trypost/tests/Pest.php
Paulo Castellano a1fa897106
Activation checklist + MCP OAuth authorize UX (#239) (#250)
* Wire onboarding activation into Account, observers, and shared Inertia data

Add onboarding casts/hasFinishedOnboarding, AccessToken ObservedBy,
Platform::connectableOptions, Post/SocialAccount onboarding broadcast hooks,
and lazy onboardingResidual share + SharedData types.

* Register onboarding routes and post-checkout activation redirects.

Wire billing processing and the sidebar checklist so owners land on
activation after subscribe, with locale sidebar/uk onboarding strings.

* Align MCP grant usability with onboarding activation checks

Unbound MCP tokens fall back to the user's current workspace and require
createPost so viewer/unscoped grants neither unlock the checklist nor
broadcast onboarding status.

* Require bound MCP workspace for onboarding activation.

Drop current-workspace fallback from usable MCP grants so checklist
detection and broadcasts match Passport token scoping; viewers still
cannot unlock the MCP step.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Harden onboarding review findings and tighten locale strings.

Fix Welcome/Persona/TrackPost suites broken by the activation route reuse
and PostObserver analytics side effects, restore Echo poll fallbacks,
reject unbound MCP grants in tests, and drop unused onboarding.mcp keys.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Remove unused sidebar and MCP authorization locale keys.

Drop dead sidebar menu/theme strings (including the overwritten
workspace label and api_keys nav entry) and unused MCP authorize
app_title/approving copy across all locales.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix SetLocale crashing on Passport Symfony OAuth responses.

OAuth errors return a raw Symfony Response without withCookie(); attach
the default locale cookie via headers so authorize no longer 500s.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Prompt OAuth guests to log in before rejecting unknown clients.

MCP Inspector often reuses a stale client_id; validateAuthorizationRequest
was returning invalid_client JSON before the login redirect. Guests now
hit /login first, then client validation runs after authentication.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Render Inertia OAuth authorize errors for browser logins.

After login, Inertia follows the intended authorize URL; raw invalid_client
JSON broke that visit. HTML/Inertia requests now get mcp/AuthorizeError
while API JSON clients still receive the OAuth error payload.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Detect Inertia OAuth error pages via Request::inertia().

Use the framework helper so post-login authorize failures keep returning
an Inertia page instead of raw OAuth JSON.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify OAuth authorize error page detection to expectsJson.

Drop the X-Inertia header sniff; browser and Inertia visits already do
not expectsJson, while API clients still receive the OAuth JSON payload.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Share MCP authorize layout and drop the error close button.

Keep authorize and authorize-error on the same centered card shell instead of the auth split layout.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify onboarding activation for reviewability and safety.

Use an exists-based MCP check, keep GETs read-only, move sync into
syncAndNotify, clear MCP skips on connect, restrict complete to owners,
and share Echo/poll via one composable.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Move MCP OAuth authorize UX out of the onboarding PR.

Keep the activation checklist focused; OAuth guest/error-page work now
lives on fix/mcp-oauth-authorize-ux.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix corrupted French MCP locale after OAuth key cleanup.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Restore MCP OAuth authorize UX onto the onboarding branch.

Keep authorize error page, guest login-before-client validation, and
SetLocale Symfony cookie fix in #250.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix OAuth prompt=none redirects and harden onboarding tests.

Keep login_required/consent_required as redirects instead of Inertia,
add regression coverage for owner-only activation, require invite email
confirmation, and align MCP connected apps with the sessions list UI.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify onboarding guards and dedupe viewed analytics.

Introduce isOnboardingOpen / belongsToAccount helpers, collapse
duplicated sync/dispatch paths, and capture onboarding.viewed once
per account.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify onboarding event, observers, and status helpers.

Tighten Account onboarding predicates, drop nullable broadcast/dispatch
APIs, and collapse repeated observer/controller guards.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Treat in-app users as always having an account.

Add resolveAccount(), tighten belongsToAccount to string ids, and fold
guest residual handling into ResolveOnboardingStatus.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Rename onboarding residual share test to progress.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify onboarding status and rename residual to progress.

