Files
XC_VM/tests/Unit/ActiveCodePackageRuleTest.php
T
rootandClaude Opus 5 e52c451e3c fix(security): resellers generate activation codes on their own terms only
ActiveCodeService::generateCodes and massAction took several values from the
reseller's request that the reseller pages never send:

- package_id: any package, not only those the reseller's group sells.
- is_trial=1: priced the codes at the package's trial_credits (usually 0)
  while issuing them as that package's official codes.
- max_connections: any connection count.
- change_package: any package, with no group check.
- enable: also set admin_enabled = 1, lifting an administrator's ban on the
  code's line.

For non-admin callers the package must now be a line package offered to the
reseller's group (the list the reseller pages show), the trial price applies
only to trial packages, the connection count comes from the package, and
enable leaves admin bans alone. Administrators keep every option.

Free extension of codes and bouquet choice are offered by the reseller page
itself and are left as designed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V2uBUbGApb4A7Rbcoi7dxA
2026-09-17 08:07:02 +00:00

28 lines
1.2 KiB
PHP

<?php
use PHPUnit\Framework\TestCase;
use XcVm\Domain\Line\ActiveCodeService;
/**
* Resellers generate and re-package activation codes only with packages their
* group sells — the same list the reseller page offers. The service took any
* package id from the request.
*/
final class ActiveCodePackageRuleTest extends TestCase {
private function allowed(array $rPackage, array $rUser): bool {
$rMethod = new ReflectionMethod(ActiveCodeService::class, 'packageAvailableTo');
$rMethod->setAccessible(true);
return $rMethod->invoke(null, $rPackage, $rUser);
}
public function testOnlyLinePackagesOfTheResellersGroup(): void {
$rReseller = ['id' => 7, 'member_group_id' => 2];
$this->assertTrue($this->allowed(['is_line' => 1, 'groups' => '[2,3]'], $rReseller));
$this->assertTrue($this->allowed(['is_line' => '1', 'groups' => '["2"]'], $rReseller));
$this->assertFalse($this->allowed(['is_line' => 1, 'groups' => '[3]'], $rReseller), 'another group');
$this->assertFalse($this->allowed(['is_line' => 0, 'groups' => '[2]'], $rReseller), 'not a line package');
$this->assertFalse($this->allowed(['is_line' => 1, 'groups' => ''], $rReseller), 'no groups');
}
}