Compare commits

..

23 Commits

Author SHA1 Message Date
1d58e0ad38 Merge branch 'feature/event_scoped_admin' into homo 2026-10-01 10:29:49 -03:00
856b9a6706 refactor: update menu code references from 'onticket.adminapp.tickets' to 'adminapp.tickets' 2026-10-01 10:29:06 -03:00
e7bece5bfd Merge branch 'refactor/inventory_stock' into homo 2026-10-01 10:00:54 -03:00
e2cf53eacc Merge branch 'refactor/inventory_stock' into homo 2026-10-01 10:00:41 -03:00
c7fc867905 Merge pull request 'feature/event_scoped_admin' (#14) from feature/event_scoped_admin into homo
Reviewed-on: https://gitea.quo.ar/tbianchini/shopit-back/pulls/14
2026-10-01 12:51:08 +00:00
3ddff7e0ee feat(tests): enhance AdminAppTicketEventScopeTest with soft deletes and active ticket filtering 2026-10-01 09:47:32 -03:00
22de61c8c0 feat(tests): add AdminAppTicketEventScopeTest for event-based ticket management 2026-10-01 09:46:47 -03:00
2d11263adc feat(ticket): add event_id support to ticket service methods; update search, cancel, and refund calculations 2026-10-01 09:46:29 -03:00
c975b5d51d feat(menu): update ticket routes to use new menu code; add tests for menu access and route validation 2026-10-01 09:41:26 -03:00
c7afb70196 feat(staff): implement event scope for staff management; update controllers, services, and resources to handle event_id; add tests for event-based access 2026-10-01 09:25:25 -03:00
31955f862d feat(sale): implement event scope for sales, totals, and modifications; add tests for event-based access 2026-10-01 09:20:43 -03:00
bb4495c6cc feat(users): add event_id to users table and update related resources 2026-10-01 08:56:35 -03:00
6e1f0d731c Merge pull request 'homo' (#12) from homo into main
Reviewed-on: https://gitea.quo.ar/tbianchini/shopit-back/pulls/12
2026-09-30 11:37:24 +00:00
fb5221854c Merge branch 'refactor/inventory_stock' of https://gitea.quo.ar/tbianchini/shopit-back into refactor/inventory_stock 2026-09-29 08:22:42 -03:00
c5aeb19735 refactor(inventory): enhance error reporting for negative stock validation 2026-09-28 19:43:15 +00:00
9db955bdcf refactor(inventory): update stock validation rules and enforce stock_difference requirement 2026-09-28 19:43:15 +00:00
e988e55b77 feat(admin-stock): apply idempotent availability deltas 2026-09-28 19:43:15 +00:00
bc60f1caa1 refactor(inventory): record stock operations consistently 2026-09-28 19:43:15 +00:00
068d5d7f4f feat(inventory): add calculated availability and movement ledger 2026-09-28 19:43:15 +00:00
82c18e9e91 Merge branch 'tenant/smep' into homo 2026-09-28 19:27:39 +00:00
dfad6fb4b0 Merge pull request 'fix/events_integrations' (#11) from fix/events_integrations into homo
Reviewed-on: https://gitea.quo.ar/tbianchini/shopit-back/pulls/11
2026-09-28 19:15:30 +00:00
3f9b773367 feat(integrations): resolve payment context from events 2026-09-28 19:14:23 +00:00
7996d53e12 feat(events): associate purchases and integrations with events 2026-09-28 19:13:36 +00:00
37 changed files with 845 additions and 197 deletions

View File

@@ -8,12 +8,14 @@ use Illuminate\Database\Eloquent\Builder;
class PurchaseRefundSummaryService
{
public function totalForTenant(Tenant $tenant): string
public function totalForTenant(Tenant $tenant, ?int $eventId = null): string
{
$total = TicketRefund::query()
->whereHas(
'purchaseItem.purchase',
fn (Builder $query): Builder => $query->where('tenant_codigo', $tenant->codigo)
fn (Builder $query): Builder => $query
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query): Builder => $query->where('event_id', $eventId))
)
->sum('amount');

View File

@@ -32,10 +32,10 @@ class SaleController extends Controller
$tenant = $request->user()->tenant()->firstOrFail();
return SaleResource::collection(
$this->saleService->sales($tenant, $request->validated())
$this->saleService->sales($tenant, $request->validated(), $request->user()->event_id)
)->additional([
'confirmed_sales_total' => $this->saleService->confirmedSalesTotal($tenant),
'refunded_total' => $this->saleService->refundedTotal($tenant),
'confirmed_sales_total' => $this->saleService->confirmedSalesTotal($tenant, $request->user()->event_id),
'refunded_total' => $this->saleService->refundedTotal($tenant, $request->user()->event_id),
]);
}
@@ -43,7 +43,7 @@ class SaleController extends Controller
{
$tenant = $request->user()->tenant()->firstOrFail();
return new SaleDetailResource($this->saleService->detail($tenant, $sale));
return new SaleDetailResource($this->saleService->detail($tenant, $sale, $request->user()->event_id));
}
public function tickets(Request $request, int $sale): AnonymousResourceCollection
@@ -51,7 +51,7 @@ class SaleController extends Controller
$tenant = $request->user()->tenant()->firstOrFail();
return SaleTicketResource::collection(
$this->saleService->tickets($tenant, $sale)
$this->saleService->tickets($tenant, $sale, $request->user()->event_id)
);
}
@@ -59,14 +59,14 @@ class SaleController extends Controller
{
$tenant = $request->user()->tenant()->firstOrFail();
return new SaleResource($this->saleService->confirm($tenant, $sale));
return new SaleResource($this->saleService->confirm($tenant, $sale, $request->user()->event_id));
}
public function cancel(Request $request, int $sale): SaleResource
{
$tenant = $request->user()->tenant()->firstOrFail();
return new SaleResource($this->saleService->cancel($tenant, $sale));
return new SaleResource($this->saleService->cancel($tenant, $sale, $request->user()->event_id));
}
public function modifications(
@@ -76,6 +76,7 @@ class SaleController extends Controller
$this->saleService->modifications(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
$request->user()->event_id,
)
);
}
@@ -86,7 +87,7 @@ class SaleController extends Controller
return $this->salePdfService->downloadSales(
$tenant,
$this->saleService->salesForExport($tenant, $request->validated()),
$this->saleService->salesForExport($tenant, $request->validated(), $request->user()->event_id),
$request->validated('timezone'),
);
}
@@ -97,7 +98,7 @@ class SaleController extends Controller
return $this->salePdfService->downloadModifications(
$tenant,
$this->saleService->modificationsForExport($tenant, $request->validated()),
$this->saleService->modificationsForExport($tenant, $request->validated(), $request->user()->event_id),
$request->validated('timezone'),
);
}
@@ -108,7 +109,7 @@ class SaleController extends Controller
return $this->saleExcelService->downloadSales(
$tenant,
$this->saleService->salesForExport($tenant, $request->validated()),
$this->saleService->salesForExport($tenant, $request->validated(), $request->user()->event_id),
$request->validated('timezone'),
);
}
@@ -120,7 +121,7 @@ class SaleController extends Controller
return $this->saleExcelService->downloadModifications(
$tenant,
$this->saleService->modificationsForExport($tenant, $request->validated()),
$this->saleService->modificationsForExport($tenant, $request->validated(), $request->user()->event_id),
$request->validated('timezone'),
);
}

