create(); $url = route('share.download', $share); $svg = app(QrCodeService::class)->svg($url); $response = $this->get(route('share.created', $share)); $response->assertOk() ->assertSee($url, false) ->assertSee('data-test="show-qr-code"', false) ->assertSee('data-test="share-sheet"', false) ->assertSee('share-'.$share->token.'.png') ->assertDontSee('Recipients also need the password.'); // Structure, not the 1.x class string: the `data-qr-code` hook directly wraps the service's own // SVG, which draws its own white field and quiet zone — no colour class or literal colour here. expect($response->getContent()) ->toMatch('#]*\bdata-qr-code\b[^>]*>'.preg_quote($svg, '#').'#'); }); test('the QR code dialog reminds that a protected share also needs its password', function () { $share = Share::factory()->withPassword()->create(); $this->get(route('share.created', $share)) ->assertOk() ->assertSee('Recipients also need the password.'); }); test('the uploader who just set the password can copy it beside the link, without it being on screen', function () { $share = Share::factory()->withPassword()->create(); $response = $this->withSession(['share_password' => ['token' => $share->token, 'password' => Crypt::encryptString('violet-orbit-canyon')]]) ->get(route('share.created', $share)); $response->assertSee('data-test="share-password"', false) ->assertSee('Available only this once. Send it separately from the link.'); // A masked field holding the password, with the field's copy button at its end. expect($response->getContent()) ->toMatch('#]*value="violet-orbit-canyon")(?=[^>]*type="password")(?=[^>]*data-test="share-password")[^>]*>#') ->toMatch('#data-test="share-password".*?data-md-field-copy#s'); }); test('the password is not shown without a flash for this share', function (?string $flashedFor) { $share = Share::factory()->withPassword()->create(); $session = $flashedFor === null ? [] : ['share_password' => ['token' => $flashedFor, 'password' => Crypt::encryptString('violet-orbit-canyon')]]; $response = $this->withSession($session)->get(route('share.created', $share)); $response->assertOk() ->assertDontSee('data-test="share-password"', false) ->assertDontSee('violet-orbit-canyon'); })->with([ 'no flash (a reload or another visitor)' => [null], 'a flash for another share' => ['another-share-token'], ]);