create(); $this->post('/forgot-password', ['email' => $user->email]); Notification::assertSentTo($user, ResetPassword::class, function ($notification) { $response = $this->get('/reset-password/'.$notification->token); $response->assertStatus(200); return true; }); } public function test_password_can_be_reset(): void { Notification::fake(); $user = User::factory()->create(); $this->post('/forgot-password', ['email' => $user->email]); Notification::assertSentTo($user, ResetPassword::class, function ($notification) use ($user) { $response = $this->post('/reset-password', [ 'token' => $notification->token, 'email' => $user->email, 'password' => 'new-password', 'password_confirmation' => 'new-password', ]); $response ->assertSessionHasNoErrors() ->assertRedirect(route('login')); $this->assertTrue( \Hash::check('new-password', $user->fresh()->password) ); return true; }); } public function test_password_reset_fails_with_invalid_token(): void { $response = $this->post('/reset-password', [ 'token' => 'invalid-token', 'email' => 'test@example.com', 'password' => 'password', 'password_confirmation' => 'password', ]); $response->assertSessionHasErrors('email'); } public function test_password_reset_validates_required_fields(): void { $response = $this->post('/reset-password', []); $response->assertSessionHasErrors(['token', 'email', 'password']); } }