## Summary
- centralize tenant operability into a lane-aware, actor-aware policy boundary
- align selector eligibility, administrative discoverability, remembered context, tenant-bound routes, and canonical run viewers
- add focused Pest coverage plus Spec 148 artifacts and final polish task completion
## Validation
- `vendor/bin/sail artisan test --compact tests/Unit/Tenants/TenantOperabilityServiceTest.php tests/Unit/Tenants/TenantOperabilityOutcomeTest.php tests/Feature/Workspaces/ChooseTenantPageTest.php tests/Feature/Workspaces/SelectTenantControllerTest.php tests/Feature/TenantRBAC/ArchivedTenantRouteAccessTest.php tests/Feature/TenantRBAC/TenantRouteDenyAsNotFoundTest.php tests/Feature/Operations/TenantlessOperationRunViewerTest.php tests/Feature/OpsUx/OperateHubShellTest.php tests/Feature/Rbac/TenantLifecycleActionVisibilityTest.php tests/Feature/TenantRBAC/TenantSwitcherScopeTest.php tests/Feature/Rbac/TenantResourceAuthorizationTest.php tests/Feature/Filament/ManagedTenantsLandingLifecycleTest.php tests/Feature/Filament/TenantGlobalSearchLifecycleScopeTest.php tests/Feature/Onboarding/OnboardingDraftLifecycleTest.php tests/Feature/Onboarding/OnboardingDraftAuthorizationTest.php`
- `vendor/bin/sail bin pint --dirty --format agent`
- manual browser smoke checks on `/admin/choose-tenant`, `/admin/tenants`, `/admin/onboarding`, `/admin/onboarding/{draft}`, and `/admin/operations/{run}`
## Filament / platform notes
- Livewire v4 compliance preserved
- panel provider registration unchanged in `bootstrap/providers.php`
- Tenant resource global search remains backed by existing view/edit pages and is now separated from active-only selector eligibility
- destructive actions remain action closures with confirmation and authorization enforcement
- no asset pipeline changes and no new `filament:assets` deployment requirement
Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de>
Reviewed-on: #177
148 lines
5.6 KiB
PHP
148 lines
5.6 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
use App\Models\Tenant;
|
|
use App\Models\User;
|
|
use App\Models\Workspace;
|
|
use App\Models\WorkspaceMembership;
|
|
use App\Support\Workspaces\WorkspaceContext;
|
|
use Illuminate\Foundation\Testing\RefreshDatabase;
|
|
|
|
uses(RefreshDatabase::class);
|
|
|
|
it('shows onboarding and archived tenants on the managed-tenants landing with lifecycle labels', function (): void {
|
|
$workspace = Workspace::factory()->create(['slug' => 'lifecycle-ws']);
|
|
$user = User::factory()->create();
|
|
|
|
WorkspaceMembership::factory()->create([
|
|
'workspace_id' => (int) $workspace->getKey(),
|
|
'user_id' => (int) $user->getKey(),
|
|
'role' => 'owner',
|
|
]);
|
|
|
|
$active = Tenant::factory()->active()->create([
|
|
'workspace_id' => (int) $workspace->getKey(),
|
|
'name' => 'Active Tenant',
|
|
]);
|
|
$onboarding = Tenant::factory()->onboarding()->create([
|
|
'workspace_id' => (int) $workspace->getKey(),
|
|
'name' => 'Onboarding Tenant',
|
|
]);
|
|
$archived = Tenant::factory()->archived()->create([
|
|
'workspace_id' => (int) $workspace->getKey(),
|
|
'name' => 'Archived Tenant',
|
|
]);
|
|
$outsider = Tenant::factory()->active()->create(['name' => 'Other Workspace Tenant']);
|
|
|
|
$user->tenants()->syncWithoutDetaching([
|
|
$active->getKey() => ['role' => 'owner'],
|
|
$onboarding->getKey() => ['role' => 'owner'],
|
|
$archived->getKey() => ['role' => 'owner'],
|
|
$outsider->getKey() => ['role' => 'owner'],
|
|
]);
|
|
|
|
$this->actingAs($user)
|
|
->withSession([WorkspaceContext::SESSION_KEY => (int) $workspace->getKey()])
|
|
->get(route('admin.workspace.managed-tenants.index', ['workspace' => $workspace]))
|
|
->assertSuccessful()
|
|
->assertSee('Active Tenant')
|
|
->assertSee('Onboarding Tenant')
