TenantAtlas/apps/platform/tests/Feature/Filament/TenantResourceIndexIsWorkspaceScopedTest.php
ahmido e64bae9cfc feat: cut over tenant core to managed environments (#335)
## Summary
- replace the legacy Tenant and TenantMembership core models with ManagedEnvironment and ManagedEnvironmentMembership
- propagate the managed environment naming and key changes across Filament resources, pages, controllers, jobs, models, and supporting runtime paths
- add feature 279 spec artifacts and focused managed-environment test coverage for model behavior, route binding, panel context, authorization, and legacy guardrails

## Validation
- `cd apps/platform && ./vendor/bin/sail artisan test --compact tests/Feature/ManagedEnvironment/LegacyTenantCoreGuardTest.php tests/Feature/ManagedEnvironment/ManagedEnvironmentAuthorizationTest.php tests/Feature/ManagedEnvironment/ManagedEnvironmentPanelContextTest.php tests/Feature/ManagedEnvironment/ManagedEnvironmentRouteBindingTest.php tests/Unit/ManagedEnvironment/ManagedEnvironmentContextResolverTest.php tests/Unit/ManagedEnvironment/ManagedEnvironmentModelTest.php`
- `cd apps/platform && ./vendor/bin/sail bin pint --dirty --format agent`

## Notes
- branch pushed from commit `1123b122`
- browser smoke test file was added but not run in this pass

Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de>
Reviewed-on: #335
2026-05-07 06:38:14 +00:00

