test: harden housekeeping capability context
This commit is contained in:
1 parent
c63c9830b2
commit
7edca410fa
2 files changed
+39
-2
No files matched your search
@@ -65,6 +65,32 @@ describe("housekeeping capability context", () => {
|
|||||||
).toBe(true);
|
).toBe(true);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it("bypasses meaningful requirements without consulting permission methods", () => {
|
||||||
|
const permissions: PermissionSet = {
|
||||||
|
isSuperAdmin: true,
|
||||||
|
has: vi.fn(() => false),
|
||||||
|
hasAny: vi.fn(() => false),
|
||||||
|
hasAll: vi.fn(() => false),
|
||||||
|
};
|
||||||
|
const context = createHousekeepingCapabilityContext(actor, permissions);
|
||||||
|
|
||||||
|
expect(
|
||||||
|
satisfiesCapability(
|
||||||
|
context,
|
||||||
|
anyCapability("admin.users.view", "admin.logs.view"),
|
||||||
|
),
|
||||||
|
).toBe(true);
|
||||||
|
expect(
|
||||||
|
satisfiesCapability(
|
||||||
|
context,
|
||||||
|
allCapabilities("admin.users.view", "admin.logs.view"),
|
||||||
|
),
|
||||||
|
).toBe(true);
|
||||||
|
expect(permissions.has).not.toHaveBeenCalled();
|
||||||
|
expect(permissions.hasAny).not.toHaveBeenCalled();
|
||||||
|
expect(permissions.hasAll).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
it("delegates capability checks without applying rank logic", () => {
|
it("delegates capability checks without applying rank logic", () => {
|
||||||
const permissions: PermissionSet = {
|
const permissions: PermissionSet = {
|
||||||
isSuperAdmin: false,
|
isSuperAdmin: false,
|
||||||
|
|||||||
@@ -1,18 +1,28 @@
|
|||||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||||
|
|
||||||
const { getAdminContext } = vi.hoisted(() => ({ getAdminContext: vi.fn() }));
|
const { auth, getAdminContext, staleActor } = vi.hoisted(() => ({
|
||||||
|
auth: vi.fn(),
|
||||||
|
getAdminContext: vi.fn(),
|
||||||
|
staleActor: { id: 9, username: "stale-session", rank: 1 },
|
||||||
|
}));
|
||||||
|
|
||||||
vi.mock("react", () => ({
|
vi.mock("react", () => ({
|
||||||
cache: <T extends (...args: never[]) => unknown>(callback: T) => callback,
|
cache: <T extends (...args: never[]) => unknown>(callback: T) => callback,
|
||||||
}));
|
}));
|
||||||
|
|
||||||
|
vi.mock("@/lib/auth", () => ({ auth }));
|
||||||
|
vi.mock("@/lib/db", () => {
|
||||||
|
throw new Error("server capability context must not access the database");
|
||||||
|
});
|
||||||
vi.mock("@/lib/permissions", () => ({ getAdminContext }));
|
vi.mock("@/lib/permissions", () => ({ getAdminContext }));
|
||||||
|
|
||||||
|
import { auth as mockedAuth } from "@/lib/auth";
|
||||||
import { getHousekeepingCapabilityContext } from "./server-capability-context";
|
import { getHousekeepingCapabilityContext } from "./server-capability-context";
|
||||||
|
|
||||||
describe("getHousekeepingCapabilityContext", () => {
|
describe("getHousekeepingCapabilityContext", () => {
|
||||||
beforeEach(() => {
|
beforeEach(() => {
|
||||||
vi.clearAllMocks();
|
vi.clearAllMocks();
|
||||||
|
auth.mockResolvedValue({ user: staleActor });
|
||||||
getAdminContext.mockResolvedValue({
|
getAdminContext.mockResolvedValue({
|
||||||
session: {
|
session: {
|
||||||
user: {
|
user: {
|
||||||
@@ -31,7 +41,7 @@ describe("getHousekeepingCapabilityContext", () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
it("uses the refreshed administrator actor and forwarded permissions", async () => {
|
it("uses the refreshed administrator actor instead of the stale auth actor", async () => {
|
||||||
const context = await getHousekeepingCapabilityContext();
|
const context = await getHousekeepingCapabilityContext();
|
||||||
|
|
||||||
expect(context).toMatchObject({
|
expect(context).toMatchObject({
|
||||||
@@ -41,5 +51,6 @@ describe("getHousekeepingCapabilityContext", () => {
|
|||||||
expect(context.has("admin.users.view")).toBe(true);
|
expect(context.has("admin.users.view")).toBe(true);
|
||||||
expect(context.has("admin.logs.view")).toBe(false);
|
expect(context.has("admin.logs.view")).toBe(false);
|
||||||
expect(getAdminContext).toHaveBeenCalledTimes(1);
|
expect(getAdminContext).toHaveBeenCalledTimes(1);
|
||||||
|
expect(mockedAuth).not.toHaveBeenCalled();
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
Reference in new issue
Block a user