () {
$account = Account::factory()->create();
$user = User::factory()->create(['account_id' => $account->id]);
$account->update(['owner_id' => $user->id]);
$alpha = Workspace::factory()->create([
'account_id' => $account->id,
'user_id' => $user->id,
'name' => 'Alpha',
]);
$beta = Workspace::factory()->create([
'account_id' => $account->id,
'user_id' => $user->id,
'name' => 'Beta',
]);
$alpha->members()->attach($user->id, ['role' => Role::Admin->value]);
$beta->members()->attach($user->id, ['role' => Role::Admin->value]);
$user->update(['current_workspace_id' => $alpha->id]);
$clientId = mcpOauthClient('Claude');
DB::table('oauth_clients')->where('id', $clientId)->update([
'redirect_uris' => json_encode(['https://client.example/callback']),
]);
$this->actingAs($user)
->get(route('passport.authorizations.authorize', oauthAuthorizeQuery($clientId)))
->assertOk()
->assertInertia(fn ($page) => $page
->component('mcp/Authorize')
->where('selectedWorkspaceId', (string) $alpha->id)
->has('workspaces', 2)
->where('workspaces.0.name', 'Alpha')
->where('workspaces.1.name', 'Beta')
->where('workspaces.0.id', (string) $alpha->id)
->where('workspaces.1.id', (string) $beta->id));
});
test('mcp oauth always shows consent even when scopes were previously granted', function () {
$account = Account::factory()->create();
$user = User::factory()->create(['account_id' => $account->id]);
$account->update(['owner_id' => $user->id]);
$workspace = Workspace::factory()->create([
'account_id' => $account->id,
'user_id' => $user->id,
]);
$workspace->members()->attach($user->id, ['role' => Role::Admin->value]);
$user->update(['current_workspace_id' => $workspace->id]);
$clientId = mcpOauthClient('Reconnect Agent');
DB::table('oauth_clients')->where('id', $clientId)->update([
'redirect_uris' => json_encode(['https://client.example/callback']),
]);
mcpAccessToken($user, $clientId, $workspace);
$query = oauthAuthorizeQuery($clientId);
unset($query['prompt']);
$this->actingAs($user)
->get(route('passport.authorizations.authorize', $query))
->assertOk()
->assertInertia(fn ($page) => $page
->component('mcp/Authorize')
->where('client.name', 'Reconnect Agent')
->where('selectedWorkspaceId', (string) $workspace->id));
});
test('passport approve route has no mcp create-post role gate', function () {
$route = app('router')->getRoutes()->getByName('passport.authorizations.approve');
expect($route)->not->toBeNull();
$middleware = collect($route->gatherMiddleware())
->map(fn (mixed $middleware): string => is_string($middleware) ? $middleware : $middleware::class)
->implode(',');
expect($middleware)->not->toContain('EnsureCanAuthorizeMcp');
});
test('guests are redirected to login before an unknown oauth client is rejected', function () {
$unknownClientId = (string) Str::uuid();
$this->get(route('passport.authorizations.authorize', oauthAuthorizeQuery($unknownClientId)))
->assertRedirect(route('login'));
});
test('guests are redirected to login before consent for a registered oauth client', function () {
$clientId = mcpOauthClient('Guest Login Agent');
DB::table('oauth_clients')->where('id', $clientId)->update([
'redirect_uris' => json_encode(['https://client.example/callback']),
]);
$this->get(route('passport.authorizations.authorize', oauthAuthorizeQuery($clientId)))
->assertRedirect(route('login'));
});
test('authenticated users still receive invalid_client for an unknown oauth client', function () {
$user = User::factory()->create();
$unknownClientId = (string) Str::uuid();
$this->actingAs($user)
->getJson(route('passport.authorizations.authorize', oauthAuthorizeQuery($unknownClientId)))
->assertUnauthorized()
->assertJson([
'error' => 'invalid_client',
]);
});
test('browser requests render an inertia error page for an unknown oauth client', function () {
$user = User::factory()->create();
$unknownClientId = (string) Str::uuid();
$this->actingAs($user)
->get(route('passport.authorizations.authorize', oauthAuthorizeQuery($unknownClientId)))
->assertOk()
->assertInertia(fn ($page) => $page
->component('mcp/AuthorizeError')
->where('error', 'invalid_client')
->where('errorDescription', 'Client authentication failed'));
});
test('post-login redirect to authorize renders inertia instead of raw oauth json', function () {
$unknownClientId = (string) Str::uuid();
$user = User::factory()->create();
$this->get(route('passport.authorizations.authorize', oauthAuthorizeQuery($unknownClientId)))
->assertRedirect(route('login'));
$login = $this->post(route('login.store'), [
'email' => $user->email,
'password' => 'password',
]);
$login->assertRedirect();
$this->get($login->headers->get('Location'))
->assertOk()
->assertInertia(fn ($page) => $page
->component('mcp/AuthorizeError')
->where('error', 'invalid_client'));
});
test('prompt=none guests receive login_required redirect instead of an inertia error page', function () {
$redirectUri = 'https://client.example/callback';
$clientId = mcpOauthClient('Silent Auth Guest');
DB::table('oauth_clients')->where('id', $clientId)->update([
'redirect_uris' => json_encode([$redirectUri]),
]);
$response = $this->get(route(
'passport.authorizations.authorize',
oauthAuthorizeQuery($clientId, $redirectUri, prompt: 'none'),
));
$response->assertRedirect();
expect($response->headers->get('Location'))
->toStartWith($redirectUri)
->toContain('error=login_required');
});
test('prompt=none authenticated users receive consent_required redirect instead of an inertia error page', function () {
$user = User::factory()->create();
$redirectUri = 'https://client.example/callback';
$clientId = mcpOauthClient('Silent Auth User');
DB::table('oauth_clients')->where('id', $clientId)->update([
'redirect_uris' => json_encode([$redirectUri]),
]);
$response = $this->actingAs($user)
->get(route(
'passport.authorizations.authorize',
oauthAuthorizeQuery($clientId, $redirectUri, prompt: 'none'),
));
$response->assertRedirect();
expect($response->headers->get('Location'))
->toStartWith($redirectUri)
->toContain('error=consent_required');
});