create();
$url = route('share.download', $share);
$svg = app(QrCodeService::class)->svg($url);
$response = $this->get(route('share.created', $share));
$response->assertOk()
->assertSee($url, false)
->assertSee('data-test="show-qr-code"', false)
->assertSee('data-test="share-sheet"', false)
->assertSee('share-'.$share->token.'.png')
->assertDontSee('Recipients also need the password.');
// Structure, not the 1.x class string: the `data-qr-code` hook directly wraps the service's own
// SVG, which draws its own white field and quiet zone — no colour class or literal colour here.
expect($response->getContent())
->toMatch('#
]*\bdata-qr-code\b[^>]*>'.preg_quote($svg, '#').'
#');
});
test('the QR code dialog reminds that a protected share also needs its password', function () {
$share = Share::factory()->withPassword()->create();
$this->get(route('share.created', $share))
->assertOk()
->assertSee('Recipients also need the password.');
});
test('the uploader who just set the password can copy it beside the link, without it being on screen', function () {
$share = Share::factory()->withPassword()->create();
$response = $this->withSession(['share_password' => ['token' => $share->token, 'password' => Crypt::encryptString('violet-orbit-canyon')]])
->get(route('share.created', $share));
$response->assertSee('data-test="share-password"', false)
->assertSee('Available only this once. Send it separately from the link.');
// A masked field holding the password, with the field's copy button at its end.
expect($response->getContent())
->toMatch('#]*value="violet-orbit-canyon")(?=[^>]*type="password")(?=[^>]*data-test="share-password")[^>]*>#')
->toMatch('#data-test="share-password".*?data-md-field-copy#s');
});
test('the password is not shown without a flash for this share', function (?string $flashedFor) {
$share = Share::factory()->withPassword()->create();
$session = $flashedFor === null ? [] : ['share_password' => ['token' => $flashedFor, 'password' => Crypt::encryptString('violet-orbit-canyon')]];
$response = $this->withSession($session)->get(route('share.created', $share));
$response->assertOk()
->assertDontSee('data-test="share-password"', false)
->assertDontSee('violet-orbit-canyon');
})->with([
'no flash (a reload or another visitor)' => [null],
'a flash for another share' => ['another-share-token'],
]);