Use accountOrFail, extract MCP onboarding scope, auto-leave the ready
screen, and send non-onboarding checkout back to accounts.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Extract HasAccount and prefer data_get in onboarding flows.

Move account helpers off User, drop nullable sidebarProgress, and
read OAuth/onboarding payloads with data_get.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify onboarding checks and extract HasOnboarding.

Use Eloquent + policies for MCP/backfill paths, and move account
onboarding helpers into a dedicated trait.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add trait tests and tidy onboarding imports.

Cover HasAccount and HasOnboarding under Models/Traits, prefer filled() for checkout session ids, and import Throwable instead of FQCN.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify checkout session_id and OAuth error props.

Read session_id via request->string(), and take OAuth error details from the League exception instead of decoding the response body.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify PostObserver onboarding notify path.

Share one otherPosts check for first-create and last-delete instead of separate callbacks.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Use post author as onboarding sync actor.

Drop Auth::user() preference in PostObserver; checklist sync attributes to $post->user.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify SocialAccountObserver and OAuth authorize flow.

Share create/delete onboarding notify, drop Auth actor fallback to owner, and inline Passport Inertia error handling.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Use lazy Inertia props for onboarding partial reloads.

Drop partial-header branching; wrap page props in closures and always redirect completed/dismissed accounts to the calendar.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Defer sidebar onboarding progress and stamp completion as owner-only.

Skip the MCP checklist work on full Inertia visits via deferred shared props,
early-exit token scans, and keep account completion stamps owner-gated.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify deferred onboarding progress share via canShowProgress.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add User firstName for shared auth and simplify onboarding page.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Move User firstName coverage into UserTest.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Use first_name directly without empty-name fallbacks.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Resolve onboarding sample prompt on the frontend via i18n.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Stamp onboarding completion via the account owner after teammate unlocks.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Count only the account owner MCP grant toward onboarding activation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix OAuth consent auth-token mismatch for mid-activation owners.

Skip deferred onboardingProgress on Passport authorize so Inertia does not
rotate the session authToken, cover happy and stale-token paths in tests,
and polish MCP setup copy plus sidebar/onboarding layout.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Keep users on onboarding after activation completes.

Stamp completion and re-render the finished checklist instead of
redirecting to the calendar so owners can review the done state.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Clarify Passport consent-view opt-out and guard app-route deferral.

Rename the authorize-only route check and assert onboardingProgress still
defers on calendar, onboarding, and MCP settings.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Harden onboarding completion and MCP consent workspace binding.

Reject OAuth approve without a workspace, retry auto-complete until
stamped, send dismissed complete straight to calendar, and cover the
device consent defer opt-out.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Enable activation checklist for self-hosted installs.

Remove the self-hosted onboarding redirects, keep the SaaS-only dismiss backfill, and cover subscription-less owners plus skip/complete destinations.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add GitHub, Hacker News, and directories referral sources.

Expand the welcome referral step with open-source and directory discovery channels.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Refine welcome referral sources and labels.

Split Instagram/Threads, add Founder, and shorten Google, GitHub, AI, and blog option labels.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Sort accounts platforms alphabetically and drop connect hover plus.

Reuse connectableOptions for the accounts index and remove the unused plus badge on disconnected cards.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Centralize PostHog once-capture so disabled installs don't burn dedupe keys.

Move isEnabled + Cache::add into PostHogService::captureOnce and route onboarding viewed/step events through it.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify onboarding backfill to complete every existing open account.

Drop self-hosted and subscription filters; down clears completed_at again.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Drop PostHog captureOnce and use plain capture for onboarding.

