1
0

UserRepositoryTest.php 9.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263
  1. <?php
  2. declare(strict_types=1);
  3. namespace App\Tests\Repositories;
  4. use App\Repositories\UserRepository;
  5. use App\Tests\TestCase;
  6. /**
  7. * Covers the upsert + admin-promotion contract used by the auth flows.
  8. * Caller-side gating (R01-N03's BOOTSTRAP_ADMIN_* env-bootstrap) lives in
  9. * `AuthController` + `BootstrapAdmin`; this suite only pins the repo's
  10. * mechanical promoteToAdmin / forceAdmin behaviour.
  11. */
  12. final class UserRepositoryTest extends TestCase
  13. {
  14. public function testFirstUserBecomesAdminWhenPromoted(): void
  15. {
  16. $pdo = $this->makeDb();
  17. $users = new UserRepository($pdo);
  18. $this->assertSame(0, $users->count());
  19. $r = $users->upsertFromOidc(
  20. oid: 'oid-alice',
  21. email: 'alice@example.com',
  22. name: 'Alice',
  23. promoteToAdmin: true, // caller's decision — see BootstrapAdmin::matches
  24. );
  25. $this->assertTrue($r['user']->isAdmin);
  26. $this->assertNull($r['before']);
  27. }
  28. public function testSecondUserDoesNotBecomeAdmin(): void
  29. {
  30. $pdo = $this->makeDb();
  31. $users = new UserRepository($pdo);
  32. $users->upsertFromOidc('oid-alice', 'alice@x', 'Alice', true);
  33. // Caller passes promoteToAdmin=false because an admin already exists.
  34. $r2 = $users->upsertFromOidc('oid-bob', 'bob@x', 'Bob', false);
  35. $this->assertFalse($r2['user']->isAdmin);
  36. }
  37. public function testReLoginDoesNotRegressAdminStatus(): void
  38. {
  39. $pdo = $this->makeDb();
  40. $users = new UserRepository($pdo);
  41. $users->upsertFromOidc('oid-alice', 'alice@x', 'Alice', true);
  42. // simulate a later login: count > 0 so promoteToAdmin=false
  43. $r = $users->upsertFromOidc('oid-alice', 'alice@x', 'Alice', false);
  44. $this->assertTrue($r['user']->isAdmin, 're-login must not demote admin');
  45. $this->assertNotNull($r['before']);
  46. }
  47. public function testForceAdminPromotesEvenOnUpdate(): void
  48. {
  49. // Local-admin login path sets forceAdmin=true so a demoted user gets
  50. // promoted back on next sign-in.
  51. $pdo = $this->makeDb();
  52. $users = new UserRepository($pdo);
  53. $r1 = $users->upsertFromOidc('local:admin@x', 'admin@x', 'Admin', true, true);
  54. $this->assertTrue($r1['user']->isAdmin);
  55. // Manually demote.
  56. $pdo->exec('UPDATE users SET is_admin = 0 WHERE id = ' . $r1['user']->id);
  57. $r2 = $users->upsertFromOidc('local:admin@x', 'admin@x', 'Admin', false, true);
  58. $this->assertTrue($r2['user']->isAdmin, 'forceAdmin must re-promote on update');
  59. }
  60. public function testUpsertUpdatesEmailAndName(): void
  61. {
  62. $pdo = $this->makeDb();
  63. $users = new UserRepository($pdo);
  64. $users->upsertFromOidc('oid-alice', 'old@x', 'Old Name', true);
  65. $r = $users->upsertFromOidc('oid-alice', 'new@x', 'New Name', false);
  66. $this->assertSame('new@x', $r['user']->email);
  67. $this->assertSame('New Name', $r['user']->displayName);
  68. }
  69. public function testCountReflectsInsertedUsers(): void
  70. {
  71. $pdo = $this->makeDb();
  72. $users = new UserRepository($pdo);
  73. $this->assertSame(0, $users->count());
  74. $users->upsertFromOidc('oid-1', 'a@x', 'A', true);
  75. $this->assertSame(1, $users->count());
  76. $users->upsertFromOidc('oid-2', 'b@x', 'B', false);
  77. $this->assertSame(2, $users->count());
  78. // Re-upsert existing user shouldn't add a row.
