id(); $table->string('codigo')->unique(); $table->string('nombre'); $table->string('dominio'); $table->string('search_product_layout')->default('column_with_image'); $table->string('search_group_layout')->default('paginated'); }); Schema::create('events', function (Blueprint $table): void { $table->id(); $table->string('tenant_code'); $table->string('title'); $table->timestamps(); }); Schema::create('users', function (Blueprint $table): void { $table->id(); $table->string('nombre_apellido'); $table->string('email'); $table->string('active_email')->virtualAs('CASE WHEN deleted_at IS NULL THEN lower(email) ELSE NULL END'); $table->string('password'); $table->string('rol_codigo')->default('user'); $table->string('tenant_codigo')->nullable(); $table->softDeletes(); $table->timestamps(); $table->unique(['active_email', 'rol_codigo']); }); Schema::create('menues', function (Blueprint $table): void { $table->id(); $table->string('code')->unique(); $table->string('label'); $table->string('route'); $table->string('parent_menu_code')->nullable(); $table->string('content_type')->default('dynamic'); }); Schema::create('roles_menues', function (Blueprint $table): void { $table->string('rol_codigo'); $table->string('menu_codigo'); }); Schema::create('tenants_menues', function (Blueprint $table): void { $table->string('tenant_code'); $table->string('menu_code'); $table->json('static_content')->nullable(); $table->timestamps(); }); foreach ([ '2026_06_18_130006_create_personal_access_tokens_table.php', '2026_07_28_000000_create_roles_and_permissions_tables.php', '2026_07_29_000000_add_login_security_fields_to_users_table.php', '2026_07_29_000100_create_login_attempts_table.php', ] as $file) { (require database_path('migrations/'.$file))->up(); } DB::table('roles')->insert(['codigo' => 'adminapp', 'nombre' => 'AdminApp']); DB::table('tenants')->insert([ ['codigo' => 'onticket', 'nombre' => 'OnTicket', 'dominio' => 'onticket.test'], ['codigo' => 'other', 'nombre' => 'Other', 'dominio' => 'other.test'], ]); DB::table('events')->insert([ ['id' => 1, 'tenant_code' => 'onticket', 'title' => 'Evento A'], ['id' => 2, 'tenant_code' => 'onticket', 'title' => 'Evento B'], ['id' => 3, 'tenant_code' => 'other', 'title' => 'Evento ajeno'], ]); // An existing administrator must remain general after applying the new migration. DB::table('users')->insert([ 'id' => 1, 'nombre_apellido' => 'Admin', 'email' => 'admin@example.test', 'password' => Hash::make('secret123'), 'rol_codigo' => 'adminapp', 'tenant_codigo' => 'onticket', ]); $this->scopeMigration()->up(); $this->user = User::query()->findOrFail(1); $this->createOperationsSchema(); DB::table('menues')->insert([ ['code' => 'main.adminapp', 'label' => 'Administración', 'route' => '/', 'parent_menu_code' => null], ['code' => 'adminapp.ventas', 'label' => 'Ventas', 'route' => '/admin/ventas', 'parent_menu_code' => 'main.adminapp'], ]); foreach (['main.adminapp', 'adminapp.ventas'] as $code) { DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]); DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]); } } private function scopeMigration(): Migration { return require database_path('migrations/2026_09_30_000000_add_admin_scope_to_users.php'); } private function login(array $extra = []): TestResponse { return $this->postJson('/api/v1/adminapp/login', [ 'email' => ' ADMIN@EXAMPLE.TEST ', 'password' => 'secret123', ...