feat: enhance agent management and validation logic

- Updated AGENTS.md to clarify agent account restrictions and permissions.
- Implemented checks in AgentNodeAdminUserStoreController and AgentNodeRoleStoreController to restrict admin user and role creation to the agent's own node.
- Enhanced validation in AdminPlayerStoreController and AdminPlayerUpdateController to enforce credit limit and rebate rate rules based on player funding mode.
- Refactored various request classes to utilize shared admin account field rules for consistency.
- Improved error handling in services related to credit allocation and rebate limits to ensure proper validation and messaging.
This commit is contained in:
2026-06-14 21:13:27 +08:00
parent 395e1c7400
commit 5b6d4cb74d
56 changed files with 1558 additions and 222 deletions

View File

@@ -5,6 +5,7 @@ use App\Models\AgentNode;
use App\Models\AgentProfile;
use App\Support\AdminAuthProfile;
use App\Support\AgentPlatformRole;
use App\Support\SitePlatformRole;
use Illuminate\Support\Facades\Hash;
use Illuminate\Foundation\Testing\RefreshDatabase;
@@ -14,6 +15,42 @@ beforeEach(function (): void {
$this->artisan('lottery:agent-roles-sync')->assertExitCode(0);
});
test('site admin keeps agent manage and player manage without agent profile capability filter', function (): void {
$this->artisan('lottery:admin-auth-sync')->assertExitCode(0);
$siteId = (int) DB::table('admin_sites')->where('is_default', true)->value('id');
$roleId = SitePlatformRole::id();
$admin = AdminUser::query()->create([
'username' => 'site_admin_cap',
'name' => 'Site Admin Cap',
'email' => null,
'password' => Hash::make('secret-strong'),
'status' => 0,
]);
DB::table('admin_user_site_roles')->insert([
'admin_user_id' => $admin->id,
'site_id' => $siteId,
'role_id' => $roleId,
'granted_at' => now(),
]);
$fresh = $admin->fresh();
$profile = AdminAuthProfile::fromAdmin($fresh);
$perms = $profile['permissions'];
expect($profile['agent'])->toBeNull();
expect($perms)->toContain('prd.agent.view')
->and($perms)->toContain('prd.agent.manage')
->and($perms)->toContain('prd.agent.profile.manage')
->and($perms)->toContain('prd.users.manage')
->and($perms)->toContain('prd.settlement.agent.manage');
expect($fresh->hasPermissionCode('agent.node.manage'))->toBeTrue();
expect($fresh->hasPermissionCode('agent.profile.manage'))->toBeTrue();
expect($fresh->hasPermissionCode('service.players.manage'))->toBeTrue();
});
test('agent profile switches strip create player and child manage from effective permissions', function (): void {
$siteId = (int) DB::table('admin_sites')->where('is_default', true)->value('id');
$rootId = (int) DB::table('agent_nodes')->where('admin_site_id', $siteId)->where('depth', 0)->value('id');