  79. $users->upsertFromOidc('oid-1', 'a@x', 'A', false);
  80. $this->assertSame(2, $users->count());
  81. }
  82. // ------------------------------------------------------------------
  83. // Phase 9: users management page helpers
  84. // ------------------------------------------------------------------
  85. public function testAllReturnsEveryUserOrderedByEmail(): void
  86. {
  87. $pdo = $this->makeDb();
  88. $users = new UserRepository($pdo);
  89. $users->upsertFromOidc('oid-c', 'carol@x', 'Carol', true);
  90. $users->upsertFromOidc('oid-a', 'alice@x', 'Alice', false);
  91. $users->upsertFromOidc('oid-b', 'BOB@x', 'Bob', false);
  92. $all = $users->all();
  93. $this->assertCount(3, $all);
  94. $this->assertSame(['alice@x', 'BOB@x', 'carol@x'], array_map(fn($u) => $u->email, $all));
  95. }
  96. public function testCountAdmins(): void
  97. {
  98. $pdo = $this->makeDb();
  99. $users = new UserRepository($pdo);
  100. $this->assertSame(0, $users->countAdmins());
  101. $users->upsertFromOidc('oid-a', 'a@x', 'A', true);
  102. $this->assertSame(1, $users->countAdmins());
  103. $users->upsertFromOidc('oid-b', 'b@x', 'B', false);
  104. $this->assertSame(1, $users->countAdmins());
  105. $users->upsertFromOidc('oid-c', 'c@x', 'C', false, true); // forceAdmin
  106. $this->assertSame(2, $users->countAdmins());
  107. }
  108. public function testSetAdminTogglesAndReportsDiff(): void
  109. {
  110. $pdo = $this->makeDb();
  111. $users = new UserRepository($pdo);
  112. $users->upsertFromOidc('oid-a', 'a@x', 'A', true);
  113. $users->upsertFromOidc('oid-b', 'b@x', 'B', false);
  114. $bob = $users->findByOid('oid-b');
  115. $r = $users->setAdmin($bob->id, true);
  116. $this->assertFalse($r['before']->isAdmin);
  117. $this->assertTrue ($r['after']->isAdmin);
  118. $this->assertSame(2, $users->countAdmins());
  119. $r = $users->setAdmin($bob->id, false);
  120. $this->assertTrue ($r['before']->isAdmin);
  121. $this->assertFalse($r['after']->isAdmin);
  122. $this->assertSame(1, $users->countAdmins());
  123. }
  124. // ------------------------------------------------------------------
  125. // R01-N23: tombstone (soft-delete for privacy)
  126. // ------------------------------------------------------------------
  127. public function testFreshUserIsNotTombstoned(): void
  128. {
  129. $pdo = $this->makeDb();
  130. $users = new UserRepository($pdo);
  131. $r = $users->upsertFromOidc('oid-a', 'a@x', 'Alice', true);
  132. $this->assertFalse($r['user']->isTombstoned());
  133. $this->assertNull($r['user']->tombstonedAt);
  134. }
  135. public function testSetTombstonedStampsAndForcesDemote(): void
  136. {
  137. $pdo = $this->makeDb();
  138. $users = new UserRepository($pdo);
  139. $users->upsertFromOidc('oid-a', 'a@x', 'A', true); // first admin
  140. $users->upsertFromOidc('oid-b', 'b@x', 'B', false);
  141. $users->upsertFromOidc('oid-c', 'c@x', 'C', false, true); // forceAdmin → second admin
  142. $bob = $users->findByOid('oid-b');
  143. $r = $users->setTombstoned($bob->id, true);
  144. $this->assertFalse($r['before']->isTombstoned());
  145. $this->assertTrue ($r['after']->isTombstoned());
  146. $this->assertNotNull($r['after']->tombstonedAt);
