From f979e18bd0e4e97a0b3b53a7027306e25031ec8c Mon Sep 17 00:00:00 2001 From: Yoga Pangestu Date: Thu, 30 Apr 2026 08:41:31 +0700 Subject: [PATCH] test: add feature tests for system and activity log modules authorization and access --- tests/Feature/Admin/System/LogTest.php | 82 ++++++++++++++++++++++++++ 1 file changed, 82 insertions(+) create mode 100644 tests/Feature/Admin/System/LogTest.php diff --git a/tests/Feature/Admin/System/LogTest.php b/tests/Feature/Admin/System/LogTest.php new file mode 100644 index 0000000..1130208 --- /dev/null +++ b/tests/Feature/Admin/System/LogTest.php @@ -0,0 +1,82 @@ +assertRedirect(route('login')); + get(route('system.activity-logs.index'))->assertRedirect(route('login')); + }); + + it('returns 403 when user has no permission to view logs', function () { + actingAs(createUnauthorizedUser()); + + get(route('system.logs.index'))->assertStatus(403); + get(route('system.activity-logs.index'))->assertStatus(403); + }); +}); + +describe('Log Module - Authorized Actions', function () { + beforeEach(function () { + $user = createAuthorizedUser([ + 'View:Log', + 'View:Activity', + ]); + actingAs($user); + }); + + it('can access system logs index page', function () { + // Create a dummy log file to ensure it doesn't crash if no logs exist + $path = storage_path('logs/laravel.log'); + if (! File::exists(storage_path('logs'))) { + File::makeDirectory(storage_path('logs'), 0755, true); + } + File::put($path, "[2026-04-30 08:00:00] local.INFO: Test log message\n"); + + get(route('system.logs.index')) + ->assertOk() + ->assertInertia(fn ($page) => $page + ->component('admin/system/logs/index') + ->has('logFiles') + ->has('logs') + ); + }); + + it('can access activity logs index page', function () { + // Create a dummy activity + activity() + ->useLog('TestModule') + ->log('Test Activity'); + + get(route('system.activity-logs.index')) + ->assertOk() + ->assertInertia(fn ($page) => $page + ->component('admin/system/activity-log/index') + ->has('activities') + ); + }); +}); + +describe('Log Module - Unauthorized Actions', function () { + beforeEach(function () { + actingAs(createUnauthorizedUser()); + }); + + it('cannot view system logs without permission', function () { + get(route('system.logs.index'))->assertStatus(403); + }); + + it('cannot view activity logs without permission', function () { + get(route('system.activity-logs.index'))->assertStatus(403); + }); +});