View File

@@ -2,7 +2,6 @@
namespace App\Domains\Commerce\Sale\Services;
use App\Shared\Logging\Models\ValueChange;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Commerce\Purchase\Services\CheckoutService;
use App\Domains\Commerce\Purchase\Services\PurchaseRefundSummaryService;
@@ -10,6 +9,7 @@ use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Services\TicketPresentationResolver;
use App\Domains\Ticketing\Ticket\Services\TicketValidityResolver;
use App\Shared\Logging\Models\ValueChange;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Pagination\LengthAwarePaginator;
use Illuminate\Support\Collection;
@@ -21,19 +21,18 @@ class AdminAppSaleService
protected PurchaseRefundSummaryService $refundSummaryService,
) {}
public function confirmedSalesTotal(Tenant $tenant): string
public function confirmedSalesTotal(Tenant $tenant, ?int $eventId = null): string
{
$total = Purchase::query()
->where('tenant_codigo', $tenant->codigo)
$total = $this->purchasesQuery($tenant, $eventId)
->where('status', Purchase::STATUS_PAID)
->sum('total');
return number_format((float) $total, 2, '.', '');
}
public function refundedTotal(Tenant $tenant): string
public function refundedTotal(Tenant $tenant, ?int $eventId = null): string
{
return $this->refundSummaryService->totalForTenant($tenant);
return $this->refundSummaryService->totalForTenant($tenant, $eventId);
}
/**
@@ -47,43 +46,42 @@ class AdminAppSaleService
* } $filters
* @return LengthAwarePaginator<Purchase>
*/
public function sales(Tenant $tenant, array $filters = []): LengthAwarePaginator
public function sales(Tenant $tenant, array $filters = [], ?int $eventId = null): LengthAwarePaginator
{
return $this->salesQuery($tenant, $filters)
return $this->salesQuery($tenant, $filters, $eventId)
->paginateFromRequest()
->withQueryString();
}
public function detail(Tenant $tenant, int $saleId): Purchase
public function detail(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
{
return Purchase::query()
->where('tenant_codigo', $tenant->codigo)
return $this->purchasesQuery($tenant, $eventId)
->with('items')
->findOrFail($saleId);
}
/** @return Collection<int, Ticket> */
public function tickets(Tenant $tenant, int $saleId): Collection
public function tickets(Tenant $tenant, int $saleId, ?int $eventId = null): Collection
{
return $this->findForTenant($tenant, $saleId)
return $this->findForTenant($tenant, $saleId, $eventId)
->tickets()
->with([...TicketValidityResolver::RELATIONS, ...TicketPresentationResolver::RELATIONS, 'refund'])
->orderBy('id')
->get();
}
public function confirm(Tenant $tenant, int $saleId): Purchase
public function confirm(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
{
$sale = $this->findForTenant($tenant, $saleId);
$sale = $this->findForTenant($tenant, $saleId, $eventId);
return $this->saleForResponse(
$this->checkoutService->confirmPaidPurchase($sale)
);
}
public function cancel(Tenant $tenant, int $saleId): Purchase
public function cancel(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
{
$sale = $this->findForTenant($tenant, $saleId);
$sale = $this->findForTenant($tenant, $saleId, $eventId);
return $this->saleForResponse(
$this->checkoutService->cancelPurchaseFromAdmin($sale)
@@ -94,18 +92,18 @@ class AdminAppSaleService
* @param array<string, mixed> $filters
* @return Collection<int, Purchase>
*/
public function salesForExport(Tenant $tenant, array $filters = []): Collection
public function salesForExport(Tenant $tenant, array $filters = [], ?int $eventId = null): Collection
{
return $this->salesQuery($tenant, $filters)->get();
return $this->salesQuery($tenant, $filters, $eventId)->get();
}
/**
* @param array<string, mixed> $filters
* @return LengthAwarePaginator<ValueChange>
*/
public function modifications(Tenant $tenant, array $filters = []): LengthAwarePaginator
public function modifications(Tenant $tenant, array $filters = [], ?int $eventId = null): LengthAwarePaginator
{
return $this->modificationsQuery($tenant, $filters)
return $this->modificationsQuery($tenant, $filters, $eventId)
->paginateFromRequest()
->withQueryString();
}
@@ -114,13 +112,13 @@ class AdminAppSaleService
* @param array<string, mixed> $filters
* @return Collection<int, ValueChange>
*/
public function modificationsForExport(Tenant $tenant, array $filters = []): Collection
public function modificationsForExport(Tenant $tenant, array $filters = [], ?int $eventId = null): Collection
{
return $this->modificationsQuery($tenant, $filters)->get();
return $this->modificationsQuery($tenant, $filters, $eventId)->get();
}
/** @param array<string, mixed> $filters */
protected function salesQuery(Tenant $tenant, array $filters): Builder
protected function salesQuery(Tenant $tenant, array $filters, ?int $eventId = null): Builder
{
$sortColumns = [
'id' => 'id',
@@ -137,8 +135,7 @@ class AdminAppSaleService
? $requestedDirection
: 'desc';
return Purchase::query()
->where('tenant_codigo', $tenant->codigo)
return $this->purchasesQuery($tenant, $eventId)
->when($filters['q'] ?? null, function (Builder $query, string $search): void {
$term = trim($search);
@@ -176,11 +173,18 @@ class AdminAppSaleService
* @param array<string, mixed> $filters
* @return Builder<ValueChange>
*/
protected function modificationsQuery(Tenant $tenant, array $filters): Builder
protected function modificationsQuery(Tenant $tenant, array $filters, ?int $eventId = null): Builder
{
return ValueChange::query()
->where('tenant_code', $tenant->codigo)
->where('trackable_type', (new Purchase)->getMorphClass())
->when($eventId !== null, fn (Builder $query): Builder => $query->whereHasMorph(
'trackable',
[Purchase::class],
fn (Builder $sales): Builder => $sales
->where('tenant_codigo', $tenant->codigo)
->where('event_id', $eventId),
))
->when($filters['q'] ?? null, function (Builder $query, string $search): void {
$term = trim($search);
@@ -221,11 +225,18 @@ class AdminAppSaleService
->orderByDesc('id');
}
protected function findForTenant(Tenant $tenant, int $saleId): Purchase
protected function findForTenant(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
{
return $this->purchasesQuery($tenant, $eventId)
->findOrFail($saleId);
}
/** @return Builder<Purchase> */
protected function purchasesQuery(Tenant $tenant, ?int $eventId): Builder
{
return Purchase::query()
->where('tenant_codigo', $tenant->codigo)
->findOrFail($saleId);
->when($eventId !== null, fn (Builder $query): Builder => $query->where('event_id', $eventId));
}
protected function saleForResponse(Purchase $sale): Purchase

View File

@@ -29,4 +29,8 @@ Consume compras de `Purchase`, datos del tenant y entradas de `Logging`. No es d
La consulta paginada y la colección de exportación deben aplicar los mismos filtros para evitar diferencias entre pantalla, PDF y Excel.
Cuando el usuario autenticado tiene `event_id`, el controlador lo pasa al servicio como alcance obligatorio para ventas, totales, historial y exportaciones. El alcance se combina con el tenant y no se obtiene de los filtros enviados por el cliente. Los administradores sin `event_id` conservan el alcance del tenant.
El detalle, los tickets de una venta, la confirmación y la cancelación buscan la compra dentro del mismo alcance. Una venta de otro evento o sin evento devuelve 404 para un administrador con `event_id`, antes de ejecutar cualquier acción en `CheckoutService`.
El historial comparte con ventas los filtros de búsqueda, ID, fecha de venta y estado. En el historial, el estado se evalúa sobre `ValueChange.new_value`: representa el resultado de esa modificación y no el estado actual de la venta.

View File

@@ -20,6 +20,7 @@ class AdminAppAdministratorController extends Controller
return AdministratorResource::collection($this->administratorService->list(
$request->user()->tenant()->firstOrFail(),
$request->string('search')->trim()->toString() ?: null,
$request->user()->event_id,
));
}
@@ -28,6 +29,7 @@ class AdminAppAdministratorController extends Controller
return AdministratorResource::make($this->administratorService->create(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
$request->user()->event_id,
));
}
@@ -37,6 +39,7 @@ class AdminAppAdministratorController extends Controller
$request->user()->tenant()->firstOrFail(),
$administrator,
$request->validated(),
$request->user()->event_id,
));
}

View File

@@ -18,6 +18,7 @@ class AdministratorResource extends JsonResource
'dni' => $this->dni,
'email' => $this->email,
'rol_codigo' => $this->rol_codigo,
'event_id' => $this->event_id,
'role' => $this->whenLoaded('role', fn () => [
'codigo' => $this->role?->codigo,
'nombre' => $this->role?->nombre,

View File

@@ -19,9 +19,9 @@ class AdministratorService
public function __construct(private readonly ResetPasswordAttemptService $resetPasswordAttemptService) {}
/** @return Collection<int, User> */
public function list(Tenant $tenant, ?string $search = null): Collection
public function list(Tenant $tenant, ?string $search = null, ?int $eventId = null): Collection
{
return $this->query($tenant)->with('role')
return $this->query($tenant, $eventId)->with('role')
->when($search, fn (Builder $query, string $search) => $query->where(function (Builder $query) use ($search): void {
$query->where('nombre_apellido', 'like', "%{$search}%")
->orWhere('dni', 'like', "%{$search}%")
@@ -31,14 +31,15 @@ class AdministratorService
}
/** @param array<string, mixed> $data */
public function create(Tenant $tenant, array $data): User
public function create(Tenant $tenant, array $data, ?int $eventId = null): User
{
return DB::transaction(function () use ($tenant, $data): User {
return DB::transaction(function () use ($tenant, $data, $eventId): User {
$administrator = User::query()->create([
...$this->attributes($data),
'password' => Str::random(64),
'rol_codigo' => RoleCode::AdminApp->value,
'tenant_codigo' => $tenant->codigo,
'event_id' => $eventId,
]);
$this->resetPasswordAttemptService->createForAdminAppEmail(
$administrator->email,
@@ -50,10 +51,10 @@ class AdministratorService
}
/** @param array<string, mixed> $data */
public function update(Tenant $tenant, int $administratorId, array $data): User
public function update(Tenant $tenant, int $administratorId, array $data, ?int $eventId = null): User
{
return DB::transaction(function () use ($tenant, $administratorId, $data): User {
$administrator = $this->query($tenant)->lockForUpdate()->findOrFail($administratorId);
return DB::transaction(function () use ($tenant, $administratorId, $data, $eventId): User {
$administrator = $this->query($tenant, $eventId)->lockForUpdate()->findOrFail($administratorId);
$administrator->update($this->attributes($data));
return $administrator->load('role');
@@ -66,11 +67,11 @@ class AdministratorService
// Serialize deletions for this tenant, including requests already authenticated
// when another administrator removes their account.
Tenant::query()->whereKey($tenant->getKey())->lockForUpdate()->firstOrFail();
$administrator = $this->query($tenant)->lockForUpdate()->findOrFail($administratorId);
$administrator = $this->query($tenant, $actor->event_id)->lockForUpdate()->findOrFail($administratorId);
if ($administrator->is($actor)) {
throw ValidationException::withMessages(['administrator' => 'No podés eliminar tu propio usuario.']);
}
$activeAdministrators = $this->query($tenant)->lockForUpdate()->get();
$activeAdministrators = $this->query($tenant, $actor->event_id)->lockForUpdate()->get();
if ($activeAdministrators->count() <= 1) {
throw ValidationException::withMessages(['administrator' => 'El tenant debe conservar al menos un administrador.']);
}
@@ -80,10 +81,11 @@ class AdministratorService
});
}
private function query(Tenant $tenant): Builder
private function query(Tenant $tenant, ?int $eventId = null): Builder
{
return User::query()->where('tenant_codigo', $tenant->codigo)
->where('rol_codigo', RoleCode::AdminApp->value);
->where('rol_codigo', RoleCode::AdminApp->value)
->when($eventId !== null, fn (Builder $query): Builder => $query->where('event_id', $eventId));
}
/** @param array<string, mixed> $data

