Fix field-length saves, student wp-admin access, and empty instructor picker
CI / Tests (PHP 8.1) (pull_request) Successful in 49s
CI / Tests (PHP 8.2) (pull_request) Successful in 49s
CI / No Debug Code (pull_request) Successful in 2s
CI / Coding Standards (pull_request) Successful in 2m47s
CI / PHPStan (pull_request) Successful in 3m16s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m41s
CI / Build Plugin Zip (pull_request) Skipped
CI / Tests (PHP 8.1) (pull_request) Successful in 49s
CI / Tests (PHP 8.2) (pull_request) Successful in 49s
CI / No Debug Code (pull_request) Successful in 2s
CI / Coding Standards (pull_request) Successful in 2m47s
CI / PHPStan (pull_request) Successful in 3m16s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m41s
CI / Build Plugin Zip (pull_request) Skipped
Three bug fixes for the 1.2.1 section: - Fixed-size fields (question labels, offering titles/notes/e-transfer email, policy titles/slugs) no longer silently fail to save when the value exceeds its column length. The REST endpoints reject over-long values with a 400, the admin controllers refuse to insert them, and the form inputs carry a maxlength so the browser blocks over-long entry. Limits are MAX_* constants on the value objects, kept in lockstep with the schema columns. - Students are kept out of wp-admin entirely. New StudentAdminGuard redirects front-end-only users (no back-office capability) away from the dashboard and hides the admin bar for them, while administrators, studio admins, and instructors keep full access. - The Add/Edit Offering instructor picker now includes WordPress administrators when they act as instructors (the default single-account setup), so a solo studio owner is selectable instead of the dropdown being empty. composer test (618), composer lint, composer cs all pass. Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
@@ -0,0 +1,88 @@
|
||||
<?php
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace Unsupervised\Schedular\Tests\Unit\Auth;
|
||||
|
||||
use Brain\Monkey\Functions;
|
||||
use Unsupervised\Schedular\Auth\RoleManager;
|
||||
use Unsupervised\Schedular\Auth\StudentAdminGuard;
|
||||
use Unsupervised\Schedular\Tests\Unit\TestCase;
|
||||
|
||||
class StudentAdminGuardTest extends TestCase
|
||||
{
|
||||
private StudentAdminGuard $guard;
|
||||
|
||||
protected function setUp(): void
|
||||
{
|
||||
parent::setUp();
|
||||
$this->guard = new StudentAdminGuard();
|
||||
Functions\when('wp_doing_ajax')->justReturn(false);
|
||||
}
|
||||
|
||||
/**
|
||||
* @param list<string> $held Capabilities the user is treated as holding.
|
||||
*/
|
||||
private function stubUser(bool $loggedIn, array $held = []): void
|
||||
{
|
||||
Functions\when('is_user_logged_in')->justReturn($loggedIn);
|
||||
Functions\when('current_user_can')->alias(static fn (string $cap): bool => in_array($cap, $held, true));
|
||||
}
|
||||
|
||||
public function testBlocksStudentWithNoBackOfficeCapabilities(): void
|
||||
{
|
||||
// A student holds only front-end capabilities.
|
||||
$this->stubUser(true, [RoleManager::CAP_BOOK_LESSON, RoleManager::CAP_VIEW_LESSONS]);
|
||||
|
||||
self::assertTrue($this->guard->shouldBlockAdminAccess());
|
||||
}
|
||||
|
||||
public function testAllowsInstructor(): void
|
||||
{
|
||||
$this->stubUser(true, [RoleManager::CAP_MANAGE_AVAILABILITY]);
|
||||
|
||||
self::assertFalse($this->guard->shouldBlockAdminAccess());
|
||||
}
|
||||
|
||||
public function testAllowsAdministrator(): void
|
||||
{
|
||||
$this->stubUser(true, ['manage_options']);
|
||||
|
||||
self::assertFalse($this->guard->shouldBlockAdminAccess());
|
||||
}
|
||||
|
||||
public function testDoesNotBlockLoggedOutRequests(): void
|
||||
{
|
||||
$this->stubUser(false);
|
||||
|
||||
self::assertFalse($this->guard->shouldBlockAdminAccess());
|
||||
}
|
||||
|
||||
public function testDoesNotBlockAjaxRequests(): void
|
||||
{
|
||||
Functions\when('wp_doing_ajax')->justReturn(true);
|
||||
$this->stubUser(true, [RoleManager::CAP_BOOK_LESSON]);
|
||||
|
||||
self::assertFalse($this->guard->shouldBlockAdminAccess());
|
||||
}
|
||||
|
||||
public function testHidesAdminBarForStudent(): void
|
||||
{
|
||||
$this->stubUser(true, [RoleManager::CAP_BOOK_LESSON]);
|
||||
|
||||
self::assertFalse($this->guard->hideAdminBar(true));
|
||||
}
|
||||
|
||||
public function testKeepsAdminBarForInstructor(): void
|
||||
{
|
||||
$this->stubUser(true, [RoleManager::CAP_MANAGE_AVAILABILITY]);
|
||||
|
||||
self::assertTrue($this->guard->hideAdminBar(true));
|
||||
}
|
||||
|
||||
public function testLeavesAdminBarUntouchedForLoggedOutVisitor(): void
|
||||
{
|
||||
$this->stubUser(false);
|
||||
|
||||
self::assertFalse($this->guard->hideAdminBar(false));
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user