$extra, ]); } private function createOperationsSchema(): void { Schema::table('tenants', function (Blueprint $table): void { $table->unsignedBigInteger('active_event_id')->nullable(); $table->boolean('scanner_category_validation_enabled')->default(false); $table->boolean('allow_ticket_refund')->default(true); $table->boolean('allow_ticket_total_refund')->default(true); $table->boolean('allow_ticket_partial_refund')->default(true); $table->decimal('ticket_partial_refund_percentage')->default(25); }); Schema::table('users', fn (Blueprint $table) => $table->string('dni')->nullable()); Schema::table('events', function (Blueprint $table): void { $table->string('location')->nullable(); $table->string('date_text')->nullable(); }); (require database_path('migrations/2026_09_30_000200_add_refund_configuration_to_events.php'))->up(); DB::table('tenants')->where('codigo', 'onticket')->update(['active_event_id' => 2]); Schema::create('social_media', function (Blueprint $table): void { $table->id(); $table->string('code')->unique(); $table->string('nombre'); }); Schema::create('event_social_media', function (Blueprint $table): void { $table->unsignedBigInteger('event_id'); $table->string('social_media_code'); $table->string('url'); $table->integer('orden'); $table->timestamps(); }); Schema::create('event_dates', function (Blueprint $table): void { $table->id(); $table->string('tenant_code'); $table->unsignedBigInteger('event_id'); $table->date('date'); $table->time('time_start'); $table->time('time_end'); $table->unsignedBigInteger('validity_time_id')->nullable(); $table->unsignedBigInteger('rescheduled_to_event_date_id')->nullable(); $table->timestamp('suspended_at')->nullable(); }); Schema::create('validity_times', function (Blueprint $table): void { $table->id(); $table->string('type'); $table->time('start_time')->nullable(); $table->time('end_time')->nullable(); $table->timestamp('fixed_starts_at')->nullable(); $table->timestamp('fixed_expires_at')->nullable(); $table->timestamps(); }); Schema::create('categorias', function (Blueprint $table): void { $table->id(); $table->string('tenant_code')->nullable(); $table->unsignedBigInteger('categoria_id')->nullable(); $table->string('nombre'); }); Schema::create('category_scanners', function (Blueprint $table): void { $table->unsignedBigInteger('user_id'); $table->unsignedBigInteger('categoria_id'); $table->timestamps(); }); Schema::create('catalog_items', function (Blueprint $table): void { $table->id(); $table->string('tenant_code'); $table->unsignedBigInteger('event_id'); $table->unsignedBigInteger('category_id')->nullable(); $table->string('nombre'); $table->string('slug'); $table->text('descripcion')->nullable(); $table->decimal('precio')->default(0); $table->string('type')->default('standard'); $table->string('inventory_policy')->default('tracked'); $table->string('inventory_subject')->default('product'); $table->integer('group_order')->default(0); $table->boolean('has_tickets')->default(false); $table->softDeletes(); }); Schema::create('compras', function (Blueprint $table): void { $table->id(); $table->string('tenant_codigo'); $table->unsignedBigInteger('event_id'); $table->string('status'); $table->decimal('total'); $table->string('nombre_apellido'); $table->timestamps(); }); Schema::create('compra_items', function (Blueprint $table): void { $table->id(); $table->unsignedBigInteger('compra_id'); $table->integer('cantidad'); $table->string('item_nombre')->nullable(); $table->decimal('precio_unitario')->default(10); $table->decimal('total')->default(10); }); Schema::create('tickets', function (Blueprint $table): void { $table->id(); $table->string('tenant_code'); $table->unsignedBigInteger('event_id')->nullable(); $table->uuid('ticket'); foreach (['source_purchase_item_id', 'source_catalog_item_id', 'source_variant_id', 'scanner_user_id', 'user_id'] as $column) { $table->unsignedBigInteger($column)->nullable(); } foreach (['used_at', 'disabled_at', 'cancelled_at', 'refunded_at'] as $column) { $table->timestamp($column)->nullable(); } }); Schema::create('ticket_refunds', function (Blueprint $table): void { $table->id(); $table->unsignedBigInteger('purchase_item_id'); $table->decimal('amount'); }); Schema::create('scan_attempts', function (Blueprint $table): void { $table->id(); $table->string('tenant_code'); $table->unsignedBigInteger('scanner_user_id'); $table->unsignedBigInteger('ticket_id')->nullable(); $table->text('data')->nullable(); $table->string('result'); $table->timestamp('created_at')->nullable(); $table->timestamp('resolved_at')->nullable(); }); (require database_path('migrations/2026_09_30_000400_add_event_id_to_scan_attempts.php'))->up(); Schema::create('value_changes', function (Blueprint $table): void { $table->id(); $table->string('tenant_code'); $table->string('trackable_type'); $table->unsignedBigInteger('trackable_id'); $table->string('attribute'); $table->string('old_value')->nullable(); $table->string('new_value')->nullable(); $table->string('actor_type')->default('user'); $table->unsignedBigInteger('user_id')->nullable(); $table->timestamp('changed_at')->nullable(); }); DB::table('roles')->insert(['codigo' => 'scanner', 'nombre' => 'Scanner']); DB::table('permisos')->insert(['codigo' => 'tickets.escanear', 'nombre' => 'Escanear']); DB::table('roles_permisos')->insert(['rol_codigo' => 'scanner', 'codigo_permiso' => 'tickets.escanear']); foreach (['adminapp.catalog', 'adminapp.event', 'adminapp.staff', 'adminapp.inicio'] as $code) { DB::table('menues')->insert(['code' => $code, 'label' => $code, 'route' => '/admin/test', 'parent_menu_code' => 'main.adminapp']); DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]); DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]); } } private function actingEventAdmin(): void { $this->user->update(['admin_scope' => 'event', 'event_id' => 1]); Sanctum::actingAs($this->user); } public function test_event_and_refund_settings_use_user_event_even_when_tenant_active_event_changes(): void { $this->actingEventAdmin(); $this->getJson('/api/v1/adminapp/tenant/event')->assertOk()->assertJsonPath('data.id', 1) ->assertJsonPath('data.allow_ticket_refund', true); $this->putJson('/api/v1/adminapp/tenant/event', [ 'title' => 'Solo A', 'location' => 'Predio A', 'social_media' => [], 'allow_ticket_refund' => false, 'allow_ticket_total_refund' => true, 'allow_ticket_partial_refund' => true, 'ticket_partial_refund_percentage' => 30, ])->assertOk()->assertJsonPath('data.id', 1)->assertJsonPath('data.allow_ticket_refund', false); $this->assertDatabaseHas('events', ['id' => 1, 'title' => 'Solo A', 'allow_ticket_refund' => false]); $this->assertDatabaseHas('events', ['id' => 2, 'title' => 'Evento B', 'allow_ticket_refund' => true]); $this->assertDatabaseHas('tenants', ['codigo' => 'onticket', 'allow_ticket_refund' => true]); $this->getJson('/api/v1/adminapp/forms/event')->assertOk(); $this->getJson('/api/v1/adminapp/tenant/website-extras')->assertForbidden(); } public function test_dates_are_created_on_user_event_and_other_event_dates_cannot_be_changed(): void { $this->actingEventAdmin(); $this->postJson('/api/v1/adminapp/tenant/event-dates', [ 'date' => '2027-01-20', 'start_time' => '10:00', 