164 lines
6.4 KiB
PHP

<?php
declare(strict_types=1);
use App\Filament\Resources\TenantResource\Pages\ListTenants;
use App\Models\ManagedEnvironment;
use App\Models\ManagedEnvironmentMembership;
use App\Models\User;
use App\Models\Workspace;
use App\Models\WorkspaceMembership;
use App\Support\BackupHealth\TenantBackupHealthAssessment;
use App\Support\Workspaces\WorkspaceContext;
use Filament\Facades\Filament;
use Illuminate\Foundation\Testing\RefreshDatabase;
use Livewire\Livewire;
uses(RefreshDatabase::class);
it('does not show tenants from other workspaces on the tenants index', function (): void {
$user = User::factory()->create();
$workspaceA = Workspace::factory()->create(['name' => 'Workspace A']);
$workspaceB = Workspace::factory()->create(['name' => 'Workspace B']);
WorkspaceMembership::factory()->create([
'workspace_id' => $workspaceA->getKey(),
'user_id' => $user->getKey(),
'role' => 'owner',
]);
WorkspaceMembership::factory()->create([
'workspace_id' => $workspaceB->getKey(),
'user_id' => $user->getKey(),
'role' => 'owner',
]);
$tenantA = ManagedEnvironment::factory()->create([
'workspace_id' => $workspaceA->getKey(),
'external_id' => '11111111-1111-1111-1111-111111111111',
'managed_environment_id' => '11111111-1111-1111-1111-111111111111',
'name' => 'ManagedEnvironment A',
'status' => 'active',
]);
$tenantB = ManagedEnvironment::factory()->create([
'workspace_id' => $workspaceB->getKey(),
'external_id' => '22222222-2222-2222-2222-222222222222',
'managed_environment_id' => '22222222-2222-2222-2222-222222222222',
'name' => 'ManagedEnvironment B',
'status' => 'active',
]);
ManagedEnvironmentMembership::query()->create([
'managed_environment_id' => $tenantA->getKey(),
'user_id' => $user->getKey(),
'role' => 'owner',
'source' => 'manual',
'source_ref' => null,
'created_by_user_id' => null,
]);
ManagedEnvironmentMembership::query()->create([
'managed_environment_id' => $tenantB->getKey(),
'user_id' => $user->getKey(),
'role' => 'owner',
'source' => 'manual',
'source_ref' => null,
'created_by_user_id' => null,
]);
$this->actingAs($user)
->withSession([WorkspaceContext::SESSION_KEY => (int) $workspaceA->getKey()])
->get(route('filament.admin.resources.tenants.index', filamentTenantRouteParams($tenantA)))
->assertOk()
->assertSee('ManagedEnvironment A')
->assertDontSee('ManagedEnvironment B');
});
it('keeps tenant list defaults calm and persists list state in-session', function (): void {
[$user] = createUserWithTenant(role: 'owner');
$this->actingAs($user);
Filament::setTenant(null, true);
$component = Livewire::actingAs($user)
->test(\App\Filament\Resources\TenantResource\Pages\ListTenants::class)
->assertTableEmptyStateActionsExistInOrder(['add_tenant'])
->searchTable('ManagedEnvironment')
->call('sortTable', 'name', 'desc')
->set('tableFilters.environment.value', 'prod');
$table = $component->instance()->getTable();
expect($table->getPaginationPageOptions())->toBe(\App\Support\Filament\TablePaginationProfiles::resource());
expect($table->getEmptyStateHeading())->toBe('No tenants connected');
expect($table->getColumn('name')?->isSearchable())->toBeTrue();
expect($table->getColumn('name')?->isSortable())->toBeTrue();
expect($table->getColumn('managed_environment_id')?->isToggledHiddenByDefault())->toBeTrue();
expect($table->getColumn('domain')?->isToggledHiddenByDefault())->toBeTrue();
expect(count($table->getVisibleColumns()))->toBeLessThanOrEqual(7);
expect(session()->get($component->instance()->getTableSearchSessionKey()))->toBe('ManagedEnvironment');
expect(session()->get($component->instance()->getTableSortSessionKey()))->toBe('name:desc');
Livewire::actingAs($user)
->test(\App\Filament\Resources\TenantResource\Pages\ListTenants::class)
->assertSet('tableSearch', 'ManagedEnvironment')
->assertSet('tableSort', 'name:desc')
->assertSet('tableFilters.environment.value', 'prod');
});
it('keeps posture filters scoped to visible workspace tenants only', function (): void {
$visibleTenant = ManagedEnvironment::factory()->create(['status' => 'active']);
[$user, $visibleTenant] = createUserWithTenant($visibleTenant, role: 'owner', workspaceRole: 'readonly');
workspaceOverviewSeedQuietTenantTruth($visibleTenant);
workspaceOverviewSeedHealthyBackup($visibleTenant, [
'completed_at' => now()->subMinutes(10),
]);
$hiddenRecoveryTenant = ManagedEnvironment::factory()->create([
'status' => 'active',
'workspace_id' => (int) $visibleTenant->workspace_id,
'name' => 'Hidden Recovery ManagedEnvironment',
]);
workspaceOverviewSeedQuietTenantTruth($hiddenRecoveryTenant);
workspaceOverviewSeedHealthyBackup($hiddenRecoveryTenant, [
'completed_at' => now()->subMinutes(9),
]);
$hiddenBackupTenant = ManagedEnvironment::factory()->create([
'status' => 'active',
'workspace_id' => (int) $visibleTenant->workspace_id,
'name' => 'Hidden Degraded ManagedEnvironment',
]);
workspaceOverviewSeedQuietTenantTruth($hiddenBackupTenant);
workspaceOverviewSeedHealthyBackup($hiddenBackupTenant, [
'completed_at' => now()->subMinutes(8),
], [
'payload' => [],
'metadata' => [
'source' => 'metadata_only',
'assignments_fetch_failed' => true,
],
'assignments' => [],
]);
$this->actingAs($user);
session()->put(WorkspaceContext::SESSION_KEY, (int) $visibleTenant->workspace_id);
Filament::setTenant(null, true);
$recoveryFiltered = Livewire::actingAs($user)
->test(ListTenants::class)
->filterTable('recovery_evidence', ['unvalidated']);
expect($recoveryFiltered->instance()->getFilteredTableQuery()?->pluck('managed_environments.name')->all())
->toBe([(string) $visibleTenant->name]);
$backupFiltered = Livewire::actingAs($user)
->test(ListTenants::class)
->filterTable('backup_posture', [TenantBackupHealthAssessment::POSTURE_DEGRADED]);
expect($backupFiltered->instance()->getFilteredTableQuery()?->pluck('managed_environments.name')->all())
->toBe([]);
});