Remove cache-based event dedupe; callers rely on PostHogService::capture gating.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-07 20:34:43 -03:00

321 lines
9.3 KiB
PHP

<?php
declare(strict_types=1);
use App\Enums\UserWorkspace\Role;
use App\Models\AccessToken;
use App\Models\Account;
use App\Models\Plan;
use App\Models\User;
use App\Models\Workspace;
use Illuminate\Foundation\Testing\RefreshDatabase;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Str;
use Tests\BrowserTestCase;
use Tests\TestCase;
/*
|--------------------------------------------------------------------------
| Test Case
|--------------------------------------------------------------------------
|
| The closure you provide to your test functions is always bound to a specific PHPUnit test
| case class. By default, that class is "PHPUnit\Framework\TestCase". Of course, you may
| need to change it using the "pest()" function to bind a different classes or traits.
|
*/
pest()->extend(TestCase::class)
->use(RefreshDatabase::class)
->in('Feature', 'Unit');
pest()->extend(BrowserTestCase::class)
->use(RefreshDatabase::class)
->in('Browser');
/*
|--------------------------------------------------------------------------
| Expectations
|--------------------------------------------------------------------------
|
| When you're writing tests, you often need to check that values meet certain conditions. The
| "expect()" function gives you access to a set of "expectations" methods that you can use
| to assert different things. Of course, you may extend the Expectation API at any time.
|
*/
expect()->extend('toBeOne', function () {
return $this->toBe(1);
});
/*
|--------------------------------------------------------------------------
| Functions
|--------------------------------------------------------------------------
|
| While Pest is very powerful out-of-the-box, you may have some testing code specific to your
| project that you don't want to repeat in every file. Here you can also expose helpers as
| global functions to help you to reduce the number of lines of code in your test files.
|
*/
/**
* Issue a real Passport personal access token bound to a workspace and return
* the plain JWT string. Use the returned token in `Authorization: Bearer ...`
* to exercise the auth:api + workspace.token middleware stack.
*/
function passportToken(User $user, Workspace $workspace, array $scopes = []): string
{
$result = $user->createToken('Test', $scopes);
AccessToken::find($result->token->id)
->forceFill(['workspace_id' => $workspace->id])
->saveQuietly();
return $result->accessToken;
}
/**
* Create a workspace + owner + Passport token suitable for hitting the public
* API. Drop-in replacement for the legacy `createXApiToken` helpers.
*
* @param array{workspace?: Workspace} $overrides
* @return array{plain_token: string, workspace: Workspace, user: User}
*/
function createApiTestToken(array $overrides = []): array
{
$workspace = data_get($overrides, 'workspace');
if (! $workspace) {
$user = User::factory()->create();
$workspace = Workspace::factory()->create([
'account_id' => $user->account_id,
'user_id' => $user->id,
]);
$workspace->members()->attach($user->id, [
'role' => Role::Admin->value,
]);
$user->update(['current_workspace_id' => $workspace->id]);
} else {
$user = $workspace->owner ?? User::factory()->create([
'account_id' => $workspace->account_id,
]);
if ($workspace->account && $workspace->account->owner_id !== $user->id) {
$workspace->account->update(['owner_id' => $user->id]);
}
}
return [
'plain_token' => passportToken($user, $workspace),
'workspace' => $workspace,
'user' => $user,
];
}
function feedFixture(string $name): string
{
return file_get_contents(base_path("tests/fixtures/feeds/{$name}.xml"));
}
/**
* Create an account on the Workspace plan with an active subscription on the
* given Stripe price, plus N workspaces. Used by the billing-cycle tests.
*
* @param array<string, mixed> $subscriptionAttributes
*/
function billingAccount(string $price, array $subscriptionAttributes = [], int $workspaces = 1): Account
{
$plan = Plan::query()->firstOrFail();
$plan->update([
'stripe_monthly_price_id' => 'price_month',
'stripe_yearly_price_id' => 'price_year',
]);
$account = Account::factory()->create([
'plan_id' => $plan->id,
'trial_ends_at' => null,
]);
