trypost/tests/Feature/MediaControllerTest.php
Paulo Castellano ceb7b92b74 feat: PostPlatform enum, failure email, DB indexes, rate limiting, tests
Publishing improvements:
- Create PostPlatformStatus enum (Pending, Publishing, Published, Failed)
- Update PostPlatform model, jobs, factories to use enum
- Add PostPublishFailed email notification when post fails to publish
- Maizzle template + blade for failure email with platform details
- PublishPost job: add $tries=3, $backoff=30, failed() method
- Fix broadcast event to serialize enum status value

Security:
- Add rate limiting (throttle:6,1) on social connect endpoints
- Fix MediaController::reorder IDOR vulnerability
- Fix Connect.vue broken import (storeStep2 -> storeConnect)
- Fix UpdatePost data_get() consistency

Database:
- Add composite index on post_platforms (post_id, enabled)
- Add index on post_platforms (social_account_id)

Tests:
- Add 3 tests for profile photo upload/delete
- Add 2 tests for media reorder (including IDOR check)
- Fix publish tests for PostPlatformStatus enum
- Add Mail::fake() to publish tests

Cleanup:
- Remove unused AppHeader.vue and AppHeaderLayout.vue
- Remove dead BillingController methods

All 733 tests passing.
2026-03-30 16:11:38 -03:00

190 lines
5.9 KiB
PHP

<?php
declare(strict_types=1);
use App\Enums\User\Setup;
use App\Models\Media;
use App\Models\Post;
use App\Models\PostPlatform;
use App\Models\SocialAccount;
use App\Models\User;
use App\Models\Workspace;
use Illuminate\Http\UploadedFile;
use Illuminate\Support\Facades\Storage;
beforeEach(function () {
Storage::fake('local');
$this->user = User::factory()->create(['setup' => Setup::Completed]);
$this->workspace = Workspace::factory()->create(['user_id' => $this->user->id]);
$this->user->update(['current_workspace_id' => $this->workspace->id]);
$this->socialAccount = SocialAccount::factory()->create(['workspace_id' => $this->workspace->id]);
$this->post = Post::factory()->create([
'workspace_id' => $this->workspace->id,
'user_id' => $this->user->id,
]);
$this->postPlatform = PostPlatform::factory()->create([
'post_id' => $this->post->id,
'social_account_id' => $this->socialAccount->id,
]);
});
// Store tests
test('store media requires authentication', function () {
$response = $this->post(route('app.medias.store'), [
'model' => 'postPlatform',
'model_id' => $this->postPlatform->id,
'media' => UploadedFile::fake()->image('test.jpg'),
]);
$response->assertRedirect(route('login'));
});
test('store media uploads file', function () {
$response = $this->actingAs($this->user)->post(route('app.medias.store'), [
'model' => 'postPlatform',
'model_id' => $this->postPlatform->id,
'media' => UploadedFile::fake()->image('test.jpg'),
]);
$response->assertOk();
$response->assertJsonStructure(['id', 'url', 'type', 'original_filename']);
});
test('store media validates required fields', function () {
$response = $this->actingAs($this->user)->post(route('app.medias.store'), [
'model' => '',
'model_id' => '',
]);
$response->assertSessionHasErrors(['model', 'model_id', 'media']);
});
// Destroy tests
test('destroy media requires authentication', function () {
$media = Media::factory()->create([
'mediable_id' => $this->postPlatform->id,
'mediable_type' => 'postPlatform',
]);
$response = $this->delete(route('app.medias.destroy', [$this->postPlatform->id, $media]));
$response->assertRedirect(route('login'));
});
test('destroy media deletes the media', function () {
$media = Media::factory()->create([
'mediable_id' => $this->postPlatform->id,
'mediable_type' => 'postPlatform',
]);
$response = $this->actingAs($this->user)->delete(route('app.medias.destroy', [$this->postPlatform->id, $media]));
$response->assertOk();
$response->assertJson(['success' => true]);
expect(Media::find($media->id))->toBeNull();
});
test('destroy media returns 403 for mismatched model', function () {
$otherPostPlatform = PostPlatform::factory()->create([
'post_id' => $this->post->id,
'social_account_id' => $this->socialAccount->id,
]);
$media = Media::factory()->create([
'mediable_id' => $otherPostPlatform->id,
'mediable_type' => 'postPlatform',
]);
$response = $this->actingAs($this->user)->delete(route('app.medias.destroy', [$this->postPlatform->id, $media]));
$response->assertForbidden();
});
// Duplicate tests
test('duplicate media requires authentication', function () {
$media = Media::factory()->create([
'mediable_id' => $this->postPlatform->id,
'mediable_type' => 'postPlatform',
]);
$response = $this->post(route('app.medias.duplicate', $media), [
'targets' => [],
]);
$response->assertRedirect(route('login'));
});
test('duplicate media creates copies', function () {
$media = Media::factory()->create([
'mediable_id' => $this->postPlatform->id,
'mediable_type' => 'postPlatform',
]);
$otherPostPlatform = PostPlatform::factory()->create([
'post_id' => $this->post->id,
'social_account_id' => $this->socialAccount->id,
]);
$response = $this->actingAs($this->user)->post(route('app.medias.duplicate', $media), [
'targets' => [
[
'model' => 'postPlatform',
'model_id' => $otherPostPlatform->id,
],
],
]);
$response->assertOk();
$response->assertJsonCount(1);
expect(Media::where('mediable_id', $otherPostPlatform->id)->count())->toBe(1);
});
// Reorder tests
test('reorder media updates order', function () {
$media1 = $this->postPlatform->addMedia(UploadedFile::fake()->image('img1.jpg'), 'media');
$media2 = $this->postPlatform->addMedia(UploadedFile::fake()->image('img2.jpg'), 'media');
$response = $this->actingAs($this->user)->postJson(route('app.medias.reorder'), [
'media' => [
['id' => $media1->id, 'order' => 1],
['id' => $media2->id, 'order' => 0],
],
]);
$response->assertOk();
expect($media1->refresh()->order)->toBe(1);
expect($media2->refresh()->order)->toBe(0);
});
test('reorder media rejects media from other workspace', function () {
$otherUser = User::factory()->create(['setup' => Setup::Completed]);
$otherWorkspace = Workspace::factory()->create(['user_id' => $otherUser->id]);
$otherUser->update(['current_workspace_id' => $otherWorkspace->id]);
$otherPost = Post::factory()->create([
'workspace_id' => $otherWorkspace->id,
'user_id' => $otherUser->id,
]);
$otherAccount = SocialAccount::factory()->create([
'workspace_id' => $otherWorkspace->id,
]);
$otherPlatform = PostPlatform::factory()->create([
'post_id' => $otherPost->id,
'social_account_id' => $otherAccount->id,
]);
$otherMedia = $otherPlatform->addMedia(UploadedFile::fake()->image('img.jpg'), 'media');
$response = $this->actingAs($this->user)->postJson(route('app.medias.reorder'), [
'media' => [
['id' => $otherMedia->id, 'order' => 0],
],
]);
$response->assertForbidden();
});