create([ 'username' => 'root', 'password' => 'secret12', 'is_super' => 1, ]); } private function normalAdmin(): Admin { return Admin::query()->create([ 'username' => 'staff', 'password' => 'secret12', 'is_super' => 0, ]); } #[Test] public function normal_admin_cannot_access_system_routes(): void { $staff = $this->normalAdmin(); $this->actingAs($staff, 'admin') ->get(route('admin.system.settings.index')) ->assertForbidden(); $this->actingAs($staff, 'admin') ->get(route('admin.system.admins.index')) ->assertForbidden(); } #[Test] public function super_admin_sees_system_menu_normal_does_not(): void { $this->actingAs($this->superAdmin(), 'admin') ->get(route('admin.home')) ->assertOk() ->assertSee('系统') ->assertSee('设置') ->assertSee('管理员'); $this->actingAs($this->normalAdmin(), 'admin') ->get(route('admin.home')) ->assertOk() ->assertDontSee('lay-href="'.route('admin.system.settings.index').'"', false); } #[Test] public function super_admin_can_save_settings(): void { $super = $this->superAdmin(); $this->actingAs($super, 'admin') ->post(route('admin.system.settings.update'), [ 'telegram_bot_token' => 'bot:token', 'telegram_owner_chat_id' => '-1001', 'channels_max_per_agent' => 5, 'channels_domains' => "cdn1.example.com\nhttps://cdn2.example.com/", ]) ->assertOk() ->assertJsonPath('code', 0); $this->assertSame('bot:token', Setting::query()->where('key', 'telegram.bot_token')->value('value')); $this->assertSame('bot:token', config('coruna.telegram.bot_token')); $this->assertSame(5, (int) config('coruna.channels.max_per_agent')); $this->assertSame(['cdn1.example.com', 'cdn2.example.com'], config('coruna.channel_domains')); $this->assertSame( 'cdn1.example.com,cdn2.example.com', Setting::query()->where('key', 'channels.domains')->value('value') ); } #[Test] public function super_admin_can_crud_admins(): void { $super = $this->superAdmin(); $this->actingAs($super, 'admin') ->post(route('admin.system.admins.store'), [ 'username' => 'newstaff', 'password' => 'secret12', 'is_super' => 0, ]) ->assertOk() ->assertJsonPath('code', 0); $staff = Admin::query()->where('username', 'newstaff')->first(); $this->assertNotNull($staff); $this->assertSame(0, (int) $staff->is_super); $this->actingAs($super, 'admin') ->putJson(route('admin.system.admins.update', $staff), [ 'password' => 'newpass12', 'is_super' => 0, ]) ->assertOk() ->assertJsonPath('code', 0); $this->actingAs($super, 'admin') ->deleteJson(route('admin.system.admins.destroy', $staff)) ->assertOk() ->assertJsonPath('code', 0); $this->assertDatabaseMissing('admins', ['username' => 'newstaff']); } #[Test] public function cannot_delete_last_super_admin(): void { $super = $this->superAdmin(); $this->actingAs($super, 'admin') ->deleteJson(route('admin.system.admins.destroy', $super)) ->assertStatus(422); $this->assertDatabaseHas('admins', ['id' => $super->id]); } }