import { test, expect } from '@playwright/test';
import { BASE_URL, ADMIN, AUDITOR, FINANCE, loginAs, registerAndLogin } from '../helpers';

test.describe('WFBO ROLE_AUDITOR — System Adjustments', () => {

    test('only an auditor sees the System Adjustment form', async ({ page }) => {
        const { mobile } = await registerAndLogin(page);

        // Auditor: form present.
        await loginAs(page, AUDITOR.mobile, AUDITOR.password);
        await page.goto(`${BASE_URL}/wfbo/users?search=${encodeURIComponent(mobile)}`);
        const href = await page.locator('[data-testid^="user-row-"]').first()
            .locator('[data-testid^="btn-view-transactions-"]').getAttribute('href');
        await page.goto(`${BASE_URL}${href ?? ''}`);
        await expect(page.locator('[data-testid="wallet-adjustment-form"]')).toBeVisible();

        // Plain admin and finance: no form.
        for (const staff of [ADMIN, FINANCE]) {
            await loginAs(page, staff.mobile, staff.password);
            await page.goto(`${BASE_URL}${href ?? ''}`);
            await expect(page.locator('[data-testid="wallet-adjustment-form"]')).toHaveCount(0);
        }
    });

    test('the wallet-adjustment endpoint is 403 for a non-auditor', async ({ page }) => {
        const { mobile } = await registerAndLogin(page);
        await loginAs(page, AUDITOR.mobile, AUDITOR.password);
        await page.goto(`${BASE_URL}/wfbo/users?search=${encodeURIComponent(mobile)}`);
        const href = await page.locator('[data-testid^="user-row-"]').first()
            .locator('[data-testid^="btn-view-transactions-"]').getAttribute('href');
        const uid = (href ?? '').match(/users\/(\d+)\//)?.[1];

        await loginAs(page, ADMIN.mobile, ADMIN.password);
        const res = await page.request.post(`${BASE_URL}/wfbo/users/${uid}/wallet-adjustment`, {
            form: { amount: '10', reason: 'blocked' },
        });
        expect(res.status()).toBe(403);
    });

    test('an admin can grant and revoke the Auditor role from the Actions menu', async ({ page }) => {
        const { mobile } = await registerAndLogin(page);

        await loginAs(page, ADMIN.mobile, ADMIN.password);
        await page.goto(`${BASE_URL}/wfbo/users?search=${encodeURIComponent(mobile)}`);
        const row  = page.locator('[data-testid^="user-row-"]').first();
        const uid  = (await row.getAttribute('data-testid'))?.replace('user-row-', '');
        const href = await row.locator('[data-testid^="btn-view-transactions-"]').getAttribute('href');
        await page.goto(`${BASE_URL}${href ?? ''}`);

        // Grant.
        await page.click('[data-testid="btn-actions"]');
        await page.click('[data-testid="btn-promote-auditor"]');
        await page.click('[data-testid="btn-confirm-action"]');
        await expect(page.locator('[data-testid="flash-success"]')).toBeVisible();

        await page.goto(`${BASE_URL}/wfbo/users?search=${encodeURIComponent(mobile)}`);
        await expect(
            page.locator(`[data-testid="user-row-${uid}"]`).locator('.badge-role', { hasText: 'Auditor' }),
        ).toBeVisible();

        // Revoke.
        await page.goto(`${BASE_URL}${href ?? ''}`);
        await page.click('[data-testid="btn-actions"]');
        await page.click('[data-testid="btn-demote-auditor"]');
        await expect(page.locator('[data-testid="flash-success"]')).toBeVisible();

        await page.goto(`${BASE_URL}/wfbo/users?search=${encodeURIComponent(mobile)}`);
        await expect(
            page.locator(`[data-testid="user-row-${uid}"]`).locator('.badge-role', { hasText: 'Auditor' }),
        ).toHaveCount(0);
    });
});
