2026-01-15 01:13:44 +00:00
|
|
|
<?php
|
|
|
|
|
|
|
|
|
|
use App\Models\User;
|
|
|
|
|
use Illuminate\Support\Facades\RateLimiter;
|
2026-01-20 19:53:54 +00:00
|
|
|
use Illuminate\Support\Str;
|
2026-01-15 01:13:44 +00:00
|
|
|
|
|
|
|
|
test('login screen can be rendered', function () {
|
|
|
|
|
$response = $this->get(route('login'));
|
|
|
|
|
|
|
|
|
|
$response->assertOk();
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('users can authenticate using the login screen', function () {
|
|
|
|
|
$user = User::factory()->create();
|
|
|
|
|
|
|
|
|
|
$response = $this->post(route('login.store'), [
|
|
|
|
|
'email' => $user->email,
|
|
|
|
|
'password' => 'password',
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$this->assertAuthenticated();
|
2026-01-20 19:53:54 +00:00
|
|
|
$response->assertRedirect(route('calendar', absolute: false));
|
2026-01-15 01:13:44 +00:00
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('users can not authenticate with invalid password', function () {
|
|
|
|
|
$user = User::factory()->create();
|
|
|
|
|
|
|
|
|
|
$this->post(route('login.store'), [
|
|
|
|
|
'email' => $user->email,
|
|
|
|
|
'password' => 'wrong-password',
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$this->assertGuest();
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('users can logout', function () {
|
|
|
|
|
$user = User::factory()->create();
|
|
|
|
|
|
|
|
|
|
$response = $this->actingAs($user)->post(route('logout'));
|
|
|
|
|
|
|
|
|
|
$this->assertGuest();
|
2026-01-20 19:53:54 +00:00
|
|
|
$response->assertRedirect('/');
|
2026-01-15 01:13:44 +00:00
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('users are rate limited', function () {
|
|
|
|
|
$user = User::factory()->create();
|
|
|
|
|
|
2026-01-20 19:53:54 +00:00
|
|
|
$throttleKey = Str::transliterate(Str::lower($user->email).'|127.0.0.1');
|
|
|
|
|
|
|
|
|
|
RateLimiter::hit($throttleKey, 60);
|
|
|
|
|
RateLimiter::hit($throttleKey, 60);
|
|
|
|
|
RateLimiter::hit($throttleKey, 60);
|
|
|
|
|
RateLimiter::hit($throttleKey, 60);
|
|
|
|
|
RateLimiter::hit($throttleKey, 60);
|
2026-01-15 01:13:44 +00:00
|
|
|
|
|
|
|
|
$response = $this->post(route('login.store'), [
|
|
|
|
|
'email' => $user->email,
|
|
|
|
|
'password' => 'wrong-password',
|
|
|
|
|
]);
|
|
|
|
|
|
2026-01-20 19:53:54 +00:00
|
|
|
$response->assertSessionHasErrors('email');
|
2026-01-17 15:36:49 +00:00
|
|
|
});
|