View File

@@ -55,6 +55,8 @@ No agrega tablas ni migraciones. No modifica el CRUD de escáneres ni el fronten
## Verificación
Cuando el actor tiene `event_id`, los nuevos administradores heredan su evento y el listado, la búsqueda, la edición y la baja se limitan a ese evento dentro del tenant. La comprobación de administradores activos también usa ese alcance. El evento se toma del usuario autenticado, no del cuerpo de la solicitud; sin `event_id` se conserva el comportamiento por tenant.
`php artisan test tests/Feature/Administrator/AdministratorControllerTest.php`
Las pruebas cubren CRUD, normalización y unicidad del email, establecimiento de

View File

@@ -2,11 +2,12 @@
namespace App\Domains\Core\Auth\Models;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Domains\Core\Authorization\Models\Role;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Ticketing\Event\Models\EventDateChangeView;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Ticketing\Event\Models\EventDateChangeView;
use App\Domains\Ticketing\Ticket\Models\ScanAttempt;
use Database\Factories\UserFactory;
use Illuminate\Database\Eloquent\Attributes\Fillable;
@@ -20,7 +21,7 @@ use Illuminate\Foundation\Auth\User as Authenticatable;
use Illuminate\Notifications\Notifiable;
use Laravel\Sanctum\HasApiTokens;
#[Fillable(['nombre_apellido', 'email', 'password', 'dni', 'telefono', 'google_id', 'rol_codigo', 'tenant_codigo'])]
#[Fillable(['nombre_apellido', 'email', 'password', 'dni', 'telefono', 'google_id', 'rol_codigo', 'tenant_codigo', 'event_id'])]
#[Hidden(['password', 'remember_token', 'active_email', 'active_google_id'])]
class User extends Authenticatable
{
@@ -86,6 +87,12 @@ class User extends Authenticatable
return $this->belongsTo(Tenant::class, 'tenant_codigo', 'codigo');
}
/** @return BelongsTo<Event, $this> */
public function event(): BelongsTo
{
return $this->belongsTo(Event::class);
}
/** @return BelongsToMany<Category, $this> */
public function scanCategories(): BelongsToMany
{
@@ -103,6 +110,7 @@ class User extends Authenticatable
protected function casts(): array
{
return [
'event_id' => 'integer',
'email_verified_at' => 'datetime',
'password' => 'hashed',
'failed_login_attempts' => 'integer',

View File

@@ -24,6 +24,7 @@ class UserResource extends JsonResource
'telefono' => $this->telefono,
'rol_codigo' => $this->rol_codigo,
'tenant_codigo' => $this->tenant_codigo,
'event_id' => $this->event_id,
'categories' => $this->whenLoaded('scanCategories', fn () => $this->scanCategories
->map(fn ($category) => [
'id' => $category->id,

View File

@@ -26,6 +26,7 @@ class AdminAppStaffController extends Controller
return StaffResource::collection($this->staffService->list(
$request->user()->tenant()->firstOrFail(),
$request->string('search')->trim()->toString() ?: null,
$request->user()->event_id,
));
}
@@ -34,6 +35,7 @@ class AdminAppStaffController extends Controller
return StaffResource::make($this->staffService->create(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
$request->user()->event_id,
));
}
@@ -43,12 +45,13 @@ class AdminAppStaffController extends Controller
$request->user()->tenant()->firstOrFail(),
$staff,
$request->validated(),
$request->user()->event_id,
));
}
public function destroy(Request $request, int $staff): Response
{
$this->staffService->delete($request->user()->tenant()->firstOrFail(), $staff);
$this->staffService->delete($request->user()->tenant()->firstOrFail(), $staff, $request->user()->event_id);
return response()->noContent();
}
@@ -60,6 +63,7 @@ class AdminAppStaffController extends Controller
$scanner = $this->staffService->find(
$request->user()->tenant()->firstOrFail(),
$staff,
$request->user()->event_id,
);
return ScanAttemptResource::collection(

View File

@@ -18,6 +18,7 @@ class StaffResource extends JsonResource
'dni' => $this->dni,
'email' => $this->email,
'rol_codigo' => $this->rol_codigo,
'event_id' => $this->event_id,
'role' => $this->whenLoaded('role', fn () => [
'codigo' => $this->role?->codigo,
'nombre' => $this->role?->nombre,

View File

@@ -2,11 +2,11 @@
namespace App\Domains\Core\Staff\Services;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Core\Auth\Models\ResetPasswordAttempt;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\ResetPasswordAttemptService;
use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Core\Tenant\Models\Tenant;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Database\Eloquent\Collection;
@@ -22,9 +22,9 @@ class StaffService
) {}
/** @return Collection<int, User> */
public function list(Tenant $tenant, ?string $search = null): Collection
public function list(Tenant $tenant, ?string $search = null, ?int $eventId = null): Collection
{
return $this->staffQuery($tenant)
return $this->staffQuery($tenant, $eventId)
->with(['role', 'scanCategories' => fn ($query) => $query->orderBy('nombre')])
->when($search, function (Builder $query, string $search): void {
$query->where(function (Builder $query) use ($search): void {
@@ -52,18 +52,19 @@ class StaffService
}
/** @param array<string, mixed> $data */
public function create(Tenant $tenant, array $data): User
public function create(Tenant $tenant, array $data, ?int $eventId = null): User
{
$categoryIds = $this->categoryIdsFor($tenant, $data);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds);
return DB::transaction(function () use ($tenant, $data, $categoryIds): User {
return DB::transaction(function () use ($tenant, $data, $categoryIds, $eventId): User {
$staff = User::query()->create([
...Arr::only($data, ['nombre_apellido', 'dni', 'email']),
'email' => mb_strtolower(trim((string) $data['email'])),
'password' => Str::random(64),
'rol_codigo' => RoleCode::Scanner->value,
'tenant_codigo' => $tenant->codigo,
'event_id' => $eventId,
]);
$staff->scanCategories()->sync($categoryIds);
$this->resetPasswordAttemptService->createForScannerEmail(
@@ -76,9 +77,9 @@ class StaffService
}
/** @param array<string, mixed> $data */
public function update(Tenant $tenant, int $staffId, array $data): User
public function update(Tenant $tenant, int $staffId, array $data, ?int $eventId = null): User
{
$staff = $this->find($tenant, $staffId);
$staff = $this->find($tenant, $staffId, $eventId);
$categoryIds = $this->categoryIdsFor($tenant, $data);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds);
@@ -92,9 +93,9 @@ class StaffService
});
}
public function delete(Tenant $tenant, int $staffId): void
public function delete(Tenant $tenant, int $staffId, ?int $eventId = null): void
{
$staff = $this->find($tenant, $staffId);
$staff = $this->find($tenant, $staffId, $eventId);
DB::transaction(function () use ($staff): void {
$staff->tokens()->delete();
@@ -102,16 +103,17 @@ class StaffService
});
}
public function find(Tenant $tenant, int $staffId): User
public function find(Tenant $tenant, int $staffId, ?int $eventId = null): User
{
return $this->staffQuery($tenant)->findOrFail($staffId);
return $this->staffQuery($tenant, $eventId)->findOrFail($staffId);
}
private function staffQuery(Tenant $tenant): Builder
private function staffQuery(Tenant $tenant, ?int $eventId = null): Builder
{
return User::query()
->where('tenant_codigo', $tenant->codigo)
->where('rol_codigo', RoleCode::Scanner->value);
->where('rol_codigo', RoleCode::Scanner->value)
->when($eventId !== null, fn (Builder $query): Builder => $query->where('event_id', $eventId));
}
/**

View File

@@ -18,3 +18,5 @@ Recurso REST `/v1/adminapp/tenant/staff`, excepto detalle individual, protegido
## Dependencias y reglas
Usa `Auth/User` como entidad de personal, `Authorization` para su rol, `Catalog/Category` para asignaciones y `Tenant` para aislamiento. Toda búsqueda, edición o borrado debe comprobar que el usuario pertenece al tenant autenticado.
Si el administrador autenticado tiene `event_id`, el alta de scanners hereda ese valor y las búsquedas, ediciones, bajas y consultas de intentos de escaneo se limitan a personal del mismo evento. El cliente no puede elegir ni cambiar el evento. Sin `event_id`, se mantiene el alcance por tenant.

