Add invite-only group classes
CI / Tests (PHP 8.2) (pull_request) Successful in 44s
CI / Tests (PHP 8.1) (pull_request) Successful in 49s
CI / No Debug Code (pull_request) Successful in 2s
CI / PHPStan (pull_request) Successful in 2m49s
CI / Coding Standards (pull_request) Successful in 2m55s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m40s
CI / Build Plugin Zip (pull_request) Skipped

Group classes can now be marked invite-only (us_offerings.access_mode).
Invite-only classes are hidden from the public catalog and reachable only
when the instructor lets someone in via one of three paths, managed from
My Lessons -> My Group Classes:

- Add students directly: enrols them now with a pending payment.
- Make available: grants registered students access to self-enrol through
  the normal paid flow (multi-select, emailed a notice).
- Invite by email: tokenised registration invite tied to the class for a
  non-account address; after they register the class becomes enrollable.
  Reuses an existing pending invite instead of sending a second link.

New us_group_access table records grants; GET /offerings merges granted
invite-only classes for the caller; enrolment requires a grant
(403 invite_required) and flips it to enrolled on success.

composer test (487), composer lint, composer cs all pass.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
2026-07-23 13:51:02 -03:00
co-authored by Claude Opus 4.8
parent 25aeba9dc1
commit a281935811
33 changed files with 1598 additions and 38 deletions
+2 -1
View File
@@ -35,11 +35,12 @@ class InviteRepositoryTest extends TestCase
return $d['email'] === '[email protected]'
&& $d['token'] === 'tok123'
&& $d['kind'] === Invite::KIND_PERSONAL
&& $d['offering_id'] === null
&& $d['status'] === Invite::STATUS_PENDING
&& $d['invited_by'] === 2
&& $d['expires_at'] === null;
}),
['%s', '%s', '%s', '%s', '%s', '%d', '%d', '%s', '%s', '%s']
['%s', '%s', '%s', '%s', '%d', '%s', '%d', '%d', '%s', '%s', '%s']
);
$this->db->insert_id = 5;
+35 -1
View File
@@ -155,8 +155,42 @@ class InviteTest extends TestCase
{
$arr = (new Invite('[email protected]', 'tok', id: 1))->toArray();
foreach (['id', 'email', 'token', 'role', 'kind', 'status', 'invited_by', 'accepted_user_id', 'accepted_at', 'expires_at'] as $key) {
foreach (['id', 'email', 'token', 'role', 'kind', 'status', 'invited_by', 'accepted_user_id', 'accepted_at', 'expires_at', 'offering_id'] as $key) {
self::assertArrayHasKey($key, $arr);
}
}
public function testOfferingIdRoundTrips(): void
{
$invite = Invite::fromRow((object) [
'id' => '5',
'email' => '[email protected]',
'token' => 'tok123',
'role' => RoleManager::STUDENT,
'status' => Invite::STATUS_PENDING,
'invited_by' => '2',
'accepted_user_id' => null,
'accepted_at' => null,
'offering_id' => '8',
]);
self::assertSame(8, $invite->offeringId);
self::assertSame(8, $invite->toArray()['offering_id']);
}
public function testOfferingIdDefaultsToNullWhenColumnMissing(): void
{
$invite = Invite::fromRow((object) [
'id' => '5',
'email' => '[email protected]',
'token' => 'tok123',
'role' => RoleManager::STUDENT,
'status' => Invite::STATUS_PENDING,
'invited_by' => null,
'accepted_user_id' => null,
'accepted_at' => null,
]);
self::assertNull($invite->offeringId);
}
}
@@ -81,4 +81,42 @@ class RegistrationMailerTest extends TestCase
{
self::assertFalse((new RegistrationMailer())->sendRejected(''));
}
public function testSendClassAccessGrantedEmailsTheStudent(): void
{
Functions\expect('wp_mail')
->once()
->with(
'[email protected]',
Mockery::on(static fn (string $subject): bool => str_contains($subject, 'Choir')),
Mockery::on(static fn (string $body): bool => str_contains($body, 'Choir'))
)
->andReturn(true);
self::assertTrue((new RegistrationMailer())->sendClassAccessGranted($this->user('[email protected]'), 'Choir'));
}
public function testSendClassAccessGrantedReturnsFalseWithoutRecipient(): void
{
self::assertFalse((new RegistrationMailer())->sendClassAccessGranted($this->user(''), 'Choir'));
}
public function testSendClassInviteIncludesTheLink(): void
{
Functions\expect('wp_mail')
->once()
->with(
'[email protected]',
Mockery::type('string'),
Mockery::on(static fn (string $body): bool => str_contains($body, 'http://join.test'))
)
->andReturn(true);
self::assertTrue((new RegistrationMailer())->sendClassInvite('[email protected]', 'http://join.test', 'Choir'));
}
public function testSendClassInviteReturnsFalseWithoutRecipient(): void
{
self::assertFalse((new RegistrationMailer())->sendClassInvite('', 'http://join.test', 'Choir'));
}
}
+26
View File
@@ -9,6 +9,7 @@ use Unsupervised\Schedular\Auth\Invite;
use Unsupervised\Schedular\Auth\InviteRepository;
use Unsupervised\Schedular\Auth\RegistrationMailer;
use Unsupervised\Schedular\Auth\RegistrationPage;
use Unsupervised\Schedular\GroupClass\GroupAccessRepository;
use Unsupervised\Schedular\Payment\StudioSettings;
use Unsupervised\Schedular\Policy\AcceptanceRepository;
use Unsupervised\Schedular\Policy\Policy;
@@ -45,11 +46,15 @@ class RegistrationPageTest extends TestCase
$questions->shouldReceive('findByScope')->andReturn([])->byDefault();
$answers->shouldReceive('insert')->andReturn(1)->byDefault();
$access = Mockery::mock(GroupAccessRepository::class);
$access->shouldReceive('linkStudentByEmail')->andReturn(true)->byDefault();
$this->ctx = [
'invites' => $invites,
'policies' => $policies,
'questions' => $questions,
'answers' => $answers,
'access' => $access,
'mailer' => Mockery::mock(RegistrationMailer::class),
'settings' => Mockery::mock(StudioSettings::class),
];
@@ -63,6 +68,7 @@ class RegistrationPageTest extends TestCase
$this->ctx['mailer'],
$questions,
$answers,
$access,
);
$_POST = [];
@@ -110,6 +116,26 @@ class RegistrationPageTest extends TestCase
self::assertSame('invite', $this->submit($invite, false));
}
public function testInviteAcceptanceLinksClassGrantForTheEmail(): void
{
$_POST = [ 'password' => 'password123', 'display_name' => 'Ada' ];
Functions\when('email_exists')->justReturn(false);
Functions\when('wp_insert_user')->justReturn(42);
Functions\when('is_wp_error')->justReturn(false);
$this->ctx['invites']->shouldReceive('markAccepted')->once();
Functions\when('wp_set_current_user')->justReturn(null);
Functions\when('wp_set_auth_cookie')->justReturn(null);
// A personal invite tied to a class grant links the new account to it.
$this->ctx['access']->shouldReceive('linkStudentByEmail')->once()->with('[email protected]', 42)->andReturn(true);
$invite = new Invite(email: '[email protected]', token: 'hash', offeringId: 8);
self::assertSame('invite', $this->submit($invite, false));
}
public function testOpenBranchCreatesPendingWithoutLoginAndEmails(): void
{
$_POST = [ 'password' => 'password123', 'display_name' => 'Ada', 'email' => '[email protected]' ];