<?php

namespace Tests\Feature\Security;

use App\Models\User;
use Tests\TestCase;

/**
 * Security assertions that do not require RefreshDatabase / mysql CLI schema load.
 */
class SecurityStaticChecksTest extends TestCase
{
    public function test_face_attendance_rejects_unauthenticated(): void
    {
        $this->postJson('/api/face/attendance', [
            'face_data' => 'data:image/png;base64,aaa',
            'mode' => 'login',
        ])->assertUnauthorized();
    }

    public function test_security_headers_present_on_web_and_api(): void
    {
        $this->get('/login')
            ->assertOk()
            ->assertHeader('X-Frame-Options', 'DENY')
            ->assertHeader('X-Content-Type-Options', 'nosniff')
            ->assertHeader('Content-Security-Policy');

        $this->postJson('/api/auth/login', [
            'email' => 'nobody@example.test',
            'password' => 'bad',
        ])->assertHeader('X-Frame-Options', 'DENY');
    }

    public function test_cors_does_not_allow_star_origin(): void
    {
        $origins = config('cors.allowed_origins');
        $this->assertIsArray($origins);
        $this->assertNotContains('*', $origins);
    }

    public function test_mass_assignment_blocks_is_superadmin_from_fill(): void
    {
        \Illuminate\Database\Eloquent\Model::reguard();

        $user = new User;
        $user->fill([
            'name' => 'Attacker',
            'email' => 'attacker@example.test',
            'is_superadmin' => true,
            'user_type' => User::USER_TYPE_SUPERADMIN,
        ]);

        $this->assertArrayNotHasKey('is_superadmin', $user->getAttributes());
        $this->assertArrayNotHasKey('user_type', $user->getAttributes());
        $this->assertSame('Attacker', $user->name);

        \Illuminate\Database\Eloquent\Model::unguard();
    }

    public function test_user_hidden_includes_two_factor_and_bank_fields(): void
    {
        $user = new User;
        $hidden = $user->getHidden();
        foreach (['two_factor_secret', 'account_number', 'pan_number', 'ifsc_code', 'uan_number'] as $field) {
            $this->assertContains($field, $hidden);
        }
    }
}
