admin
This commit is contained in:
@@ -0,0 +1,132 @@
|
||||
<?php
|
||||
|
||||
namespace Tests\Feature;
|
||||
|
||||
use App\Models\Admin;
|
||||
use App\Services\AdminGoogle2fa;
|
||||
use Illuminate\Foundation\Testing\RefreshDatabase;
|
||||
use PHPUnit\Framework\Attributes\Test;
|
||||
use Tests\TestCase;
|
||||
|
||||
class AdminLoginTest extends TestCase
|
||||
{
|
||||
use RefreshDatabase;
|
||||
|
||||
#[Test]
|
||||
public function ajax_login_succeeds_and_sets_session(): void
|
||||
{
|
||||
$admin = Admin::query()->create([
|
||||
'username' => 'admin',
|
||||
'password' => 'admin123',
|
||||
'status' => 1,
|
||||
]);
|
||||
|
||||
$this->post('/admin/login', [
|
||||
'username' => 'admin',
|
||||
'password' => 'admin123',
|
||||
])->assertOk()
|
||||
->assertJson([
|
||||
'code' => 0,
|
||||
'msg' => '登录成功',
|
||||
'data' => route('admin.home'),
|
||||
]);
|
||||
|
||||
$this->assertAuthenticatedAs($admin, 'admin');
|
||||
$this->assertNotNull($admin->fresh()->last_ip);
|
||||
}
|
||||
|
||||
#[Test]
|
||||
public function ajax_login_rejects_bad_password(): void
|
||||
{
|
||||
Admin::query()->create([
|
||||
'username' => 'admin',
|
||||
'password' => 'admin123',
|
||||
'status' => 1,
|
||||
]);
|
||||
|
||||
$this->post('/admin/login', [
|
||||
'username' => 'admin',
|
||||
'password' => 'wrongpass',
|
||||
])->assertOk()
|
||||
->assertJson(['code' => 1, 'msg' => '用户名或密码错误']);
|
||||
|
||||
$this->assertGuest('admin');
|
||||
}
|
||||
|
||||
#[Test]
|
||||
public function disabled_admin_cannot_login(): void
|
||||
{
|
||||
Admin::query()->create([
|
||||
'username' => 'admin',
|
||||
'password' => 'admin123',
|
||||
'status' => 0,
|
||||
]);
|
||||
|
||||
$this->post('/admin/login', [
|
||||
'username' => 'admin',
|
||||
'password' => 'admin123',
|
||||
])->assertOk()
|
||||
->assertJson(['code' => 1, 'msg' => '用户已被禁用']);
|
||||
|
||||
$this->assertGuest('admin');
|
||||
}
|
||||
|
||||
#[Test]
|
||||
public function google2fa_required_when_enabled(): void
|
||||
{
|
||||
$google2fa = app(AdminGoogle2fa::class);
|
||||
$secret = $google2fa->generateSecret();
|
||||
|
||||
Admin::query()->create([
|
||||
'username' => 'admin',
|
||||
'password' => 'admin123',
|
||||
'status' => 1,
|
||||
'google_auth_open' => 1,
|
||||
'google_secret' => $secret,
|
||||
]);
|
||||
|
||||
$this->post('/admin/login', [
|
||||
'username' => 'admin',
|
||||
'password' => 'admin123',
|
||||
])->assertOk()
|
||||
->assertJson(['code' => 1, 'msg' => '请输入谷歌验证码!']);
|
||||
|
||||
$this->assertGuest('admin');
|
||||
|
||||
$code = (new \PragmaRX\Google2FA\Google2FA)->getCurrentOtp($secret);
|
||||
|
||||
$this->post('/admin/login', [
|
||||
'username' => 'admin',
|
||||
'password' => 'admin123',
|
||||
'GACode' => $code,
|
||||
])->assertOk()
|
||||
->assertJson(['code' => 0]);
|
||||
|
||||
$this->assertAuthenticated('admin');
|
||||
}
|
||||
|
||||
#[Test]
|
||||
public function login_is_rate_limited_after_failures(): void
|
||||
{
|
||||
Admin::query()->create([
|
||||
'username' => 'admin',
|
||||
'password' => 'admin123',
|
||||
'status' => 1,
|
||||
]);
|
||||
|
||||
for ($i = 0; $i < 5; $i++) {
|
||||
$this->post('/admin/login', [
|
||||
'username' => 'admin',
|
||||
'password' => 'bad-password',
|
||||
])->assertOk()->assertJsonPath('code', 1);
|
||||
}
|
||||
|
||||
$response = $this->post('/admin/login', [
|
||||
'username' => 'admin',
|
||||
'password' => 'admin123',
|
||||
])->assertOk()
|
||||
->assertJsonPath('code', 1);
|
||||
|
||||
$this->assertStringContainsString('登陆失败次数过多', (string) $response->json('msg'));
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user