'end_time' => '12:00', ])->assertSuccessful(); $this->assertDatabaseHas('event_dates', ['event_id' => 1, 'date' => '2027-01-20']); DB::table('event_dates')->insert(['id' => 20, 'event_id' => 2, 'tenant_code' => 'onticket', 'date' => '2027-01-20', 'time_start' => '10:00', 'time_end' => '12:00']); $this->postJson('/api/v1/adminapp/tenant/event-dates/20/suspend')->assertNotFound(); $this->postJson('/api/v1/adminapp/tenant/event-dates/20/reschedule', ['date' => '2027-01-21'])->assertNotFound(); $this->assertDatabaseHas('event_dates', ['id' => 20, 'suspended_at' => null]); } public function test_sales_totals_details_exports_and_history_are_scoped_to_user_event(): void { $this->actingEventAdmin(); foreach ([1, 2] as $id) { DB::table('compras')->insert(['id' => $id, 'tenant_codigo' => 'onticket', 'event_id' => $id, 'status' => 'paid', 'total' => $id * 100, 'nombre_apellido' => 'Cliente', 'created_at' => now()]); DB::table('compra_items')->insert(['id' => $id, 'compra_id' => $id, 'cantidad' => 1]); DB::table('ticket_refunds')->insert(['purchase_item_id' => $id, 'amount' => $id * 10]); DB::table('value_changes')->insert(['tenant_code' => 'onticket', 'trackable_type' => (new Purchase)->getMorphClass(), 'trackable_id' => $id, 'attribute' => 'status', 'new_value' => 'paid', 'changed_at' => now()]); } $this->getJson('/api/v1/adminapp/tenant/sales')->assertOk()->assertJsonCount(1, 'data') ->assertJsonPath('confirmed_sales_total', '100.00')->assertJsonPath('refunded_total', '10.00'); $this->getJson('/api/v1/adminapp/tenant/sales/1')->assertOk(); foreach (['', '/tickets'] as $suffix) { $this->getJson('/api/v1/adminapp/tenant/sales/2'.$suffix)->assertNotFound(); } foreach (['confirm', 'cancel'] as $action) { $this->postJson('/api/v1/adminapp/tenant/sales/2/'.$action)->assertNotFound(); } $this->getJson('/api/v1/adminapp/tenant/sales/modifications')->assertOk()->assertJsonCount(1, 'data'); $service = app(AdminAppSaleService::class); $tenant = $this->user->tenant; $this->assertSame([1], $service->salesForExport($tenant, [], 1)->pluck('id')->all()); $this->assertSame([1], $service->modificationsForExport($tenant, [], 1)->pluck('trackable_id')->all()); } private function scanner(int $eventId, int $id = 10): User { return User::query()->create(['id' => $id, 'nombre_apellido' => 'Scanner', 'email' => "scanner{$id}@example.test", 'password' => 'password', 'dni' => '123', 'tenant_codigo' => 'onticket', 'rol_codigo' => 'scanner', 'admin_scope' => 'event', 'event_id' => $eventId]); } public function test_staff_is_created_on_admin_event_and_other_staff_cannot_be_managed(): void { $this->actingEventAdmin(); $scanner = $this->scanner(2); $this->getJson('/api/v1/adminapp/tenant/staff')->assertOk()->assertJsonCount(0, 'data'); $payload = ['nombre_apellido' => 'Nuevo', 'email' => 'nuevo@example.test', 'dni' => '123']; $this->putJson('/api/v1/adminapp/tenant/staff/'.$scanner->id, $payload)->assertNotFound(); $this->deleteJson('/api/v1/adminapp/tenant/staff/'.$scanner->id)->assertNotFound(); $this->getJson('/api/v1/adminapp/tenant/staff/'.$scanner->id.'/scan-attempts')->assertNotFound(); $this->mock(ResetPasswordAttemptService::class, fn ($mock) => $mock->shouldReceive('createForScannerEmail')->once()); $this->postJson('/api/v1/adminapp/tenant/staff', [...