View File

@@ -29,7 +29,7 @@ class TicketController extends Controller
$tenant = $request->user()->tenant()->firstOrFail();
return new AdminAppTicketCollection(
$this->ticketService->search($tenant, $request->validated())
$this->ticketService->search($tenant, $request->validated(), $request->user()->event_id)
);
}
@@ -37,7 +37,7 @@ class TicketController extends Controller
{
$tenant = $request->user()->tenant()->firstOrFail();
return new AdminAppTicketResource($this->ticketService->cancel($tenant, $ticket));
return new AdminAppTicketResource($this->ticketService->cancel($tenant, $ticket, $request->user()->event_id));
}
public function calculateRefund(Request $request, int $ticket): AdminAppTicketRefundCalculationResource
@@ -45,7 +45,7 @@ class TicketController extends Controller
$tenant = $request->user()->tenant()->firstOrFail();
return new AdminAppTicketRefundCalculationResource(
$this->ticketService->calculateRefund($tenant, $ticket)
$this->ticketService->calculateRefund($tenant, $ticket, $request->user()->event_id)
);
}
@@ -69,7 +69,7 @@ class TicketController extends Controller
return $this->ticketPdfService->download(
$tenant,
$this->ticketService->ticketsForExport($tenant, $request->validated()),
$this->ticketService->ticketsForExport($tenant, $request->validated(), $request->user()->event_id),
$request->validated('timezone'),
);
}
@@ -80,7 +80,7 @@ class TicketController extends Controller
return $this->ticketExcelService->download(
$tenant,
$this->ticketService->ticketsForExport($tenant, $request->validated()),
$this->ticketService->ticketsForExport($tenant, $request->validated(), $request->user()->event_id),
$request->validated('timezone'),
);
}

View File

@@ -41,9 +41,9 @@ class AdminAppTicketService
/**
* @param array{q?: string|null, category?: string|null, product?: string|null, type?: string|null, date?: string|null, size?: string|null, status?: string|null, page?: int, per_page?: int, sort_by?: string|null, sort_direction?: string|null} $filters
*/
public function search(Tenant $tenant, array $filters = []): AdminAppTicketResult
public function search(Tenant $tenant, array $filters = [], ?int $eventId = null): AdminAppTicketResult
{
$query = $this->baseQuery($tenant, $filters);
$query = $this->baseQuery($tenant, $filters, $eventId);
$countQuery = clone $query;
$databaseSorted = $this->applyDatabaseSort($query, $tenant, $filters);
@@ -77,7 +77,7 @@ class AdminAppTicketService
tickets: $tickets,
scannedTickets: $scannedTickets,
totalTickets: $totalTickets,
refundedTotal: $this->refundSummaryService->totalForTenant($tenant),
refundedTotal: $this->refundSummaryService->totalForTenant($tenant, $eventId),
);
}
@@ -85,9 +85,9 @@ class AdminAppTicketService
* @param array{q?: string|null, category?: string|null, product?: string|null, type?: string|null, date?: string|null, size?: string|null, status?: string|null, sort_by?: string|null, sort_direction?: string|null} $filters
* @return Collection<int, Ticket>
*/
public function ticketsForExport(Tenant $tenant, array $filters = []): Collection
public function ticketsForExport(Tenant $tenant, array $filters = [], ?int $eventId = null): Collection
{
$query = $this->baseQuery($tenant, $filters);
$query = $this->baseQuery($tenant, $filters, $eventId);
$databaseSorted = $this->applyDatabaseSort($query, $tenant, $filters);
$tickets = $query
->with(self::RELATIONS)
@@ -97,11 +97,10 @@ class AdminAppTicketService
return $databaseSorted ? $tickets : $this->sortTickets($tickets, $tenant, $filters);
}
public function cancel(Tenant $tenant, int $ticketId): Ticket
public function cancel(Tenant $tenant, int $ticketId, ?int $eventId = null): Ticket
{
return DB::transaction(function () use ($tenant, $ticketId): Ticket {
$ticket = Ticket::query()
->where('tenant_code', $tenant->codigo)
return DB::transaction(function () use ($tenant, $ticketId, $eventId): Ticket {
$ticket = $this->ticketsQuery($tenant, $eventId)
->lockForUpdate()
->findOrFail($ticketId);
@@ -124,10 +123,9 @@ class AdminAppTicketService
* partial: string|null,
* }
*/
public function calculateRefund(Tenant $tenant, int $ticketId): array
public function calculateRefund(Tenant $tenant, int $ticketId, ?int $eventId = null): array
{
$ticket = Ticket::query()
->where('tenant_code', $tenant->codigo)
$ticket = $this->ticketsQuery($tenant, $eventId)
->findOrFail($ticketId);
if (! $ticket->can_refund()) {
@@ -175,14 +173,13 @@ class AdminAppTicketService
string $refundType,
?User $createdBy = null,
): Ticket {
$this->ensureRefundIsAllowed($tenant, $refundType);
return DB::transaction(function () use ($tenant, $ticketId, $refundType, $createdBy): Ticket {
$ticket = Ticket::query()
->where('tenant_code', $tenant->codigo)
$ticket = $this->ticketsQuery($tenant, $createdBy?->event_id)
->lockForUpdate()
->findOrFail($ticketId);
$this->ensureRefundIsAllowed($tenant, $refundType);
if (! $ticket->can_refund()) {
if ($ticket->status !== Ticket::STATUS_ACTIVE) {
throw ValidationException::withMessages([
@@ -310,12 +307,11 @@ class AdminAppTicketService
* @param array{q?: string|null, category?: string|null, product?: string|null, type?: string|null, date?: string|null, size?: string|null, status?: string|null, page?: int, per_page?: int} $filters
* @return Builder<Ticket>
*/
private function baseQuery(Tenant $tenant, array $filters): Builder
private function baseQuery(Tenant $tenant, array $filters, ?int $eventId = null): Builder
{
$search = trim((string) ($filters['q'] ?? ''));
$query = Ticket::query()
->where('tenant_code', $tenant->codigo)
$query = $this->ticketsQuery($tenant, $eventId)
->when($search !== '', function (Builder $query) use ($search): void {
$this->applySearchFilter($query, $search);
})
@@ -355,6 +351,14 @@ class AdminAppTicketService
return $query;
}
/** @return Builder<Ticket> */
private function ticketsQuery(Tenant $tenant, ?int $eventId): Builder
{
return Ticket::query()
->where('tenant_code', $tenant->codigo)
->when($eventId !== null, fn (Builder $query): Builder => $query->where('tickets.event_id', $eventId));
}
/** @param Builder<Ticket> $query */
private function applySearchFilter(Builder $query, string $search): void
{

View File

@@ -89,6 +89,10 @@ Bajo `/v1/adminapp/tenant`, protegido por `auth:sanctum`, `adminapp.tenant` y el
`TicketPdfService` genera la descarga y `TicketResource`/`ValidityTimeResource` definen las respuestas.
Si el administrador autenticado tiene `event_id`, las consultas de Tickets y sus exportaciones se limitan a `tickets.event_id` dentro del tenant. Los contadores usan el mismo alcance y el total reembolsado se limita a las compras del evento. Sin `event_id`, se conserva el alcance por tenant.
La cancelación, el cálculo de reembolso y el reembolso buscan el ticket dentro de ese alcance antes de validar o ejecutar la operación. Un ticket de otro evento o sin evento devuelve 404 para un administrador con evento asignado. El alcance se obtiene del usuario autenticado, no de los parámetros del cliente.
## Dependencias y reglas
Depende de `Purchase`, `Catalog`, `Tenant` y `Auth`. La generación debe ser idempotente ante reintentos del evento. `TicketNotAvailableException` y `TicketGenerationException` separan indisponibilidad de errores de generación.

