TenantAtlas/apps/platform/tests/Feature/OpsUx/BulkTenantIsolationTest.php
ahmido e64bae9cfc feat: cut over tenant core to managed environments (#335)
## Summary
- replace the legacy Tenant and TenantMembership core models with ManagedEnvironment and ManagedEnvironmentMembership
- propagate the managed environment naming and key changes across Filament resources, pages, controllers, jobs, models, and supporting runtime paths
- add feature 279 spec artifacts and focused managed-environment test coverage for model behavior, route binding, panel context, authorization, and legacy guardrails

## Validation
- `cd apps/platform && ./vendor/bin/sail artisan test --compact tests/Feature/ManagedEnvironment/LegacyTenantCoreGuardTest.php tests/Feature/ManagedEnvironment/ManagedEnvironmentAuthorizationTest.php tests/Feature/ManagedEnvironment/ManagedEnvironmentPanelContextTest.php tests/Feature/ManagedEnvironment/ManagedEnvironmentRouteBindingTest.php tests/Unit/ManagedEnvironment/ManagedEnvironmentContextResolverTest.php tests/Unit/ManagedEnvironment/ManagedEnvironmentModelTest.php`
- `cd apps/platform && ./vendor/bin/sail bin pint --dirty --format agent`

## Notes
- branch pushed from commit `1123b122`
- browser smoke test file was added but not run in this pass

Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de>
Reviewed-on: #335
2026-05-07 06:38:14 +00:00

32 lines
1001 B
PHP

<?php
use App\Models\ManagedEnvironment;
use App\Services\OperationRunService;
use App\Services\Operations\BulkSelectionIdentity;
it('rejects bulk enqueue when target_scope entra_tenant_id mismatches tenant', function () {
$tenant = ManagedEnvironment::factory()->create([
'managed_environment_id' => 'tenant-a',
'external_id' => 'tenant-a',
]);
/** @var BulkSelectionIdentity $selection */
$selection = app(BulkSelectionIdentity::class);
$selectionIdentity = $selection->fromIds([1, 2, 3]);
/** @var OperationRunService $runs */
$runs = app(OperationRunService::class);
$runs->enqueueBulkOperation(
tenant: $tenant,
type: 'policy.bulk_delete',
targetScope: ['entra_tenant_id' => 'tenant-b'],
selectionIdentity: $selectionIdentity,
dispatcher: fn (): null => null,
initiator: null,
extraContext: [],
emitQueuedNotification: false,
);
})->throws(InvalidArgumentException::class);