createTicketReservationSchema('onticket'); $this->app->register(DomPdfServiceProvider::class); Schema::table('users', fn (Blueprint $table) => $table->string('rol_codigo')->default('adminapp')); Schema::table('tenants', fn (Blueprint $table) => $table->string('nombre')->default('OnTicket')); Schema::create('menues', function (Blueprint $table): void { $table->string('code')->primary(); $table->string('label')->nullable(); $table->string('parent_menu_code')->nullable(); $table->string('content_type')->default('dynamic'); $table->text('static_content_schema')->nullable(); $table->string('route')->nullable(); $table->timestamps(); }); Schema::create('tenants_menues', function (Blueprint $table): void { $table->string('tenant_code'); $table->string('menu_code'); $table->text('static_content')->nullable(); $table->timestamps(); $table->unique(['tenant_code', 'menu_code']); }); Schema::create('roles', function (Blueprint $table): void { $table->id(); $table->string('codigo')->unique(); }); Schema::create('roles_menues', function (Blueprint $table): void { $table->string('rol_codigo'); $table->string('menu_codigo'); $table->unique(['rol_codigo', 'menu_codigo']); }); DB::table('menues')->insert(['code' => 'main.adminapp', 'label' => 'Administración']); DB::table('roles')->insert([['codigo' => 'admin'], ['codigo' => 'adminapp'], ['codigo' => 'user']]); $this->migration()->up(); $validity = Mockery::mock(TicketValidityResolver::class); $validity->shouldReceive('resolveVariant')->andReturn(ResolvedTicketValidity::unrestricted()); $validity->shouldReceive('resolveTicket')->andReturn(ResolvedTicketValidity::unrestricted()); $this->app->instance(TicketValidityResolver::class, $validity); } private function migration() { return require database_path('migrations/2026_10_02_010000_add_ticket_reservations_adminapp_menu.php'); } private function login(int $id = 1): void { Sanctum::actingAs(User::findOrFail($id)); } private function payload(): array { return ['idempotency_key' => (string) Str::uuid(), 'rows' => [ ['catalog_item_id' => 1, 'variant_id' => 1, 'tipo_pago' => 'otro_metodo'], ['catalog_item_id' => 2, 'variant_id' => null, 'tipo_pago' => 'sin_cargo'], ]]; } public function test_menu_migration_and_seeder_only_assign_onticket_and_admin_roles(): void { DB::table('tenants_menues')->insert(['tenant_code' => 'other', 'menu_code' => 'adminapp.ticket-reservations']); $this->migration()->up(); $this->assertSame(['onticket'], DB::table('tenants_menues')->where('menu_code', 'adminapp.ticket-reservations')->pluck('tenant_code')->all()); $this->assertSame(['admin', 'adminapp'], DB::table('roles_menues')->where('menu_codigo', 'adminapp.ticket-reservations')->orderBy('rol_codigo')->pluck('rol_codigo')->all()); $this->seed(MenuSeeder::class); $this->assertDatabaseHas('menues', ['code' => 'adminapp.ticket-reservations', 'parent_menu_code' => 'main.adminapp', 'route' => '/admin/ticket-reservations']); $this->assertSame(['onticket'], DB::table('tenants_menues')->where('menu_code', 'adminapp.ticket-reservations')->pluck('tenant_code')->all()); $this->assertDatabaseMissing('roles_menues', ['rol_codigo' => 'user', 'menu_codigo' => 'adminapp.ticket-reservations']); $this->migration()->down(); $this->assertDatabaseMissing('menues', ['code' => 'adminapp.ticket-reservations']); $this->assertDatabaseHas('menues', ['code' => 'main.adminapp']); } public function test_authentication_adminapp_role_and_menu_are_required(): void { $this->getJson(self::URL.'