viewAny(User::factory()->create()))->toBeTrue(); }); test('view allows the booking\'s owner', function () { $policy = new BookingPolicy; $owner = User::factory()->create(); $booking = Booking::factory()->create(['user_id' => $owner->id]); expect($policy->view($owner, $booking))->toBeTrue(); }); test('view rejects a non-owner without the view_bookings permission', function () { $policy = new BookingPolicy; $stranger = User::factory()->create(); $booking = Booking::factory()->create(['user_id' => User::factory()->create()->id]); expect($policy->view($stranger, $booking))->toBeFalse(); }); test('view allows a non-owner with the view_bookings permission (admin/support)', function () { $policy = new BookingPolicy; $admin = User::factory()->create()->givePermissionTo('view_bookings'); $booking = Booking::factory()->create(['user_id' => User::factory()->create()->id]); expect($policy->view($admin, $booking))->toBeTrue(); }); test('create is open to any authenticated user', function () { $policy = new BookingPolicy; expect($policy->create(User::factory()->create()))->toBeTrue(); }); test('cancel allows the booking\'s owner', function () { $policy = new BookingPolicy; $owner = User::factory()->create(); $booking = Booking::factory()->create(['user_id' => $owner->id]); expect($policy->cancel($owner, $booking))->toBeTrue(); }); test('cancel allows staff with the manage_bookings permission on someone else\'s booking', function () { $policy = new BookingPolicy; $staff = User::factory()->create()->givePermissionTo('manage_bookings'); $booking = Booking::factory()->create(['user_id' => User::factory()->create()->id]); expect($policy->cancel($staff, $booking))->toBeTrue(); }); test('cancel rejects a non-owner without the manage_bookings permission', function () { $policy = new BookingPolicy; $stranger = User::factory()->create(); $booking = Booking::factory()->create(['user_id' => User::factory()->create()->id]); expect($policy->cancel($stranger, $booking))->toBeFalse(); }); test('refund requires the process_refunds permission', function () { $policy = new BookingPolicy; $withPermission = User::factory()->create()->givePermissionTo('process_refunds'); $withoutPermission = User::factory()->create(); expect($policy->refund($withPermission, null))->toBeTrue() ->and($policy->refund($withoutPermission, null))->toBeFalse(); }); test('delete allows staff with manage_bookings on a cancelled booking', function () { $policy = new BookingPolicy; $staff = User::factory()->create()->givePermissionTo('manage_bookings'); $booking = Booking::factory()->create(['status' => BookingStatus::Cancelled]); expect($policy->delete($staff, $booking))->toBeTrue(); }); test('delete allows staff with manage_bookings on an expired booking', function () { $policy = new BookingPolicy; $staff = User::factory()->create()->givePermissionTo('manage_bookings'); $booking = Booking::factory()->create(['status' => BookingStatus::Expired]); expect($policy->delete($staff, $booking))->toBeTrue(); }); test('delete rejects a pending_payment or confirmed booking even with manage_bookings', function () { $policy = new BookingPolicy; $staff = User::factory()->create()->givePermissionTo('manage_bookings'); $pending = Booking::factory()->create(['status' => BookingStatus::PendingPayment]); $confirmed = Booking::factory()->create(['status' => BookingStatus::Confirmed]); expect($policy->delete($staff, $pending))->toBeFalse() ->and($policy->delete($staff, $confirmed))->toBeFalse(); }); test('delete rejects a cancelled booking without manage_bookings, even for the owner', function () { $policy = new BookingPolicy; $owner = User::factory()->create(); $booking = Booking::factory()->create(['user_id' => $owner->id, 'status' => BookingStatus::Cancelled]); expect($policy->delete($owner, $booking))->toBeFalse(); }); test('restore requires the manage_bookings permission', function () { $policy = new BookingPolicy; $staff = User::factory()->create()->givePermissionTo('manage_bookings'); $stranger = User::factory()->create(); $booking = Booking::factory()->create(); expect($policy->restore($staff, $booking))->toBeTrue() ->and($policy->restore($stranger, $booking))->toBeFalse(); });