## Summary - retire the tenant panel runtime and converge operator routing on the workspace-first admin shell - update tenant, operations, and required-permissions navigation helpers to use canonical workspace-scoped URLs - repair the focused feature coverage, add the Spec 280 browser smoke, and record the implementation close-out in the requirements checklist ## Validation - `cd apps/platform && ./vendor/bin/sail artisan test --compact tests/Feature/WorkspaceFoundation tests/Feature/Workspaces tests/Feature/ManagedEnvironment tests/Feature/RequiredPermissions tests/Feature/Operations tests/Feature/MonitoringOperationsTest.php` - `cd apps/platform && ./vendor/bin/sail artisan test --compact tests/Browser/Spec280WorkspaceTenancyEnvironmentRoutingSmokeTest.php` - `cd apps/platform && ./vendor/bin/sail bin pint --dirty --format agent` ## Note - `origin/platform` is not present on the remote; `platform-dev` is the clean base branch that limits this PR to the Spec 280 prep commit plus the implementation commit. Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de> Reviewed-on: #340
147 lines
6.6 KiB
PHP
147 lines
6.6 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
use App\Filament\Pages\TenantDashboard;
|
|
use App\Models\ManagedEnvironment;
|
|
use App\Support\Workspaces\WorkspaceContext;
|
|
use Filament\Facades\Filament;
|
|
use Illuminate\Foundation\Testing\RefreshDatabase;
|
|
|
|
uses(RefreshDatabase::class);
|
|
|
|
it('shows only active tenants and no-tenant helper copy on the choose-tenant page', function (): void {
|
|
$activeTenant = ManagedEnvironment::factory()->active()->create(['name' => 'Choose Active ManagedEnvironment']);
|
|
[$user, $activeTenant] = createUserWithTenant(tenant: $activeTenant, role: 'owner');
|
|
|
|
$otherActiveTenant = ManagedEnvironment::factory()->active()->create([
|
|
'workspace_id' => (int) $activeTenant->workspace_id,
|
|
'name' => 'Choose Other Active ManagedEnvironment',
|
|
]);
|
|
$onboardingTenant = ManagedEnvironment::factory()->onboarding()->create([
|
|
'workspace_id' => (int) $activeTenant->workspace_id,
|
|
'name' => 'Choose Onboarding ManagedEnvironment',
|
|
]);
|
|
$archivedTenant = ManagedEnvironment::factory()->archived()->create([
|
|
'workspace_id' => (int) $activeTenant->workspace_id,
|
|
'name' => 'Choose Archived ManagedEnvironment',
|
|
]);
|
|
|
|
createUserWithTenant(tenant: $otherActiveTenant, user: $user, role: 'owner');
|
|
createUserWithTenant(tenant: $onboardingTenant, user: $user, role: 'owner', ensureDefaultMicrosoftProviderConnection: false);
|
|
createUserWithTenant(tenant: $archivedTenant, user: $user, role: 'owner', ensureDefaultMicrosoftProviderConnection: false);
|
|
|
|
Filament::setTenant(null, true);
|
|
|
|
$this->actingAs($user)
|
|
->withSession([WorkspaceContext::SESSION_KEY => (int) $activeTenant->workspace_id])
|
|
->get('/admin/choose-tenant')
|
|
->assertSuccessful()
|
|
->assertSee('Choose Active ManagedEnvironment')
|
|
->assertSee('Choose Other Active ManagedEnvironment')
|
|
->assertDontSee('Choose Onboarding ManagedEnvironment')
|
|
->assertDontSee('Choose Archived ManagedEnvironment')
|
|
->assertSee('Select the tenant for your normal active operating context.')
