2026-09-04 11:28:59 +01:00
|
|
|
<?php
|
|
|
|
|
|
|
|
|
|
declare(strict_types=1);
|
|
|
|
|
|
|
|
|
|
namespace Tests;
|
|
|
|
|
|
|
|
|
|
final class ProjectTest extends ApiTestCase
|
|
|
|
|
{
|
|
|
|
|
public function test_projects_require_authentication(): void
|
|
|
|
|
{
|
|
|
|
|
self::assertSame(401, $this->request('GET', '/api/projects')->getStatusCode());
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public function test_create_and_list_projects(): void
|
|
|
|
|
{
|
|
|
|
|
$auth = $this->authHeader();
|
|
|
|
|
|
2026-09-05 01:25:53 +01:00
|
|
|
$created = $this->request('POST', '/api/projects', ['title' => ' Groceries '], $auth);
|
2026-09-04 11:28:59 +01:00
|
|
|
|
|
|
|
|
self::assertSame(201, $created->getStatusCode());
|
|
|
|
|
$project = $this->decode($created)['project'];
|
|
|
|
|
self::assertSame('Groceries', $project['title']);
|
|
|
|
|
self::assertSame(0, $project['card_count']);
|
|
|
|
|
|
|
|
|
|
$index = $this->decode($this->request('GET', '/api/projects', null, $auth));
|
|
|
|
|
self::assertCount(1, $index['projects']);
|
|
|
|
|
self::assertSame($project['id'], $index['projects'][0]['id']);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public function test_projects_come_back_alphabetically(): void
|
|
|
|
|
{
|
|
|
|
|
$auth = $this->authHeader();
|
|
|
|
|
|
|
|
|
|
foreach (['Banana', 'apple', 'Cherry'] as $title) {
|
|
|
|
|
$this->request('POST', '/api/projects', ['title' => $title], $auth);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
$titles = array_column($this->decode($this->request('GET', '/api/projects', null, $auth))['projects'], 'title');
|
|
|
|
|
self::assertSame(['apple', 'Banana', 'Cherry'], $titles);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public function test_an_owner_cannot_exceed_100_projects(): void
|
|
|
|
|
{
|
|
|
|
|
$auth = $this->authHeader();
|
|
|
|
|
|
|
|
|
|
for ($i = 1; $i <= 100; $i++) {
|
|
|
|
|
$response = $this->request('POST', '/api/projects', ['title' => "Project {$i}"], $auth);
|
|
|
|
|
self::assertSame(201, $response->getStatusCode(), "project {$i} should be created");
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
$overflow = $this->request('POST', '/api/projects', ['title' => 'One too many'], $auth);
|
|
|
|
|
self::assertSame(409, $overflow->getStatusCode());
|
|
|
|
|
self::assertStringContainsString('100', $this->decode($overflow)['error']['message']);
|
|
|
|
|
|
|
|
|
|
// The cap is per owner, so a different user is unaffected.
|
|
|
|
|
$other = $this->authHeader('roomy@example.com');
|
|
|
|
|
self::assertSame(201, $this->request('POST', '/api/projects', ['title' => 'Fine'], $other)->getStatusCode());
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public function test_project_creation_validates_title(): void
|
|
|
|
|
{
|
2026-09-05 01:25:53 +01:00
|
|
|
$response = $this->request('POST', '/api/projects', [], $this->authHeader());
|
2026-09-04 11:28:59 +01:00
|
|
|
|
|
|
|
|
self::assertSame(422, $response->getStatusCode());
|
|
|
|
|
self::assertArrayHasKey('title', $this->decode($response)['error']['details']);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public function test_a_project_is_only_visible_to_its_owner(): void
|
|
|
|
|
{
|
|
|
|
|
$owner = $this->authHeader('owner@example.com');
|
|
|
|
|
$other = $this->authHeader('other@example.com');
|
|
|
|
|
|
|
|
|
|
$projectId = $this->decode(
|
|
|
|
|
$this->request('POST', '/api/projects', ['title' => 'Private'], $owner),
|
|
|
|
|
)['project']['id'];
|
|
|
|
|
|
|
|
|
|
self::assertSame(200, $this->request('GET', "/api/projects/{$projectId}", null, $owner)->getStatusCode());
|
|
|
|
|
self::assertSame(404, $this->request('GET', "/api/projects/{$projectId}", null, $other)->getStatusCode());
|
|
|
|
|
self::assertSame(404, $this->request('PATCH', "/api/projects/{$projectId}", ['title' => 'x'], $other)->getStatusCode());
|
|
|
|
|
self::assertSame(404, $this->request('DELETE', "/api/projects/{$projectId}", null, $other)->getStatusCode());
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public function test_update_and_delete_project(): void
|
|
|
|
|
{
|
|
|
|
|
$auth = $this->authHeader();
|
|
|
|
|
$projectId = $this->decode(
|
|
|
|
|
$this->request('POST', '/api/projects', ['title' => 'Draft'], $auth),
|
|
|
|
|
)['project']['id'];
|
|
|
|
|
|
|
|
|
|
$updated = $this->decode(
|
|
|
|
|
$this->request('PATCH', "/api/projects/{$projectId}", ['title' => 'Final'], $auth),
|
|
|
|
|
