feat(cms): add recovery history and operational reliability tools
CI / check (push) Failing after 22s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped

This commit is contained in:
Simo committed 2026-09-09 21:57:56 +02:00
1 parent 89526af344
commit 1ef405be0a
92 files changed
+6384 -267

No files matched your search

+23
View File
@@ -0,0 +1,23 @@
import { expect, it } from "vitest";
import { PERMS } from "../permission-slugs";
import { previewRoleAccess } from "./permission-preview";
it("requires dashboard access before reporting a module usable", () => {
const p = previewRoleAccess([PERMS.USERS_VIEW], false);
expect(p.canEnter).toBe(false);
expect(p.sections.find((s) => s.href === "/admin/users")?.allowed).toBe(
false,
);
});
it("shows grants and denies without combining another role", () => {
const p = previewRoleAccess([PERMS.ADMIN_DASHBOARD, PERMS.USERS_VIEW], false);
expect(p.sections.find((s) => s.href === "/admin/users")?.allowed).toBe(true);
expect(p.actions.find((s) => s.slug === PERMS.USERS_EDIT)?.granted).toBe(
false,
);
});
it("applies the existing highest-rank override", () => {
const p = previewRoleAccess([], true);
expect(p.canEnter).toBe(true);
expect(p.actions.every((a) => a.granted)).toBe(true);
});
+33
View File
@@ -0,0 +1,33 @@
import { ADMIN_NAV_GROUPS } from "../admin-nav";
import { PERMS } from "../permission-slugs";
/** Role-only simulation; never used to authorize a request. */
export function previewRoleAccess(
slugs: readonly string[],
superAdmin: boolean,
) {
const grants = new Set(slugs);
const has = (slug: string) => superAdmin || grants.has(slug);
const canEnter = has(PERMS.ADMIN_DASHBOARD);
return {
canEnter,
sections: ADMIN_NAV_GROUPS.flatMap((group) =>
group.items.map((item) => ({
href: item.href,
labelKey: item.labelKey,
required:
typeof item.permission === "string"
? [item.permission]
: [...(item.permission ?? [])],
allowed:
canEnter &&
(!item.permission ||
(typeof item.permission === "string"
? has(item.permission)
: item.permission.some(has))),
})),
),
actions: [...new Set(Object.values(PERMS))]
.sort()
.map((slug) => ({ slug, granted: has(slug) })),
};
}