Files
famous-ly4-ev/app-modules/shared/tests/Feature/ApiErrorEnvelopeTest.php
T
Nyan Lin Paing 46f9b8d5a3 Phase 6: security & ops hardening (T6.1-T6.5)
- T6.1: named rate limiters (api-read/api-write/api-auth/api-webhooks),
  applied per module route group with tighter limits on booking/payment
  writes and the KBZ webhook than read-only catalog/routing endpoints.
- T6.2: install spatie/laravel-activitylog; LogsActivity on Booking/
  Payment/Refund status transitions and catalog/pricing admin CRUD
  (EvCompany, Destination, DepartureTimeSlot, EvRoute, RoutePricing).
  New IdentityPlugin with a read-only AuditLogResource gated by
  view_audit_log.
- T6.3: JSON error envelope for api/* in bootstrap/app.php (401/403/404/
  405/429/500 fallback), plus PaymentGatewayException (422 declined /
  502 unavailable).
- T6.4: feature tests proving the FastAPI agent token gets 403 on
  refund/cancel-not-owned and 405 (no write handler) on catalog/routing
  writes.
- T6.5: install gboquizosanchez/filament-log-viewer with a custom
  Filament admin theme (required for its views' Tailwind classes to
  compile), LOG_CHANNEL/FILAMENT_LOG_VIEWER_DRIVER=daily, registered
  under Operations in the sidebar.

252 tests passing.
2026-08-09 20:59:00 +07:00

37 lines
1.2 KiB
PHP

<?php
use App\Models\User;
/**
* T6.3 — every exception reaching an api/* route gets a consistent JSON
* envelope, regardless of the client's Accept header, and never a bare
* unenveloped 500 (bootstrap/app.php).
*/
test('an unauthenticated request to a protected api route gets a 401 JSON envelope', function () {
$this->postJson('/api/v1/bookings/EVB-DOES-NOT-EXIST/cancel')
->assertUnauthorized()
->assertJsonStructure(['message']);
});
test('a route model binding miss on an api route gets a 404 JSON envelope', function () {
$user = User::factory()->create();
$token = $user->createToken('test')->plainTextToken;
$this->withHeader('Authorization', "Bearer {$token}")
->getJson('/api/v1/bookings/EVB-DOES-NOT-EXIST')
->assertNotFound()
->assertJsonStructure(['message']);
});
test('an unknown api route gets a 404 JSON envelope, not an HTML page', function () {
$this->getJson('/api/v1/this-route-does-not-exist')
->assertNotFound()
->assertJsonStructure(['message']);
});
test('an unsupported HTTP method on a known api route gets a 405 JSON envelope', function () {
$this->putJson('/api/v1/companies')
->assertStatus(405)
->assertJsonStructure(['message']);
});