TenantAtlas/tests/Feature/BaselineDriftEngine/ResolverTest.php
ahmido 92704a2f7e Spec 118: Resumable baseline evidence capture + snapshot UX (#143)
Implements Spec 118 baseline drift engine improvements:

- Resumable, budget-aware evidence capture for baseline capture/compare runs (resume token + UI action)
- “Why no findings?” reason-code driven explanations and richer run context panels
- Baseline Snapshot resource (list/detail) with fidelity visibility
- Retention command + schedule for pruning baseline-purpose PolicyVersions
- i18n strings for Baseline Compare landing

Verification:
- `vendor/bin/sail bin pint --dirty --format agent`
- `vendor/bin/sail artisan test --compact --filter=Baseline` (159 passed)

Note:
- `docs/audits/redaction-audit-2026-03-04.md` left untracked (not part of PR).

Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de>
Reviewed-on: #143
2026-03-04 22:34:13 +00:00

146 lines
5.8 KiB
PHP

<?php
use App\Models\InventoryItem;
use App\Models\Policy;
use App\Models\PolicyVersion;
use App\Services\Baselines\BaselineSnapshotIdentity;
use App\Services\Baselines\CurrentStateHashResolver;
use App\Services\Drift\DriftHasher;
use App\Services\Drift\Normalizers\AssignmentsNormalizer;
use App\Services\Drift\Normalizers\SettingsNormalizer;
use App\Services\Drift\Normalizers\ScopeTagsNormalizer;
use Carbon\CarbonImmutable;
it('Baseline resolver prefers content evidence over meta evidence when available', function () {
[, $tenant] = createUserWithTenant();
$policy = Policy::factory()->create([
'tenant_id' => (int) $tenant->getKey(),
'policy_type' => 'settingsCatalogPolicy',
'external_id' => 'policy-a',
'platform' => 'windows10',
]);
$policyVersion = PolicyVersion::factory()->create([
'tenant_id' => (int) $tenant->getKey(),
'policy_id' => (int) $policy->getKey(),
'policy_type' => (string) $policy->policy_type,
'platform' => (string) $policy->platform,
'captured_at' => CarbonImmutable::parse('2026-03-01 10:00:00'),
'snapshot' => [
'settings' => [
['name' => 'settingA', 'value' => 1],
],
],
]);
$inventory = InventoryItem::factory()->create([
'tenant_id' => (int) $tenant->getKey(),
'policy_type' => (string) $policy->policy_type,
'external_id' => (string) $policy->external_id,
'meta_jsonb' => [
'odata_type' => '#microsoft.graph.deviceManagementConfigurationPolicy',
'etag' => 'W/"meta-etag"',
'scope_tag_ids' => [],
'assignment_target_count' => 1,
],
'last_seen_at' => CarbonImmutable::parse('2026-03-01 11:00:00'),
'last_seen_operation_run_id' => null,
]);
$expectedContentHash = app(DriftHasher::class)->hashNormalized([
'settings' => app(SettingsNormalizer::class)->normalizeForDiff(
is_array($policyVersion->snapshot) ? $policyVersion->snapshot : [],
(string) $policyVersion->policy_type,
is_string($policyVersion->platform) ? $policyVersion->platform : null,
),
'assignments' => app(AssignmentsNormalizer::class)->normalizeForDiff([]),
'scope_tag_ids' => app(ScopeTagsNormalizer::class)->normalizeIds([]),
]);
$expectedMetaHash = app(BaselineSnapshotIdentity::class)->hashItemContent(
policyType: (string) $inventory->policy_type,
subjectExternalId: (string) $inventory->external_id,
metaJsonb: is_array($inventory->meta_jsonb) ? $inventory->meta_jsonb : [],
);
$resolver = app(CurrentStateHashResolver::class);
$result = $resolver->resolveForSubjects(
tenant: $tenant,
subjects: [
['policy_type' => (string) $policy->policy_type, 'subject_external_id' => (string) $policy->external_id],
],
since: null,
latestInventorySyncRunId: null,
);
expect($result)->toHaveKey((string) $policy->policy_type.'|'.(string) $policy->external_id);
$evidence = $result[(string) $policy->policy_type.'|'.(string) $policy->external_id];
expect($evidence)->not->toBeNull();
expect($evidence?->hash)->toBe($expectedContentHash);
expect($evidence?->hash)->not->toBe($expectedMetaHash);
expect($evidence?->provenance()['fidelity'])->toBe('content');
expect($evidence?->provenance()['source'])->toBe('policy_version');
});
it('Baseline resolver obeys since rule and falls back to meta evidence when content is too old', function () {
[, $tenant] = createUserWithTenant();
$policy = Policy::factory()->create([
'tenant_id' => (int) $tenant->getKey(),
'policy_type' => 'settingsCatalogPolicy',
'external_id' => 'policy-b',
'platform' => 'windows10',
]);
PolicyVersion::factory()->create([
'tenant_id' => (int) $tenant->getKey(),
'policy_id' => (int) $policy->getKey(),
'policy_type' => (string) $policy->policy_type,
'platform' => (string) $policy->platform,
'captured_at' => CarbonImmutable::parse('2026-03-01 10:00:00'),
'snapshot' => [
'settings' => [
['name' => 'settingB', 'value' => 2],
],
],
]);
$inventory = InventoryItem::factory()->create([
'tenant_id' => (int) $tenant->getKey(),
'policy_type' => (string) $policy->policy_type,
'external_id' => (string) $policy->external_id,
'meta_jsonb' => [
'odata_type' => '#microsoft.graph.deviceManagementConfigurationPolicy',
'etag' => 'W/"meta-etag-b"',
'scope_tag_ids' => [],
'assignment_target_count' => 1,
],
'last_seen_at' => CarbonImmutable::parse('2026-03-02 10:00:00'),
'last_seen_operation_run_id' => null,
]);
$expectedMetaHash = app(BaselineSnapshotIdentity::class)->hashItemContent(
policyType: (string) $inventory->policy_type,
subjectExternalId: (string) $inventory->external_id,
metaJsonb: is_array($inventory->meta_jsonb) ? $inventory->meta_jsonb : [],
);
$resolver = app(CurrentStateHashResolver::class);
$result = $resolver->resolveForSubjects(
tenant: $tenant,
subjects: [
['policy_type' => (string) $policy->policy_type, 'subject_external_id' => (string) $policy->external_id],
],
since: CarbonImmutable::parse('2026-03-02 00:00:00'),
latestInventorySyncRunId: null,
);
$evidence = $result[(string) $policy->policy_type.'|'.(string) $policy->external_id] ?? null;
expect($evidence)->not->toBeNull();
expect($evidence?->hash)->toBe($expectedMetaHash);
expect($evidence?->provenance()['fidelity'])->toBe('meta');
expect($evidence?->provenance()['source'])->toBe('inventory');
});