2026-08-06 14:34:50 +00:00
|
|
|
<?php
|
|
|
|
|
|
|
|
|
|
declare(strict_types=1);
|
|
|
|
|
|
|
|
|
|
use App\Actions\Billing\StartSubscriptionCheckout;
|
|
|
|
|
use App\Enums\Plan\Slug;
|
|
|
|
|
use App\Enums\PostHog\WelcomeEvent;
|
|
|
|
|
use App\Enums\User\Goal;
|
|
|
|
|
use App\Enums\User\Persona;
|
|
|
|
|
use App\Enums\User\ReferralSource;
|
|
|
|
|
use App\Jobs\PostHog\SendEvent;
|
|
|
|
|
use App\Models\Account;
|
|
|
|
|
use App\Models\Plan;
|
|
|
|
|
use App\Models\User;
|
|
|
|
|
use Illuminate\Support\Facades\Bus;
|
|
|
|
|
use Illuminate\Support\Facades\Route;
|
|
|
|
|
|
|
|
|
|
beforeEach(function () {
|
|
|
|
|
config(['trypost.self_hosted' => false]);
|
|
|
|
|
$this->user = User::factory()->create();
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('welcome redirects to the persona step', function () {
|
|
|
|
|
$this->actingAs($this->user)
|
|
|
|
|
->get(route('app.welcome'))
|
|
|
|
|
->assertRedirect(route('app.welcome.persona'));
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('persona renders for an unsubscribed account', function () {
|
|
|
|
|
$this->actingAs($this->user)
|
|
|
|
|
->get(route('app.welcome.persona'))
|
|
|
|
|
->assertOk()
|
|
|
|
|
->assertInertia(fn ($page) => $page
|
|
|
|
|
->component('welcome/Persona', false)
|
|
|
|
|
->has('personas', count(Persona::cases()))
|
|
|
|
|
);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('persona requires a valid selection', function (array $payload) {
|
|
|
|
|
$this->actingAs($this->user)
|
|
|
|
|
->post(route('app.welcome.persona.store'), $payload)
|
|
|
|
|
->assertSessionHasErrors('persona');
|
|
|
|
|
|
|
|
|
|
expect($this->user->fresh()->persona)->toBeNull();
|
|
|
|
|
})->with([
|
|
|
|
|
'missing' => [[]],
|
|
|
|
|
'invalid' => [['persona' => 'not-a-persona']],
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
test('persona store saves the selection mirrors it to PostHog and advances to goals', function () {
|
|
|
|
|
config(['services.posthog.enabled' => true, 'services.posthog.api_key' => 'phc_test']);
|
|
|
|
|
Bus::fake();
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user)
|
|
|
|
|
->post(route('app.welcome.persona.store'), ['persona' => Persona::Agency->value])
|
|
|
|
|
->assertRedirect(route('app.welcome.goals'));
|
|
|
|
|
|
|
|
|
|
expect($this->user->fresh()->persona)->toBe(Persona::Agency);
|
|
|
|
|
Bus::assertDispatched(SendEvent::class, fn (SendEvent $event): bool => $event->method === 'capture'
|
|
|
|
|
&& data_get($event->payload, 'distinctId') === $this->user->id
|
|
|
|
|
&& data_get($event->payload, 'event') === WelcomeEvent::Persona->value
|
|
|
|
|
&& data_get($event->payload, 'properties.persona') === Persona::Agency->value);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('goals redirects to persona until a persona is selected', function () {
|
|
|
|
|
$this->actingAs($this->user)
|
|
|
|
|
->get(route('app.welcome.goals'))
|
|
|
|
|
->assertRedirect(route('app.welcome.persona'));
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('goals renders after a persona is selected', function () {
|
|
|
|
|
$this->user->update(['persona' => Persona::Agency->value]);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh())
|
|
|
|
|
->get(route('app.welcome.goals'))
|
|
|
|
|
->assertOk()
|
|
|
|
|
->assertInertia(fn ($page) => $page
|
|
|
|
|
->component('welcome/Goals', false)
|
|
|
|
|
->has('goals', count(Goal::cases()))
|
|
|
|
|
);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('goals requires at least one valid goal', function (array $goals, string $error) {
|
|
|
|
|
$this->user->update(['persona' => Persona::Agency->value]);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh())
|
|
|
|
|
->post(route('app.welcome.goals.store'), ['goals' => $goals])
|
|
|
|
|
->assertSessionHasErrors($error);
|
|
|
|
|
|
|
|
|
|
expect($this->user->fresh()->goals)->toBeNull();
|
|
|
|
|
})->with([
|
|
|
|
|
'empty' => [[], 'goals'],
|
|
|
|
|
'invalid' => [['not-a-goal'], 'goals.0'],
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
test('goals store saves choices mirrors them to PostHog and advances to referral source', function () {
|
|
