- $book = Book::query()->first();
- $this->setEntityRestrictions($book);
-
- try {
- $this->visit($book->getUrl());
- } catch (\Exception $exception) {}
-
- $this->see('Book not found')
- ->dontSee($book->name)
- ->visit('/login')
- ->type('password', '#password')
- ->press('Log In')
- ->seePageUrlIs($book->getUrl())
- ->see($book->name);
+ $book = $this->entities->book();
+ $this->permissions->setEntityPermissions($book);
+
+ $resp = $this->get($book->getUrl());
+ $resp->assertSee('Book not found');
+
+ $this->get('/login');
+ $resp = $this->post('/login', ['email' => '
[email protected]', 'password' => 'password']);
+ $resp->assertRedirect($book->getUrl());
+ $this->followRedirects($resp)->assertSee($book->name);
+ }
+
+ public function test_public_view_can_take_on_other_roles()
+ {
+ $this->setSettings(['app-public' => 'true']);
+ $newRole = $this->users->attachNewRole(User::getDefault(), []);
+ $page = $this->entities->page();
+ $this->permissions->disableEntityInheritedPermissions($page);
+ $this->permissions->addEntityPermission($page, ['view', 'update'], $newRole);
+
+ $resp = $this->get($page->getUrl());
+ $resp->assertOk();
+
+ $this->withHtml($resp)->assertLinkExists($page->getUrl('/edit'));
+ }
+
+ public function test_public_user_cannot_view_or_update_their_profile()
+ {
+ $this->setSettings(['app-public' => 'true']);
+ $guest = $this->users->guest();
+
+ $resp = $this->get($guest->getEditUrl());
+ $this->assertPermissionError($resp);
+
+ $resp = $this->put($guest->getEditUrl(), ['name' => 'My new guest name']);
+ $this->assertPermissionError($resp);