View File

@@ -41,7 +41,7 @@ return new class extends Migration
return;
}
$sourcePath = public_path('images/website_types/onticket/'.self::FILENAME);
$sourcePath = public_path('images/website_types/'.self::FILENAME);
if (! is_file($sourcePath)) {
throw new RuntimeException("Favicon not found at path: {$sourcePath}");

View File

@@ -1,47 +0,0 @@
<?php
use App\Domains\Core\Tenant\Models\AdminWebsiteType;
use App\Domains\Core\Tenant\Services\AdminWebsiteTypeService;
use Illuminate\Database\Migrations\Migration;
use Illuminate\Http\UploadedFile;
use Illuminate\Support\Facades\Storage;
return new class extends Migration
{
public function up(): void
{
if (app()->environment('testing')) {
Storage::fake('s3');
}
if (! AdminWebsiteType::query()->where('codigo', 'shopit')->exists()) {
return;
}
app(AdminWebsiteTypeService::class)->updateOrCreate(
['codigo' => 'shopit'],
[
'primary_color' => '#2FD3AC',
'site_logo' => $this->uploadedImage('shopit_logo.png', 'image/png'),
'footer_logo' => $this->uploadedImage('shopit_footer_logo.png', 'image/png'),
'favicon' => $this->uploadedImage('shopit-favicon.svg', 'image/svg+xml'),
],
);
}
public function down(): void
{
// Brand assets are operational data and are intentionally preserved.
}
private function uploadedImage(string $filename, string $mimeType): UploadedFile
{
$path = public_path("images/website_types/shopit/{$filename}");
if (! is_file($path)) {
throw new RuntimeException("ShopIt image not found at path: {$path}");
}
return new UploadedFile($path, $filename, $mimeType, null, true);
}
};

View File

@@ -0,0 +1,28 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('users', function (Blueprint $table): void {
$table->foreignId('event_id')
->nullable()
->after('tenant_codigo')
->constrained('events')
->cascadeOnUpdate()
->restrictOnDelete();
});
}
public function down(): void
{
Schema::table('users', function (Blueprint $table): void {
$table->dropForeign(['event_id']);
$table->dropColumn('event_id');
});
}
};

View File

@@ -40,7 +40,7 @@ class WebsiteTypeSeeder extends Seeder
public function run(): void
{
$this->websiteTypeService->updateOrCreate(
$shopIt = $this->websiteTypeService->updateOrCreate(
['codigo' => 'shopit'],
[
'nombre' => 'ShopIt',
@@ -48,10 +48,9 @@ class WebsiteTypeSeeder extends Seeder
'scanner_domain' => 'scanner.localhost',
'site_title' => 'ShopIt',
...self::PRESENTATION,
'primary_color' => '#2FD3AC',
'site_logo' => $this->shopItLogo(),
'footer_logo' => $this->shopItFooterLogo(),
'favicon' => $this->shopItFavicon(),
'site_logo' => $this->onTicketLogo(),
'footer_logo' => $this->onTicketFooterLogo(),
'favicon' => $this->onTicketFavicon(),
],
);
@@ -84,7 +83,7 @@ class WebsiteTypeSeeder extends Seeder
...self::PRESENTATION,
'site_logo' => $this->onTicketLogo(),
'footer_logo' => $this->onTicketFooterLogo(),
'favicon' => $this->onTicketFavicon(),
'favicon' => $shopIt->favicon()->firstOrFail()->key,
],
);
@@ -205,7 +204,7 @@ class WebsiteTypeSeeder extends Seeder
private function onTicketLogo(): UploadedFile
{
$path = public_path('images/website_types/onticket/onticket_logo.png');
$path = public_path('images/website_types/onticket_logo.png');
if (! file_exists($path)) {
throw new RuntimeException("OnTicket logo not found at path: {$path}");
@@ -222,7 +221,7 @@ class WebsiteTypeSeeder extends Seeder
private function onTicketFooterLogo(): UploadedFile
{
$path = public_path('images/website_types/onticket/onticket_footer_logo.png');
$path = public_path('images/website_types/onticket_footer_logo.png');
if (! file_exists($path)) {
throw new RuntimeException("OnTicket footer logo not found at path: {$path}");
@@ -239,7 +238,7 @@ class WebsiteTypeSeeder extends Seeder
private function onTicketFavicon(): UploadedFile
{
$path = public_path('images/website_types/onticket/onticket_favicon.svg');
$path = public_path('images/website_types/onticket_favicon.svg');
if (! file_exists($path)) {
throw new RuntimeException("OnTicket favicon not found at path: {$path}");
@@ -253,30 +252,4 @@ class WebsiteTypeSeeder extends Seeder
true,
);
}
private function shopItLogo(): UploadedFile
{
return $this->uploadedImage('shopit', 'shopit_logo.png', 'image/png');
}
private function shopItFooterLogo(): UploadedFile
{
return $this->uploadedImage('shopit', 'shopit_footer_logo.png', 'image/png');
}
private function shopItFavicon(): UploadedFile
{
return $this->uploadedImage('shopit', 'shopit-favicon.svg', 'image/svg+xml');
}
private function uploadedImage(string $websiteType, string $filename, string $mimeType): UploadedFile
{
$path = public_path("images/website_types/{$websiteType}/{$filename}");
if (! file_exists($path)) {
throw new RuntimeException("Website type image not found at path: {$path}");
}
return new UploadedFile($path, $filename, $mimeType, null, true);
}
}

View File

Before

Width:  |  Height:  |  Size: 422 B

After

Width:  |  Height:  |  Size: 422 B

View File

Before

Width:  |  Height:  |  Size: 1.2 KiB

After

Width:  |  Height:  |  Size: 1.2 KiB

View File

Before

Width:  |  Height:  |  Size: 3.0 KiB

After

Width:  |  Height:  |  Size: 3.0 KiB

View File

@@ -1,10 +0,0 @@
<svg width="41" height="41" viewBox="0 0 41 41" fill="none" xmlns="http://www.w3.org/2000/svg" xmlns:se="http://svg-edit.googlecode.com" se:swatches="W3siaWQiOiJCMDBEREFFMy0zMjUwLTRERDgtOEU0RS0zMDYxREJGNUE3QTMiLCJuYW1lIjoiIzVCNUI1QiIsImhleCI6IiM1QjVCNUIifSx7ImlkIjoiRjI4QjU4NTYtNUM2OC00QkY4LTk3MDMtOTk5NDJCOTgzNTVBIiwibmFtZSI6IiMyRkQzQUMiLCJoZXgiOiIjMkZEM0FDIn1d">
<g><se:title>Layer 1</se:title><path d="m16.32,27.13c2.29,0 3.13,-0.37 3.73,-0.76c0.65,-0.42 1.17,-1.06 1.24,-1.97c0.06,-0.76 -0.29,-1.4 -0.81,-1.78c-0.7,-0.5 -2.05,-0.81 -3.21,-1.05c-1.13,-0.24 -2.14,-0.6 -3.03,-1.22c-1.06,-0.73 -1.61,-1.47 -1.96,-2.52c-0.45,-1.32 -0.36,-3.12 -0.11,-4.02c0.43,-1.54 1.35,-2.86 2.59,-3.84001c1.6,-1.26 3.58,-2.01999 6.46,-2.17999c0.3,-0.02 0.71,-0.04 1.21,-0.04c0,0 0.16,0 0.21,0h13.3c-3.68,-4.71 -9.41,-7.75 -15.85,-7.75c-11.1,0 -20.09,9 -20.09,20.09c0,2.47 0.45,4.84 1.27,7.03h15.06l-0.01,0.01z" fill="#2FD3AC" id="svg_7"/><path d="m23.11,12.59c-0.65,0 -1.64,0.03 -1.95,0.07c-1.3,0.17 -2.25,0.55 -2.82,1.31c-0.3199,0.43 -0.48,0.99 -0.29,1.66c0.31,1.07 2.1501,1.44 3.4001,1.7c1.49,0.31 2.5599,0.57 3.5899,1.08c1.06,0.53 2.03,1.41 2.51,2.43c0.46,0.98 0.6001,1.96 0.5201,3.08c-0.11,1.56 -0.4701,2.72 -0.9901,3.69c-0.49,0.91 -1.32,1.87 -2.03,2.44c-0.74,0.59 -1.81,1.38 -3.15,1.83c-1.35,0.45 -3.1399,0.63 -5.2999,0.63h-12.30005c3.68,4.68 9.39005,7.68 15.80005,7.68c11.1,0 20.0899,-9 20.0899,-20.09c0,-2.65 -0.5199,-5.18 -1.4499,-7.5h-15.6201l-0.01,-0.01z" fill="#5B5B5B" id="svg_8"/></g></svg>

Before

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.1 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 KiB

View File

@@ -17,6 +17,7 @@ class UserAuthorizationRelationsTest extends TestCase
$this->assertTrue(Schema::hasColumns('users', [
'rol_codigo',
'tenant_codigo',
'event_id',
]));
}
@@ -28,5 +29,7 @@ class UserAuthorizationRelationsTest extends TestCase
$this->assertNull($user->tenant_codigo);
$this->assertSame(RoleCode::User->value, $user->role->codigo);
$this->assertNull($user->tenant);
$this->assertNull($user->event_id);
$this->assertNull($user->event);
}
}