|
|
|
config(['services.posthog.enabled' => true, 'services.posthog.api_key' => 'phc_test']);
|
|
|
|
|
Bus::fake();
|
|
|
|
|
$this->user->update(['persona' => Persona::Creator->value]);
|
|
|
|
|
|
|
|
|
|
$goals = [Goal::AiContent->value, Goal::SaveTime->value];
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh())
|
|
|
|
|
->post(route('app.welcome.goals.store'), ['goals' => $goals])
|
|
|
|
|
->assertRedirect(route('app.welcome.referral-source'));
|
|
|
|
|
|
|
|
|
|
expect($this->user->fresh()->goals)->toBe($goals);
|
|
|
|
|
Bus::assertDispatched(SendEvent::class, fn (SendEvent $event): bool => $event->method === 'capture'
|
|
|
|
|
&& data_get($event->payload, 'event') === WelcomeEvent::Goals->value
|
|
|
|
|
&& data_get($event->payload, 'properties.goals') === $goals);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('completed welcome steps remain reachable when going back', function () {
|
|
|
|
|
$this->user->update([
|
|
|
|
|
'persona' => Persona::Agency->value,
|
|
|
|
|
'goals' => [Goal::SaveTime->value],
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh())
|
|
|
|
|
->get(route('app.welcome.persona'))
|
|
|
|
|
->assertOk()
|
|
|
|
|
->assertInertia(fn ($page) => $page->component('welcome/Persona', false));
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh())
|
|
|
|
|
->get(route('app.welcome.goals'))
|
|
|
|
|
->assertOk()
|
|
|
|
|
->assertInertia(fn ($page) => $page->component('welcome/Goals', false));
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('referral source redirects through incomplete prior steps', function (array $attributes, string $routeName) {
|
|
|
|
|
$this->user->update($attributes);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh())
|
|
|
|
|
->get(route('app.welcome.referral-source'))
|
|
|
|
|
->assertRedirect(route($routeName));
|
|
|
|
|
})->with([
|
|
|
|
|
'missing persona' => [[], 'app.welcome.persona'],
|
|
|
|
|
'missing goals' => [['persona' => Persona::Agency->value], 'app.welcome.goals'],
|
|
|
|
|
'only removed goals' => [
|
|
|
|
|
[
|
|
|
|
|
'persona' => Persona::Agency->value,
|
|
|
|
|
'goals' => ['team_collaboration', 'automate_api', 'track_performance'],
|
|
|
|
|
],
|
|
|
|
|
'app.welcome.goals',
|
|
|
|
|
],
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
test('referral source allows users who still have at least one current goal', function () {
|
|
|
|
|
$this->user->update([
|
|
|
|
|
'persona' => Persona::Agency->value,
|
|
|
|
|
'goals' => [Goal::SaveTime->value, 'team_collaboration'],
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh())
|
|
|
|
|
->get(route('app.welcome.referral-source'))
|
|
|
|
|
->assertOk()
|
|
|
|
|
->assertInertia(fn ($page) => $page->component('welcome/ReferralSource', false));
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('referral source renders after prior steps are complete', function () {
|
|
|
|
|
$this->user->update([
|
|
|
|
|
'persona' => Persona::Agency->value,
|
|
|
|
|
'goals' => [Goal::SaveTime->value],
|
|
|
|
|
]);
|
|
|
|
|
$plan = Plan::where('slug', Slug::Workspace)->firstOrFail();
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh())
|
|
|
|
|
->get(route('app.welcome.referral-source'))
|
|
|
|
|
->assertOk()
|
|
|
|
|
->assertInertia(fn ($page) => $page
|
|
|
|
|
->component('welcome/ReferralSource', false)
|
|
|
|
|
->has('sources', count(ReferralSource::cases()))
|
Activation checklist + MCP OAuth authorize UX (#239) (#250)
* Wire onboarding activation into Account, observers, and shared Inertia data
Add onboarding casts/hasFinishedOnboarding, AccessToken ObservedBy,
Platform::connectableOptions, Post/SocialAccount onboarding broadcast hooks,
and lazy onboardingResidual share + SharedData types.
* Register onboarding routes and post-checkout activation redirects.
Wire billing processing and the sidebar checklist so owners land on
activation after subscribe, with locale sidebar/uk onboarding strings.
* Align MCP grant usability with onboarding activation checks
Unbound MCP tokens fall back to the user's current workspace and require
createPost so viewer/unscoped grants neither unlock the checklist nor
broadcast onboarding status.
