<?php

namespace Tests\Feature\Auth;

use App\Models\Auth\User;
use Illuminate\Foundation\Testing\RefreshDatabase;
use Livewire\Volt\Volt;
use Spatie\Permission\Models\Permission;
use Tests\TestCase;

class AuthenticationTest extends TestCase
{
    use RefreshDatabase;

    /**
     * Crea un permiso y lo asigna al usuario.
     *
     * La tabla `permissions` de este proyecto añade `model` (NOT NULL) y
     * `description`, así que `Permission::findOrCreate()` no sirve.
     */
    private function givePermission(User $user, string $name, string $model): void
    {
        Permission::firstOrCreate(
            ['name' => $name, 'guard_name' => 'web'],
            ['model' => $model, 'description' => $name]
        );

        $user->givePermissionTo($name);
    }

    public function test_login_screen_can_be_rendered(): void
    {
        $response = $this->get('/login');

        $response
            ->assertOk()
            ->assertSeeVolt('pages.auth.login');
    }

    public function test_users_can_authenticate_using_the_login_screen(): void
    {
        $user = User::factory()->create();

        $component = Volt::test('pages.auth.login')
            ->set('form.email', $user->email)
            ->set('form.password', 'password');

        $component->call('login');

        $component
            ->assertHasNoErrors()
            ->assertRedirect(route('dashboard', absolute: false));

        $this->assertAuthenticated();
    }

    public function test_users_can_not_authenticate_with_invalid_password(): void
    {
        $user = User::factory()->create();

        $component = Volt::test('pages.auth.login')
            ->set('form.email', $user->email)
            ->set('form.password', 'wrong-password');

        $component->call('login');

        $component
            ->assertHasErrors()
            ->assertNoRedirect();

        $this->assertGuest();
    }

    public function test_navigation_menu_can_be_rendered(): void
    {
        $user = User::factory()->create();

        // El dashboard exige `admin.dashboard.index`: un usuario sin permisos recibe
        // 403, no 200. El test venía de Breeze, que no conoce Spatie Permission.
        $this->givePermission($user, 'admin.dashboard.index', 'dashboard');

        $this->actingAs($user);

        $response = $this->get('/dashboard');

        $response
            ->assertOk()
            ->assertSeeVolt('layout.navigation');
    }

    public function test_el_dashboard_exige_permiso(): void
    {
        // La contraparte del test anterior: sin el permiso no se entra. Fija que el
        // gate del dashboard sigue puesto.
        $this->actingAs(User::factory()->create());

        $this->get('/dashboard')->assertForbidden();
    }

    public function test_users_can_logout(): void
    {
        $user = User::factory()->create();

        $this->actingAs($user);

        $component = Volt::test('layout.navigation');

        $component->call('logout');

        $component
            ->assertHasNoErrors()
            // Este panel no tiene parte pública: al salir se va a /login, no a la
            // raíz (ver Layout\Navigation::logout()). Breeze esperaba '/'.
            ->assertRedirect('/login');

        $this->assertGuest();
    }
}
