## Summary - harden finding lifecycle changes behind the canonical `FindingWorkflowService` gateway - route automated resolve and reopen flows through the same audited workflow path - tighten tenant and workspace scope checks on finding actions and audit visibility - add focused spec artifacts, workflow regression coverage, automation coverage, and audit visibility tests - update legacy finding model tests to use the workflow service after direct lifecycle mutators were removed ## Testing - `vendor/bin/sail bin pint --dirty --format agent` - focused findings and audit slices passed during implementation - `vendor/bin/sail artisan test --compact tests/Feature/Models/FindingResolvedTest.php` - full repository suite passed: `2757 passed`, `8 skipped`, `14448 assertions` ## Notes - Livewire v4.0+ compliance preserved - no new Filament assets or panel providers introduced; provider registration remains in `bootstrap/providers.php` - findings stay on existing Filament action surfaces, with destructive actions still confirmation-gated - no global search behavior was changed for findings resources Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de> Reviewed-on: #181
63 lines
1.9 KiB
PHP
63 lines
1.9 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace Tests\Feature\Findings\Concerns;
|
|
|
|
use App\Models\AuditLog;
|
|
use App\Models\Finding;
|
|
use App\Models\Tenant;
|
|
use App\Models\User;
|
|
use App\Support\Audit\AuditActionId;
|
|
use Filament\Facades\Filament;
|
|
|
|
trait InteractsWithFindingsWorkflow
|
|
{
|
|
/**
|
|
* @return array{0: User, 1: Tenant}
|
|
*/
|
|
protected function actingAsFindingOperator(string $role = 'owner'): array
|
|
{
|
|
[$user, $tenant] = createUserWithTenant(role: $role);
|
|
|
|
$this->actingAs($user);
|
|
Filament::setTenant($tenant, true);
|
|
|
|
return [$user, $tenant];
|
|
}
|
|
|
|
/**
|
|
* @param array<string, mixed> $attributes
|
|
*/
|
|
protected function makeFindingForWorkflow(Tenant $tenant, string $status = Finding::STATUS_NEW, array $attributes = []): Finding
|
|
{
|
|
$factory = Finding::factory()->for($tenant);
|
|
|
|
$factory = match ($status) {
|
|
Finding::STATUS_ACKNOWLEDGED => $factory->acknowledged(),
|
|
Finding::STATUS_TRIAGED => $factory->triaged(),
|
|
Finding::STATUS_IN_PROGRESS => $factory->inProgress(),
|
|
Finding::STATUS_REOPENED => $factory->reopened(),
|
|
Finding::STATUS_RESOLVED => $factory->resolved(),
|
|
Finding::STATUS_CLOSED => $factory->closed(),
|
|
Finding::STATUS_RISK_ACCEPTED => $factory->riskAccepted(),
|
|
default => $factory,
|
|
};
|
|
|
|
return $factory->create($attributes);
|
|
}
|
|
|
|
protected function latestFindingAudit(Finding $finding, string|AuditActionId $action): ?AuditLog
|
|
{
|
|
$actionValue = $action instanceof AuditActionId ? $action->value : $action;
|
|
|
|
return AuditLog::query()
|
|
->where('tenant_id', (int) $finding->tenant_id)
|
|
->where('resource_type', 'finding')
|
|
->where('resource_id', (string) $finding->getKey())
|
|
->where('action', $actionValue)
|
|
->latest('id')
|
|
->first();
|
|
}
|
|
}
|