Files
fotospiel-app/tests/Feature/Auth/LoginTest.php

159 lines
5.1 KiB
PHP

<?php
namespace Tests\Feature\Auth;
use App\Models\User;
use Illuminate\Foundation\Testing\RefreshDatabase;
use Illuminate\Support\Facades\Auth;
use Tests\TestCase;
class LoginTest extends TestCase
{
use RefreshDatabase;
public function test_successful_login_with_valid_credentials()
{
$user = User::factory()->create([
'email' => 'valid@example.com',
'password' => bcrypt('password'),
'email_verified_at' => now(),
]);
$response = $this->post(route('login.store'), [
'login' => 'valid@example.com',
'password' => 'password',
]);
$this->assertAuthenticated();
$expectedDefault = rtrim(route('tenant.admin.app', absolute: false), '/').'/events';
$response->assertRedirect($expectedDefault);
$this->assertEquals('valid@example.com', Auth::user()->email);
}
public function test_successful_login_with_username()
{
$user = User::factory()->create([
'username' => 'validuser',
'password' => bcrypt('password'),
'email_verified_at' => now(),
]);
$response = $this->post(route('login.store'), [
'login' => 'validuser',
'password' => 'password',
]);
$this->assertAuthenticated();
$expectedDefault = rtrim(route('tenant.admin.app', absolute: false), '/').'/events';
$response->assertRedirect($expectedDefault);
$this->assertEquals('validuser', Auth::user()->username);
}
public function test_login_fails_with_invalid_credentials()
{
User::factory()->create([
'email' => 'invalid@example.com',
'password' => bcrypt('password'),
]);
$response = $this->post(route('login.store'), [
'login' => 'invalid@example.com',
'password' => 'wrongpassword',
]);
$this->assertGuest();
$response->assertStatus(302);
$response->assertRedirect(route('login', absolute: false));
$response->assertSessionHasErrors(['login' => 'Diese Anmeldedaten wurden nicht gefunden.']);
$response->assertSessionHas('error', 'Diese Anmeldedaten wurden nicht gefunden.');
}
public function test_login_success_shows_success_flash()
{
$user = User::factory()->create([
'email' => 'success@example.com',
'password' => bcrypt('password'),
'email_verified_at' => now(),
]);
$response = $this->post(route('login.store'), [
'login' => 'success@example.com',
'password' => 'password',
]);
$this->assertAuthenticated();
$expected = rtrim(route('tenant.admin.app', absolute: false), '/').'/events';
$response->assertRedirect($expected);
$response->assertSessionHas('success', 'Sie sind nun eingeloggt.');
}
public function test_login_honors_return_to_parameter()
{
$user = User::factory()->create([
'email' => 'return@example.com',
'password' => bcrypt('password'),
'email_verified_at' => now(),
]);
$target = route('tenant.admin.app', absolute: false);
$encoded = rtrim(strtr(base64_encode($target), '+/', '-_'), '=');
$response = $this->post(route('login.store'), [
'login' => 'return@example.com',
'password' => 'password',
'return_to' => $encoded,
]);
$this->assertAuthenticated();
$response->assertRedirect($target);
}
public function test_login_redirects_unverified_user_to_verification_notice()
{
$user = User::factory()->create([
'email' => 'unverified@example.com',
'password' => bcrypt('password'),
'email_verified_at' => null,
]);
$response = $this->post(route('login.store'), [
'login' => 'unverified@example.com',
'password' => 'password',
]);
$this->assertAuthenticated();
$response->assertRedirect(route('verification.notice', absolute: false));
}
public function test_rate_limiting_on_failed_logins()
{
$user = User::factory()->create([
'email' => 'ratelimit@example.com',
'password' => bcrypt('password'),
]);
// Simulate 5 failed attempts
for ($i = 0; $i < 5; $i++) {
$response = $this->post(route('login.store'), [
'login' => 'ratelimit@example.com',
'password' => 'wrongpassword',
]);
$response->assertStatus(302);
$response->assertSessionHasErrors(['login' => 'Diese Anmeldedaten wurden nicht gefunden.']);
}
$response = $this->post(route('login.store'), [
'login' => 'ratelimit@example.com',
'password' => 'wrongpassword',
]);
$this->assertGuest();
$response->assertStatus(302);
$response->assertSessionHasErrors(['login']);
$this->assertStringContainsString(
'Zu viele Login-Versuche.',
collect(session('errors')->get('login'))->first()
);
}
}