Publishing improvements: - Create PostPlatformStatus enum (Pending, Publishing, Published, Failed) - Update PostPlatform model, jobs, factories to use enum - Add PostPublishFailed email notification when post fails to publish - Maizzle template + blade for failure email with platform details - PublishPost job: add $tries=3, $backoff=30, failed() method - Fix broadcast event to serialize enum status value Security: - Add rate limiting (throttle:6,1) on social connect endpoints - Fix MediaController::reorder IDOR vulnerability - Fix Connect.vue broken import (storeStep2 -> storeConnect) - Fix UpdatePost data_get() consistency Database: - Add composite index on post_platforms (post_id, enabled) - Add index on post_platforms (social_account_id) Tests: - Add 3 tests for profile photo upload/delete - Add 2 tests for media reorder (including IDOR check) - Fix publish tests for PostPlatformStatus enum - Add Mail::fake() to publish tests Cleanup: - Remove unused AppHeader.vue and AppHeaderLayout.vue - Remove dead BillingController methods All 733 tests passing.
190 lines
5.9 KiB
PHP
190 lines
5.9 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
use App\Enums\User\Setup;
|
|
use App\Models\Media;
|
|
use App\Models\Post;
|
|
use App\Models\PostPlatform;
|
|
use App\Models\SocialAccount;
|
|
use App\Models\User;
|
|
use App\Models\Workspace;
|
|
use Illuminate\Http\UploadedFile;
|
|
use Illuminate\Support\Facades\Storage;
|
|
|
|
beforeEach(function () {
|
|
Storage::fake('local');
|
|
$this->user = User::factory()->create(['setup' => Setup::Completed]);
|
|
$this->workspace = Workspace::factory()->create(['user_id' => $this->user->id]);
|
|
$this->user->update(['current_workspace_id' => $this->workspace->id]);
|
|
|
|
$this->socialAccount = SocialAccount::factory()->create(['workspace_id' => $this->workspace->id]);
|
|
$this->post = Post::factory()->create([
|
|
'workspace_id' => $this->workspace->id,
|
|
'user_id' => $this->user->id,
|
|
]);
|
|
$this->postPlatform = PostPlatform::factory()->create([
|
|
'post_id' => $this->post->id,
|
|
'social_account_id' => $this->socialAccount->id,
|
|
]);
|
|
});
|
|
|
|
// Store tests
|
|
test('store media requires authentication', function () {
|
|
$response = $this->post(route('app.medias.store'), [
|
|
'model' => 'postPlatform',
|
|
'model_id' => $this->postPlatform->id,
|
|
'media' => UploadedFile::fake()->image('test.jpg'),
|
|
]);
|
|
|
|
$response->assertRedirect(route('login'));
|
|
});
|
|
|
|
test('store media uploads file', function () {
|
|
$response = $this->actingAs($this->user)->post(route('app.medias.store'), [
|
|
'model' => 'postPlatform',
|
|
'model_id' => $this->postPlatform->id,
|
|
'media' => UploadedFile::fake()->image('test.jpg'),
|
|
]);
|
|
|
|
$response->assertOk();
|
|
$response->assertJsonStructure(['id', 'url', 'type', 'original_filename']);
|
|
});
|
|
|
|
test('store media validates required fields', function () {
|
|
$response = $this->actingAs($this->user)->post(route('app.medias.store'), [
|
|
'model' => '',
|
|
'model_id' => '',
|
|
]);
|
|
|
|
$response->assertSessionHasErrors(['model', 'model_id', 'media']);
|
|
});
|
|
|
|
// Destroy tests
|
|
test('destroy media requires authentication', function () {
|
|
$media = Media::factory()->create([
|
|
'mediable_id' => $this->postPlatform->id,
|
|
'mediable_type' => 'postPlatform',
|
|
]);
|
|
|
|
$response = $this->delete(route('app.medias.destroy', [$this->postPlatform->id, $media]));
|
|
|
|
$response->assertRedirect(route('login'));
|
|
});
|
|
|
|
test('destroy media deletes the media', function () {
|
|
$media = Media::factory()->create([
