89 lines
3.0 KiB
PHP
89 lines
3.0 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace Tests\Feature\SecurityReport;
|
|
|
|
use App\Models\SecurityReport;
|
|
use App\Models\User;
|
|
use Illuminate\Foundation\Testing\RefreshDatabase;
|
|
use Inertia\Testing\AssertableInertia;
|
|
use Tests\TestCase;
|
|
|
|
final class SecurityReportAdminTest extends TestCase
|
|
{
|
|
use RefreshDatabase;
|
|
|
|
protected function setUp(): void
|
|
{
|
|
parent::setUp();
|
|
|
|
config(['security-report.enabled' => true]);
|
|
}
|
|
|
|
public function test_guest_cannot_open_security_report_page(): void
|
|
{
|
|
$this->get('/moderation/system/security-report')
|
|
->assertRedirect(route('login'));
|
|
}
|
|
|
|
public function test_normal_user_cannot_open_security_report_page(): void
|
|
{
|
|
$user = User::factory()->create(['role' => 'user']);
|
|
|
|
$this->actingAs($user)
|
|
->get('/moderation/system/security-report')
|
|
->assertRedirect(route('index'));
|
|
}
|
|
|
|
public function test_staff_non_admin_cannot_open_security_report_page(): void
|
|
{
|
|
$manager = User::factory()->create(['role' => 'manager']);
|
|
|
|
$this->actingAs($manager)
|
|
->get('/moderation/system/security-report')
|
|
->assertForbidden();
|
|
}
|
|
|
|
public function test_admin_can_open_security_report_index_and_detail(): void
|
|
{
|
|
$admin = User::factory()->create(['role' => 'admin']);
|
|
$report = SecurityReport::query()->create([
|
|
'status' => 'completed_with_findings',
|
|
'started_at' => now()->subMinute(),
|
|
'finished_at' => now(),
|
|
'total_critical' => 1,
|
|
'total_high' => 2,
|
|
'total_medium' => 3,
|
|
'total_low' => 4,
|
|
'total_unknown' => 0,
|
|
'composer_outdated_count' => 5,
|
|
'npm_outdated_count' => 6,
|
|
'triggered_by' => 'artisan',
|
|
'summary' => [
|
|
'total' => ['critical' => 1, 'high' => 2, 'medium' => 3, 'low' => 4, 'unknown' => 0],
|
|
],
|
|
'composer_audit' => ['advisories' => ['laravel/framework' => [['severity' => 'high', 'title' => 'Test advisory']]]],
|
|
'npm_audit' => ['vulnerabilities' => ['vite' => ['severity' => 'moderate', 'via' => [['title' => 'Moderate issue']]]]],
|
|
]);
|
|
|
|
$this->actingAs($admin)
|
|
->get('/moderation/system/security-report')
|
|
->assertOk()
|
|
->assertInertia(fn (AssertableInertia $page) => $page
|
|
->component('Admin/System/SecurityReportIndex')
|
|
->where('latest.id', $report->id)
|
|
->where('latest.total_critical', 1)
|
|
->where('reports.data.0.id', $report->id));
|
|
|
|
$this->actingAs($admin)
|
|
->get('/moderation/system/security-report/' . $report->id)
|
|
->assertOk()
|
|
->assertInertia(fn (AssertableInertia $page) => $page
|
|
->component('Admin/System/SecurityReportShow')
|
|
->where('report.id', $report->id)
|
|
->where('report.total_high', 2)
|
|
->where('report.composer_advisories.0.package', 'laravel/framework'));
|
|
}
|
|
}
|