test: add audit, staff-activity, and abuse-guard test suites (75 files, 376 tests)
This commit is contained in:
1 parent
04b9844f0f
commit
2e9db75eca
3 files changed
+299
No files matched your search
@@ -0,0 +1,127 @@
|
||||
import { describe, expect, it, vi, beforeEach } from "vitest";
|
||||
|
||||
const create = vi.hoisted(() => vi.fn());
|
||||
const findMany = vi.hoisted(() => vi.fn());
|
||||
const count = vi.hoisted(() => vi.fn());
|
||||
const userFindMany = vi.hoisted(() => vi.fn());
|
||||
|
||||
vi.mock("@/lib/prisma", () => ({
|
||||
prisma: {
|
||||
adminAuditLog: { create, findMany, count },
|
||||
user: { findMany: userFindMany },
|
||||
},
|
||||
}));
|
||||
|
||||
vi.mock("@/env", () => ({ env: {} }));
|
||||
|
||||
import { logAudit, getAuditLogs } from "./audit";
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
});
|
||||
|
||||
describe("logAudit", () => {
|
||||
it("creates an audit entry", async () => {
|
||||
create.mockResolvedValue({ id: 1 });
|
||||
await logAudit({
|
||||
userId: 1,
|
||||
action: "test_action",
|
||||
target: "user",
|
||||
targetId: 42,
|
||||
});
|
||||
const data = create.mock.calls[0][0].data;
|
||||
expect(data.userId).toBe(1);
|
||||
expect(data.action).toBe("test_action");
|
||||
expect(data.target).toBe("user");
|
||||
expect(data.targetId).toBe(42);
|
||||
});
|
||||
|
||||
it("redacts sensitive keys in payload", async () => {
|
||||
create.mockResolvedValue({ id: 1 });
|
||||
await logAudit({
|
||||
userId: 1,
|
||||
action: "update",
|
||||
target: "user",
|
||||
targetId: 1,
|
||||
before: { username: "foo", password: "secret123" },
|
||||
after: { username: "bar", password: "newsecret" },
|
||||
});
|
||||
const data = create.mock.calls[0][0].data;
|
||||
expect(JSON.parse(data.before).password).toBe("[Redacted]");
|
||||
expect(JSON.parse(data.after).password).toBe("[Redacted]");
|
||||
expect(JSON.parse(data.diff).username).toEqual({ from: "foo", to: "bar" });
|
||||
});
|
||||
|
||||
it("omits diff when only before or after is missing", async () => {
|
||||
create.mockResolvedValue({ id: 1 });
|
||||
await logAudit({
|
||||
userId: 1,
|
||||
action: "delete",
|
||||
target: "user",
|
||||
before: { username: "foo" },
|
||||
});
|
||||
const data = create.mock.calls[0][0].data;
|
||||
expect(data.diff).toBeNull();
|
||||
});
|
||||
|
||||
it("handles empty payloads", async () => {
|
||||
create.mockResolvedValue({ id: 1 });
|
||||
await logAudit({ userId: 1, action: "view", target: "page" });
|
||||
expect(create).toHaveBeenCalledOnce();
|
||||
});
|
||||
|
||||
it("flattens nested objects", async () => {
|
||||
create.mockResolvedValue({ id: 1 });
|
||||
await logAudit({
|
||||
userId: 1,
|
||||
action: "update_settings",
|
||||
target: "user",
|
||||
before: { nested: { key: "val" } },
|
||||
after: {},
|
||||
});
|
||||
const data = create.mock.calls[0][0].data;
|
||||
expect(JSON.parse(data.before)).toEqual({ nested: { key: "val" } });
|
||||
});
|
||||
});
|
||||
|
||||
describe("getAuditLogs", () => {
|
||||
it("returns paginated logs with usernames", async () => {
|
||||
findMany.mockResolvedValue([
|
||||
{ id: 1, userId: 1, action: "test", target: "user", targetId: null, before: null, after: null, diff: null, createdAt: "2024-01-01" },
|
||||
{ id: 2, userId: 2, action: "test2", target: "room", targetId: null, before: null, after: null, diff: null, createdAt: "2024-01-02" },
|
||||
]);
|
||||
count.mockResolvedValue(2);
|
||||
userFindMany.mockResolvedValue([
|
||||
{ id: 1, username: "alice" },
|
||||
{ id: 2, username: "bob" },
|
||||
]);
|
||||
|
||||
const result = await getAuditLogs({ page: 1, perPage: 20 });
|
||||
expect(result.rows).toHaveLength(2);
|
||||
expect(result.rows[0].username).toBe("alice");
|
||||
expect(result.rows[1].username).toBe("bob");
|
||||
expect(result.total).toBe(2);
|
||||
expect(result.lastPage).toBe(1);
|
||||
});
|
||||
|
||||
it("filters by search term", async () => {
|
||||
findMany.mockResolvedValue([]);
|
||||
count.mockResolvedValue(0);
|
||||
await getAuditLogs({ search: "test" });
|
||||
expect(findMany).toHaveBeenCalledWith(
|
||||
expect.objectContaining({
|
||||
where: { OR: [{ action: { contains: "test" } }, { target: { contains: "test" } }] },
|
||||
}),
|
||||
);
|
||||
});
|
||||
|
||||
it("falls back to User #id for unknown users", async () => {
|
||||
findMany.mockResolvedValue([
|
||||
{ id: 1, userId: 99, action: "x", target: "y", targetId: null, before: null, after: null, diff: null, createdAt: "2024-01-01" },
|
||||
]);
|
||||
count.mockResolvedValue(1);
|
||||
userFindMany.mockResolvedValue([]);
|
||||
const result = await getAuditLogs();
|
||||
expect(result.rows[0].username).toBe("User #99");
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user