|
|
'mediable_id' => $this->postPlatform->id,
|
|
'mediable_type' => 'postPlatform',
|
|
]);
|
|
|
|
$response = $this->actingAs($this->user)->delete(route('app.medias.destroy', [$this->postPlatform->id, $media]));
|
|
|
|
$response->assertOk();
|
|
$response->assertJson(['success' => true]);
|
|
expect(Media::find($media->id))->toBeNull();
|
|
});
|
|
|
|
test('destroy media returns 403 for mismatched model', function () {
|
|
$otherPostPlatform = PostPlatform::factory()->create([
|
|
'post_id' => $this->post->id,
|
|
'social_account_id' => $this->socialAccount->id,
|
|
]);
|
|
|
|
$media = Media::factory()->create([
|
|
'mediable_id' => $otherPostPlatform->id,
|
|
'mediable_type' => 'postPlatform',
|
|
]);
|
|
|
|
$response = $this->actingAs($this->user)->delete(route('app.medias.destroy', [$this->postPlatform->id, $media]));
|
|
|
|
$response->assertForbidden();
|
|
});
|
|
|
|
// Duplicate tests
|
|
test('duplicate media requires authentication', function () {
|
|
$media = Media::factory()->create([
|
|
'mediable_id' => $this->postPlatform->id,
|
|
'mediable_type' => 'postPlatform',
|
|
]);
|
|
|
|
$response = $this->post(route('app.medias.duplicate', $media), [
|
|
'targets' => [],
|
|
]);
|
|
|
|
$response->assertRedirect(route('login'));
|
|
});
|
|
|
|
test('duplicate media creates copies', function () {
|
|
$media = Media::factory()->create([
|
|
'mediable_id' => $this->postPlatform->id,
|
|
'mediable_type' => 'postPlatform',
|
|
]);
|
|
|
|
$otherPostPlatform = PostPlatform::factory()->create([
|
|
'post_id' => $this->post->id,
|
|
'social_account_id' => $this->socialAccount->id,
|
|
]);
|
|
|
|
$response = $this->actingAs($this->user)->post(route('app.medias.duplicate', $media), [
|
|
'targets' => [
|
|
[
|
|
'model' => 'postPlatform',
|
|
'model_id' => $otherPostPlatform->id,
|
|
],
|
|
],
|
|
]);
|
|
|
|
$response->assertOk();
|
|
$response->assertJsonCount(1);
|
|
|
|
expect(Media::where('mediable_id', $otherPostPlatform->id)->count())->toBe(1);
|
|
});
|
|
|
|
// Reorder tests
|
|
test('reorder media updates order', function () {
|
|
$media1 = $this->postPlatform->addMedia(UploadedFile::fake()->image('img1.jpg'), 'media');
|
|
$media2 = $this->postPlatform->addMedia(UploadedFile::fake()->image('img2.jpg'), 'media');
|
|
|
|
$response = $this->actingAs($this->user)->postJson(route('app.medias.reorder'), [
|
|
'media' => [
|
|
['id' => $media1->id, 'order' => 1],
|
|
['id' => $media2->id, 'order' => 0],
|
|
],
|
|
]);
|
|
|
|
$response->assertOk();
|
|
|
|
expect($media1->refresh()->order)->toBe(1);
|
|
expect($media2->refresh()->order)->toBe(0);
|
|
});
|
|
|
|
test('reorder media rejects media from other workspace', function () {
|
|
$otherUser = User::factory()->create(['setup' => Setup::Completed]);
|
|
$otherWorkspace = Workspace::factory()->create(['user_id' => $otherUser->id]);
|
|
$otherUser->update(['current_workspace_id' => $otherWorkspace->id]);
|
|
|
|
$otherPost = Post::factory()->create([
|
|
'workspace_id' => $otherWorkspace->id,
|
|
'user_id' => $otherUser->id,
|
|
]);
|
|
|
|
$otherAccount = SocialAccount::factory()->create([
|
|
'workspace_id' => $otherWorkspace->id,
|
|
]);
|
|
|
|
$otherPlatform = PostPlatform::factory()->create([
|
|
'post_id' => $otherPost->id,
|
|
'social_account_id' => $otherAccount->id,
|
|
]);
|
|
|
|
$otherMedia = $otherPlatform->addMedia(UploadedFile::fake()->image('img.jpg'), 'media');
|
|
|
|
$response = $this->actingAs($this->user)->postJson(route('app.medias.reorder'), [
|
|
'media' => [
|
|
['id' => $otherMedia->id, 'order' => 0],
|
|
],
|
|
]);
|
|
|
|
$response->assertForbidden();
|
|
});
|