/form')->assertUnauthorized(); $this->login(); DB::table('users')->where('id', 1)->update(['rol_codigo' => 'user']); $this->login(); $this->getJson(self::URL)->assertForbidden(); DB::table('users')->where('id', 1)->update(['rol_codigo' => 'adminapp']); $this->login(); DB::table('tenants_menues')->delete(); $this->getJson(self::URL.'/form')->assertNotFound(); $this->postJson(self::URL, $this->payload())->assertNotFound(); } public function test_other_tenant_is_rejected_even_if_the_menu_is_assigned(): void { DB::table('tenants_menues')->insert(['tenant_code' => 'other', 'menu_code' => 'adminapp.ticket-reservations']); $this->login(2); foreach (['', '/form', '/pdf', '/excel', '/1/ticket/pdf'] as $suffix) { $this->getJson(self::URL.$suffix)->assertForbidden(); } $this->postJson(self::URL, $this->payload())->assertForbidden(); $this->deleteJson(self::URL.'/1')->assertForbidden(); } public function test_form_uses_generic_variants_and_keeps_reserved_variants_with_remaining_stock(): void { $this->login(); $this->postJson(self::URL, $this->payload())->assertOk(); $form = $this->getJson(self::URL.'/form')->assertOk(); $this->assertSame([1, 2, 4], array_column($form->json('data.items'), 'id')); $this->assertSame(2, $form->json('data.items.0.variants.0.available_stock')); $this->assertSame(250, $form->json('data.items.0.variants.0.price')); $this->assertStringContainsString('NORMAL', $form->json('data.items.0.variants.0.label')); $form->assertJsonPath('data.items.1.requires_variant', false)->assertJsonPath('data.items.2.available_stock', null); DB::table('variantes')->where('id', 2)->update(['sales_disabled_at' => now()]); DB::table('inventories')->where('id', 1)->update(['real_stock' => 1]); DB::table('catalog_items')->where('id', 2)->update(['sales_end_at' => now()->subMinute()]); $hidden = $this->getJson(self::URL.'/form')->assertOk(); $this->assertSame([4], array_column($hidden->json('data.items'), 'id')); $this->assertSame([1, 2, 4], array_column($hidden->json('data.filter_items'), 'id')); } public function test_active_event_only_limits_new_selections_and_not_history(): void { $this->login(); $this->postJson(self::URL, $this->payload())->assertOk(); DB::table('tenants')->where('codigo', 'onticket')->update(['active_event_id' => 10]); DB::table('catalog_items')->where('id', 4)->update(['event_id' => 10]); $form = $this->getJson(self::URL.'/form')->assertOk(); $this->assertSame([4], array_column($form->json('data.items'), 'id')); $this->getJson(self::URL)->assertOk()->assertJsonPath('meta.total', 2); } public function test_reserves_mixed_items_replays_filters_and_cancels_with_the_real_generator(): void { $this->login(); $payload = $this->payload(); $created = $this->postJson(self::URL, $payload)->assertOk(); $created->assertJsonPath('data.0.catalog_item_id', 1)->assertJsonPath('data.0.importe', '250.00') ->assertJsonPath('data.1.variant', null)->assertJsonPath('data.1.importe', '0.00'); $replay = $this->postJson(self::URL, $payload)->assertOk(); $this->assertSame($created->json('data'), $replay->json('data')); $this->getJson(self::URL.'?catalog_item_id=1&variant_id=1&tipo_pago=otro_metodo&per_page=1') ->assertOk()->assertJsonPath('meta.total', 1)->assertJsonPath('data.0.variant.id', 1); $this->assertDatabaseCount('tickets', 2); $this->assertDatabaseHas('tickets', ['source_catalog_item_id' => 2, 'source_variant_id' => null]); $id = $created->json('data.0.id'); $ticketId = $created->json('data.0.ticket_id'); $this->deleteJson(self::URL.'