  147. $this->assertSame('(former user)', $r['after']->publicEmail());
  148. $this->assertSame('(former user)', $r['after']->publicDisplayName());
  149. $this->assertSame('b@x', $r['after']->email, 'audit-snapshot email is preserved');
  150. $this->assertSame('B', $r['after']->displayName, 'audit-snapshot display name is preserved');
  151. $this->assertFalse($r['after']->isAdmin, 'tombstone forces is_admin=0');
  152. }
  153. public function testSetTombstonedClearsAdminEvenForCurrentlyAdminUsers(): void
  154. {
  155. $pdo = $this->makeDb();
  156. $users = new UserRepository($pdo);
  157. $users->upsertFromOidc('oid-a', 'a@x', 'A', true); // first admin (kept)
  158. $users->upsertFromOidc('oid-b', 'b@x', 'B', false, true); // forceAdmin → second admin
  159. $bob = $users->findByOid('oid-b');
  160. $this->assertTrue($bob->isAdmin);
  161. $users->setTombstoned($bob->id, true);
  162. $bob = $users->findByOid('oid-b');
  163. $this->assertFalse($bob->isAdmin, 'tombstoning an admin must demote them');
  164. $this->assertSame(1, $users->countAdmins());
  165. }
  166. public function testRestoreClearsTombstoneButDoesNotPromote(): void
  167. {
  168. $pdo = $this->makeDb();
  169. $users = new UserRepository($pdo);
  170. $users->upsertFromOidc('oid-a', 'a@x', 'A', true);
  171. $users->upsertFromOidc('oid-b', 'b@x', 'B', false, true);
  172. $bob = $users->findByOid('oid-b');
  173. $users->setTombstoned($bob->id, true);
  174. $bob = $users->findByOid('oid-b');
  175. $this->assertTrue($bob->isTombstoned());
  176. $this->assertFalse($bob->isAdmin, 'precondition: tombstone demoted bob');
  177. $r = $users->setTombstoned($bob->id, false);
  178. $this->assertFalse($r['after']->isTombstoned());
  179. $this->assertNull($r['after']->tombstonedAt);
  180. $this->assertFalse($r['after']->isAdmin, 'restore must NOT auto-promote');
  181. }
  182. public function testOidcSignInUntombstones(): void
  183. {
  184. $pdo = $this->makeDb();
  185. $users = new UserRepository($pdo);
  186. $users->upsertFromOidc('oid-a', 'a@x', 'A', true);
  187. $alice = $users->findByOid('oid-a');
  188. $users->setTombstoned($alice->id, true);
  189. $this->assertTrue($users->findByOid('oid-a')->isTombstoned());
  190. // A successful OIDC sign-in (the upsert path the AuthController calls)
  191. // must clear the tombstone — the user has demonstrated they still hold
  192. // the identity, so the `(former user)` label would lie.
  193. $r = $users->upsertFromOidc('oid-a', 'a@x', 'A', false);
  194. $this->assertFalse($r['user']->isTombstoned());
  195. }
  196. public function testForceAdminAlsoUntombstones(): void
  197. {
  198. // Local-admin login path: forceAdmin=true also clears any
  199. // tombstone, so a tombstoned configured admin can come back.
  200. $pdo = $this->makeDb();
  201. $users = new UserRepository($pdo);
  202. $users->upsertFromOidc('local:admin@x', 'admin@x', 'Admin', true, true);
  203. $admin = $users->findByOid('local:admin@x');
  204. $users->setTombstoned($admin->id, true);
  205. $r = $users->upsertFromOidc('local:admin@x', 'admin@x', 'Admin', false, true);
  206. $this->assertFalse($r['user']->isTombstoned());
  207. $this->assertTrue($r['user']->isAdmin, 'forceAdmin path still re-promotes');
  208. }
  209. }