View File

@@ -0,0 +1,76 @@
<?php
namespace Tests\Feature\Menu;
use App\Domains\Core\Auth\Models\User;
use App\Http\Middleware\EnsureTenantHasMenu;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Route;
use Illuminate\Support\Facades\Schema;
use PHPUnit\Framework\Attributes\DataProvider;
use Symfony\Component\HttpKernel\Exception\HttpException;
use Tests\TestCase;
class TicketMenuAccessTest extends TestCase
{
public static function menuAssignments(): array
{
return [
'new code' => ['onticket.adminapp.tickets', 'current', false],
'old code' => ['adminapp.tickets', 'current', true],
'another tenant' => ['adminapp.tickets', 'other', false],
'unrelated menu' => ['adminapp.ventas', 'current', false],
];
}
#[DataProvider('menuAssignments')]
public function test_ticket_menu_requires_an_association_with_the_authenticated_tenant(string $menuCode, string $assignedTenant, bool $allowed): void
{
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo');
});
Schema::create('menues', function (Blueprint $table): void {
$table->id();
$table->string('code');
});
Schema::create('tenants_menues', function (Blueprint $table): void {
$table->string('tenant_code');
$table->string('menu_code');
});
DB::table('tenants')->insert(['codigo' => 'current']);
DB::table('menues')->insert(['code' => $menuCode]);
DB::table('tenants_menues')->insert(['tenant_code' => $assignedTenant, 'menu_code' => $menuCode]);
$user = new User(['tenant_codigo' => 'current']);
$request = Request::create('/api/v1/adminapp/tenant/tickets');
$request->setUserResolver(fn () => $user);
if (! $allowed) {
$this->expectException(HttpException::class);
$this->expectExceptionCode(0);
}
try {
$response = (new EnsureTenantHasMenu)->handle($request, fn () => response('allowed'), 'adminapp.tickets');
$this->assertSame('allowed', $response->getContent());
} catch (HttpException $exception) {
$this->assertSame(404, $exception->getStatusCode());
throw $exception;
}
}
public function test_all_ticket_routes_and_filter_form_use_the_updated_menu_codes(): void
{
foreach ([
'adminapp.tickets.index', 'adminapp.tickets.cancel',
'adminapp.tickets.calculate-refund', 'adminapp.tickets.refund',
'adminapp.tickets.pdf', 'adminapp.tickets.excel', 'adminapp.forms.tickets-filter',
] as $name) {
$route = Route::getRoutes()->getByName($name);
$this->assertNotNull($route);
$this->assertContains('tenant.menu:adminapp.tickets', $route->gatherMiddleware());
}
}
}

View File

@@ -0,0 +1,57 @@
<?php
namespace Tests\Feature\Migrations;
use App\Domains\Core\Administrator\Resources\AdministratorResource;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Resources\UserResource;
use Illuminate\Database\QueryException;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Tests\TestCase;
class AddEventIdToUsersTest extends TestCase
{
public function test_event_assignment_preserves_existing_users_and_restricts_event_deletion(): void
{
Schema::create('events', function (Blueprint $table): void {
$table->id();
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->string('tenant_codigo')->nullable();
$table->softDeletes();
$table->timestamps();
});
DB::table('users')->insert(['id' => 1, 'tenant_codigo' => 'legacy']);
DB::table('events')->insert(['id' => 42]);
$migration = require database_path('migrations/2026_10_01_000000_add_event_id_to_users_table.php');
$migration->up();
$legacy = User::query()->findOrFail(1);
$this->assertNull($legacy->event_id);
$this->assertNull($legacy->event);
$this->assertSame('legacy', $legacy->tenant_codigo);
$legacy->update(['event_id' => '42']);
$user = $legacy->fresh();
$this->assertSame(42, $user->event_id);
$this->assertSame(42, $user->event->id);
$this->assertSame(42, UserResource::make($user)->resolve(new Request)['event_id']);
$this->assertSame(42, AdministratorResource::make($user)->resolve(new Request)['event_id']);
try {
DB::table('events')->where('id', 42)->delete();
$this->fail('An assigned event must not be deleted.');
} catch (QueryException $exception) {
$this->assertStringContainsString('FOREIGN KEY', $exception->getMessage());
}
$migration->down();
$this->assertFalse(Schema::hasColumn('users', 'event_id'));
$this->assertSame('legacy', DB::table('users')->where('id', 1)->value('tenant_codigo'));
}
}

View File

@@ -34,7 +34,7 @@ class SetWebsiteTypeFaviconTest extends TestCase
$this->assertSame(1, DB::table('attachments')->where('filename', 'onticket_favicon.svg')->count());
Storage::disk('s3')->assertExists($attachment->path);
$this->assertSame(
file_get_contents(public_path('images/website_types/onticket/onticket_favicon.svg')),
file_get_contents(public_path('images/website_types/onticket_favicon.svg')),
Storage::disk('s3')->get($attachment->path),
);
}

View File

@@ -0,0 +1,183 @@
<?php
namespace Tests\Feature\Sale;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Commerce\Purchase\Services\CheckoutService;
use App\Domains\Commerce\Sale\Services\AdminAppSaleExcelService;
use App\Domains\Commerce\Sale\Services\AdminAppSalePdfService;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Authorization\Enums\RoleCode;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Laravel\Sanctum\Sanctum;
use Mockery\MockInterface;
use Symfony\Component\HttpFoundation\StreamedResponse;
use Tests\TestCase;
class AdminAppSaleEventScopeTest extends TestCase
{
protected function setUp(): void
{
parent::setUp();
// Isolated schema: the full legacy migration chain cannot run on SQLite.
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo');
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->softDeletes();
});
Schema::create('compras', function (Blueprint $table): void {
$table->id();
$table->string('tenant_codigo');
$table->unsignedBigInteger('event_id')->nullable();
$table->string('nombre_apellido');
$table->string('status');
$table->decimal('total', 12, 2);
$table->timestamps();
});
Schema::create('compra_items', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('compra_id');
$table->integer('cantidad');
});
Schema::create('tickets', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('source_purchase_item_id');
});
Schema::create('ticket_refunds', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('purchase_item_id');
$table->decimal('amount', 12, 2);
});
Schema::create('value_changes', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('trackable_type');
$table->unsignedBigInteger('trackable_id');
$table->string('attribute');
$table->string('old_value');
$table->string('new_value');
$table->timestamp('changed_at');
$table->string('actor_type');
$table->unsignedBigInteger('user_id')->nullable();
});
DB::table('tenants')->insert(['codigo' => 'onticket']);
foreach ([1 => ['onticket', 10], 2 => ['onticket', 20], 3 => ['onticket', null], 4 => ['other', 10]] as $id => [$tenant, $event]) {
DB::table('compras')->insert([
'id' => $id,
'tenant_codigo' => $tenant,
'event_id' => $event,
'nombre_apellido' => 'Cliente',
'status' => Purchase::STATUS_PAID,
'total' => $id * 100,
'created_at' => now(),
'updated_at' => now(),
]);
DB::table('compra_items')->insert(['id' => $id, 'compra_id' => $id, 'cantidad' => 1]);
DB::table('ticket_refunds')->insert(['purchase_item_id' => $id, 'amount' => $id * 10]);
DB::table('value_changes')->insert([
'id' => $id,
'tenant_code' => $tenant,
'trackable_type' => (new Purchase)->getMorphClass(),
'trackable_id' => $id,
'attribute' => 'status',
'old_value' => Purchase::STATUS_PENDING_PAYMENT,
'new_value' => Purchase::STATUS_PAID,
'changed_at' => now(),
'actor_type' => 'system',
]);
}
$this->actingAsAdministrator(10);
}
public function test_list_totals_and_filters_cannot_escape_the_authenticated_event(): void
{
$this->getJson('/api/v1/adminapp/tenant/sales?event_id=20&q=Cliente')
->assertOk()
->assertJsonCount(1, 'data')
->assertJsonPath('data.0.id', 1)
->assertJsonPath('confirmed_sales_total', '100.00')
->assertJsonPath('refunded_total', '10.00');
$this->getJson('/api/v1/adminapp/tenant/sales?id=2')->assertOk()->assertJsonCount(0, 'data');
$this->getJson('/api/v1/adminapp/tenant/sales/modifications?q=Cliente')
->assertOk()->assertJsonCount(1, 'data')->assertJsonPath('data.0.sale_id', 1);
}
public function test_unscoped_administrators_keep_access_to_all_sales_in_their_tenant(): void
{
$this->actingAsAdministrator(null);
$this->getJson('/api/v1/adminapp/tenant/sales')->assertOk()->assertJsonCount(3, 'data')
->assertJsonPath('confirmed_sales_total', '600.00')->assertJsonPath('refunded_total', '60.00');
$this->getJson('/api/v1/adminapp/tenant/sales/modifications')->assertOk()->assertJsonCount(3, 'data');
$this->getJson('/api/v1/adminapp/tenant/sales/2')->assertOk();
$this->getJson('/api/v1/adminapp/tenant/sales/3')->assertOk();
}
public function test_foreign_and_unassigned_sales_are_inaccessible_before_any_checkout_action(): void
{
$this->mock(CheckoutService::class, function (MockInterface $mock): void {
$mock->shouldNotReceive('confirmPaidPurchase');
$mock->shouldNotReceive('cancelPurchaseFromAdmin');
});
foreach ([2, 3, 4] as $id) {
$this->getJson("/api/v1/adminapp/tenant/sales/{$id}")->assertNotFound();
$this->getJson("/api/v1/adminapp/tenant/sales/{$id}/tickets")->assertNotFound();
$this->postJson("/api/v1/adminapp/tenant/sales/{$id}/confirm", ['event_id' => 20])->assertNotFound();
$this->postJson("/api/v1/adminapp/tenant/sales/{$id}/cancel", ['event_id' => 20])->assertNotFound();
}
$this->assertSame(Purchase::STATUS_PAID, DB::table('compras')->where('id', 2)->value('status'));
}
public function test_own_event_allows_detail_tickets_and_checkout_actions(): void
{
// Empty snapshots keep this fixture focused on authorization.
DB::table('compra_items')->where('compra_id', 1)->delete();
$this->mock(CheckoutService::class, function (MockInterface $mock): void {
foreach (['confirmPaidPurchase', 'cancelPurchaseFromAdmin'] as $method) {
$mock->shouldReceive($method)->once()->withArgs(fn (Purchase $sale): bool => $sale->id === 1)
->andReturnUsing(fn (Purchase $sale): Purchase => $sale);
}
});
$this->getJson('/api/v1/adminapp/tenant/sales/1')->assertOk()->assertJsonPath('data.id', 1);
$this->getJson('/api/v1/adminapp/tenant/sales/1/tickets')->assertOk();
$this->postJson('/api/v1/adminapp/tenant/sales/1/confirm')->assertOk()->assertJsonPath('data.id', 1);
$this->postJson('/api/v1/adminapp/tenant/sales/1/cancel')->assertOk()->assertJsonPath('data.id', 1);
}
public function test_pdf_and_excel_exports_only_receive_sales_and_history_for_the_own_event(): void
{
foreach ([AdminAppSalePdfService::class, AdminAppSaleExcelService::class] as $class) {
$this->mock($class, function (MockInterface $mock) use ($class): void {
foreach (['downloadSales', 'downloadModifications'] as $method) {
$mock->shouldReceive($method)->once()->withArgs(
fn ($tenant, Collection $rows, $timezone): bool => $tenant->codigo === 'onticket'
&& $rows->pluck('id')->all() === [1] && $timezone === 'UTC'
)->andReturn($class === AdminAppSalePdfService::class
? response('pdf') : new StreamedResponse(fn () => print ('excel')));
}
});
}
foreach (['pdf', 'excel', 'modifications/pdf', 'modifications/excel'] as $path) {
$this->getJson("/api/v1/adminapp/tenant/sales/{$path}?timezone=UTC&event_id=20")->assertOk();
}
}
private function actingAsAdministrator(?int $eventId): void
{
$user = new User;
$user->setRawAttributes([
'id' => 1,
'rol_codigo' => RoleCode::AdminApp->value,
'tenant_codigo' => 'onticket',
'event_id' => $eventId,
]);
Sanctum::actingAs($user);
}
}

