unverified()->create(); $response = $this->actingAs($user)->get(route('verification.notice')); $response->assertOk(); }); test('email can be verified', function () { $user = User::factory()->unverified()->create(); Event::fake(); $verificationUrl = URL::temporarySignedRoute( 'verification.verify', now()->addMinutes(60), ['id' => $user->id, 'hash' => sha1($user->email)] ); $response = $this->actingAs($user)->get($verificationUrl); Event::assertDispatched(Verified::class); expect($user->fresh()->hasVerifiedEmail())->toBeTrue(); $response->assertRedirect(route('app.calendar', absolute: false).'?verified=1'); }); test('email is not verified with invalid hash', function () { $user = User::factory()->unverified()->create(); Event::fake(); $verificationUrl = URL::temporarySignedRoute( 'verification.verify', now()->addMinutes(60), ['id' => $user->id, 'hash' => sha1('wrong-email')] ); $this->actingAs($user)->get($verificationUrl); Event::assertNotDispatched(Verified::class); expect($user->fresh()->hasVerifiedEmail())->toBeFalse(); }); test('email is not verified with invalid user id', function () { $user = User::factory()->unverified()->create(); Event::fake(); $verificationUrl = URL::temporarySignedRoute( 'verification.verify', now()->addMinutes(60), ['id' => 123, 'hash' => sha1($user->email)] ); $this->actingAs($user)->get($verificationUrl); Event::assertNotDispatched(Verified::class); expect($user->fresh()->hasVerifiedEmail())->toBeFalse(); }); test('verified user is redirected to dashboard from verification prompt', function () { $user = User::factory()->create(); Event::fake(); $response = $this->actingAs($user)->get(route('verification.notice')); Event::assertNotDispatched(Verified::class); $response->assertRedirect(route('app.calendar', absolute: false)); }); test('already verified user visiting verification link is redirected without firing event again', function () { $user = User::factory()->create(); Event::fake(); $verificationUrl = URL::temporarySignedRoute( 'verification.verify', now()->addMinutes(60), ['id' => $user->id, 'hash' => sha1($user->email)] ); $this->actingAs($user)->get($verificationUrl) ->assertRedirect(route('app.calendar', absolute: false).'?verified=1'); Event::assertNotDispatched(Verified::class); expect($user->fresh()->hasVerifiedEmail())->toBeTrue(); }); test('verification email has no manage-notifications link — it is a transactional, unauthenticated email', function () { $user = User::factory()->unverified()->create(); $html = view('mail.email-verification', [ 'title' => 'Verify your email address', 'previewText' => 'Please verify your email address.', 'user' => $user, 'url' => 'https://example.com/verify', ])->render(); expect($html)->not->toContain('Manage notifications'); });