$payload, 'event_id' => 2]) ->assertSuccessful()->assertJsonPath('data.event_id', 1); $this->assertDatabaseHas('users', ['email' => 'nuevo@example.test', 'event_id' => 1, 'admin_scope' => 'event']); } public function test_scanner_rejects_foreign_event_qr_without_consuming_or_disclosing_ticket(): void { $scanner = $this->scanner(1); Sanctum::actingAs($scanner); $uuid = '11111111-1111-4111-8111-111111111111'; DB::table('tickets')->insert(['id' => 20, 'tenant_code' => 'onticket', 'event_id' => 2, 'ticket' => $uuid]); $this->getJson('/api/v1/scanner/tickets/'.$uuid)->assertNotFound(); $this->postJson('/api/v1/scanner/tickets/scan', ['data' => $uuid])->assertOk() ->assertJsonPath('data.scan_attempt.result', 'ticket_not_found')->assertJsonPath('data.ticket', null); $this->assertDatabaseHas('tickets', ['id' => 20, 'used_at' => null, 'scanner_user_id' => null]); $this->assertDatabaseHas('scan_attempts', ['scanner_user_id' => $scanner->id, 'event_id' => 1, 'ticket_id' => null]); } public function test_scanner_history_and_detail_follow_assignment_changes_and_invalid_event_is_denied(): void { $scanner = $this->scanner(1); Sanctum::actingAs($scanner); $response = $this->postJson('/api/v1/scanner/tickets/scan', ['data' => 'invalid'])->assertOk(); $id = $response->json('data.scan_attempt.id'); $this->getJson('/api/v1/scanner/attempts')->assertOk()->assertJsonCount(1, 'data'); $scanner->update(['event_id' => 2]); $this->getJson('/api/v1/scanner/attempts')->assertOk()->assertJsonCount(0, 'data'); $this->getJson('/api/v1/scanner/attempts/'.$id)->assertNotFound(); $scanner->update(['event_id' => null]); $this->getJson('/api/v1/scanner/attempts')->assertForbidden(); } public function test_initial_assignment_migration_preserves_existing_scopes_and_ignores_missing_events(): void { $this->user->update(['admin_scope' => 'event', 'event_id' => 1]); $scanner = $this->scanner(1); $scanner->update(['event_id' => null, 'admin_scope' => 'tenant']); $migration = require database_path('migrations/2026_09_30_000100_assign_active_event_to_staff_users.php'); $migration->up(); $migration->up(); $this->assertDatabaseHas('users', ['id' => 1, 'event_id' => 1]); $this->assertDatabaseHas('users', ['id' => $scanner->id, 'event_id' => 2, 'admin_scope' => 'event']); DB::table('tenants')->where('codigo', 'onticket')->update(['active_event_id' => 3]); $scanner->refresh()->update(['event_id' => null, 'admin_scope' => 'tenant']); $migration->up(); $this->assertDatabaseHas('users', ['id' => $scanner->id, 'event_id' => null, 'admin_scope' => 'event']); } public function test_deprecated_menus_are_removed_with_their_role_and_tenant_assignments(): void { foreach (['adminapp.categories', 'adminapp.combos'] as $code) { DB::table('menues')->insert(['code' => $code, 'label' => $code, 'route' => '/admin/old']); DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]); DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]); } (require database_path('migrations/2026_09_30_000300_remove_deprecated_admin_menus.php'))->up(); foreach (['adminapp.categories', 'adminapp.combos'] as $code) { $this->assertDatabaseMissing('menues', ['code' => $code]); $this->assertDatabaseMissing('roles_menues', ['menu_codigo' => $code]); $this->assertDatabaseMissing('tenants_menues', ['menu_code' => $code]); } } public function test_scanner_accepts_ticket_from_its_event_and_cannot_consume_it_twice(): void { $scanner = $this->scanner(1); Sanctum::actingAs($scanner); $uuid = '11111111-1111-4111-8111-111111111111'; DB::table('tickets')->insert(['id' => 20, 'tenant_code' => 'onticket', 'event_id' => 1, 'ticket' => $uuid]); $this->postJson('/api/v1/scanner/tickets/scan', ['data' => $uuid])->assertOk() ->assertJsonPath('data.scan_attempt.result', 'accepted')->assertJsonPath('data.ticket.id', 20); $this->assertNotNull(DB::table('tickets')->where('id', 20)->value('used_at')); $this->postJson('/api/v1/scanner/tickets/scan', ['data' => $uuid])->assertOk() ->assertJsonPath('data.scan_attempt.result', 'already_scanned'); $this->getJson('/api/v1/scanner/tickets/'.