/'.$id)->assertNoContent(); $this->assertNotNull(Ticket::findOrFail($ticketId)->cancelled_at); $this->assertSame(0, Inventory::findOrFail(1)->entry_reserved_stock); $this->getJson(self::URL)->assertOk()->assertJsonPath('meta.total', 1); } public function test_invalid_selection_and_client_prices_are_rejected_atomically(): void { $this->login(); $payload = $this->payload(); $payload['rows'][0]['catalog_item_id'] = 3; $this->postJson(self::URL, $payload)->assertUnprocessable()->assertJsonValidationErrors('rows.0.variant_id'); $payload = $this->payload(); $payload['rows'][1]['importe'] = 1; $this->postJson(self::URL, $payload)->assertUnprocessable()->assertJsonValidationErrors('rows.1'); $this->assertDatabaseCount('tickets', 0); $this->assertSame(0, (int) Inventory::sum('entry_reserved_stock')); } public function test_exports_use_generic_columns_filters_and_timezone(): void { $this->login(); $this->postJson(self::URL, $this->payload())->assertOk(); $query = '?catalog_item_id=2&timezone=America/Argentina/Buenos_Aires'; $this->getJson(self::URL.'/pdf?timezone=invalid')->assertUnprocessable(); $pdf = $this->get(self::URL.'/pdf'.$query)->assertOk()->assertHeader('Content-Type', 'application/pdf'); $this->assertStringStartsWith('%PDF', $pdf->getContent()); $excel = $this->get(self::URL.'/excel'.$query)->assertOk(); $content = $excel->streamedContent(); $this->assertStringStartsWith('PK', $content); $filename = tempnam(sys_get_temp_dir(), 'ticket-reservations-test-'); try { file_put_contents($filename, $content); $sheet = IOFactory::load($filename)->getActiveSheet(); $this->assertSame(['Ítem', 'Variante', 'ID', 'Fecha', 'Importe', 'Pago'], $sheet->rangeToArray('A1:F1')[0]); $this->assertSame(2, $sheet->getHighestRow()); $this->assertSame('Sin variante', $sheet->getCell('B2')->getValue()); $this->assertSame('Sin cargo', $sheet->getCell('F2')->getValue()); $this->assertSame('dd/mm/yyyy hh:mm', $sheet->getStyle('D2')->getNumberFormat()->getFormatCode()); } finally { unlink($filename); } } public function test_individual_ticket_download_and_cancellation_are_scoped_by_tenant(): void { $this->login(); $created = $this->postJson(self::URL, $this->payload())->assertOk(); $pdf = Mockery::mock(TicketPdfService::class); $pdf->shouldReceive('download')->once()->andReturnUsing(function ($tenant, $tickets) use ($created) { $this->assertSame('onticket', $tenant->codigo); $this->assertSame($created->json('data.0.ticket_id'), $tickets->sole()->id); return response('%PDF-test', 200, ['Content-Type' => 'application/pdf']); }); $this->app->instance(TicketPdfService::class, $pdf); $this->get(self::URL.'/'.$created->json('data.0.id').'/ticket/pdf')->assertOk(); $foreign = $this->app->make(EntryReservationService::class) ->reserve(User::findOrFail(2), (string) Str::uuid(), [ ['catalog_item_id' => 3, 'tipo_pago' => 'sin_cargo'], ])->sole(); $this->getJson(self::URL.'/'.$foreign->id.'/ticket/pdf')->assertNotFound(); $this->deleteJson(self::URL.'/'.$foreign->id)->assertNotFound(); $this->assertNull(Ticket::findOrFail($foreign->ticket_id)->cancelled_at); } public function test_user_event_scope_limits_form_filters_history_exports_and_individual_actions(): void { DB::table('catalog_items')->where('id', 1)->update(['event_id' => 10]); DB::table('catalog_items')->whereIn('id', [2, 4])->update(['event_id' => 20]); $this->login(); $created = $this->postJson(self::URL, $this->payload())->assertOk(); $ownId = $created->json('data.0.id'); $outsideId = $created->json('data.1.id'); DB::table('users')->where('id', 1)->update(['event_id' => 10]); DB::table('tenants')->where('codigo', 'onticket')->update(['active_event_id' => 20]); $this->login(); $form = $this->getJson(self::URL.'