* Require bound MCP workspace for onboarding activation.
Drop current-workspace fallback from usable MCP grants so checklist
detection and broadcasts match Passport token scoping; viewers still
cannot unlock the MCP step.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Harden onboarding review findings and tighten locale strings.
Fix Welcome/Persona/TrackPost suites broken by the activation route reuse
and PostObserver analytics side effects, restore Echo poll fallbacks,
reject unbound MCP grants in tests, and drop unused onboarding.mcp keys.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Remove unused sidebar and MCP authorization locale keys.
Drop dead sidebar menu/theme strings (including the overwritten
workspace label and api_keys nav entry) and unused MCP authorize
app_title/approving copy across all locales.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Fix SetLocale crashing on Passport Symfony OAuth responses.
OAuth errors return a raw Symfony Response without withCookie(); attach
the default locale cookie via headers so authorize no longer 500s.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Prompt OAuth guests to log in before rejecting unknown clients.
MCP Inspector often reuses a stale client_id; validateAuthorizationRequest
was returning invalid_client JSON before the login redirect. Guests now
hit /login first, then client validation runs after authentication.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Render Inertia OAuth authorize errors for browser logins.
After login, Inertia follows the intended authorize URL; raw invalid_client
JSON broke that visit. HTML/Inertia requests now get mcp/AuthorizeError
while API JSON clients still receive the OAuth error payload.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Detect Inertia OAuth error pages via Request::inertia().
Use the framework helper so post-login authorize failures keep returning
an Inertia page instead of raw OAuth JSON.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify OAuth authorize error page detection to expectsJson.
Drop the X-Inertia header sniff; browser and Inertia visits already do
not expectsJson, while API clients still receive the OAuth JSON payload.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Share MCP authorize layout and drop the error close button.
Keep authorize and authorize-error on the same centered card shell instead of the auth split layout.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify onboarding activation for reviewability and safety.
Use an exists-based MCP check, keep GETs read-only, move sync into
syncAndNotify, clear MCP skips on connect, restrict complete to owners,
and share Echo/poll via one composable.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Move MCP OAuth authorize UX out of the onboarding PR.
Keep the activation checklist focused; OAuth guest/error-page work now
lives on fix/mcp-oauth-authorize-ux.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Fix corrupted French MCP locale after OAuth key cleanup.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Restore MCP OAuth authorize UX onto the onboarding branch.
Keep authorize error page, guest login-before-client validation, and
SetLocale Symfony cookie fix in #250.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Fix OAuth prompt=none redirects and harden onboarding tests.
Keep login_required/consent_required as redirects instead of Inertia,
add regression coverage for owner-only activation, require invite email
confirmation, and align MCP connected apps with the sessions list UI.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify onboarding guards and dedupe viewed analytics.
Introduce isOnboardingOpen / belongsToAccount helpers, collapse
duplicated sync/dispatch paths, and capture onboarding.viewed once
per account.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify onboarding event, observers, and status helpers.
Tighten Account onboarding predicates, drop nullable broadcast/dispatch
APIs, and collapse repeated observer/controller guards.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Treat in-app users as always having an account.
Add resolveAccount(), tighten belongsToAccount to string ids, and fold
guest residual handling into ResolveOnboardingStatus.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Rename onboarding residual share test to progress.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify onboarding status and rename residual to progress.
Use accountOrFail, extract MCP onboarding scope, auto-leave the ready
screen, and send non-onboarding checkout back to accounts.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Extract HasAccount and prefer data_get in onboarding flows.
Move account helpers off User, drop nullable sidebarProgress, and
read OAuth/onboarding payloads with data_get.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify onboarding checks and extract HasOnboarding.
Use Eloquent + policies for MCP/backfill paths, and move account
onboarding helpers into a dedicated trait.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Add trait tests and tidy onboarding imports.
Cover HasAccount and HasOnboarding under Models/Traits, prefer filled() for checkout session ids, and import Throwable instead of FQCN.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify checkout session_id and OAuth error props.
Read session_id via request->string(), and take OAuth error details from the League exception instead of decoding the response body.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify PostObserver onboarding notify path.
Share one otherPosts check for first-create and last-delete instead of separate callbacks.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Use post author as onboarding sync actor.
Drop Auth::user() preference in PostObserver; checklist sync attributes to $post->user.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify SocialAccountObserver and OAuth authorize flow.
Share create/delete onboarding notify, drop Auth actor fallback to owner, and inline Passport Inertia error handling.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Use lazy Inertia props for onboarding partial reloads.
