<?php

namespace Tests\Unit;

use App\Models\Company;
use App\Models\User;
use App\Services\Auth\TenantLoginResolver;
use Illuminate\Foundation\Testing\RefreshDatabase;
use Illuminate\Support\Facades\Hash;
use Tests\TestCase;

class TenantLoginResolverTest extends TestCase
{
    use RefreshDatabase;

    public function test_single_password_match_among_duplicate_emails_returns_that_user(): void
    {
        $a = Company::query()->create(['name' => 'Co A', 'short_name' => 'coa', 'status' => 'active']);
        $b = Company::query()->create(['name' => 'Co B', 'short_name' => 'cob', 'status' => 'active']);
        User::factory()->create([
            'email' => 'shared@example.com',
            'company_id' => $a->id,
            'password' => Hash::make('other-password'),
        ]);
        $match = User::factory()->create([
            'email' => 'shared@example.com',
            'company_id' => $b->id,
            'password' => Hash::make('password123'),
        ]);

        $resolver = app(TenantLoginResolver::class);
        $found = $resolver->findUserByEmailAndPassword(null, 'shared@example.com', 'password123');

        $this->assertNotNull($found);
        $this->assertSame($match->id, $found->id);
        $this->assertFalse($resolver->hasMultiplePasswordMatches(null, 'shared@example.com', 'password123'));
    }

    public function test_multiple_password_matches_returns_null_and_flags_ambiguous(): void
    {
        $a = Company::query()->create(['name' => 'Co A', 'short_name' => 'coa', 'status' => 'active']);
        $b = Company::query()->create(['name' => 'Co B', 'short_name' => 'cob', 'status' => 'active']);
        User::factory()->create([
            'email' => 'shared@example.com',
            'company_id' => $a->id,
            'password' => Hash::make('password123'),
        ]);
        User::factory()->create([
            'email' => 'shared@example.com',
            'company_id' => $b->id,
            'password' => Hash::make('password123'),
        ]);

        $resolver = app(TenantLoginResolver::class);

        $this->assertNull($resolver->findUserByEmailAndPassword(null, 'shared@example.com', 'password123'));
        $this->assertTrue($resolver->hasMultiplePasswordMatches(null, 'shared@example.com', 'password123'));
    }

    public function test_company_scope_still_limits_password_match(): void
    {
        $a = Company::query()->create(['name' => 'Co A', 'short_name' => 'coa', 'status' => 'active']);
        $b = Company::query()->create(['name' => 'Co B', 'short_name' => 'cob', 'status' => 'active']);
        $userA = User::factory()->create([
            'email' => 'shared@example.com',
            'company_id' => $a->id,
            'password' => Hash::make('password123'),
        ]);
        User::factory()->create([
            'email' => 'shared@example.com',
            'company_id' => $b->id,
            'password' => Hash::make('password123'),
        ]);

        $found = app(TenantLoginResolver::class)
            ->findUserByEmailAndPassword('coa', 'shared@example.com', 'password123');

        $this->assertNotNull($found);
        $this->assertSame($userA->id, $found->id);
    }

    public function test_password_reset_find_user_requires_unique_email_without_company(): void
    {
        $a = Company::query()->create(['name' => 'Co A', 'short_name' => 'coa', 'status' => 'active']);
        $b = Company::query()->create(['name' => 'Co B', 'short_name' => 'cob', 'status' => 'active']);
        User::factory()->create(['email' => 'shared@example.com', 'company_id' => $a->id]);
        User::factory()->create(['email' => 'shared@example.com', 'company_id' => $b->id]);

        $this->assertNull(app(TenantLoginResolver::class)->findUser(null, 'shared@example.com'));
        $this->assertNotNull(app(TenantLoginResolver::class)->findUser('coa', 'shared@example.com'));
    }
}
