Files
unsupervised-scheduler/tests/Unit/Offering/OfferingEndpointTest.php
T
thatguygriffandClaude Opus 5 0f30f28e92
CI / Tests (PHP 8.1) (pull_request) Successful in 46s
CI / No Debug Code (pull_request) Successful in 2s
CI / Tests (PHP 8.2) (pull_request) Successful in 56s
CI / PHPStan (pull_request) Successful in 2m56s
CI / Coding Standards (pull_request) Successful in 2m58s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m41s
CI / Build Plugin Zip (pull_request) Skipped
Let offering managers read the offerings catalogue
The block editor's group-class picker fetches GET /offerings, whose
permission callback only accepted book_lesson — a capability held by
students alone. Administrators and instructors editing a page were
rejected with a 403 and the picker silently rendered an empty list.

Read access now accepts book_lesson or manage_offerings. The listing is
unchanged: active offerings only, public ones plus the invite-only
classes the caller has been granted, without the e-transfer email.

Closes #121

Co-Authored-By: Claude Opus 5 <[email protected]>
2026-07-28 12:54:58 -03:00

192 lines
7.6 KiB
PHP

<?php
declare(strict_types=1);
namespace Unsupervised\Schedular\Tests\Unit\Offering;
use Brain\Monkey\Functions;
use Mockery;
use Unsupervised\Schedular\Auth\RoleManager;
use Unsupervised\Schedular\GroupClass\GroupAccessRepository;
use Unsupervised\Schedular\Offering\Offering;
use Unsupervised\Schedular\Offering\OfferingEndpoint;
use Unsupervised\Schedular\Offering\OfferingRepository;
use Unsupervised\Schedular\Tests\Unit\TestCase;
class OfferingEndpointTest extends TestCase
{
private OfferingRepository&Mockery\MockInterface $repository;
private GroupAccessRepository&Mockery\MockInterface $access;
private OfferingEndpoint $endpoint;
protected function setUp(): void
{
parent::setUp();
Functions\when('get_current_user_id')->justReturn(5);
Functions\when('get_userdata')->justReturn((object) ['display_name' => 'Ada Lovelace']);
$this->repository = Mockery::mock(OfferingRepository::class);
$this->access = Mockery::mock(GroupAccessRepository::class);
$this->endpoint = new OfferingEndpoint($this->repository, $this->access);
}
private function group(int $id, string $access): Offering
{
return new Offering(instructorId: 3, kind: Offering::KIND_GROUP_CLASS, title: "Class $id", accessMode: $access, id: $id);
}
public function testIndexReturnsPublicOfferingsOnlyWhenNoGrants(): void
{
$this->repository->shouldReceive('findAll')
->once()
->with(0, '', Mockery::on(static fn ($v): bool => true === $v), Offering::ACCESS_PUBLIC)
->andReturn([$this->group(1, Offering::ACCESS_PUBLIC)]);
$this->access->shouldReceive('findGrantedOfferingIds')->with(5)->andReturn([]);
$data = $this->endpoint->index(new \WP_REST_Request())->get_data();
self::assertCount(1, $data);
self::assertSame(1, $data[0]['id']);
}
public function testIndexMergesGrantedInviteOnlyOfferings(): void
{
$this->repository->shouldReceive('findAll')
->once()
->with(0, '', Mockery::any(), Offering::ACCESS_PUBLIC)
->andReturn([$this->group(1, Offering::ACCESS_PUBLIC)]);
$this->access->shouldReceive('findGrantedOfferingIds')->with(5)->andReturn([8]);
$this->repository->shouldReceive('findById')->with(8)->andReturn($this->group(8, Offering::ACCESS_INVITE_ONLY));
$data = $this->endpoint->index(new \WP_REST_Request())->get_data();
self::assertSame([1, 8], array_column($data, 'id'));
}
public function testIndexOmitsGrantedOfferingThatIsNoLongerInviteOnly(): void
{
$this->repository->shouldReceive('findAll')->andReturn([]);
$this->access->shouldReceive('findGrantedOfferingIds')->with(5)->andReturn([8]);
// Grant persists but the class was flipped back to public — it is already
// in the public list, so it must not be appended a second time.
$this->repository->shouldReceive('findById')->with(8)->andReturn($this->group(8, Offering::ACCESS_PUBLIC));
$data = $this->endpoint->index(new \WP_REST_Request())->get_data();
self::assertSame([], $data);