Drop partial-header branching; wrap page props in closures and always redirect completed/dismissed accounts to the calendar.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Defer sidebar onboarding progress and stamp completion as owner-only.
Skip the MCP checklist work on full Inertia visits via deferred shared props,
early-exit token scans, and keep account completion stamps owner-gated.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify deferred onboarding progress share via canShowProgress.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Add User firstName for shared auth and simplify onboarding page.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Move User firstName coverage into UserTest.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Use first_name directly without empty-name fallbacks.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Resolve onboarding sample prompt on the frontend via i18n.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Stamp onboarding completion via the account owner after teammate unlocks.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Count only the account owner MCP grant toward onboarding activation.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Fix OAuth consent auth-token mismatch for mid-activation owners.
Skip deferred onboardingProgress on Passport authorize so Inertia does not
rotate the session authToken, cover happy and stale-token paths in tests,
and polish MCP setup copy plus sidebar/onboarding layout.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Keep users on onboarding after activation completes.
Stamp completion and re-render the finished checklist instead of
redirecting to the calendar so owners can review the done state.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Clarify Passport consent-view opt-out and guard app-route deferral.
Rename the authorize-only route check and assert onboardingProgress still
defers on calendar, onboarding, and MCP settings.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Harden onboarding completion and MCP consent workspace binding.
Reject OAuth approve without a workspace, retry auto-complete until
stamped, send dismissed complete straight to calendar, and cover the
device consent defer opt-out.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Enable activation checklist for self-hosted installs.
Remove the self-hosted onboarding redirects, keep the SaaS-only dismiss backfill, and cover subscription-less owners plus skip/complete destinations.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Add GitHub, Hacker News, and directories referral sources.
Expand the welcome referral step with open-source and directory discovery channels.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Refine welcome referral sources and labels.
Split Instagram/Threads, add Founder, and shorten Google, GitHub, AI, and blog option labels.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Sort accounts platforms alphabetically and drop connect hover plus.
Reuse connectableOptions for the accounts index and remove the unused plus badge on disconnected cards.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Centralize PostHog once-capture so disabled installs don't burn dedupe keys.
Move isEnabled + Cache::add into PostHogService::captureOnce and route onboarding viewed/step events through it.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify onboarding backfill to complete every existing open account.
Drop self-hosted and subscription filters; down clears completed_at again.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Drop PostHog captureOnce and use plain capture for onboarding.
Remove cache-based event dedupe; callers rely on PostHogService::capture gating.
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-07 23:34:43 +00:00
|
|
|
->where('sources', fn ($sources): bool => collect($sources)->contains(ReferralSource::GitHub->value)
|
|
|
|
|
&& collect($sources)->contains(ReferralSource::Threads->value)
|
|
|
|
|
&& collect($sources)->contains(ReferralSource::HackerNews->value)
|
|
|
|
|
&& collect($sources)->contains(ReferralSource::Directories->value)
|
|
|
|
|
&& collect($sources)->contains(ReferralSource::Founder->value))
|
2026-08-06 14:34:50 +00:00
|
|
|
->where('plan.name', $plan->name)
|
|
|
|
|
->where('plan.interval', 'monthly')
|
|
|
|
|
);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('referral source requires a valid selection', function (array $payload) {
|
|
|
|
|
$this->user->update([
|
|
|
|
|
'persona' => Persona::Agency->value,
|
|
|
|
|
'goals' => [Goal::SaveTime->value],
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh())
|
|
|
|
|
->post(route('app.welcome.referral-source.store'), $payload)
|
|
|
|
|
->assertSessionHasErrors('referral_source');
|
|
|
|
|
|
|
|
|
|
expect($this->user->fresh()->referral_source)->toBeNull();
|
|
|
|
|
})->with([
|
|
|
|
|
'missing' => [[]],
|
|
|
|
|
'invalid' => [['referral_source' => 'not-a-source']],
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
