Critical: - Fix EnsureUserSetupIsComplete middleware route name prefixes and redirect Subscription step to subscribe page (not onboarding) - Fix MCP session pollution: Auth::setUser() instead of Auth::login() - Remove dead BillingController::addWorkspace/removeWorkspace methods - Remove broken Workspace::pendingInvites() method Security (IDOR): - MediaController: add workspace ownership verification on all endpoints - UpdatePostRequest: scope label_ids validation to current workspace - UpdatePostRequest: scope platform IDs validation to current post Security (other): - Fix open redirect in login and registration (validate internal URLs) - Add validation to API PostController store/update (was $request->all()) - Prevent Owner role assignment via updateRole endpoint - Fix API post author attribution to use workspace owner Authorization: - PostController: use createPost policy instead of view for store/update/destroy Logic: - Post Status enum labels now use translation system instead of hardcoded Portuguese - Workspace deletion cleans up current_workspace_id for all affected members - StoreWorkspaceInviteRequest: replace Portuguese validation messages with __() Rename onboarding: - Step1.vue -> Role.vue, Step2.vue -> Connect.vue - Controller methods: step1->role, storeStep1->storeRole, step2->connect, storeStep2->storeConnect All 728 tests passing.
83 lines
2.8 KiB
PHP
83 lines
2.8 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
use App\Enums\User\Setup;
|
|
use App\Models\User;
|
|
use App\Models\Workspace;
|
|
|
|
test('user with completed setup can access protected routes', function () {
|
|
config(['trypost.self_hosted' => true]);
|
|
|
|
$user = User::factory()->create(['setup' => Setup::Completed]);
|
|
$workspace = Workspace::factory()->create(['user_id' => $user->id]);
|
|
$workspace->members()->attach($user->id, ['role' => 'owner']);
|
|
$user->update(['current_workspace_id' => $workspace->id]);
|
|
|
|
$this->actingAs($user)
|
|
->get(route('app.calendar'))
|
|
->assertOk();
|
|
});
|
|
|
|
test('user on role step is redirected to onboarding step 1', function () {
|
|
config(['trypost.self_hosted' => true]);
|
|
|
|
$user = User::factory()->create(['setup' => Setup::Role]);
|
|
$workspace = Workspace::factory()->create(['user_id' => $user->id]);
|
|
$workspace->members()->attach($user->id, ['role' => 'owner']);
|
|
$user->update(['current_workspace_id' => $workspace->id]);
|
|
|
|
$this->actingAs($user)
|
|
->get(route('app.calendar'))
|
|
->assertRedirect(route('app.onboarding.role'));
|
|
});
|
|
|
|
test('user on connections step is redirected to onboarding step 2', function () {
|
|
config(['trypost.self_hosted' => true]);
|
|
|
|
$user = User::factory()->create(['setup' => Setup::Connections]);
|
|
$workspace = Workspace::factory()->create(['user_id' => $user->id]);
|
|
$workspace->members()->attach($user->id, ['role' => 'owner']);
|
|
$user->update(['current_workspace_id' => $workspace->id]);
|
|
|
|
$this->actingAs($user)
|
|
->get(route('app.calendar'))
|
|
->assertRedirect(route('app.onboarding.connect'));
|
|
});
|
|
|
|
test('user on subscription step is redirected to subscribe', function () {
|
|
config(['trypost.self_hosted' => true]);
|
|
|
|
$user = User::factory()->create(['setup' => Setup::Subscription]);
|
|
$workspace = Workspace::factory()->create(['user_id' => $user->id]);
|
|
$workspace->members()->attach($user->id, ['role' => 'owner']);
|
|
$user->update(['current_workspace_id' => $workspace->id]);
|
|
|
|
$this->actingAs($user)
|
|
->get(route('app.calendar'))
|
|
->assertRedirect(route('app.subscribe'));
|
|
});
|
|
|
|
test('user on role step can access onboarding step 1', function () {
|
|
$user = User::factory()->create(['setup' => Setup::Role]);
|
|
|
|
$this->actingAs($user)
|
|
->get(route('app.onboarding.role'))
|
|
->assertOk();
|
|
});
|
|
|
|
test('user on connections step can access onboarding step 2', function () {
|
|
$user = User::factory()->create(['setup' => Setup::Connections]);
|
|
|
|
$this->actingAs($user)
|
|
->get(route('app.onboarding.connect'))
|
|
->assertOk();
|
|
});
|
|
|
|
test('user on connections step can access social connect routes', function () {
|
|
$user = User::factory()->create(['setup' => Setup::Connections]);
|
|
|
|
$this->actingAs($user)
|
|
->get(route('app.social.linkedin.connect'))
|
|
->assertRedirect();
|
|
});
|