$account->subscriptions()->create(array_merge([
'type' => Account::SUBSCRIPTION_NAME,
'stripe_id' => 'sub_'.fake()->uuid(),
'stripe_status' => 'active',
'stripe_price' => $price,
'quantity' => $workspaces,
], $subscriptionAttributes));
Workspace::factory()->count($workspaces)->create(['account_id' => $account->id]);
return $account->refresh();
}
/**
* Attach an active default subscription to the given account.
*/
function subscribeAccount(Account $account): void
{
$account->subscriptions()->create([
'type' => Account::SUBSCRIPTION_NAME,
'stripe_id' => 'sub_'.fake()->uuid(),
'stripe_status' => 'active',
'stripe_price' => 'price_123',
]);
}
/**
* Insert an OAuth client suitable for MCP connection tests.
*/
function mcpOauthClient(string $name = 'My Agent'): string
{
$id = (string) Str::uuid();
DB::table('oauth_clients')->insert([
'id' => $id,
'name' => $name,
'secret' => null,
'provider' => null,
'redirect_uris' => '[]',
'grant_types' => json_encode(['authorization_code', 'refresh_token']),
'revoked' => false,
'created_at' => now(),
'updated_at' => now(),
]);
return $id;
}
/**
* @return array<string, string>
*/
function oauthAuthorizeQuery(
string $clientId,
string $redirectUri = 'https://client.example/callback',
string $prompt = 'consent',
): array {
$verifier = Str::random(64);
$challenge = rtrim(strtr(base64_encode(hash('sha256', $verifier, true)), '+/', '-_'), '=');
return [
'client_id' => $clientId,
'redirect_uri' => $redirectUri,
'response_type' => 'code',
'scope' => 'mcp:use',
'state' => 'test-state',
'code_challenge' => $challenge,
'code_challenge_method' => 'S256',
'prompt' => $prompt,
];
}
/**
* Create an active OAuth access token for MCP connection tests.
*
* @param list<string> $scopes
*/
function mcpAccessToken(
User $user,
string $clientId,
?Workspace $workspace = null,
array $scopes = ['mcp:use'],
): AccessToken {
$token = new AccessToken;
$token->forceFill([
'id' => Str::random(80),
'user_id' => $user->id,
'client_id' => $clientId,
'workspace_id' => $workspace?->id,
'name' => 'MCP',
'scopes' => $scopes,
'revoked' => false,
'expires_at' => now()->addYear(),
])->save();
return $token->refresh();
}
/**
* Issue a Passport token, attach it to a dedicated MCP OAuth client, and bind
* it to a workspace — the post-#222 shape used by middleware / MCP endpoint tests.
*
* @param list<string> $scopes
* @return array{token: AccessToken, plain_token: string}
*/
function mcpBearerToken(User $user, Workspace $workspace, array $scopes = ['mcp:use']): array
{
$result = $user->createToken('MCP', $scopes);
$token = AccessToken::query()->findOrFail($result->token->id);
// Reassign to a dedicated MCP client so we never mutate Passport's shared
// personal-access client (which would poison PAT fixtures in the same run).
$token->forceFill([
'client_id' => mcpOauthClient(),
'workspace_id' => $workspace->id,
])->saveQuietly();
return [
'token' => $token->refresh(),
'plain_token' => $result->accessToken,
];
}
/**
* Move a member onto a shared account (stranded-member / invitee fixture).
*
* @return array{
* owner: User,
* member: User,
* shared_workspaces: list<Workspace>
* }
*/
function strandedMemberOnSharedAccount(
int $sharedWorkspaces = 0,
bool $attachMember = true,
bool $attachMemberToAll = true,
bool $setMemberCurrent = false,
?User $owner = null,
?string $memberEmail = null,
): array {
$owner ??= User::factory()->create();
$member = User::factory()->create(array_filter([
'email' => $memberEmail,
]));
// Closed-account model: the member's empty signup shell is gone after
// accepting the invite, so drop it here to match the real state.
$member->account?->delete();
$shared = [];
for ($i = 0; $i < $sharedWorkspaces; $i++) {
$workspace = Workspace::factory()->create([
'account_id' => $owner->account_id,
'user_id' => $owner->id,
]);
$workspace->members()->syncWithoutDetaching([
$owner->id => ['role' => Role::Admin->value],
]);
if ($attachMember && ($attachMemberToAll || $i === 0)) {
$workspace->members()->attach($member->id, [
'role' => Role::Member->value,
]);
}
$shared[] = $workspace;
}
$member->update([
'account_id' => $owner->account_id,
'current_workspace_id' => ($setMemberCurrent && $shared !== [])
? $shared[0]->id
: null,
]);
return [
'owner' => $owner->fresh(),
'member' => $member->fresh(),
'shared_workspaces' => $shared,
];
}