test('referral source store saves the source and starts Stripe checkout without a social account', function () {
|
|
|
|
|
config(['services.posthog.enabled' => true, 'services.posthog.api_key' => 'phc_test']);
|
|
|
|
|
Bus::fake();
|
|
|
|
|
$this->user->update([
|
|
|
|
|
'persona' => Persona::Agency->value,
|
|
|
|
|
'goals' => [Goal::SaveTime->value],
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
Plan::where('slug', Slug::Workspace)->firstOrFail()->update([
|
|
|
|
|
'stripe_monthly_price_id' => 'price_monthly_test',
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$this->mock(StartSubscriptionCheckout::class)
|
|
|
|
|
->shouldReceive('redirect')
|
|
|
|
|
->once()
|
|
|
|
|
->withArgs(fn (Account $account, string $priceId, string $cancelUrl): bool => $account->is($this->user->account)
|
|
|
|
|
&& $priceId === 'price_monthly_test'
|
|
|
|
|
&& $cancelUrl === route('app.welcome.referral-source'))
|
|
|
|
|
->andReturn(redirect('https://checkout.stripe.test/session'));
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh())
|
|
|
|
|
->post(route('app.welcome.referral-source.store'), [
|
|
|
|
|
'referral_source' => ReferralSource::ProductHunt->value,
|
|
|
|
|
])
|
|
|
|
|
->assertRedirect('https://checkout.stripe.test/session');
|
|
|
|
|
|
|
|
|
|
expect($this->user->fresh()->referral_source)->toBe(ReferralSource::ProductHunt);
|
|
|
|
|
Bus::assertDispatched(SendEvent::class, fn (SendEvent $event): bool => $event->method === 'capture'
|
|
|
|
|
&& data_get($event->payload, 'event') === WelcomeEvent::Referral->value
|
|
|
|
|
&& data_get($event->payload, 'properties.referral_source') === ReferralSource::ProductHunt->value);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('welcome steps redirect to calendar for subscribed accounts', function (string $routeName, string $method, array $payload = []) {
|
|
|
|
|
subscribeAccount($this->user->account);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh());
|
|
|
|
|
|
|
|
|
|
$response = $method === 'get'
|
|
|
|
|
? $this->get(route($routeName))
|
|
|
|
|
: $this->post(route($routeName), $payload);
|
|
|
|
|
|
|
|
|
|
$response->assertRedirect(route('app.calendar'));
|
|
|
|
|
})->with([
|
|
|
|
|
'persona' => ['app.welcome.persona', 'get'],
|
|
|
|
|
'persona store' => ['app.welcome.persona.store', 'post', ['persona' => Persona::Agency->value]],
|
|
|
|
|
'goals' => ['app.welcome.goals', 'get'],
|
|
|
|
|
'goals store' => ['app.welcome.goals.store', 'post', ['goals' => [Goal::SaveTime->value]]],
|
|
|
|
|
'referral source' => ['app.welcome.referral-source', 'get'],
|
|
|
|
|
'referral source store' => ['app.welcome.referral-source.store', 'post', ['referral_source' => ReferralSource::Google->value]],
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
test('welcome redirects generic-trial accounts with app access to calendar', function () {
|
|
|
|
|
config(['trypost.billing.require_card_for_trial' => false]);
|
|
|
|
|
|
|
|
|
|
$this->user->account->forceFill([
|
|
|
|
|
'trial_ends_at' => now()->addDays(8),
|
|
|
|
|
])->save();
|
|
|
|
|
|
|
|
|
|
expect($this->user->account->fresh()->hasAppAccess())->toBeTrue()
|
|
|
|
|
->and($this->user->account->fresh()->subscribed(Account::SUBSCRIPTION_NAME))->toBeFalse();
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh())
|
|
|
|
|
->get(route('app.welcome.persona'))
|
|
|
|
|
->assertRedirect(route('app.calendar'));
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('welcome steps redirect to calendar in self hosted mode', function (string $routeName, string $method, array $payload = []) {
|
|
|
|
|
config(['trypost.self_hosted' => true]);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user);
|
|
|
|
|
|
|
|
|
|
$response = $method === 'get'
|
|
|
|
|
? $this->get(route($routeName))
|
|
|
|
|
: $this->post(route($routeName), $payload);
|
|
|
|
|
|
|
|
|
|
$response->assertRedirect(route('app.calendar'));
|
|
|
|
|
})->with([
|
|
|
|
|
'persona' => ['app.welcome.persona', 'get'],
|
|
|
|
|
'persona store' => ['app.welcome.persona.store', 'post', ['persona' => Persona::Agency->value]],
|
|
|
|
|
'goals' => ['app.welcome.goals', 'get'],
|
|
|
|
|
'goals store' => ['app.welcome.goals.store', 'post', ['goals' => [Goal::SaveTime->value]]],
|
|
|
|
|
'referral source' => ['app.welcome.referral-source', 'get'],
|
|
|
|
|
'referral source store' => ['app.welcome.referral-source.store', 'post', ['referral_source' => ReferralSource::Google->value]],
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
test('old onboarding icp routes are not registered', function (string $routeName) {
|
|
|
|
|
expect(Route::has($routeName))->toBeFalse();
|
|
|
|
|
})->with([
|
Activation checklist + MCP OAuth authorize UX (#239) (#250)
* Wire onboarding activation into Account, observers, and shared Inertia data
Add onboarding casts/hasFinishedOnboarding, AccessToken ObservedBy,
Platform::connectableOptions, Post/SocialAccount onboarding broadcast hooks,
and lazy onboardingResidual share + SharedData types.
