TenantAtlas/apps/platform/tests/Feature/Artifacts/EvidenceSnapshotSourceTaxonomyTest.php
ahmido 75ebade345 feat: implement provider-neutral artifact source taxonomy (#343)
## Summary

Implements Spec 284 for provider-neutral artifact source taxonomy.

- add shared artifact source descriptor, resolver, taxonomy, and provider-detail support
- update findings, evidence snapshots, stored reports, inventory items, and tenant review surfaces to disclose descriptor-first artifact summaries
- add bounded Pest unit, feature, guard, and browser coverage for the taxonomy slice
- include the completed Spec 284 package artifacts under `specs/284-provider-neutral-artifact-source-taxonomy/`

## Notes

- branch: `284-provider-neutral-artifact-source-taxonomy`
- commit: `bf8d59e0`
- this PR was created as part of the requested commit/push/PR flow against `platform-dev`

Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de>
Reviewed-on: #343
2026-05-08 23:47:31 +00:00

88 lines
3.7 KiB
PHP

<?php
declare(strict_types=1);
use App\Models\EvidenceSnapshot;
use App\Models\Finding;
use App\Models\StoredReport;
use App\Services\Evidence\EvidenceSnapshotService;
use App\Support\Evidence\EvidenceSnapshotStatus;
it('carries artifact source descriptors through evidence snapshot payloads and items', function (): void {
[$user, $tenant] = createUserWithTenant(ensureDefaultMicrosoftProviderConnection: true);
$connection = $tenant->providerConnections()->where('provider', 'microsoft')->where('is_default', true)->firstOrFail();
StoredReport::factory()->permissionPosture()->create([
'managed_environment_id' => (int) $tenant->getKey(),
'workspace_id' => (int) $tenant->workspace_id,
'fingerprint' => 'permission-report-fingerprint',
'payload' => [
'provider_key' => 'microsoft',
'provider_connection_id' => (int) $connection->getKey(),
'posture_score' => 90,
'required_count' => 4,
'granted_count' => 4,
],
]);
Finding::factory()->create([
'managed_environment_id' => (int) $tenant->getKey(),
'workspace_id' => (int) $tenant->workspace_id,
'evidence_jsonb' => ['policy_type' => 'deviceCompliancePolicy'],
]);
$payload = app(EvidenceSnapshotService::class)->buildSnapshotPayload($tenant);
$permissionItem = collect($payload['items'])->firstWhere('dimension_key', 'permission_posture');
expect($permissionItem['source_descriptor'])->toMatchArray([
'workspace_id' => (int) $tenant->workspace_id,
'tenant_id' => (int) $tenant->getKey(),
'managed_environment_id' => (int) $tenant->getKey(),
'source_family' => 'stored_report',
'source_kind' => 'stored_report',
'provider_key' => 'microsoft',
'provider_connection_id' => (int) $connection->getKey(),
'source_target_kind' => 'managed_environment',
'source_target_identifier' => (string) $tenant->getKey(),
'control_key' => 'strong_authentication',
'package_run_id' => null,
])
->and($permissionItem['summary_payload']['source_descriptor'])->toMatchArray($permissionItem['source_descriptor'])
->and($payload['summary']['dimensions'])->each->toHaveKey('source_descriptor');
$snapshot = EvidenceSnapshot::query()->create([
'managed_environment_id' => (int) $tenant->getKey(),
'workspace_id' => (int) $tenant->workspace_id,
'status' => EvidenceSnapshotStatus::Active->value,
'fingerprint' => $payload['fingerprint'],
'completeness_state' => $payload['completeness'],
'summary' => $payload['summary'],
'generated_at' => now(),
]);
foreach ($payload['items'] as $item) {
$snapshot->items()->create([
'managed_environment_id' => (int) $tenant->getKey(),
'workspace_id' => (int) $tenant->workspace_id,
'dimension_key' => $item['dimension_key'],
'state' => $item['state'],
'required' => $item['required'],
'source_kind' => $item['source_kind'],
'source_record_type' => $item['source_record_type'],
'source_record_id' => $item['source_record_id'],
'source_fingerprint' => $item['source_fingerprint'],
'measured_at' => $item['measured_at'],
'freshness_at' => $item['freshness_at'],
'summary_payload' => $item['summary_payload'],
'sort_order' => $item['sort_order'],
]);
}
$persistedPermissionItem = $snapshot->items()->where('dimension_key', 'permission_posture')->firstOrFail();
expect($persistedPermissionItem->artifactSourceDescriptor()->toArray())
->toMatchArray($permissionItem['source_descriptor']);
$this->actingAs($user);
});