View File

@@ -23,7 +23,7 @@ class WebsiteTypeSeederTest extends TestCase
$this->assertSame(2, AdminWebsiteType::query()->count());
$this->assertSame(3, StorefrontWebsiteType::query()->count());
$this->assertSame(6, Attachment::query()->count());
$this->assertSame(5, Attachment::query()->count());
$expectedPresentation = [
'primary_color' => '#FF7006',
@@ -45,15 +45,12 @@ class WebsiteTypeSeederTest extends TestCase
$this->assertSame('ShopIt', $shopIt->nombre);
$this->assertSame('localhost', $shopIt->dominio);
$this->assertSame('scanner.localhost', $shopIt->scanner_domain);
$this->assertSame(
[...$expectedPresentation, 'primary_color' => '#2FD3AC'],
$shopIt->only(array_keys($expectedPresentation)),
);
$this->assertSame('shopit_logo.png', $shopIt->siteLogo->filename);
$this->assertSame($expectedPresentation, $shopIt->only(array_keys($expectedPresentation)));
$this->assertSame('onticket_logo.png', $shopIt->siteLogo->filename);
Storage::disk('s3')->assertExists($shopIt->siteLogo->path);
$this->assertSame('shopit_footer_logo.png', $shopIt->footerLogo->filename);
$this->assertSame('onticket_footer_logo.png', $shopIt->footerLogo->filename);
Storage::disk('s3')->assertExists($shopIt->footerLogo->path);
$this->assertSame('shopit-favicon.svg', $shopIt->favicon->filename);
$this->assertSame('onticket_favicon.svg', $shopIt->favicon->filename);
Storage::disk('s3')->assertExists($shopIt->favicon->path);
$shopItStorefront = StorefrontWebsiteType::query()->where('codigo', 'shopit')->with('extras')->sole();
$this->assertSame('standard', $shopItStorefront->header_type);
@@ -87,7 +84,7 @@ class WebsiteTypeSeederTest extends TestCase
Storage::disk('s3')->assertExists($onTicket->footerLogo->path);
$this->assertNotSame($shopIt->site_logo, $onTicket->site_logo);
$this->assertNotSame($shopIt->footer_logo, $onTicket->footer_logo);
$this->assertNotSame($shopIt->favicon_id, $onTicket->favicon_id);
$this->assertSame($shopIt->favicon_id, $onTicket->favicon_id);
$this->assertSame('onticket_favicon.svg', $onTicket->favicon->filename);
$onTicketStorefront = StorefrontWebsiteType::query()->where('codigo', 'onticket')->with('extras')->sole();
$this->assertSame('standard', $onTicketStorefront->header_type);

View File

@@ -0,0 +1,158 @@
<?php
namespace Tests\Feature\Staff;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\ResetPasswordAttemptService;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Laravel\Sanctum\Sanctum;
use Mockery\MockInterface;
use Tests\TestCase;
class StaffEventScopeTest extends TestCase
{
protected function setUp(): void
{
parent::setUp();
// Exercise HTTP authorization on SQLite without the incompatible legacy migrations.
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo');
$table->boolean('scanner_category_validation_enabled')->default(false);
});
Schema::create('roles', function (Blueprint $table): void {
$table->id();
$table->string('codigo');
$table->string('nombre');
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->string('rol_codigo');
$table->string('tenant_codigo');
$table->unsignedBigInteger('event_id')->nullable();
$table->string('nombre_apellido');
$table->string('dni');
$table->string('email');
$table->string('active_email')->nullable();
$table->string('password')->nullable();
$table->timestamps();
$table->softDeletes();
});
Schema::create('categorias', function (Blueprint $table): void {
$table->id();
$table->string('nombre');
$table->string('tenant_code')->nullable();
$table->unsignedBigInteger('categoria_id')->nullable();
});
Schema::create('catalog_items', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('category_id');
$table->string('tenant_code');
$table->softDeletes();
});
Schema::create('category_scanners', function (Blueprint $table): void {
$table->unsignedBigInteger('user_id');
$table->unsignedBigInteger('categoria_id');
$table->timestamps();
});
Schema::create('personal_access_tokens', function (Blueprint $table): void {
$table->id();
$table->string('tokenable_type');
$table->unsignedBigInteger('tokenable_id');
});
DB::table('tenants')->insert(['codigo' => 'onticket']);
foreach (['adminapp', 'scanner'] as $role) {
DB::table('roles')->insert(['codigo' => $role, 'nombre' => $role]);
foreach ([10, 20, null] as $eventId) {
$this->insertUser($role, 'onticket', $eventId);
}
$this->insertUser($role, 'other', 10);
}
Sanctum::actingAs(User::query()->findOrFail(1));
}
public function test_lists_and_searches_are_restricted_to_the_authenticated_event(): void
{
foreach (['administrators' => 1, 'staff' => 5] as $path => $id) {
foreach (['', '?search=Persona&event_id=20'] as $query) {
$this->getJson("/api/v1/adminapp/tenant/{$path}{$query}")
->assertOk()->assertJsonCount(1, 'data')
->assertJsonPath('data.0.id', $id)->assertJsonPath('data.0.event_id', 10);
}
}
}
public function test_creation_inherits_the_actor_event_even_if_the_client_supplies_another(): void
{
$this->mock(ResetPasswordAttemptService::class, function (MockInterface $mock): void {
$mock->shouldReceive('createForAdminAppEmail')->once();
$mock->shouldReceive('createForScannerEmail')->once();
});
foreach (['administrators' => 'adminapp', 'staff' => 'scanner'] as $path => $role) {
$this->postJson("/api/v1/adminapp/tenant/{$path}", [
...$this->payload("new-{$role}@example.com"), 'event_id' => 20,
])->assertSuccessful()->assertJsonPath('data.event_id', 10);
$this->assertDatabaseHas('users', ['email' => "new-{$role}@example.com", 'event_id' => 10, 'rol_codigo' => $role]);
}
}
public function test_foreign_and_unassigned_staff_cannot_be_edited_deleted_or_inspected(): void
{
foreach (['administrators' => [2, 3, 4], 'staff' => [6, 7, 8]] as $path => $ids) {
foreach ($ids as $id) {
$this->putJson("/api/v1/adminapp/tenant/{$path}/{$id}", $this->payload("update-{$id}@example.com"))->assertNotFound();
$this->deleteJson("/api/v1/adminapp/tenant/{$path}/{$id}")->assertNotFound();
$this->assertDatabaseHas('users', ['id' => $id, 'deleted_at' => null, 'email' => "person-{$id}@example.com"]);
if ($path === 'staff') {
$this->getJson("/api/v1/adminapp/tenant/staff/{$id}/scan-attempts")->assertNotFound();
}
}
}
}
public function test_own_staff_can_be_edited_and_deleted_without_changing_its_event(): void
{
$adminId = $this->insertUser('adminapp', 'onticket', 10);
foreach (['administrators' => $adminId, 'staff' => 5] as $path => $id) {
$this->putJson("/api/v1/adminapp/tenant/{$path}/{$id}", [
...$this->payload("updated-{$id}@example.com"), 'event_id' => 20,
])->assertOk()->assertJsonPath('data.event_id', 10);
$this->deleteJson("/api/v1/adminapp/tenant/{$path}/{$id}")->assertNoContent();
$this->assertSoftDeleted('users', ['id' => $id]);
}
}
public function test_unscoped_actor_keeps_tenant_lists_and_creates_without_an_event(): void
{
Sanctum::actingAs(User::query()->findOrFail(3));
$this->mock(ResetPasswordAttemptService::class, function (MockInterface $mock): void {
$mock->shouldReceive('createForAdminAppEmail')->once();
$mock->shouldReceive('createForScannerEmail')->once();
});
foreach (['administrators', 'staff'] as $path) {
$this->getJson("/api/v1/adminapp/tenant/{$path}")->assertOk()->assertJsonCount(3, 'data');
$this->postJson("/api/v1/adminapp/tenant/{$path}", $this->payload("legacy-{$path}@example.com"))
->assertSuccessful()->assertJsonPath('data.event_id', null);
}
}
private function insertUser(string $role, string $tenant, ?int $eventId): int
{
$id = DB::table('users')->count() + 1;
return DB::table('users')->insertGetId([
'id' => $id, 'rol_codigo' => $role, 'tenant_codigo' => $tenant,
'event_id' => $eventId, 'nombre_apellido' => 'Persona', 'dni' => '12345678',
'email' => "person-{$id}@example.com", 'active_email' => "person-{$id}@example.com",
]);
}
private function payload(string $email): array
{
return ['nombre_apellido' => 'Persona editada', 'dni' => '87654321', 'email' => $email];
}
}