* Register onboarding routes and post-checkout activation redirects.
Wire billing processing and the sidebar checklist so owners land on
activation after subscribe, with locale sidebar/uk onboarding strings.
* Align MCP grant usability with onboarding activation checks
Unbound MCP tokens fall back to the user's current workspace and require
createPost so viewer/unscoped grants neither unlock the checklist nor
broadcast onboarding status.
* Require bound MCP workspace for onboarding activation.
Drop current-workspace fallback from usable MCP grants so checklist
detection and broadcasts match Passport token scoping; viewers still
cannot unlock the MCP step.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Harden onboarding review findings and tighten locale strings.
Fix Welcome/Persona/TrackPost suites broken by the activation route reuse
and PostObserver analytics side effects, restore Echo poll fallbacks,
reject unbound MCP grants in tests, and drop unused onboarding.mcp keys.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Remove unused sidebar and MCP authorization locale keys.
Drop dead sidebar menu/theme strings (including the overwritten
workspace label and api_keys nav entry) and unused MCP authorize
app_title/approving copy across all locales.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Fix SetLocale crashing on Passport Symfony OAuth responses.
OAuth errors return a raw Symfony Response without withCookie(); attach
the default locale cookie via headers so authorize no longer 500s.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Prompt OAuth guests to log in before rejecting unknown clients.
MCP Inspector often reuses a stale client_id; validateAuthorizationRequest
was returning invalid_client JSON before the login redirect. Guests now
hit /login first, then client validation runs after authentication.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Render Inertia OAuth authorize errors for browser logins.
After login, Inertia follows the intended authorize URL; raw invalid_client
JSON broke that visit. HTML/Inertia requests now get mcp/AuthorizeError
while API JSON clients still receive the OAuth error payload.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Detect Inertia OAuth error pages via Request::inertia().
Use the framework helper so post-login authorize failures keep returning
an Inertia page instead of raw OAuth JSON.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify OAuth authorize error page detection to expectsJson.
Drop the X-Inertia header sniff; browser and Inertia visits already do
not expectsJson, while API clients still receive the OAuth JSON payload.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Share MCP authorize layout and drop the error close button.
Keep authorize and authorize-error on the same centered card shell instead of the auth split layout.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify onboarding activation for reviewability and safety.
Use an exists-based MCP check, keep GETs read-only, move sync into
syncAndNotify, clear MCP skips on connect, restrict complete to owners,
and share Echo/poll via one composable.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Move MCP OAuth authorize UX out of the onboarding PR.
Keep the activation checklist focused; OAuth guest/error-page work now
lives on fix/mcp-oauth-authorize-ux.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Fix corrupted French MCP locale after OAuth key cleanup.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Restore MCP OAuth authorize UX onto the onboarding branch.
Keep authorize error page, guest login-before-client validation, and
SetLocale Symfony cookie fix in #250.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Fix OAuth prompt=none redirects and harden onboarding tests.
Keep login_required/consent_required as redirects instead of Inertia,
add regression coverage for owner-only activation, require invite email
confirmation, and align MCP connected apps with the sessions list UI.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify onboarding guards and dedupe viewed analytics.
Introduce isOnboardingOpen / belongsToAccount helpers, collapse
duplicated sync/dispatch paths, and capture onboarding.viewed once
per account.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify onboarding event, observers, and status helpers.
Tighten Account onboarding predicates, drop nullable broadcast/dispatch
APIs, and collapse repeated observer/controller guards.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Treat in-app users as always having an account.
Add resolveAccount(), tighten belongsToAccount to string ids, and fold
guest residual handling into ResolveOnboardingStatus.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Rename onboarding residual share test to progress.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify onboarding status and rename residual to progress.
Use accountOrFail, extract MCP onboarding scope, auto-leave the ready
screen, and send non-onboarding checkout back to accounts.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Extract HasAccount and prefer data_get in onboarding flows.
Move account helpers off User, drop nullable sidebarProgress, and
read OAuth/onboarding payloads with data_get.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify onboarding checks and extract HasOnboarding.
Use Eloquent + policies for MCP/backfill paths, and move account
onboarding helpers into a dedicated trait.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Add trait tests and tidy onboarding imports.
Cover HasAccount and HasOnboarding under Models/Traits, prefer filled() for checkout session ids, and import Throwable instead of FQCN.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify checkout session_id and OAuth error props.
Read session_id via request->string(), and take OAuth error details from the League exception instead of decoding the response body.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify PostObserver onboarding notify path.
