Fix field-length saves, student wp-admin access, and empty instructor picker
CI / Tests (PHP 8.1) (pull_request) Successful in 49s
CI / Tests (PHP 8.2) (pull_request) Successful in 49s
CI / No Debug Code (pull_request) Successful in 2s
CI / Coding Standards (pull_request) Successful in 2m47s
CI / PHPStan (pull_request) Successful in 3m16s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m41s
CI / Build Plugin Zip (pull_request) Skipped

Three bug fixes for the 1.2.1 section:

- Fixed-size fields (question labels, offering titles/notes/e-transfer
  email, policy titles/slugs) no longer silently fail to save when the
  value exceeds its column length. The REST endpoints reject over-long
  values with a 400, the admin controllers refuse to insert them, and the
  form inputs carry a maxlength so the browser blocks over-long entry.
  Limits are MAX_* constants on the value objects, kept in lockstep with
  the schema columns.

- Students are kept out of wp-admin entirely. New StudentAdminGuard
  redirects front-end-only users (no back-office capability) away from the
  dashboard and hides the admin bar for them, while administrators, studio
  admins, and instructors keep full access.

- The Add/Edit Offering instructor picker now includes WordPress
  administrators when they act as instructors (the default single-account
  setup), so a solo studio owner is selectable instead of the dropdown
  being empty.

composer test (618), composer lint, composer cs all pass.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
2026-07-24 20:22:04 -03:00
co-authored by Claude Opus 4.8
parent 3aa65bad06
commit 721c4be1d6
20 changed files with 561 additions and 20 deletions
@@ -0,0 +1,70 @@
<?php
declare(strict_types=1);
namespace Unsupervised\Schedular\Tests\Unit\Registration;
use Brain\Monkey\Functions;
use Mockery;
use Unsupervised\Schedular\Offering\Offering;
use Unsupervised\Schedular\Offering\OfferingRepository;
use Unsupervised\Schedular\Registration\Question;
use Unsupervised\Schedular\Registration\QuestionEndpoint;
use Unsupervised\Schedular\Registration\QuestionRepository;
use Unsupervised\Schedular\Tests\Unit\TestCase;
class QuestionEndpointTest extends TestCase
{
private QuestionRepository&Mockery\MockInterface $questions;
private OfferingRepository&Mockery\MockInterface $offerings;
private QuestionEndpoint $endpoint;
protected function setUp(): void
{
parent::setUp();
Functions\when('get_current_user_id')->justReturn(5);
Functions\when('current_user_can')->justReturn(false);
Functions\when('absint')->alias(static fn ($v): int => abs((int) $v));
Functions\when('sanitize_text_field')->returnArg();
$this->questions = Mockery::mock(QuestionRepository::class);
$this->offerings = Mockery::mock(OfferingRepository::class);
$this->endpoint = new QuestionEndpoint($this->questions, $this->offerings);
// The caller (instructor 5) owns offering 9, so the ownership gate passes
// and validation is reached.
$this->offerings->shouldReceive('findById')->with(9)->andReturn(
new Offering(instructorId: 5, kind: Offering::KIND_GROUP_CLASS, title: 'Choir', id: 9)
);
}
public function testCreateRejectsLabelLongerThanColumnLimit(): void
{
// The insert must never be attempted for an over-long label — the bug was
// that it reached the DB, silently failed, and returned success anyway.
$this->questions->shouldNotReceive('insert');
$request = new \WP_REST_Request([
'offering_id' => 9,
'label' => str_repeat('a', Question::MAX_LABEL_LENGTH + 1),
]);
$response = $this->endpoint->create($request);
self::assertInstanceOf(\WP_Error::class, $response);
self::assertSame(400, $response->error_data['invalid_question']['status']);
}
public function testCreateAcceptsLabelAtColumnLimit(): void
{
$this->questions->shouldReceive('insert')->once()->andReturn(42);
$request = new \WP_REST_Request([
'offering_id' => 9,
'label' => str_repeat('a', Question::MAX_LABEL_LENGTH),
]);
$response = $this->endpoint->create($request);
self::assertInstanceOf(\WP_REST_Response::class, $response);
self::assertSame(201, $response->get_status());
}
}