Magic-Link und Pressekontakt-Zugang zu einer Seite (/anmeldelink) zusammengeführt; altes Login-Modal entfernt, /pressekontakt-zugang leitet weiter. - ContactAccessService deckt jetzt Firmen-E-Mail UND Pressekontakt-E-Mail ab, portalübergreifend (ohne PortalScope). Eine E-Mail mehrfach hinterlegt → genau ein Account, dem alle Firmen + Kontakte zugeordnet werden. - Zugeordnete Firmen erhalten Pivot-Rolle 'responsible' (Schreibzugriff auf Stammdaten, Kontakte, Pressemitteilungen) statt nur 'member'; bestehende Lese-Pivots werden hochgestuft, Owner bleiben unangetastet. - Neuer Login-Listener (SyncCompanyMembershipsOnLogin) frischt die Zuordnungen bei JEDEM Login (Magic-Link, Passwort, Google) auf – auch nachträglich (API) hinzugekommene Firmen/Kontakte mit gleicher E-Mail greifen. - Auth-Bereich erzwingt Hellmodus: aus dem Portal übernommene .dark-Klasse wird am <html> entfernt (Login war im Dark Mode hängengeblieben). - Tests: Firmen-E-Mail-Login, Multi-Firmen-Aggregation, Schreibzugriff/Upgrade, Per-Login-Re-Sync, Auth-Hellmodus. Sicherheits-Doku aktualisiert. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
185 lines
5.7 KiB
PHP
185 lines
5.7 KiB
PHP
<?php
|
|
|
|
use App\Mail\MagicLoginLink;
|
|
use App\Models\MagicLink;
|
|
use App\Models\User;
|
|
use Database\Seeders\RolesAndPermissionsSeeder;
|
|
use Illuminate\Support\Facades\Mail;
|
|
use Livewire\Volt\Volt as LivewireVolt;
|
|
use Tests\TestCase;
|
|
|
|
test('user can request a magic login link from the magic-link page', function () {
|
|
Mail::fake();
|
|
$user = User::factory()->create(['is_active' => true]);
|
|
|
|
LivewireVolt::test('auth.magic-link')
|
|
->set('email', $user->email)
|
|
->call('requestLink')
|
|
->assertHasNoErrors();
|
|
|
|
Mail::assertSent(MagicLoginLink::class, function (MagicLoginLink $mail) use ($user) {
|
|
return $mail->user->is($user) && str_contains($mail->loginUrl, '/magic-login/');
|
|
});
|
|
|
|
$magicLink = MagicLink::query()->firstOrFail();
|
|
|
|
expect($magicLink->user_id)->toBe($user->id);
|
|
expect($magicLink->token_hash)->toHaveLength(64);
|
|
});
|
|
|
|
test('the magic link form validates its email field and clears on success', function () {
|
|
Mail::fake();
|
|
$user = User::factory()->create(['is_active' => true]);
|
|
|
|
// Leere Eingabe → Validierungsfehler, keine Mail.
|
|
LivewireVolt::test('auth.magic-link')
|
|
->set('email', '')
|
|
->call('requestLink')
|
|
->assertHasErrors(['email']);
|
|
|
|
Mail::assertNothingSent();
|
|
|
|
// Gültige Eingabe → Feld wird geleert.