Share one otherPosts check for first-create and last-delete instead of separate callbacks.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Use post author as onboarding sync actor.
Drop Auth::user() preference in PostObserver; checklist sync attributes to $post->user.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify SocialAccountObserver and OAuth authorize flow.
Share create/delete onboarding notify, drop Auth actor fallback to owner, and inline Passport Inertia error handling.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Use lazy Inertia props for onboarding partial reloads.
Drop partial-header branching; wrap page props in closures and always redirect completed/dismissed accounts to the calendar.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Defer sidebar onboarding progress and stamp completion as owner-only.
Skip the MCP checklist work on full Inertia visits via deferred shared props,
early-exit token scans, and keep account completion stamps owner-gated.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify deferred onboarding progress share via canShowProgress.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Add User firstName for shared auth and simplify onboarding page.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Move User firstName coverage into UserTest.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Use first_name directly without empty-name fallbacks.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Resolve onboarding sample prompt on the frontend via i18n.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Stamp onboarding completion via the account owner after teammate unlocks.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Count only the account owner MCP grant toward onboarding activation.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Fix OAuth consent auth-token mismatch for mid-activation owners.
Skip deferred onboardingProgress on Passport authorize so Inertia does not
rotate the session authToken, cover happy and stale-token paths in tests,
and polish MCP setup copy plus sidebar/onboarding layout.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Keep users on onboarding after activation completes.
Stamp completion and re-render the finished checklist instead of
redirecting to the calendar so owners can review the done state.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Clarify Passport consent-view opt-out and guard app-route deferral.
Rename the authorize-only route check and assert onboardingProgress still
defers on calendar, onboarding, and MCP settings.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Harden onboarding completion and MCP consent workspace binding.
Reject OAuth approve without a workspace, retry auto-complete until
stamped, send dismissed complete straight to calendar, and cover the
device consent defer opt-out.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Enable activation checklist for self-hosted installs.
Remove the self-hosted onboarding redirects, keep the SaaS-only dismiss backfill, and cover subscription-less owners plus skip/complete destinations.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Add GitHub, Hacker News, and directories referral sources.
Expand the welcome referral step with open-source and directory discovery channels.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Refine welcome referral sources and labels.
Split Instagram/Threads, add Founder, and shorten Google, GitHub, AI, and blog option labels.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Sort accounts platforms alphabetically and drop connect hover plus.
Reuse connectableOptions for the accounts index and remove the unused plus badge on disconnected cards.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Centralize PostHog once-capture so disabled installs don't burn dedupe keys.
Move isEnabled + Cache::add into PostHogService::captureOnce and route onboarding viewed/step events through it.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Simplify onboarding backfill to complete every existing open account.
Drop self-hosted and subscription filters; down clears completed_at again.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Drop PostHog captureOnce and use plain capture for onboarding.
Remove cache-based event dedupe; callers rely on PostHogService::capture gating.
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-07 23:34:43 +00:00
|
|
|
// `app.onboarding` is reused for the post-subscription activation checklist.
|
2026-08-06 14:34:50 +00:00
|
|
|
'store' => 'app.onboarding.store',
|
|
|
|
|
'goals' => 'app.onboarding.goals',
|
|
|
|
|
'goals store' => 'app.onboarding.goals.store',
|
|
|
|
|
'referral source' => 'app.onboarding.referral-source',
|
|
|
|
|
'referral source store' => 'app.onboarding.referral-source.store',
|
|
|
|
|
'connect' => 'app.onboarding.connect',
|
|
|
|
|
'checkout' => 'app.onboarding.checkout',
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
test('members cannot start Stripe checkout from welcome', function () {
|
|
|
|
|
$member = User::factory()->create(['account_id' => $this->user->account_id]);
|
|
|
|
|
$member->update([
|
|
|
|
|
'persona' => Persona::Agency->value,
|
|
|
|
|
'goals' => [Goal::SaveTime->value],
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$this->mock(StartSubscriptionCheckout::class)->shouldNotReceive('redirect');
|
|
|
|
|
|
|
|
|
|
// Members never reach the referral step — they are held on the
|
|
|
|
|
// subscription-required screen before any checkout attempt.