/form')->assertOk(); $this->assertSame([1], array_column($form->json('data.items'), 'id')); $this->assertSame([1], array_column($form->json('data.filter_items'), 'id')); $this->getJson(self::URL)->assertOk()->assertJsonPath('meta.total', 1)->assertJsonPath('data.0.id', $ownId); $this->getJson(self::URL.'?catalog_item_id=2&event_id=20')->assertOk()->assertJsonPath('meta.total', 0); $this->getJson(self::URL.'/'.$outsideId.'/ticket/pdf')->assertNotFound(); $this->deleteJson(self::URL.'/'.$outsideId)->assertNotFound(); $this->assertNull(Ticket::findOrFail($created->json('data.1.ticket_id'))->cancelled_at); $pdf = Mockery::mock(EntryReservationPdfService::class); $pdf->shouldReceive('download')->once()->andReturnUsing(function ($tenant, $reservations) use ($ownId) { $this->assertSame([$ownId], $reservations->pluck('id')->all()); return response('%PDF-test', 200); }); $this->app->instance(EntryReservationPdfService::class, $pdf); $this->get(self::URL.'/pdf?timezone=UTC')->assertOk(); $excel = Mockery::mock(EntryReservationExcelService::class); $excel->shouldReceive('download')->once()->andReturnUsing(function ($tenant, $reservations) use ($ownId) { $this->assertSame([$ownId], $reservations->pluck('id')->all()); return response()->streamDownload(fn () => print ('test'), 'reservations.xlsx'); }); $this->app->instance(EntryReservationExcelService::class, $excel); $this->get(self::URL.'/excel?timezone=UTC')->assertOk(); $this->deleteJson(self::URL.'/'.$ownId)->assertNoContent(); } public function test_user_event_scope_overrides_active_event_for_new_reservations_and_rejects_other_items(): void { DB::table('catalog_items')->where('id', 1)->update(['event_id' => 10]); DB::table('catalog_items')->where('id', 2)->update(['event_id' => 20]); DB::table('tenants')->where('codigo', 'onticket')->update(['active_event_id' => 20]); DB::table('users')->where('id', 1)->update(['event_id' => 10]); $this->login(); $this->postJson(self::URL, $this->payload())->assertUnprocessable()->assertJsonValidationErrors('rows.1.catalog_item_id'); $this->assertDatabaseCount('tickets', 0); $payload = $this->payload(); $payload['rows'] = [$payload['rows'][0]]; $created = $this->postJson(self::URL, $payload)->assertOk(); $this->assertDatabaseHas('tickets', ['id' => $created->json('data.0.ticket_id'), 'event_id' => 10]); $this->postJson(self::URL, $payload)->assertOk()->assertJsonPath('data.0.id', $created->json('data.0.id')); $this->assertDatabaseCount('tickets', 1); } public function test_retries_cannot_replay_a_mixed_event_batch_after_user_scope_changes(): void { DB::table('catalog_items')->where('id', 1)->update(['event_id' => 10]); DB::table('catalog_items')->where('id', 2)->update(['event_id' => 20]); $this->login(); $payload = $this->payload(); $created = $this->postJson(self::URL, $payload)->assertOk(); // Cancelled rows still belong to the batch and cannot bypass the new scope. $this->deleteJson(self::URL.'/'.$created->json('data.1.id'))->assertNoContent(); DB::table('users')->where('id', 1)->update(['event_id' => 10]); $this->login(); $this->postJson(self::URL, $payload)->assertForbidden(); $this->assertDatabaseCount('tickets', 2); $this->assertDatabaseCount('reservation_batches', 1); } }