feat: enhance agent management and validation logic

- Updated AGENTS.md to clarify agent account restrictions and permissions.
- Implemented checks in AgentNodeAdminUserStoreController and AgentNodeRoleStoreController to restrict admin user and role creation to the agent's own node.
- Enhanced validation in AdminPlayerStoreController and AdminPlayerUpdateController to enforce credit limit and rebate rate rules based on player funding mode.
- Refactored various request classes to utilize shared admin account field rules for consistency.
- Improved error handling in services related to credit allocation and rebate limits to ensure proper validation and messaging.
This commit is contained in:
2026-06-14 21:13:27 +08:00
parent 395e1c7400
commit 5b6d4cb74d
56 changed files with 1558 additions and 222 deletions

View File

@@ -11,6 +11,7 @@ uses(RefreshDatabase::class);
beforeEach(function (): void {
ensureAdminActionCatalogSeeded();
$this->artisan('lottery:admin-auth-sync')->assertExitCode(0);
ensureRootAgentProfileSeeded();
});
test('super admin can update agent profile with capability flags', function (): void {
@@ -194,15 +195,169 @@ test('bound agent cannot update own profile share and credit', function (): void
->putJson('/api/v1/admin/agent-nodes/'.$agentNode->id.'/profile', [
'total_share_rate' => 99,
'credit_limit' => 999_999,
'can_create_player' => false,
])
->assertForbidden();
});
test('site admin cannot change root agent credit limit via profile update', function (): void {
$siteId = (int) DB::table('admin_sites')->where('is_default', true)->value('id');
$rootId = (int) DB::table('agent_nodes')->where('admin_site_id', $siteId)->where('depth', 0)->value('id');
$roleId = \App\Support\SitePlatformRole::id();
$siteAdmin = AdminUser::query()->create([
'username' => 'root_credit_site_admin',
'name' => 'Root Credit Site Admin',
'email' => null,
'password' => Hash::make('secret-strong'),
'status' => 0,
]);
DB::table('admin_user_site_roles')->insert([
'admin_user_id' => $siteAdmin->id,
'site_id' => $siteId,
'role_id' => $roleId,
'granted_at' => now(),
]);
$token = $siteAdmin->createToken('test', ['*'], now()->addDay())->plainTextToken;
$this->withHeader('Authorization', 'Bearer '.$token)
->putJson('/api/v1/admin/agent-nodes/'.$rootId.'/profile', [
'credit_limit' => 9_999_999,
'rebate_limit' => 0.5,
])
->assertForbidden();
});
test('super admin can change root agent credit limit', function (): void {
$siteId = (int) DB::table('admin_sites')->where('is_default', true)->value('id');
$rootId = (int) DB::table('agent_nodes')->where('admin_site_id', $siteId)->where('depth', 0)->value('id');
$super = AdminUser::query()->create([
'username' => 'root_credit_super',
'name' => 'Root Credit Super',
'email' => null,
'password' => Hash::make('secret-strong'),
'status' => 0,
]);
grantSuperAdminRole($super);
$token = $super->createToken('test', ['*'], now()->addDay())->plainTextToken;
$this->withHeader('Authorization', 'Bearer '.$token)
->putJson('/api/v1/admin/agent-nodes/'.$rootId.'/profile', [
'credit_limit' => 88_888,
])
->assertOk()
->assertJsonPath('data.credit_limit', 88888);
});
test('child agent profile update rejects credit above parent available', function (): void {
$siteId = (int) DB::table('admin_sites')->where('is_default', true)->value('id');
$rootId = (int) DB::table('agent_nodes')->where('admin_site_id', $siteId)->where('depth', 0)->value('id');
$service = app(\App\Services\Agent\AgentNodeService::class);
\App\Models\AgentProfile::query()->updateOrCreate(
['agent_node_id' => $rootId],
[
'total_share_rate' => 100,
'credit_limit' => 5000,
'allocated_credit' => 0,
'used_credit' => 0,
'rebate_limit' => 1,
'default_player_rebate' => 0,
],
);
$super = AdminUser::query()->create([
'username' => 'child_credit_super',
'name' => 'Child Credit Super',
'email' => null,
'password' => Hash::make('secret-strong'),
'status' => 0,
]);
grantSuperAdminRole($super);
$child = $service->createChild($super, agentChildPayload([
'parent_id' => $rootId,
'code' => 'child-credit-cap',
'name' => 'Child Credit Cap',
'username' => 'child_credit_cap',
'credit_limit' => 1000,
]));
$token = $super->createToken('test', ['*'], now()->addDay())->plainTextToken;
$this->withHeader('Authorization', 'Bearer '.$token)
->putJson('/api/v1/admin/agent-nodes/'.$child->id.'/profile', [
'credit_limit' => 9000,
])
->assertStatus(422)