|
|
|
|
|
$this->actingAs($member->fresh())
|
|
|
|
|
->get(route('app.welcome.referral-source'))
|
|
|
|
|
->assertRedirect(route('app.welcome.subscription-required'));
|
|
|
|
|
|
|
|
|
|
$this->actingAs($member->fresh())
|
|
|
|
|
->post(route('app.welcome.referral-source.store'), [
|
|
|
|
|
'referral_source' => ReferralSource::Google->value,
|
|
|
|
|
])
|
|
|
|
|
->assertRedirect(route('app.welcome.subscription-required'));
|
|
|
|
|
|
|
|
|
|
expect($member->fresh()->referral_source)->toBeNull();
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('members without app access are held on the subscription required screen', function (string $routeName, string $method, array $payload = []) {
|
|
|
|
|
$member = User::factory()->create(['account_id' => $this->user->account_id]);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($member->fresh());
|
|
|
|
|
|
|
|
|
|
$response = $method === 'get'
|
|
|
|
|
? $this->get(route($routeName))
|
|
|
|
|
: $this->post(route($routeName), $payload);
|
|
|
|
|
|
|
|
|
|
$response->assertRedirect(route('app.welcome.subscription-required'));
|
|
|
|
|
})->with([
|
|
|
|
|
'persona' => ['app.welcome.persona', 'get'],
|
|
|
|
|
'persona store' => ['app.welcome.persona.store', 'post', ['persona' => Persona::Agency->value]],
|
|
|
|
|
'goals' => ['app.welcome.goals', 'get'],
|
|
|
|
|
'goals store' => ['app.welcome.goals.store', 'post', ['goals' => [Goal::SaveTime->value]]],
|
|
|
|
|
'referral source' => ['app.welcome.referral-source', 'get'],
|
|
|
|
|
'referral source store' => ['app.welcome.referral-source.store', 'post', ['referral_source' => ReferralSource::Google->value]],
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
test('subscription required screen renders for members without app access', function () {
|
|
|
|
|
$member = User::factory()->create(['account_id' => $this->user->account_id]);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($member->fresh())
|
|
|
|
|
->get(route('app.welcome.subscription-required'))
|
|
|
|
|
->assertOk()
|
|
|
|
|
->assertInertia(fn ($page) => $page
|
|
|
|
|
->component('welcome/SubscriptionRequired', false)
|
|
|
|
|
->where('ownerName', $this->user->name)
|
|
|
|
|
);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('subscription required screen sends owners back to the welcome flow', function () {
|
|
|
|
|
$this->actingAs($this->user)
|
|
|
|
|
->get(route('app.welcome.subscription-required'))
|
|
|
|
|
->assertRedirect(route('app.welcome.persona'));
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('subscription required screen sends subscribed users to the calendar', function () {
|
|
|
|
|
subscribeAccount($this->user->account);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh())
|
|
|
|
|
->get(route('app.welcome.subscription-required'))
|
|
|
|
|
->assertRedirect(route('app.calendar'));
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('subscription required screen sends members with app access to the calendar', function () {
|
|
|
|
|
['owner' => $owner, 'member' => $member] = strandedMemberOnSharedAccount();
|
|
|
|
|
subscribeAccount($owner->account);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($member)
|
|
|
|
|
->get(route('app.welcome.subscription-required'))
|
|
|
|
|
->assertRedirect(route('app.calendar'));
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('subscription required screen redirects to calendar in self hosted mode', function () {
|
|
|
|
|
config(['trypost.self_hosted' => true]);
|
|
|
|
|
|
|
|
|
|
$member = User::factory()->create(['account_id' => $this->user->account_id]);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($member->fresh())
|
|
|
|
|
->get(route('app.welcome.subscription-required'))
|
|
|
|
|
->assertRedirect(route('app.calendar'));
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('welcome sends members with app access to the calendar', function () {
|
|
|
|
|
['owner' => $owner, 'member' => $member] = strandedMemberOnSharedAccount();
|
|
|
|
|
subscribeAccount($owner->account);
|
|
|
|
|
|
|
|
|
|
$this->actingAs($member)
|
|
|
|
|
->get(route('app.welcome.persona'))
|
|
|
|
|
->assertRedirect(route('app.calendar'));
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('referral source store fails loudly when the monthly price is not configured', function () {
|
|
|
|
|
$this->user->update([
|
|
|
|
|
'persona' => Persona::Agency->value,
|
|
|
|
|
'goals' => [Goal::SaveTime->value],
|
|
|
|
|
]);
|
|
|
|
|
Plan::where('slug', Slug::Workspace)->update(['stripe_monthly_price_id' => null]);
|
|
|
|
|
|
|
|
|
|
$this->mock(StartSubscriptionCheckout::class)->shouldNotReceive('redirect');
|
|
|
|
|
|
|
|
|
|
$this->actingAs($this->user->fresh())
|
|
|
|
|
->post(route('app.welcome.referral-source.store'), [
|
|
|
|
|
'referral_source' => ReferralSource::Google->value,
|
|
|
|
|
])
|
|
|
|
|
->assertServerError();
|
|
|
|
|
});
|