)['project'];
|
|
|
|
|
self::assertSame('Final', $updated['title']);
|
|
|
|
|
|
|
|
|
|
self::assertSame(204, $this->request('DELETE', "/api/projects/{$projectId}", null, $auth)->getStatusCode());
|
|
|
|
|
self::assertSame(404, $this->request('GET', "/api/projects/{$projectId}", null, $auth)->getStatusCode());
|
|
|
|
|
}
|
|
|
|
|
|
2026-09-04 15:22:33 +01:00
|
|
|
public function test_cards_land_in_the_first_status_and_track_completion(): void
|
2026-09-04 11:28:59 +01:00
|
|
|
{
|
|
|
|
|
$auth = $this->authHeader();
|
|
|
|
|
$projectId = $this->decode(
|
|
|
|
|
$this->request('POST', '/api/projects', ['title' => 'Chores'], $auth),
|
|
|
|
|
)['project']['id'];
|
2026-09-04 15:22:33 +01:00
|
|
|
$firstStatus = $this->decode(
|
|
|
|
|
$this->request('GET', "/api/projects/{$projectId}/statuses", null, $auth),
|
|
|
|
|
)['statuses'][0];
|
2026-09-04 11:28:59 +01:00
|
|
|
|
|
|
|
|
foreach (['Wash up', 'Hoover', 'Bins'] as $text) {
|
|
|
|
|
$this->request('POST', "/api/projects/{$projectId}/cards", ['text' => $text], $auth);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
$cards = $this->decode($this->request('GET', "/api/projects/{$projectId}/cards", null, $auth))['cards'];
|
|
|
|
|
self::assertSame(['Wash up', 'Hoover', 'Bins'], array_column($cards, 'text'));
|
|
|
|
|
self::assertSame([0, 1, 2], array_column($cards, 'position'));
|
2026-09-04 15:22:33 +01:00
|
|
|
self::assertSame([$firstStatus['id'], $firstStatus['id'], $firstStatus['id']], array_column($cards, 'status_id'));
|
2026-09-04 11:28:59 +01:00
|
|
|
self::assertFalse($cards[0]['complete']);
|
|
|
|
|
|
|
|
|
|
$done = $this->decode(
|
2026-09-04 15:22:33 +01:00
|
|
|
$this->request('PATCH', "/api/cards/{$cards[0]['id']}", ['complete' => true], $auth),
|
2026-09-04 11:28:59 +01:00
|
|
|
)['card'];
|
|
|
|
|
self::assertTrue($done['complete']);
|
|
|
|
|
|
|
|
|
|
$project = $this->decode($this->request('GET', "/api/projects/{$projectId}", null, $auth))['project'];
|
|
|
|
|
self::assertSame(3, $project['card_count']);
|
|
|
|
|
self::assertSame(1, $project['completed_count']);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public function test_card_creation_accepts_explicit_position_and_validates_text(): void
|
|
|
|
|
{
|
|
|
|
|
$auth = $this->authHeader();
|
|
|
|
|
$projectId = $this->decode(
|
|
|
|
|
$this->request('POST', '/api/projects', ['title' => 'P'], $auth),
|
|
|
|
|
)['project']['id'];
|
|
|
|
|
|
|
|
|
|
$card = $this->decode(
|
|
|
|
|
$this->request('POST', "/api/projects/{$projectId}/cards", ['text' => 'Pinned', 'position' => 5], $auth),
|
|
|
|
|
)['card'];
|
|
|
|
|
self::assertSame(5, $card['position']);
|
|
|
|
|
|
|
|
|
|
$bad = $this->request('POST', "/api/projects/{$projectId}/cards", ['text' => ' '], $auth);
|
|
|
|
|
self::assertSame(422, $bad->getStatusCode());
|
|
|
|
|
self::assertArrayHasKey('text', $this->decode($bad)['error']['details']);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public function test_deleting_a_project_cascades_to_its_cards(): void
|
|
|
|
|
{
|
|
|
|
|
$auth = $this->authHeader();
|
|
|
|
|
$projectId = $this->decode(
|
|
|
|
|
$this->request('POST', '/api/projects', ['title' => 'Temp'], $auth),
|
|
|
|
|
)['project']['id'];
|
|
|
|
|
$cardId = $this->decode(
|
|
|
|
|
$this->request('POST', "/api/projects/{$projectId}/cards", ['text' => 'x'], $auth),
|
|
|
|
|
)['card']['id'];
|
|
|
|
|
|
|
|
|
|
$this->request('DELETE', "/api/projects/{$projectId}", null, $auth);
|
|
|
|
|
|
2026-09-04 15:22:33 +01:00
|
|
|
// The card went with its project.
|
|
|
|
|
self::assertSame(404, $this->request('GET', "/api/cards/{$cardId}", null, $auth)->getStatusCode());
|
2026-09-04 11:28:59 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public function test_cards_under_another_users_project_are_not_reachable(): void
|
|
|
|
|
{
|
|
|
|
|
$owner = $this->authHeader('owner2@example.com');
|
|
|
|
|
$other = $this->authHeader('other2@example.com');
|
|
|
|
|
|
|
|
|
|
$projectId = $this->decode(
|
|
|
|
|
$this->request('POST', '/api/projects', ['title' => 'Mine'], $owner),
|
|
|
|
|
)['project']['id'];
|
|
|
|
|
|
|
|
|
|
self::assertSame(
|
|
|
|
|
404,
|
|
|
|
|
$this->request('POST', "/api/projects/{$projectId}/cards", ['text' => 'sneaky'], $other)->getStatusCode(),
|
|
|
|
|
);
|
|
|
|
|
self::assertSame(
|
|
|
|
|
404,
|
|
|
|
|
$this->request('GET', "/api/projects/{$projectId}/cards", null, $other)->getStatusCode(),
|
|
|
|
|
);
|
|
|
|
|
}
|
|
|
|
|
}
|