->assertJsonPath('code', ErrorCode::ValidationFailed->value);
});
test('child agent profile update rejects rebate above parent', function (): void {
$siteId = (int) DB::table('admin_sites')->where('is_default', true)->value('id');
$rootId = (int) DB::table('agent_nodes')->where('admin_site_id', $siteId)->where('depth', 0)->value('id');
$service = app(\App\Services\Agent\AgentNodeService::class);
\App\Models\AgentProfile::query()->updateOrCreate(
['agent_node_id' => $rootId],
[
'total_share_rate' => 100,
'credit_limit' => 10000,
'allocated_credit' => 0,
'used_credit' => 0,
'rebate_limit' => 0.2,
'default_player_rebate' => 0,
],
);
$super = AdminUser::query()->create([
'username' => 'child_rebate_super',
'name' => 'Child Rebate Super',
'email' => null,
'password' => Hash::make('secret-strong'),
'status' => 0,
]);
grantSuperAdminRole($super);
$child = $service->createChild($super, agentChildPayload([
'parent_id' => $rootId,
'code' => 'child-rebate-cap',
'name' => 'Child Rebate Cap',
'username' => 'child_rebate_cap',
'rebate_limit' => 1,
]));
$token = $super->createToken('test', ['*'], now()->addDay())->plainTextToken;
$this->withHeader('Authorization', 'Bearer '.$token)
->putJson('/api/v1/admin/agent-nodes/'.$child->id.'/profile', [
'rebate_limit' => 50,
])
->assertStatus(422)
->assertJsonPath('code', ErrorCode::ValidationFailed->value);
});
test('agent profile update rejects default rebate above limit', function (): void {
$siteId = (int) DB::table('admin_sites')->where('is_default', true)->value('id');
$rootId = (int) DB::table('agent_nodes')->where('admin_site_id', $siteId)->where('depth', 0)->value('id');
$service = app(\App\Services\Agent\AgentNodeService::class);
\App\Models\AgentProfile::query()->updateOrCreate(
['agent_node_id' => $rootId],
[
'total_share_rate' => 100,
'credit_limit' => 10000,
'allocated_credit' => 0,
'used_credit' => 0,
'rebate_limit' => 1,
'default_player_rebate' => 0,
],
);
$super = AdminUser::query()->create([
'username' => 'profile_super2',
'name' => 'Profile Super',
@@ -229,3 +384,68 @@ test('agent profile update rejects default rebate above limit', function (): voi
->assertStatus(422)
->assertJsonPath('code', ErrorCode::ValidationFailed->value);
});
test('partial agent profile update preserves unchanged share rate', function (): void {
$siteId = (int) DB::table('admin_sites')->where('is_default', true)->value('id');
$rootId = (int) DB::table('agent_nodes')->where('admin_site_id', $siteId)->where('depth', 0)->value('id');
$service = app(\App\Services\Agent\AgentNodeService::class);
$super = AdminUser::query()->create([
'username' => 'partial_profile_super',
'name' => 'Partial Profile Super',
'email' => null,
'password' => Hash::make('secret-strong'),
'status' => 0,
]);
grantSuperAdminRole($super);
$child = $service->createChild($super, agentChildPayload([
'parent_id' => $rootId,
'code' => 'partial-profile-child',
'name' => 'Partial Profile Child',
'username' => 'partial_profile_child',
'total_share_rate' => 15,
'credit_limit' => 2000,
]));
$token = $super->createToken('test', ['*'], now()->addDay())->plainTextToken;
$this->withHeader('Authorization', 'Bearer '.$token)
->putJson('/api/v1/admin/agent-nodes/'.$child->id.'/profile', [
'credit_limit' => 2500,
])
->assertOk()
->assertJsonPath('data.total_share_rate', 15)
->assertJsonPath('data.credit_limit', 2500);
});
test('agent node update rejects chinese username', function (): void {
$siteId = (int) DB::table('admin_sites')->where('is_default', true)->value('id');
$rootId = (int) DB::table('agent_nodes')->where('admin_site_id', $siteId)->where('depth', 0)->value('id');
$service = app(\App\Services\Agent\AgentNodeService::class);
$super = AdminUser::query()->create([
'username' => 'cn_username_super',
'name' => 'CN Username Super',
'email' => null,
'password' => Hash::make('secret-strong'),
'status' => 0,
]);
grantSuperAdminRole($super);
$child = $service->createChild($super, agentChildPayload([
'parent_id' => $rootId,
'code' => 'cn-username-child',
'name' => 'CN Username Child',
'username' => 'cn_child_login',
]));
$token = $super->createToken('test', ['*'], now()->addDay())->plainTextToken;
$this->withHeader('Authorization', 'Bearer '.$token)
->putJson('/api/v1/admin/agent-nodes/'.$child->id, [
'username' => '中文账号',
])
->assertStatus(422)
->assertJsonPath('code', ErrorCode::ValidationFailed->value);
});