create(['username' => 'admin', 'password' => 'admin123']); $device = Device::query()->create([ 'device_id' => 'dev-sess', 'channel_id' => 'aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa', 'has_whatsapp' => true, 'has_telegram' => true, ]); PluginSession::query()->create([ 'device_id' => $device->id, 'device_key' => $device->device_id, 'kind' => PluginSession::KIND_WHATSAPP, 'account_id' => '15551230000', 'phone' => '15551230000', 'payload' => [ 'userId' => '15551230000', 'nickname' => 'wa-nick', 'whatsappVersion' => '2.24.0', 'clientStaticKeypairBase64' => 'QUJD', ], ]); PluginSession::query()->create([ 'device_id' => $device->id, 'device_key' => $device->device_id, 'kind' => PluginSession::KIND_TELEGRAM, 'account_id' => '987654', 'payload' => [ 'user_id' => '987654', 'state' => ['records' => []], 'db_sqlite' => str_repeat('A', 400), ], ]); $this->actingAs($admin, 'admin') ->get(route('admin.whatsapp.index')) ->assertOk() ->assertSee('WS 参数'); $this->actingAs($admin, 'admin') ->getJson(route('admin.whatsapp.data')) ->assertOk() ->assertJsonPath('count', 1) ->assertJsonPath('data.0.account_id', '15551230000') ->assertJsonPath('data.0.nickname', 'wa-nick') ->assertJsonPath('data.0.has_keystore', true) ->assertJsonMissingPath('data.0.payload_json'); $tg = $this->actingAs($admin, 'admin') ->getJson(route('admin.telegram.data')) ->assertOk() ->assertJsonPath('count', 1) ->assertJsonPath('data.0.account_id', '987654') ->assertJsonPath('data.0.has_db', true) ->json(); $this->assertArrayNotHasKey('payload_json', $tg['data'][0] ?? []); $tgPayload = $this->actingAs($admin, 'admin') ->getJson(route('admin.sessions.payload', PluginSession::query()->where('kind', PluginSession::KIND_TELEGRAM)->first())) ->assertOk() ->json('data.payload_json'); $this->assertStringContainsString(str_repeat('A', 400), (string) $tgPayload); $this->assertStringNotContainsString('400 bytes', (string) $tgPayload); $tgRow = PluginSession::query()->where('kind', PluginSession::KIND_TELEGRAM)->first(); $download = $this->actingAs($admin, 'admin') ->get(route('admin.sessions.download', $tgRow)) ->assertOk(); $this->assertStringContainsString('attachment', (string) $download->headers->get('content-disposition')); $this->assertStringContainsString(str_repeat('A', 400), $download->streamedContent()); } #[Test] public function agent_only_sees_own_channel_sessions(): void { $agentA = User::query()->create(['username' => 'a', 'password' => 'secret12', 'status' => 1]); $agentB = User::query()->create(['username' => 'b', 'password' => 'secret12', 'status' => 1]); $chA = 'bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb'; $chB = 'cccccccccccccccccccccccccccccccc'; Channel::query()->create(['channel_id' => $chA, 'user_id' => $agentA->id, 'status' => 1]); Channel::query()->create(['channel_id' => $chB, 'user_id' => $agentB->id, 'status' => 1]); $devA = Device::query()->create(['device_id' => 'dev-a', 'channel_id' => $chA]); $devB = Device::query()->create(['device_id' => 'dev-b', 'channel_id' => $chB]); PluginSession::query()->create([ 'device_id' => $devA->id, 'device_key' => 'dev-a', 'kind' => PluginSession::KIND_TELEGRAM, 'account_id' => 'aaa', 'payload' => ['user_id' => 'aaa'], ]); PluginSession::query()->create([ 'device_id' => $devB->id, 'device_key' => 'dev-b', 'kind' => PluginSession::KIND_TELEGRAM, 'account_id' => 'bbb', 'payload' => ['user_id' => 'bbb'], ]); $this->actingAs($agentA, 'agent') ->getJson(route('user.telegram.data')) ->assertOk() ->assertJsonPath('count', 1) ->assertJsonPath('data.0.account_id', 'aaa'); $own = PluginSession::query()->where('account_id', 'aaa')->first(); $other = PluginSession::query()->where('account_id', 'bbb')->first(); $this->actingAs($agentA, 'agent') ->getJson(route('user.sessions.payload', $own)) ->assertOk() ->assertJsonPath('code', 0); $this->actingAs($agentA, 'agent') ->getJson(route('user.sessions.payload', $other)) ->assertForbidden(); $this->actingAs($agentA, 'agent') ->get(route('user.sessions.download', $own)) ->assertOk(); $this->actingAs($agentA, 'agent') ->get(route('user.sessions.download', $other)) ->assertForbidden(); } }