TenantAtlas/tests/Unit/Support/RestoreSafety/RestoreSafetyAssessmentTest.php
ahmido a107e7e41b feat: restore safety integrity and queue slide-over (#210)
## Summary
- add the Spec 181 restore-safety layer with scope fingerprinting, preview/check integrity states, execution safety snapshots, result attention, and operator-facing copy across the wizard, restore detail, and canonical operation detail
- add focused unit and feature coverage for restore-safety assessment, result attention, and restore-linked operation detail
- switch the finding exceptions queue `Inspect exception` action to a native Filament slide-over while preserving query-param-backed inline summary behavior

## Testing
- `vendor/bin/sail artisan test --compact tests/Feature/Monitoring/FindingExceptionsQueueTest.php tests/Feature/Filament/RestoreSafetyIntegrityWizardTest.php tests/Feature/Filament/RestoreResultAttentionSurfaceTest.php tests/Feature/Operations/RestoreLinkedOperationDetailTest.php tests/Unit/Support/RestoreSafety`

## Notes
- Spec 181 checklist is complete (`specs/181-restore-safety-integrity/checklists/requirements.md`)
- the branch still has unchecked follow-up tasks in `specs/181-restore-safety-integrity/tasks.md`: `T012`, `T018`, `T019`, `T023`, `T025`, `T029`, `T032`, `T033`, `T041`, `T042`, `T043`, `T044`
- Filament v5 / Livewire v4 compliance is preserved, no panel provider registration changes were made, no global-search behavior was added, destructive actions remain confirmation-gated, and no new Filament assets were introduced

Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de>
Reviewed-on: #210
2026-04-06 23:37:14 +00:00

106 lines
4.1 KiB
PHP

<?php
declare(strict_types=1);
use App\Models\Tenant;
use App\Support\RestoreSafety\RestoreSafetyAssessment;
use App\Support\RestoreSafety\RestoreSafetyResolver;
use Illuminate\Foundation\Testing\RefreshDatabase;
uses(RefreshDatabase::class);
it('marks current evidence with warnings as ready with caution', function (): void {
$tenant = Tenant::factory()->create([
'rbac_status' => 'ok',
'rbac_last_checked_at' => now(),
]);
[$user] = createUserWithTenant(tenant: $tenant, role: 'owner');
ensureDefaultProviderConnection($tenant, 'microsoft');
/** @var RestoreSafetyResolver $resolver */
$resolver = app(RestoreSafetyResolver::class);
$data = [
'backup_set_id' => 50,
'scope_mode' => 'selected',
'backup_item_ids' => [4, 5],
'group_mapping' => ['group-a' => 'target-a'],
'check_summary' => ['blocking' => 0, 'warning' => 2, 'safe' => 1],
'check_results' => [['code' => 'warning', 'severity' => 'warning']],
'checks_ran_at' => now('UTC')->toIso8601String(),
'preview_summary' => ['generated_at' => now('UTC')->toIso8601String()],
'preview_diffs' => [['policy_identifier' => 'policy-1']],
'preview_ran_at' => now('UTC')->toIso8601String(),
];
$data['check_basis'] = $resolver->checksBasisFromData($data);
$data['preview_basis'] = $resolver->previewBasisFromData($data);
$data = \App\Filament\Resources\RestoreRunResource::synchronizeRestoreSafetyDraft($data);
$assessment = $resolver->safetyAssessment($tenant, $user, $data);
expect($assessment->state)->toBe(RestoreSafetyAssessment::STATE_READY_WITH_CAUTION)
->and($assessment->positiveClaimSuppressed)->toBeTrue()
->and($assessment->primaryNextAction)->toBe('review_warnings');
});
it('marks invalidated preview evidence as risky', function (): void {
$tenant = Tenant::factory()->create([
'rbac_status' => 'ok',
'rbac_last_checked_at' => now(),
]);
[$user] = createUserWithTenant(tenant: $tenant, role: 'owner');
ensureDefaultProviderConnection($tenant, 'microsoft');
/** @var RestoreSafetyResolver $resolver */
$resolver = app(RestoreSafetyResolver::class);
$currentData = [
'backup_set_id' => 50,
'scope_mode' => 'selected',
'backup_item_ids' => [4, 6],
'group_mapping' => ['group-a' => 'target-a'],
'check_summary' => ['blocking' => 0, 'warning' => 0, 'safe' => 1],
'check_results' => [['code' => 'safe', 'severity' => 'safe']],
'checks_ran_at' => now('UTC')->toIso8601String(),
'preview_summary' => ['generated_at' => now('UTC')->toIso8601String()],
'preview_diffs' => [['policy_identifier' => 'policy-1']],
'preview_ran_at' => now('UTC')->toIso8601String(),
];
$previousPreview = [
...$currentData,
'backup_item_ids' => [4, 5],
];
$currentData['check_basis'] = $resolver->checksBasisFromData($currentData);
$currentData['preview_basis'] = $resolver->previewBasisFromData($previousPreview);
$currentData = \App\Filament\Resources\RestoreRunResource::synchronizeRestoreSafetyDraft($currentData);
$assessment = $resolver->safetyAssessment($tenant, $user, $currentData);
expect($assessment->state)->toBe(RestoreSafetyAssessment::STATE_RISKY)
->and($assessment->previewIntegrity->state)->toBe('invalidated')
->and($assessment->primaryNextAction)->toBe('regenerate_preview');
});
it('treats empty stored basis arrays as missing evidence instead of legacy stale', function (): void {
/** @var RestoreSafetyResolver $resolver */
$resolver = app(RestoreSafetyResolver::class);
$data = [
'backup_set_id' => 50,
'scope_mode' => 'all',
'backup_item_ids' => [],
'group_mapping' => [],
'check_basis' => [],
'preview_basis' => [],
'check_summary' => [],
'preview_summary' => [],
'checks_ran_at' => null,
'preview_ran_at' => null,
];
expect($resolver->checksIntegrityFromData($data)->state)->toBe('not_run')
->and($resolver->previewIntegrityFromData($data)->state)->toBe('not_generated');
});