# Admin Dashboard Error Report

Date: 2026-03-11

Command used:

```powershell
php artisan test tests\Feature\AdminAuthTest.php tests\Feature\AdminDashboardRouteSmokeTest.php tests\Feature\BranchTest.php tests\Feature\Core\SettingTest.php tests\Feature\FormSubmissionTest.php tests\Feature\FormValidationTest.php tests\Feature\FormSecurityTest.php
```

Summary:

- Passed: 102 tests/assertion groups
- Failed: 9 tests
- Risky: 1 test
- Route discovery: `php artisan route:list --path=admin` now completes successfully

## Fixed during review

- Added a compatibility `ResponseApi` trait so admin site controllers can load.
- Added `Admin\settings\MainController@getDistricts` so the `admin.setting.getDistricts` route is valid.
- Added missing `title` columns for `roles` and `permissions`.
- Loaded `app/Helpers/main_helper.php` at boot and added a fallback `toastr()` helper.
- Fixed branch delete assertions to match soft-delete behavior and added tests for `toggleStatus`, `setAsMain`, and `restore`.
- Fixed broken dashboard actions:
  - `UsersController` now supports image uploads and resource `show`/`destroy`.
  - `RolesController` now supports `load_edit`, correct `show`, correct permissions view, and resource `destroy`.
  - `PermissionsController` now supports resource `show`/`destroy`.
  - Reordered `roles/load_edit` before `roles/{role}` so the route is reachable.

## Real application defects still failing

1. User update does not persist the name field
   - Failing test: `Tests\Feature\FormSubmissionTest::test_admin_user_update_form_success`
   - Cause: [`UsersController.php`](/f:/xampp8.2/htdocs/erp/app/Http/Controllers/Admin/Users/UsersController.php) writes `$insert_data['user']` instead of `$insert_data['name']` in `update()`.

2. Email validation is too permissive for malformed input
   - Failing test: `Tests\Feature\FormValidationTest::test_form_validates_email_format`
   - Impact: at least one malformed email in the test set is accepted by [`AdminStoreRequest.php`](/f:/xampp8.2/htdocs/erp/app/Http/Requests/Admin/AdminStoreRequest.php).

3. Password confirmation is not enforced on user creation
   - Failing test: `Tests\Feature\FormValidationTest::test_form_password_confirmation_mismatch`
   - Cause: [`AdminStoreRequest.php`](/f:/xampp8.2/htdocs/erp/app/Http/Requests/Admin/AdminStoreRequest.php) has no `confirmed` rule for `password`.

4. User name input is stored without sanitization
   - Failing tests:
     - `Tests\Feature\FormSubmissionTest::test_form_xss_protection_in_user_name`
     - `Tests\Feature\FormSecurityTest::test_form_sanitizes_html_tags_in_name`
   - Impact: HTML/script payloads are persisted in the `name` column.

5. Null-byte input is stored without normalization/rejection
   - Failing test: `Tests\Feature\FormSecurityTest::test_form_prevents_null_byte_injection`
   - Impact: `user_name` accepts `\x00` and stores it directly.

## Test/spec issues still present

1. Duplicate permission seed collision in the test
   - Failing test: `Tests\Feature\FormSubmissionTest::test_permission_create_form_success`
   - Cause: it tries to create `products.delete`, which is already seeded by `RolePermissionSeeder`.

2. SQL injection test expects invalid email input to be stored
   - Failing test: `Tests\Feature\FormSubmissionTest::test_form_sql_injection_protection_in_email`
   - Cause: the test expectation is wrong; the payload is blocked by email validation.

3. GET request test targets a URI shared by `index` and `store`
   - Failing test: `Tests\Feature\FormSubmissionTest::test_post_form_rejects_get_request`
   - Cause: `route('admin.UserManagement.users.store')` and `route('admin.UserManagement.users.index')` resolve to the same URI with different HTTP verbs, so a GET correctly returns the index page.

4. CSRF placeholder test is still risky
   - Risky test: `Tests\Feature\FormSubmissionTest::test_form_without_csrf_token_fails`
   - Cause: the test performs no assertions.

## Residual warnings

- The suite still emits PHPUnit 11 deprecation warnings because many tests use `/** @test */` docblock metadata instead of PHPUnit attributes.