View File

@@ -0,0 +1,178 @@
<?php
namespace Tests\Feature\Ticket;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketExcelService;
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketPdfService;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Laravel\Sanctum\Sanctum;
use Mockery\MockInterface;
use Symfony\Component\HttpFoundation\StreamedResponse;
use Tests\TestCase;
class AdminAppTicketEventScopeTest extends TestCase
{
protected function setUp(): void
{
parent::setUp();
// Keep HTTP tests isolated from legacy migrations incompatible with SQLite.
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo');
$table->string('timezone')->default('UTC');
$table->boolean('allow_ticket_refund')->default(false);
$table->boolean('allow_ticket_total_refund')->default(false);
$table->boolean('allow_ticket_partial_refund')->default(false);
});
Schema::create('menues', function (Blueprint $table): void {
$table->id();
$table->string('code');
});
Schema::create('tenants_menues', function (Blueprint $table): void {
$table->string('tenant_code');
$table->string('menu_code');
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->string('nombre_apellido');
$table->softDeletes();
});
Schema::create('tickets', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->unsignedBigInteger('event_id')->nullable();
$table->string('ticket');
foreach (['source_variant_id', 'source_catalog_item_id', 'source_purchase_item_id', 'scanner_user_id', 'user_id'] as $column) {
$table->unsignedBigInteger($column)->nullable();
}
foreach (['used_at', 'disabled_at', 'cancelled_at', 'refunded_at'] as $column) {
$table->timestamp($column)->nullable();
}
$table->timestamps();
});
Schema::create('compras', function (Blueprint $table): void {
$table->id();
$table->string('tenant_codigo');
$table->unsignedBigInteger('event_id')->nullable();
$table->string('nombre_apellido');
});
Schema::create('compra_items', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('compra_id');
$table->decimal('precio_unitario', 12, 2);
});
Schema::create('ticket_refunds', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('ticket_id')->nullable();
$table->unsignedBigInteger('purchase_item_id');
$table->decimal('amount', 12, 2);
});
Schema::create('desfile_entry_reservations', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('ticket_id');
$table->softDeletes();
});
Schema::create('value_changes', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('trackable_type');
$table->unsignedBigInteger('trackable_id');
$table->string('attribute');
$table->string('old_value')->nullable();
$table->string('new_value')->nullable();
$table->timestamp('changed_at');
$table->string('actor_type');
$table->unsignedBigInteger('user_id')->nullable();
});
DB::table('tenants')->insert(['codigo' => 'onticket']);
DB::table('menues')->insert(['code' => 'adminapp.tickets']);
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => 'adminapp.tickets']);
foreach ([1 => ['onticket', 10], 2 => ['onticket', 20], 3 => ['onticket', null], 4 => ['other', 10]] as $id => [$tenant, $event]) {
DB::table('tickets')->insert([
'id' => $id, 'tenant_code' => $tenant, 'event_id' => $event,
'ticket' => "ticket-{$id}", 'used_at' => now(),
]);
DB::table('compras')->insert(['id' => $id, 'tenant_codigo' => $tenant, 'event_id' => $event, 'nombre_apellido' => 'Cliente']);
DB::table('compra_items')->insert(['id' => $id, 'compra_id' => $id, 'precio_unitario' => 100]);
DB::table('ticket_refunds')->insert(['purchase_item_id' => $id, 'amount' => $id * 10]);
}
$this->actingAsAdmin(10);
}
public function test_list_counts_refunded_total_and_search_cannot_escape_the_user_event(): void
{
$this->getJson('/api/v1/adminapp/tenant/tickets?sort_by=id&event_id=20')
->assertOk()->assertJsonCount(1, 'data')->assertJsonPath('data.0.id', 1)
->assertJsonPath('scanned_tickets', 1)->assertJsonPath('total_tickets', 1)
->assertJsonPath('refunded_total', '10.00');
$this->getJson('/api/v1/adminapp/tenant/tickets?q=2')->assertOk()->assertJsonCount(0, 'data');
// Status uses sorting in memory rather than the database.
$this->getJson('/api/v1/adminapp/tenant/tickets?sort_by=status')
->assertOk()->assertJsonCount(1, 'data')->assertJsonPath('data.0.id', 1);
DB::table('tickets')->where('id', 1)->update(['used_at' => null]);
$this->getJson('/api/v1/adminapp/tenant/tickets?status=active')
->assertOk()->assertJsonCount(1, 'data')
->assertJsonPath('scanned_tickets', 0)->assertJsonPath('total_tickets', 1);
}
public function test_foreign_unassigned_and_other_tenant_tickets_cannot_be_modified_or_refunded(): void
{
foreach ([2, 3, 4] as $id) {
$this->postJson("/api/v1/adminapp/tenant/tickets/{$id}/cancel", ['event_id' => 20])->assertNotFound();
$this->getJson("/api/v1/adminapp/tenant/tickets/{$id}/refund")->assertNotFound();
$this->postJson("/api/v1/adminapp/tenant/tickets/{$id}/refund", ['refund_type' => 'total', 'event_id' => 20])->assertNotFound();
$this->assertDatabaseHas('tickets', ['id' => $id, 'cancelled_at' => null, 'refunded_at' => null]);
}
$this->assertDatabaseCount('value_changes', 0);
$this->assertDatabaseCount('ticket_refunds', 4);
}
public function test_own_ticket_can_be_cancelled_and_refund_requests_reach_business_validation(): void
{
DB::table('tickets')->where('id', 1)->update(['used_at' => null]);
$this->getJson('/api/v1/adminapp/tenant/tickets/1/refund')->assertUnprocessable();
$this->postJson('/api/v1/adminapp/tenant/tickets/1/refund', ['refund_type' => 'total'])->assertUnprocessable();
$this->postJson('/api/v1/adminapp/tenant/tickets/1/cancel')->assertOk();
$this->assertNotNull(DB::table('tickets')->where('id', 1)->value('cancelled_at'));
}
public function test_unscoped_admin_keeps_the_tenant_scope(): void
{
$this->actingAsAdmin(null);
$this->getJson('/api/v1/adminapp/tenant/tickets?sort_by=id')
->assertOk()->assertJsonCount(3, 'data')->assertJsonPath('total_tickets', 3)
->assertJsonPath('refunded_total', '60.00');
DB::table('tickets')->where('id', 3)->update(['used_at' => null]);
$this->postJson('/api/v1/adminapp/tenant/tickets/3/cancel')->assertOk();
$this->postJson('/api/v1/adminapp/tenant/tickets/4/cancel')->assertNotFound();
}
public function test_pdf_and_excel_receive_only_the_tickets_of_the_user_event(): void
{
foreach ([AdminAppTicketPdfService::class, AdminAppTicketExcelService::class] as $class) {
$this->mock($class, function (MockInterface $mock) use ($class): void {
$mock->shouldReceive('download')->once()->withArgs(
fn ($tenant, Collection $tickets, $timezone): bool => $tenant->codigo === 'onticket'
&& $tickets->pluck('id')->all() === [1] && $timezone === 'UTC'
)->andReturn($class === AdminAppTicketPdfService::class
? response('pdf') : new StreamedResponse(fn () => print ('excel')));
});
}
foreach (['pdf', 'excel'] as $format) {
$this->getJson("/api/v1/adminapp/tenant/tickets/{$format}?timezone=UTC&event_id=20")->assertOk();
}
}
private function actingAsAdmin(?int $eventId): void
{
$user = new User;
$user->setRawAttributes(['id' => 1, 'rol_codigo' => 'adminapp', 'tenant_codigo' => 'onticket', 'event_id' => $eventId]);
Sanctum::actingAs($user);
}
}