$uuid)->assertOk(); } public function test_refund_calculation_uses_ticket_event_configuration_instead_of_tenant_defaults(): void { Schema::create('desfile_entry_reservations', function (Blueprint $table): void { $table->id(); $table->unsignedBigInteger('ticket_id'); $table->softDeletes(); }); DB::table('ticket_refunds')->delete(); DB::table('compra_items')->insert(['id' => 1, 'compra_id' => 1, 'cantidad' => 1, 'precio_unitario' => 100, 'total' => 100]); DB::table('tickets')->insert(['id' => 20, 'tenant_code' => 'onticket', 'event_id' => 1, 'ticket' => '11111111-1111-4111-8111-111111111111', 'source_purchase_item_id' => 1]); DB::table('events')->where('id', 1)->update(['ticket_partial_refund_percentage' => 75]); $calculation = app(AdminAppTicketService::class) ->calculateRefund($this->user->tenant, 20); $this->assertSame(['total' => '100.00', 'partial' => '75.00'], $calculation); DB::table('events')->where('id', 1)->update(['allow_ticket_refund' => false]); $this->assertFalse(Ticket::query()->findOrFail(20)->allow_refund()); } public function test_staff_category_options_and_assignments_exclude_other_event_products(): void { $this->actingEventAdmin(); DB::table('tenants')->where('codigo', 'onticket')->update(['scanner_category_validation_enabled' => true]); foreach ([1, 2] as $id) { DB::table('categorias')->insert(['id' => $id, 'nombre' => "Categoria {$id}", 'tenant_code' => 'onticket']); DB::table('catalog_items')->insert(['id' => $id, 'tenant_code' => 'onticket', 'event_id' => $id, 'nombre' => "Producto {$id}", 'slug' => "producto-{$id}", 'category_id' => $id]); } $this->getJson('/api/v1/adminapp/forms/staff')->assertOk()->assertJsonCount(1, 'data.categories') ->assertJsonPath('data.categories.0.id', 1); $this->postJson('/api/v1/adminapp/tenant/staff', ['nombre_apellido' => 'Nuevo', 'dni' => '123', 'email' => 'nuevo@example.test', 'category_ids' => [2]])->assertUnprocessable()->assertJsonValidationErrors('category_ids'); $this->assertDatabaseMissing('users', ['email' => 'nuevo@example.test']); } public function test_initial_migration_assigns_existing_tenant_admin_and_blocks_staff_without_active_event(): void { $unassigned = $this->scanner(1); $unassigned->update(['tenant_codigo' => 'other', 'admin_scope' => 'tenant', 'event_id' => null]); (require database_path('migrations/2026_09_30_000100_assign_active_event_to_staff_users.php'))->up(); $this->assertDatabaseHas('users', ['id' => 1, 'admin_scope' => 'event', 'event_id' => 2]); $this->assertDatabaseHas('users', ['id' => $unassigned->id, 'admin_scope' => 'event', 'event_id' => null]); $this->user->refresh(); $this->assertFalse($this->user->isTenantAdministrator()); $this->login()->assertOk()->assertJsonPath('user.event_id', 2); } public function test_scanner_login_validates_event_before_issuing_a_token(): void { $scanner = $this->scanner(1); $this->postJson('/api/v1/scanner/login', ['email' => $scanner->email, 'password' => 'password']) ->assertOk()->assertJsonPath('user.event_id', 1); $scanner->update(['event_id' => null]); $this->postJson('/api/v1/scanner/login', ['email' => $scanner->email, 'password' => 'password']) ->assertUnprocessable()->assertJsonValidationErrors('email'); $this->assertDatabaseCount('personal_access_tokens', 1); $this->assertSame(0, $scanner->refresh()->failed_login_attempts); } }