create(); $acceptedFollower = User::factory()->create([ 'account_verified_at' => now(), 'bio' => 'Cuisine équilibrée.', ]); $pendingFollower = User::factory()->create(); $acceptedFollower->following()->attach($user, ['status' => FollowStatus::Accepted]); $pendingFollower->following()->attach($user, ['status' => FollowStatus::Pending]); Sanctum::actingAs($user); $this->getJson("/api/users/{$user->id}/followers?per_page=10") ->assertOk() ->assertJsonCount(1, 'data') ->assertJsonPath('data.0.id', $acceptedFollower->id) ->assertJsonPath('data.0.bio', 'Cuisine équilibrée.') ->assertJsonPath('data.0.accountVerified', true) ->assertJsonPath('meta.total', 1) ->assertJsonMissing(['id' => $pendingFollower->id]); }); it('lists only accepted followed accounts and exposes the pagination total', function () { $user = User::factory()->create(); $accepted = User::factory()->count(3)->create(); $pending = User::factory()->create(); $accepted->each( fn (User $followed): mixed => $user->following()->attach( $followed, ['status' => FollowStatus::Accepted], ), ); $user->following()->attach($pending, ['status' => FollowStatus::Pending]); Sanctum::actingAs($user); $this->getJson("/api/users/{$user->id}/following?per_page=2") ->assertOk() ->assertJsonCount(2, 'data') ->assertJsonPath('meta.total', 3) ->assertJsonPath('meta.per_page', 2) ->assertJsonMissing(['id' => $pending->id]); }); it('does not expose another users social lists', function () { $user = User::factory()->create(); $otherUser = User::factory()->create(); Sanctum::actingAs($user); $this->getJson("/api/users/{$otherUser->id}/followers")->assertForbidden(); $this->getJson("/api/users/{$otherUser->id}/following")->assertForbidden(); });