<?php

declare(strict_types=1);

namespace Tests\Unit\Security;

use App\Models\FinancialOperation;
use PHPUnit\Framework\Attributes\Test;
use Tests\TestCase;

/**
 * FIX H-02: FinancialOperation usa $fillable explícito en lugar de $guarded = [].
 *
 * Verifica que columnas sensibles no son mass-assignable.
 */
class FinancialOperationGuardTest extends TestCase
{
    #[Test]
    public function financial_operation_has_explicit_fillable(): void
    {
        $model = new FinancialOperation;

        $this->assertNotEmpty(
            $model->getFillable(),
            'FinancialOperation debe definir $fillable explícito.'
        );
    }

    #[Test]
    public function id_is_not_mass_assignable(): void
    {
        $model = new FinancialOperation;

        $this->assertNotContains(
            'id',
            $model->getFillable(),
            'El campo id no debe ser mass-assignable.'
        );
    }

    #[Test]
    public function timestamps_are_not_mass_assignable(): void
    {
        $model = new FinancialOperation;
        $fillable = $model->getFillable();

        $this->assertNotContains('created_at', $fillable);
        $this->assertNotContains('updated_at', $fillable);
    }

    #[Test]
    public function expected_financial_columns_are_fillable(): void
    {
        $model = new FinancialOperation;
        $fillable = $model->getFillable();

        foreach (['operation_type', 'user_id', 'cash_out', 'cash_in', 'credit_amount', 'notes'] as $column) {
            $this->assertContains(
                $column,
                $fillable,
                "El campo '{$column}' debería ser fillable."
            );
        }
    }

    #[Test]
    public function fill_with_arbitrary_column_is_ignored(): void
    {
        $model = new FinancialOperation;
        $model->fill(['arbitrary_column' => 'injected_value', 'operation_type' => 'credit_disbursement']);

        $this->assertNull($model->getAttribute('arbitrary_column'));
        $this->assertSame('credit_disbursement', $model->getAttribute('operation_type'));
    }
}