}
public function testIndexRespectsKindFilterForGrantedOfferings(): void
{
$this->repository->shouldReceive('findAll')
->with(0, Offering::KIND_PRIVATE_LESSON, Mockery::any(), Offering::ACCESS_PUBLIC)
->andReturn([]);
$this->access->shouldReceive('findGrantedOfferingIds')->with(5)->andReturn([8]);
// Granted class is a group class; the request filters to private lessons.
$this->repository->shouldReceive('findById')->with(8)->andReturn($this->group(8, Offering::ACCESS_INVITE_ONLY));
$data = $this->endpoint->index(new \WP_REST_Request(['kind' => Offering::KIND_PRIVATE_LESSON]))->get_data();
self::assertSame([], $data);
}
public function testIndexIncludesInstructorNameForEachOffering(): void
{
$instructor = Mockery::mock(\WP_User::class);
$instructor->first_name = 'Ada';
$instructor->last_name = 'Lovelace';
$instructor->nickname = 'ada_login';
$instructor->display_name = 'ada_login';
Functions\when('get_userdata')->justReturn($instructor);
$this->repository->shouldReceive('findAll')->andReturn([$this->group(1, Offering::ACCESS_PUBLIC)]);
$this->access->shouldReceive('findGrantedOfferingIds')->with(5)->andReturn([]);
$data = $this->endpoint->index(new \WP_REST_Request())->get_data();
// Real name is shown, not the login-style display name.
self::assertSame('Ada Lovelace', $data[0]['instructor_name']);
}
public function testIndexOmitsEtransferEmailFromPublicListing(): void
{
$this->repository->shouldReceive('findAll')->andReturn([
new Offering(instructorId: 3, kind: Offering::KIND_GROUP_CLASS, title: 'Choir', etransferEmail: '[email protected]', id: 1),
]);
$this->access->shouldReceive('findGrantedOfferingIds')->with(5)->andReturn([]);
$data = $this->endpoint->index(new \WP_REST_Request())->get_data();
self::assertArrayNotHasKey('etransfer_email', $data[0]);
}
public function testCanReadAllowsStudentsWhoMayBook(): void
{
Functions\when('is_user_logged_in')->justReturn(true);
Functions\when('current_user_can')->alias(
static fn (string $cap): bool => RoleManager::CAP_BOOK_LESSON === $cap
);
self::assertTrue($this->endpoint->canRead());
}
public function testCanReadAllowsOfferingManagersWhoCannotBook(): void
{
Functions\when('is_user_logged_in')->justReturn(true);
Functions\when('current_user_can')->alias(
static fn (string $cap): bool => RoleManager::CAP_MANAGE_OFFERINGS === $cap
);
self::assertTrue($this->endpoint->canRead());
}
public function testCanReadRejectsLoggedInUserWithNeitherCapability(): void
{
Functions\when('is_user_logged_in')->justReturn(true);
Functions\when('current_user_can')->justReturn(false);
self::assertFalse($this->endpoint->canRead());
}
public function testCanReadRejectsLoggedOutVisitors(): void
{
Functions\when('is_user_logged_in')->justReturn(false);
Functions\when('current_user_can')->justReturn(true);
self::assertFalse($this->endpoint->canRead());
}
public function testCreateRejectsTitleLongerThanColumnLimit(): void
{
Functions\when('sanitize_text_field')->returnArg();
Functions\when('sanitize_email')->returnArg();
$this->repository->shouldNotReceive('insert');
$request = new \WP_REST_Request([
'kind' => Offering::KIND_GROUP_CLASS,
'title' => str_repeat('a', Offering::MAX_TITLE_LENGTH + 1),
]);
$response = $this->endpoint->create($request);
self::assertInstanceOf(\WP_Error::class, $response);
self::assertSame(400, $response->error_data['invalid_offering']['status']);
}
public function testCreateRejectsScheduleNoteLongerThanColumnLimit(): void
{
Functions\when('sanitize_text_field')->returnArg();
Functions\when('sanitize_email')->returnArg();
$this->repository->shouldNotReceive('insert');
$request = new \WP_REST_Request([
'kind' => Offering::KIND_GROUP_CLASS,
'title' => 'Choir',
'schedule_note' => str_repeat('a', Offering::MAX_SCHEDULE_NOTE_LENGTH + 1),
]);
$response = $this->endpoint->create($request);
self::assertInstanceOf(\WP_Error::class, $response);
self::assertSame(400, $response->error_data['invalid_offering']['status']);
}
}