Phase 6 of S2b. 37 new tests, 820 → 857 passing across the suite. Feature suites (api/tests/Feature/FormBuilder/): - FormSchemaApiTest: CRUD, publish/unpublish, rotate-public-token (with grace window), edit-lock conflict, typed-confirmation delete, 401 on unauthenticated, 403 on outsider. - FormFieldApiTest: create, reorder, binding-change guard (422 w/o force, 200 with force), conditional_logic cycle rejection, 401 unauth. - FormSubmissionApiTest: draft → values → submit stores schema snapshot + version; review records reviewer; delegation creates active row; draft update blocked for non-subject non-delegatee (403). - FormValueSecurityTest: FieldAccessService hides admin-only fields from non-admin; subject-self bypass; admin-only field leaks through neither admin list nor non-admin detail responses (§22.9 intent). - PublicFormApiTest: portal-visible non-admin fields only; unknown token → 404; happy-path submission; expired-previous-token → 410; grace window still allows submission. - FormSchemaWebhookApiTest: url/secret NEVER returned in resources; DeliverFormWebhookJob rejects 10.x private-ip SSRF (response_body_excerpt logs rejection). - FilterRegistryApiTest: response shape includes tags + form_field sources; form_field filter registers. Integration contract (§31.10): - TagPickerSyncListenerTest: 5 cases proving (a) no-op on user_id=null, (b) sync on submit, (c) deferred sync via PersonIdentityService::confirmMatch, (d) organiser_assigned tags preserved on rebuild, (e) idempotent rerun. Fixes discovered while writing tests: - SyncTagPickerSelectionsOnSubmit: removed hardcoded connection='redis' so tests run via sync queue (QUEUE_CONNECTION fallback). - FormSubmissionService: corrected FormSubmissionReviewed / DraftUpdated event signatures to match S1 event classes. - FormSubmission model: added schema_version_at_submit / snapshot / anonymised_at / submission_duration_seconds / auto_save_count to $fillable so bulk operations + factory states populate consistently. - FormSchema: added version, edit_lock_user_id, edit_lock_expires_at to $fillable; factory now sets version=1 explicitly. - FormValueService: public submission path (actor=null) enforces is_portal_visible=true AND is_admin_only=false at the write layer instead of running FieldAccessService against a null user. - MigrationRollbackTest: target the S2a drop migration by filename. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
107 lines
2.9 KiB
PHP
107 lines
2.9 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Models\FormBuilder;
|
|
|
|
use App\Enums\FormBuilder\FormSubmissionReviewStatus;
|
|
use App\Enums\FormBuilder\FormSubmissionStatus;
|
|
use App\Models\User;
|
|
use Illuminate\Database\Eloquent\Concerns\HasUlids;
|
|
use Illuminate\Database\Eloquent\Factories\HasFactory;
|
|
use Illuminate\Database\Eloquent\Model;
|
|
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
|
use Illuminate\Database\Eloquent\Relations\HasMany;
|
|
use Illuminate\Database\Eloquent\Relations\MorphTo;
|
|
use Illuminate\Database\Eloquent\SoftDeletes;
|
|
|
|
/**
|
|
* No direct activity-log hooks on this model: lifecycle events fire from the
|
|
* FormSubmissionService (arriving in S2) per ARCH §17.1.
|
|
*/
|
|
final class FormSubmission extends Model
|
|
{
|
|
use HasFactory;
|
|
use HasUlids;
|
|
use SoftDeletes;
|
|
|
|
protected $fillable = [
|
|
'form_schema_id',
|
|
'subject_type',
|
|
'subject_id',
|
|
'submitted_by_user_id',
|
|
'public_submitter_name',
|
|
'public_submitter_email',
|
|
'public_submitter_ip',
|
|
'public_submitter_ip_anonymised_at',
|
|
'status',
|
|
'review_status',
|
|
'reviewed_by_user_id',
|
|
'reviewed_at',
|
|
'review_notes',
|
|
'submitted_at',
|
|
'schema_version_at_submit',
|
|
'schema_snapshot',
|
|
'submission_duration_seconds',
|
|
'auto_save_count',
|
|
'anonymised_at',
|
|
'is_test',
|
|
'submitted_in_locale',
|
|
'opened_at',
|
|
'first_interacted_at',
|
|
'idempotency_key',
|
|
];
|
|
|
|
/** @var array<string, string> */
|
|
protected $casts = [
|
|
'status' => FormSubmissionStatus::class,
|
|
'review_status' => FormSubmissionReviewStatus::class,
|
|
'schema_snapshot' => 'array',
|
|
'is_test' => 'bool',
|
|
'submitted_at' => 'datetime',
|
|
'reviewed_at' => 'datetime',
|
|
'anonymised_at' => 'datetime',
|
|
'opened_at' => 'datetime',
|
|
'first_interacted_at' => 'datetime',
|
|
'public_submitter_ip_anonymised_at' => 'datetime',
|
|
'schema_version_at_submit' => 'int',
|
|
'submission_duration_seconds' => 'int',
|
|
'auto_save_count' => 'int',
|
|
];
|
|
|
|
public function schema(): BelongsTo
|
|
{
|
|
return $this->belongsTo(FormSchema::class, 'form_schema_id');
|
|
}
|
|
|
|
public function subject(): MorphTo
|
|
{
|
|
return $this->morphTo();
|
|
}
|
|
|
|
public function submittedBy(): BelongsTo
|
|
{
|
|
return $this->belongsTo(User::class, 'submitted_by_user_id');
|
|
}
|
|
|
|
public function reviewedBy(): BelongsTo
|
|
{
|
|
return $this->belongsTo(User::class, 'reviewed_by_user_id');
|
|
}
|
|
|
|
public function values(): HasMany
|
|
{
|
|
return $this->hasMany(FormValue::class);
|
|
}
|
|
|
|
public function sectionStatuses(): HasMany
|
|
{
|
|
return $this->hasMany(FormSubmissionSectionStatus::class);
|
|
}
|
|
|
|
public function delegations(): HasMany
|
|
{
|
|
return $this->hasMany(FormSubmissionDelegation::class);
|
|
}
|
|
}
|