|
|
->assertSee('No tenant selected is still a valid workspace state');
|
|
});
|
|
|
|
it('shows a workspace-safe empty state when no selectable tenants remain', function (): void {
|
|
$onboardingTenant = ManagedEnvironment::factory()->onboarding()->create(['name' => 'Only Onboarding ManagedEnvironment']);
|
|
[$user, $onboardingTenant] = createUserWithTenant(
|
|
tenant: $onboardingTenant,
|
|
role: 'owner',
|
|
ensureDefaultMicrosoftProviderConnection: false,
|
|
);
|
|
|
|
Filament::setTenant(null, true);
|
|
|
|
$this->actingAs($user)
|
|
->withSession([WorkspaceContext::SESSION_KEY => (int) $onboardingTenant->workspace_id])
|
|
->get('/admin/choose-tenant')
|
|
->assertSuccessful()
|
|
->assertSee('No active tenants available')
|
|
->assertSee('Workspace-level pages still work with no tenant selected')
|
|
->assertSee('View managed tenants');
|
|
});
|
|
|
|
it('keeps selector eligibility narrower than managed-tenant administrative discoverability', function (): void {
|
|
$activeTenant = ManagedEnvironment::factory()->active()->create(['name' => 'Selector Active ManagedEnvironment']);
|
|
[$user, $activeTenant] = createUserWithTenant(tenant: $activeTenant, role: 'owner', ensureDefaultMicrosoftProviderConnection: false);
|
|
|
|
$onboardingTenant = ManagedEnvironment::factory()->onboarding()->create([
|
|
'workspace_id' => (int) $activeTenant->workspace_id,
|
|
'name' => 'Selector Onboarding ManagedEnvironment',
|
|
]);
|
|
$archivedTenant = ManagedEnvironment::factory()->archived()->create([
|
|
'workspace_id' => (int) $activeTenant->workspace_id,
|
|
'name' => 'Selector Archived ManagedEnvironment',
|
|
]);
|
|
|
|
createUserWithTenant(tenant: $onboardingTenant, user: $user, role: 'owner', workspaceRole: 'owner', ensureDefaultMicrosoftProviderConnection: false);
|
|
createUserWithTenant(tenant: $archivedTenant, user: $user, role: 'owner', workspaceRole: 'owner', ensureDefaultMicrosoftProviderConnection: false);
|
|
|
|
Filament::setTenant(null, true);
|
|
|
|
$this->actingAs($user)
|
|
->withSession([WorkspaceContext::SESSION_KEY => (int) $activeTenant->workspace_id])
|
|
->get('/admin/choose-tenant')
|
|
->assertSuccessful()
|
|
->assertSee('Selector Active ManagedEnvironment')
|
|
->assertDontSee('Selector Onboarding ManagedEnvironment')
|
|
->assertDontSee('Selector Archived ManagedEnvironment');
|
|
|
|
$this->actingAs($user)
|
|
->withSession([WorkspaceContext::SESSION_KEY => (int) $activeTenant->workspace_id])
|
|
->get(route('admin.workspace.managed-tenants.index', ['workspace' => $activeTenant->workspace]))
|
|
->assertSuccessful()
|
|
->assertSee('Selector Active ManagedEnvironment')
|
|
->assertSee('Selector Onboarding ManagedEnvironment')
|
|
->assertSee('Selector Archived ManagedEnvironment');
|
|
});
|
|
|
|
it('redirects clear selected tenant from tenant-bound pages back to a workspace-safe managed-tenants page', function (): void {
|
|
[$user, $tenant] = createUserWithTenant(role: 'owner');
|
|
|
|
Filament::setTenant($tenant, true);
|
|
|
|
$this->actingAs($user)
|
|
->withSession([
|
|
WorkspaceContext::SESSION_KEY => (int) $tenant->workspace_id,
|
|
WorkspaceContext::LAST_TENANT_IDS_SESSION_KEY => [
|
|
(string) $tenant->workspace_id => (int) $tenant->getKey(),
|
|
],
|
|
])
|
|
->from(TenantDashboard::getUrl(tenant: $tenant))
|
|
->post(route('admin.clear-tenant-context'))
|
|
->assertRedirect(route('admin.workspace.managed-tenants.index', ['workspace' => $tenant->workspace]));
|
|
|
|
$this->withSession([
|
|
WorkspaceContext::SESSION_KEY => (int) $tenant->workspace_id,
|
|
])->get(route('admin.operations.index', ['workspace' => $tenant->workspace]))
|
|
->assertSuccessful()
|
|
->assertSee('All tenants');
|
|
});
|
|
|
|
it('redirects clear selected tenant from the evidence index to the workspace-safe evidence overview', function (): void {
|
|
[$user, $tenant] = createUserWithTenant(role: 'owner');
|
|
|
|
Filament::setTenant($tenant, true);
|
|
|
|
$this->actingAs($user)
|
|
->withSession([
|
|
WorkspaceContext::SESSION_KEY => (int) $tenant->workspace_id,
|
|
WorkspaceContext::LAST_TENANT_IDS_SESSION_KEY => [
|
|
(string) $tenant->workspace_id => (int) $tenant->getKey(),
|
|
],
|
|
])
|
|
->from('/admin/evidence')
|
|
->post(route('admin.clear-tenant-context'))
|
|
->assertRedirect(route('admin.evidence.overview'));
|
|
|
|
$this->withSession([
|
|
WorkspaceContext::SESSION_KEY => (int) $tenant->workspace_id,
|
|
])->get(route('admin.evidence.overview'))
|
|
->assertSuccessful()
|
|
->assertSee('No evidence snapshots in this scope');
|
|
});
|