|
|
->assertSee('Archived Tenant')
|
|
->assertSee('Active')
|
|
->assertSee('Onboarding')
|
|
->assertSee('Archived')
|
|
->assertDontSee('Other Workspace Tenant');
|
|
});
|
|
|
|
it('keeps managed tenants discoverable with no selected tenant context', function (): void {
|
|
$workspace = Workspace::factory()->create(['slug' => 'discoverable-managed-tenants']);
|
|
$user = User::factory()->create();
|
|
|
|
WorkspaceMembership::factory()->create([
|
|
'workspace_id' => (int) $workspace->getKey(),
|
|
'user_id' => (int) $user->getKey(),
|
|
'role' => 'owner',
|
|
]);
|
|
|
|
$onboardingTenant = Tenant::factory()->onboarding()->create([
|
|
'workspace_id' => (int) $workspace->getKey(),
|
|
'name' => 'Discoverable Onboarding Tenant',
|
|
]);
|
|
$draftTenant = Tenant::factory()->draft()->create([
|
|
'workspace_id' => (int) $workspace->getKey(),
|
|
'name' => 'Discoverable Draft Tenant',
|
|
]);
|
|
$archivedTenant = Tenant::factory()->archived()->create([
|
|
'workspace_id' => (int) $workspace->getKey(),
|
|
'name' => 'Discoverable Archived Tenant',
|
|
]);
|
|
|
|
$user->tenants()->syncWithoutDetaching([
|
|
$draftTenant->getKey() => ['role' => 'owner'],
|
|
$onboardingTenant->getKey() => ['role' => 'owner'],
|
|
$archivedTenant->getKey() => ['role' => 'owner'],
|
|
]);
|
|
|
|
$this->actingAs($user)
|
|
->withSession([WorkspaceContext::SESSION_KEY => (int) $workspace->getKey()])
|
|
->get(route('admin.workspace.managed-tenants.index', ['workspace' => $workspace]))
|
|
->assertSuccessful()
|
|
->assertSee('Discoverable Draft Tenant')
|
|
->assertSee('Discoverable Onboarding Tenant')
|
|
->assertSee('Discoverable Archived Tenant');
|
|
});
|
|
|
|
it('keeps administrative landing discoverability broader than choose-tenant selection', function (): void {
|
|
$workspace = Workspace::factory()->create(['slug' => 'landing-vs-selector']);
|
|
$user = User::factory()->create();
|
|
|
|
WorkspaceMembership::factory()->create([
|
|
'workspace_id' => (int) $workspace->getKey(),
|
|
'user_id' => (int) $user->getKey(),
|
|
'role' => 'owner',
|
|
]);
|
|
|
|
$activeTenant = Tenant::factory()->active()->create([
|
|
'workspace_id' => (int) $workspace->getKey(),
|
|
'name' => 'Landing Active Tenant',
|
|
]);
|
|
$draftTenant = Tenant::factory()->draft()->create([
|
|
'workspace_id' => (int) $workspace->getKey(),
|
|
'name' => 'Landing Draft Tenant',
|
|
]);
|
|
$onboardingTenant = Tenant::factory()->onboarding()->create([
|
|
'workspace_id' => (int) $workspace->getKey(),
|
|
'name' => 'Landing Onboarding Tenant',
|
|
]);
|
|
$archivedTenant = Tenant::factory()->archived()->create([
|
|
'workspace_id' => (int) $workspace->getKey(),
|
|
'name' => 'Landing Archived Tenant',
|
|
]);
|
|
|
|
$user->tenants()->syncWithoutDetaching([
|
|
$activeTenant->getKey() => ['role' => 'owner'],
|
|
$draftTenant->getKey() => ['role' => 'owner'],
|
|
$onboardingTenant->getKey() => ['role' => 'owner'],
|
|
$archivedTenant->getKey() => ['role' => 'owner'],
|
|
]);
|
|
|
|
$this->actingAs($user)
|
|
->withSession([WorkspaceContext::SESSION_KEY => (int) $workspace->getKey()])
|
|
->get(route('admin.workspace.managed-tenants.index', ['workspace' => $workspace]))
|
|
->assertSuccessful()
|
|
->assertSee('Landing Active Tenant')
|
|
->assertSee('Landing Draft Tenant')
|
|
->assertSee('Landing Onboarding Tenant')
|
|
->assertSee('Landing Archived Tenant');
|
|
|
|
$this->actingAs($user)
|
|
->withSession([WorkspaceContext::SESSION_KEY => (int) $workspace->getKey()])
|
|
->get('/admin/choose-tenant')
|
|
->assertSuccessful()
|
|
->assertSee('Landing Active Tenant')
|
|
->assertDontSee('Landing Draft Tenant')
|
|
->assertDontSee('Landing Onboarding Tenant')
|
|
->assertDontSee('Landing Archived Tenant');
|
|
});
|