2024-06-12 03:58:12 -07:00
|
|
|
<?php
|
|
|
|
|
|
|
|
namespace Tests\Feature\Users\Api;
|
|
|
|
|
|
|
|
use App\Models\Company;
|
|
|
|
use App\Models\User;
|
|
|
|
use Illuminate\Testing\Fluent\AssertableJson;
|
|
|
|
use Laravel\Passport\Passport;
|
|
|
|
use Tests\TestCase;
|
|
|
|
|
|
|
|
class ViewUserTest extends TestCase
|
|
|
|
{
|
|
|
|
|
2024-06-12 04:12:15 -07:00
|
|
|
public function testCanReturnUser()
|
2024-06-12 03:58:12 -07:00
|
|
|
{
|
|
|
|
$user = User::factory()->create();
|
|
|
|
|
2024-06-12 04:31:41 -07:00
|
|
|
$this->actingAsForApi(User::factory()->viewUsers()->create())
|
2024-06-12 03:58:12 -07:00
|
|
|
->getJson(route('api.users.show', $user))
|
|
|
|
->assertOk();
|
|
|
|
}
|
|
|
|
|
2024-06-12 04:03:33 -07:00
|
|
|
public function testPermissionsWithCompanyableToDeleteUser()
|
2024-06-12 03:58:12 -07:00
|
|
|
{
|
|
|
|
|
|
|
|
$this->settings->enableMultipleFullCompanySupport();
|
|
|
|
|
|
|
|
[$companyA, $companyB] = Company::factory()->count(2)->create();
|
|
|
|
|
|
|
|
$superuser = User::factory()->superuser()->create();
|
|
|
|
$userFromA = User::factory()->for($companyA)->create();
|
|
|
|
$userFromB = User::factory()->for($companyB)->create();
|
|
|
|
|
2024-06-12 04:31:41 -07:00
|
|
|
$this->actingAsForApi(User::factory()->deleteUsers()->for($companyA)->create())
|
|
|
|
->deleteJson(route('api.users.destroy', $userFromA->id))
|
|
|
|
->assertOk()
|
|
|
|
->assertStatus(200)
|
|
|
|
->assertStatusMessageIs('success')
|
|
|
|
->json();
|
2024-06-12 03:58:12 -07:00
|
|
|
|
2024-06-12 04:31:41 -07:00
|
|
|
$this->actingAsForApi(User::factory()->deleteUsers()->for($companyB)->create())
|
|
|
|
->deleteJson(route('api.users.destroy', $userFromA->id))
|
|
|
|
->assertStatus(403);
|
2024-06-12 03:58:12 -07:00
|
|
|
|
2024-06-12 04:31:41 -07:00
|
|
|
$this->actingAsForApi($superuser)
|
|
|
|
->deleteJson(route('api.users.destroy', $userFromA->id))
|
|
|
|
->assertOk()
|
|
|
|
->assertStatus(200)
|
|
|
|
->assertStatusMessageIs('success')
|
|
|
|
->json();
|
|
|
|
|
|
|
|
$this->actingAsForApi($superuser)
|
|
|
|
->deleteJson(route('api.users.destroy', $userFromB->id))
|
|
|
|
->assertOk()
|
|
|
|
->assertStatus(200)
|
|
|
|
->assertStatusMessageIs('success')
|
|
|
|
->json();
|
2024-06-12 03:58:12 -07:00
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|