actingAs(User::factory()->create()); $this->get('/dashboard')->assertOk(); }); test('staff enforcement walks un-enrolled staff to the 2fa setup screen', function () { app(Settings::class)->set(Setting::TwoFactorEnforcement, 'staff'); $this->actingAs(User::factory()->create()); $this->get('/dashboard')->assertRedirect(route('two-factor.show')); }); test('staff enforcement leaves clients alone', function () { User::factory()->create(); app(Settings::class)->set(Setting::TwoFactorEnforcement, 'staff'); $this->actingAs(User::factory()->client()->create()); $this->get('/dashboard')->assertOk(); }); test('client enforcement walks un-enrolled clients to the 2fa setup screen', function () { User::factory()->create(); app(Settings::class)->set(Setting::TwoFactorEnforcement, 'clients'); $this->actingAs(User::factory()->client()->create()); $this->get('/dashboard')->assertRedirect(route('two-factor.show')); }); test('everyone enforcement covers both types', function () { app(Settings::class)->set(Setting::TwoFactorEnforcement, 'all'); $this->actingAs(User::factory()->create()); $this->get('/dashboard')->assertRedirect(route('two-factor.show')); $this->actingAs(User::factory()->client()->create()); $this->get('/dashboard')->assertRedirect(route('two-factor.show')); }); test('the 2fa setup screen itself and logout stay reachable under enforcement', function () { app(Settings::class)->set(Setting::TwoFactorEnforcement, 'all'); $this->actingAs(User::factory()->create()); $this->get('/settings/two-factor')->assertOk(); $this->post('/settings/two-factor')->assertRedirect(); $this->post('/logout')->assertRedirect('/'); }); test('enrolled users are not redirected under enforcement', function () { app(Settings::class)->set(Setting::TwoFactorEnforcement, 'all'); $user = User::factory()->create(['two_factor_confirmed_at' => now()]); $this->actingAs($user); $this->get('/dashboard')->assertOk(); }); test('staff can change the enforcement setting', function () { $this->actingAs(User::factory()->create()); $this->get('/system/settings/security')->assertInertia( fn (AssertableInertia $page) => $page ->component('system/settings/security') ->where('two_factor_enforcement', 'none'), ); $this->patch('/system/settings/security', [ 'two_factor_enforcement' => 'clients', 'password_min_length' => 12, 'password_reject_breached' => true, ])->assertRedirect(); expect(app(Settings::class)->get(Setting::TwoFactorEnforcement))->toBe('clients'); }); test('an invalid enforcement value is rejected', function () { $this->actingAs(User::factory()->create()); $this->patch('/system/settings/security', ['two_factor_enforcement' => 'sometimes']) ->assertSessionHasErrors('two_factor_enforcement'); }); test('clients cannot access security settings', function () { User::factory()->create(); $this->actingAs(User::factory()->client()->create()); $this->get('/system/settings/security')->assertRedirect(route('dashboard')); $this->patch('/system/settings/security', ['two_factor_enforcement' => 'all'])->assertForbidden(); });