Phase 6 of S2b. 37 new tests, 820 → 857 passing across the suite. Feature suites (api/tests/Feature/FormBuilder/): - FormSchemaApiTest: CRUD, publish/unpublish, rotate-public-token (with grace window), edit-lock conflict, typed-confirmation delete, 401 on unauthenticated, 403 on outsider. - FormFieldApiTest: create, reorder, binding-change guard (422 w/o force, 200 with force), conditional_logic cycle rejection, 401 unauth. - FormSubmissionApiTest: draft → values → submit stores schema snapshot + version; review records reviewer; delegation creates active row; draft update blocked for non-subject non-delegatee (403). - FormValueSecurityTest: FieldAccessService hides admin-only fields from non-admin; subject-self bypass; admin-only field leaks through neither admin list nor non-admin detail responses (§22.9 intent). - PublicFormApiTest: portal-visible non-admin fields only; unknown token → 404; happy-path submission; expired-previous-token → 410; grace window still allows submission. - FormSchemaWebhookApiTest: url/secret NEVER returned in resources; DeliverFormWebhookJob rejects 10.x private-ip SSRF (response_body_excerpt logs rejection). - FilterRegistryApiTest: response shape includes tags + form_field sources; form_field filter registers. Integration contract (§31.10): - TagPickerSyncListenerTest: 5 cases proving (a) no-op on user_id=null, (b) sync on submit, (c) deferred sync via PersonIdentityService::confirmMatch, (d) organiser_assigned tags preserved on rebuild, (e) idempotent rerun. Fixes discovered while writing tests: - SyncTagPickerSelectionsOnSubmit: removed hardcoded connection='redis' so tests run via sync queue (QUEUE_CONNECTION fallback). - FormSubmissionService: corrected FormSubmissionReviewed / DraftUpdated event signatures to match S1 event classes. - FormSubmission model: added schema_version_at_submit / snapshot / anonymised_at / submission_duration_seconds / auto_save_count to $fillable so bulk operations + factory states populate consistently. - FormSchema: added version, edit_lock_user_id, edit_lock_expires_at to $fillable; factory now sets version=1 explicitly. - FormValueService: public submission path (actor=null) enforces is_portal_visible=true AND is_admin_only=false at the write layer instead of running FieldAccessService against a null user. - MigrationRollbackTest: target the S2a drop migration by filename. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
74 lines
2.3 KiB
PHP
74 lines
2.3 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace Database\Factories\FormBuilder;
|
|
|
|
use App\Enums\FormBuilder\FormPurpose;
|
|
use App\Enums\FormBuilder\FormSchemaSnapshotMode;
|
|
use App\Enums\FormBuilder\FormSubmissionMode;
|
|
use App\Models\FormBuilder\FormSchema;
|
|
use App\Models\Organisation;
|
|
use Illuminate\Database\Eloquent\Factories\Factory;
|
|
use Illuminate\Support\Str;
|
|
|
|
/** @extends Factory<FormSchema> */
|
|
final class FormSchemaFactory extends Factory
|
|
{
|
|
protected $model = FormSchema::class;
|
|
|
|
/** @return array<string, mixed> */
|
|
public function definition(): array
|
|
{
|
|
$purpose = fake()->randomElement([
|
|
FormPurpose::EVENT_REGISTRATION,
|
|
FormPurpose::FEEDBACK,
|
|
FormPurpose::INCIDENT_REPORT,
|
|
FormPurpose::USER_PROFILE,
|
|
]);
|
|
$name = 'Formulier '.fake('nl_NL')->words(2, true);
|
|
|
|
return [
|
|
'organisation_id' => Organisation::factory(),
|
|
'owner_type' => null,
|
|
'owner_id' => null,
|
|
'name' => $name,
|
|
'slug' => Str::slug($name).'-'.Str::lower(Str::random(4)),
|
|
'purpose' => $purpose,
|
|
'custom_purpose_slug' => null,
|
|
'description' => fake('nl_NL')->sentence(),
|
|
'is_published' => false,
|
|
'submission_mode' => $purpose->defaultSubmissionMode(),
|
|
'locale' => 'nl',
|
|
'snapshot_mode' => FormSchemaSnapshotMode::NEVER,
|
|
'freeze_on_submit' => false,
|
|
'section_level_submit' => false,
|
|
'auto_save_enabled' => false,
|
|
'version' => 1,
|
|
];
|
|
}
|
|
|
|
public function custom(string $slug): static
|
|
{
|
|
return $this->state(fn () => [
|
|
'purpose' => FormPurpose::CUSTOM,
|
|
'submission_mode' => FormSubmissionMode::SINGLE,
|
|
'custom_purpose_slug' => $slug,
|
|
]);
|
|
}
|
|
|
|
public function published(): static
|
|
{
|
|
return $this->state(fn () => ['is_published' => true]);
|
|
}
|
|
|
|
public function forPurpose(FormPurpose $purpose): static
|
|
{
|
|
return $this->state(fn () => [
|
|
'purpose' => $purpose,
|
|
'submission_mode' => $purpose->defaultSubmissionMode(),
|
|
'custom_purpose_slug' => $purpose === FormPurpose::CUSTOM ? 'custom-'.Str::lower(Str::random(6)) : null,
|
|
]);
|
|
}
|
|
}
|