TenantAtlas/apps/platform/tests/Feature/Auth/BackupHealthBrowserFixtureLoginTest.php
ahmido acc8947384 feat: harden governance action semantics (#229)
## Summary
- add the Spec 194 governance action catalog, friction classes, reason policies, and regression guards
- align exception, review, evidence, finding, tenant, provider connection, and system run actions to the shared semantics model
- add focused feature, RBAC, audit, unit, and browser coverage, including the tenant detail triage header consistency update

## Verification
- ran the focused Spec 194 verification pack from the quickstart and task plan
- ran targeted tenant triage coverage after the detail-header update
- ran `cd apps/platform && ./vendor/bin/sail bin pint --dirty --format agent`

## Filament Notes
- Filament v5 / Livewire v4 compliance preserved
- provider registration remains in `apps/platform/bootstrap/providers.php`
- globally searchable resources were not changed
- destructive actions remain confirmation-gated and server-authorized
- no new Filament assets were introduced; the existing `cd apps/platform && php artisan filament:assets` deploy step stays unchanged

Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de>
Reviewed-on: #229
2026-04-12 21:21:44 +00:00

46 lines
1.8 KiB
PHP

<?php
declare(strict_types=1);
use App\Filament\Pages\TenantDashboard;
use App\Filament\Resources\BackupSetResource;
use App\Http\Middleware\SuppressDebugbarForSmokeRequests;
use App\Models\Tenant;
use App\Models\User;
use App\Models\Workspace;
use App\Support\Workspaces\WorkspaceContext;
it('logs into the seeded backup-health browser fixture through the local helper', function (): void {
$this->artisan('tenantpilot:backup-health:seed-browser-fixture', ['--no-interaction' => true])
->assertSuccessful();
$workspaceConfig = config('tenantpilot.backup_health.browser_smoke_fixture.workspace');
$userConfig = config('tenantpilot.backup_health.browser_smoke_fixture.user');
$scenarioConfig = config('tenantpilot.backup_health.browser_smoke_fixture.blocked_drillthrough');
$tenantRouteKey = $scenarioConfig['tenant_id'] ?? $scenarioConfig['tenant_external_id'];
$workspace = Workspace::query()->where('slug', $workspaceConfig['slug'])->first();
$user = User::query()->where('email', $userConfig['email'])->first();
$tenant = Tenant::query()->where('external_id', $tenantRouteKey)->first();
expect($workspace)->not->toBeNull();
expect($user)->not->toBeNull();
expect($tenant)->not->toBeNull();
$this->get(route('admin.local.backup-health-browser-fixture-login'))
->assertRedirect(TenantDashboard::getUrl(tenant: $tenant))
->assertPlainCookie(
SuppressDebugbarForSmokeRequests::COOKIE_NAME,
SuppressDebugbarForSmokeRequests::COOKIE_VALUE,
);
$this->assertAuthenticatedAs($user);
expect(session(WorkspaceContext::SESSION_KEY))->toBe((int) $workspace->getKey());
$this->get(TenantDashboard::getUrl(tenant: $tenant))
->assertOk();
$this->get(BackupSetResource::getUrl('index', tenant: $tenant))
->assertForbidden();
});