seed(AuthorizationSeeder::class); WebsiteType::query()->create(['codigo' => 'onticket', 'nombre' => 'OnTicket']); } public function test_authentication_is_required_to_read_a_sale_detail(): void { $this->getJson('/api/v1/adminapp/tenant/sales/1')->assertUnauthorized(); } public function test_an_adminapp_user_can_read_a_sale_detail_from_its_tenant(): void { $tenant = $this->createTenant('acme'); Sanctum::actingAs($this->createAdminAppUser($tenant)); $purchase = Purchase::query()->create([ 'tenant_codigo' => $tenant->codigo, 'status' => Purchase::STATUS_PAID, 'total' => '40000.00', 'nombre_apellido' => 'Ada Lovelace', ]); PurchaseItem::query()->create([ 'compra_id' => $purchase->id, 'source_catalog_item_id' => 10, 'nombre' => 'Comida', 'item_nombre' => 'Comida', 'variant_attributes' => [ ['name' => 'Fecha', 'value' => ['2026-10-12']], ['name' => 'Servicio', 'value' => 'Almuerzo'], ], 'cantidad' => 2, 'precio_unitario' => '10000.00', 'total' => '20000.00', ]); $this->getJson("/api/v1/adminapp/tenant/sales/{$purchase->id}") ->assertOk() ->assertJsonPath('data.id', $purchase->id) ->assertJsonPath('data.items.0.product', 'Comida') ->assertJsonPath('data.items.0.event_dates.0', '2026-10-12') ->assertJsonPath('data.items.0.quantity', 2) ->assertJsonPath('data.items.0.unit_price', '10000.00') ->assertJsonPath('data.items.0.total', '20000.00') ->assertJsonPath('data.total', '40000.00'); } public function test_an_adminapp_user_cannot_read_a_sale_from_another_tenant(): void { $tenant = $this->createTenant('acme'); $otherTenant = $this->createTenant('other'); Sanctum::actingAs($this->createAdminAppUser($tenant)); $foreignPurchase = Purchase::query()->create([ 'tenant_codigo' => $otherTenant->codigo, 'status' => Purchase::STATUS_PAID, 'total' => '10000.00', ]); $this->getJson("/api/v1/adminapp/tenant/sales/{$foreignPurchase->id}") ->assertNotFound(); } private function createTenant(string $code): Tenant { return Tenant::query()->create([ 'codigo' => $code, 'nombre' => ucfirst($code), 'dominio' => "{$code}.test", 'website_type_code' => 'onticket', ]); } private function createAdminAppUser(Tenant $tenant): User { return User::factory()->create([ 'rol_codigo' => RoleCode::AdminApp->value, 'tenant_codigo' => $tenant->codigo, ]); } }