TenantAtlas/tests/Feature/TenantRBAC/TenantMembershipCrudTest.php
Ahmed Darrazi 3b1dd98f52 feat(rbac): Implement Tenant RBAC v1
This commit introduces a comprehensive Role-Based Access Control (RBAC) system for TenantAtlas.

- Implements authentication via Microsoft Entra ID (OIDC).
- Manages authorization on a per-Suite-Tenant basis using a  table.
- Follows a capabilities-first approach, using Gates and Policies.
- Includes a break-glass mechanism for platform superadmins.
- Adds policies for bootstrapping tenants and managing admin responsibilities.
2026-01-25 16:01:50 +01:00

37 lines
1.1 KiB
PHP

<?php
use App\Models\User;
use App\Services\Auth\TenantMembershipManager;
use App\Support\TenantRole;
use Illuminate\Foundation\Testing\RefreshDatabase;
uses(RefreshDatabase::class);
it('can add, change role, and remove tenant members', function () {
[$actor, $tenant] = createUserWithTenant(role: 'owner');
$member = User::factory()->create();
$manager = app(TenantMembershipManager::class);
$membership = $manager->addMember($tenant, $actor, $member, TenantRole::Readonly);
$this->assertDatabaseHas('tenant_memberships', [
'id' => $membership->getKey(),
'tenant_id' => $tenant->getKey(),
'user_id' => $member->getKey(),
'role' => 'readonly',
'source' => 'manual',
]);
$updated = $manager->changeRole($tenant, $actor, $membership, TenantRole::Operator);
expect($updated->role)->toBe('operator');
$manager->removeMember($tenant, $actor, $updated);
$this->assertDatabaseMissing('tenant_memberships', [
'tenant_id' => $tenant->getKey(),
'user_id' => $member->getKey(),
]);
});