TenantAtlas/tests/Feature/Verification/PreviousVerificationReportResolverTest.php
ahmido da1adbdeb5 Spec 119: Drift cutover to Baseline Compare (golden master) (#144)
Implements Spec 119 (Drift Golden Master Cutover):

- Baseline Compare is the only drift writer (`source = baseline.compare`).
- Drift findings now store diff-compatible `evidence_jsonb` (summary.kind, baseline/current policy_version_id refs, fidelity + provenance).
- Findings UI renders one-sided diffs for `missing_policy`/`unexpected_policy` when a single ref exists; otherwise shows explicit “diff unavailable”.
- Removes legacy drift generator runtime (jobs/services/UI) and related tests.
- Adds one-time migration to delete legacy drift findings (`finding_type=drift` where source is null or != baseline.compare).
- Scopes baseline capture & landing duplicate warnings to latest completed inventory sync.
- Canonicalizes compliance `scheduledActionsForRule` drift signal and keeps legacy snapshots comparable.

Tests:
- `vendor/bin/sail artisan test --compact` (full suite per tasks)
- Focused pack: BaselinePolicyVersionResolverTest, BaselineCompareDriftEvidenceContractTest, DriftFindingDiffUnavailableTest, LegacyDriftFindingsCleanupMigrationTest, ComplianceNoncomplianceActionsDriftTest

Notes:
- Livewire v4+ / Filament v5 compatible (no legacy APIs).
- No new external dependencies.

Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de>
Reviewed-on: #144
2026-03-06 14:30:49 +00:00

124 lines
4.1 KiB
PHP

<?php
declare(strict_types=1);
use App\Models\OperationRun;
use App\Models\ProviderConnection;
use App\Services\Verification\StartVerification;
use App\Support\OperationRunStatus;
use App\Support\Verification\PreviousVerificationReportResolver;
use Filament\Facades\Filament;
use Illuminate\Support\Facades\Queue;
it('resolves the previous report id for the same identity (including provider_connection_id)', function (): void {
[$user, $tenant] = createUserWithTenant(role: 'operator');
$this->actingAs($user);
$tenant->makeCurrent();
Filament::setTenant($tenant, true);
$connectionId = (int) ProviderConnection::factory()->create([
'tenant_id' => (int) $tenant->getKey(),
])->getKey();
$previous = OperationRun::factory()->create([
'tenant_id' => (int) $tenant->getKey(),
'workspace_id' => (int) $tenant->workspace_id,
'type' => 'provider.connection.check',
'status' => OperationRunStatus::Completed->value,
'run_identity_hash' => 'same-hash',
'context' => [
'provider_connection_id' => $connectionId,
],
]);
$current = OperationRun::factory()->create([
'tenant_id' => (int) $tenant->getKey(),
'workspace_id' => (int) $tenant->workspace_id,
'type' => 'provider.connection.check',
'status' => OperationRunStatus::Completed->value,
'run_identity_hash' => 'same-hash',
'context' => [
'provider_connection_id' => $connectionId,
],
]);
expect(PreviousVerificationReportResolver::resolvePreviousReportId($current))
->toBe((int) $previous->getKey());
});
it('does not resolve previous report ids across provider connections', function (): void {
[$user, $tenant] = createUserWithTenant(role: 'operator');
$this->actingAs($user);
$tenant->makeCurrent();
Filament::setTenant($tenant, true);
$connectionA = (int) ProviderConnection::factory()->create(['tenant_id' => (int) $tenant->getKey()])->getKey();
$connectionB = (int) ProviderConnection::factory()->create(['tenant_id' => (int) $tenant->getKey()])->getKey();
OperationRun::factory()->create([
'tenant_id' => (int) $tenant->getKey(),
'workspace_id' => (int) $tenant->workspace_id,
'type' => 'provider.connection.check',
'status' => OperationRunStatus::Completed->value,
'run_identity_hash' => 'same-hash',
'context' => [
'provider_connection_id' => $connectionA,
],
]);
$current = OperationRun::factory()->create([
'tenant_id' => (int) $tenant->getKey(),
'workspace_id' => (int) $tenant->workspace_id,
'type' => 'provider.connection.check',
'status' => OperationRunStatus::Completed->value,
'run_identity_hash' => 'same-hash',
'context' => [
'provider_connection_id' => $connectionB,
],
]);
expect(PreviousVerificationReportResolver::resolvePreviousReportId($current))
->toBeNull();
});
it('includes provider_connection_id in the verification run identity hash (no cross-connection dedupe)', function (): void {
Queue::fake();
[$user, $tenant] = createUserWithTenant(role: 'operator');
$this->actingAs($user);
$tenant->makeCurrent();
Filament::setTenant($tenant, true);
$connectionA = ProviderConnection::factory()->create([
'tenant_id' => $tenant->getKey(),
'provider' => 'microsoft',
'entra_tenant_id' => fake()->uuid(),
]);
$connectionB = ProviderConnection::factory()->create([
'tenant_id' => $tenant->getKey(),
'provider' => 'microsoft',
'entra_tenant_id' => fake()->uuid(),
]);
$starter = app(StartVerification::class);
$runA = $starter->providerConnectionCheck(
tenant: $tenant,
connection: $connectionA,
initiator: $user,
)->run->refresh();
$runB = $starter->providerConnectionCheck(
tenant: $tenant,
connection: $connectionB,
initiator: $user,
)->run->refresh();
expect($runA->getKey())->not->toBe($runB->getKey());
expect($runA->run_identity_hash)->not->toBe($runB->run_identity_hash);
});