|
|
LivewireVolt::test('auth.magic-link')
|
|
->set('email', $user->email)
|
|
->call('requestLink')
|
|
->assertHasNoErrors()
|
|
->assertSet('email', '');
|
|
});
|
|
|
|
test('magic link requests are rate limited per email', function () {
|
|
/** @var TestCase $this */
|
|
Mail::fake();
|
|
$user = User::factory()->create(['is_active' => true]);
|
|
|
|
foreach (range(1, 3) as $ignored) {
|
|
LivewireVolt::test('auth.magic-link')
|
|
->set('email', $user->email)
|
|
->call('requestLink')
|
|
->assertHasNoErrors();
|
|
}
|
|
|
|
LivewireVolt::test('auth.magic-link')
|
|
->set('email', $user->email)
|
|
->call('requestLink')
|
|
->assertHasErrors(['email']);
|
|
|
|
Mail::assertSent(MagicLoginLink::class, 3);
|
|
});
|
|
|
|
test('admin can login with a valid magic link and lands on admin dashboard', function () {
|
|
/** @var TestCase $this */
|
|
$this->seed(RolesAndPermissionsSeeder::class);
|
|
Mail::fake();
|
|
$user = User::factory()->create(['is_active' => true]);
|
|
$user->assignRole('admin');
|
|
|
|
LivewireVolt::test('auth.magic-link')
|
|
->set('email', $user->email)
|
|
->call('requestLink');
|
|
|
|
$sentMail = null;
|
|
|
|
Mail::assertSent(MagicLoginLink::class, function (MagicLoginLink $mail) use (&$sentMail) {
|
|
$sentMail = $mail;
|
|
|
|
return true;
|
|
});
|
|
|
|
expect($sentMail)->not->toBeNull();
|
|
/** @var MagicLoginLink $sentMail */
|
|
$this->get($sentMail->loginUrl)
|
|
->assertRedirect(route('dashboard', absolute: false));
|
|
|
|
$this->assertAuthenticatedAs($user);
|
|
|
|
expect(MagicLink::query()->firstOrFail()->consumed_at)->not->toBeNull();
|
|
$user->refresh();
|
|
expect($user->last_login_at)->not->toBeNull();
|
|
expect($user->last_login_ip)->toBe('127.0.0.1');
|
|
});
|
|
|
|
test('customer is redirected to me dashboard after magic link login', function () {
|
|
/** @var TestCase $this */
|
|
$this->seed(RolesAndPermissionsSeeder::class);
|
|
Mail::fake();
|
|
$customer = User::factory()->create(['is_active' => true]);
|
|
$customer->assignRole('customer');
|
|
|
|
LivewireVolt::test('auth.magic-link')
|
|
->set('email', $customer->email)
|
|
->call('requestLink');
|
|
|
|
$sentMail = null;
|
|
Mail::assertSent(MagicLoginLink::class, function (MagicLoginLink $mail) use (&$sentMail) {
|
|
$sentMail = $mail;
|
|
|
|
return true;
|
|
});
|
|
|
|
/** @var MagicLoginLink $sentMail */
|
|
$this->get($sentMail->loginUrl)
|
|
->assertRedirect(route('me.dashboard', absolute: false));
|
|
|
|
$this->assertAuthenticatedAs($customer);
|
|
});
|
|
|
|
test('a stale intended admin url does not send a customer into the 403 admin area', function () {
|
|
/** @var TestCase $this */
|
|
$this->seed(RolesAndPermissionsSeeder::class);
|
|
$customer = User::factory()->create(['is_active' => true]);
|
|
$customer->assignRole('customer');
|
|
|
|
$plainToken = 'intended-token';
|
|
MagicLink::query()->create([
|
|
'user_id' => $customer->id,
|
|
'token_hash' => hash('sha256', $plainToken),
|
|
'purpose' => 'login',
|
|
'expires_at' => now()->addMinutes(5),
|
|
]);
|
|
|
|
// Als Gast zuvor /dashboard besucht → intended-URL liegt in der Session.
|
|
$this->withSession(['url.intended' => route('dashboard')]);
|
|
|
|
$this->get(route('magic-links.consume', ['token' => $plainToken]))
|
|
->assertRedirect(route('me.dashboard', absolute: false));
|
|
|
|
$this->assertAuthenticatedAs($customer);
|
|
});
|
|
|
|
test('expired magic link can not be used', function () {
|
|
/** @var TestCase $this */
|
|
$user = User::factory()->create(['is_active' => true]);
|
|
$plainToken = 'expired-token';
|
|
|
|
MagicLink::query()->create([
|
|
'user_id' => $user->id,
|
|
'token_hash' => hash('sha256', $plainToken),
|
|
'purpose' => 'login',
|
|
'expires_at' => now()->subMinute(),
|
|
]);
|
|
|
|
$this->get(route('magic-links.consume', ['token' => $plainToken]))
|
|
->assertRedirect(route('login', absolute: false));
|
|
|
|
$this->assertGuest();
|
|
});
|
|
|
|
test('consumed magic link can not be reused', function () {
|
|
/** @var TestCase $this */
|
|
$user = User::factory()->create(['is_active' => true]);
|
|
$plainToken = 'consumed-token';
|
|
|
|
MagicLink::query()->create([
|
|
'user_id' => $user->id,
|
|
'token_hash' => hash('sha256', $plainToken),
|
|
'purpose' => 'login',
|
|
'expires_at' => now()->addMinutes(5),
|
|
'consumed_at' => now()->subMinute(),
|
|
]);
|
|
|
|
$this->get(route('magic-links.consume', ['token' => $plainToken]))
|
|
->assertRedirect(route('login', absolute: false));
|
|
|
|
$this->assertGuest();
|
|
});
|