This commit is contained in:
1 parent
8efd032cc6
commit
df38dccbf1
735 files changed
+128321
-120870
No files matched your search
@@ -1,40 +1,59 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { decideAuthorization, isDynamicSuperAdmin } from "@/lib/admin/authorization-policy";
|
||||
import {
|
||||
decideAuthorization,
|
||||
isDynamicSuperAdmin,
|
||||
} from "@/lib/admin/authorization-policy";
|
||||
|
||||
describe("isDynamicSuperAdmin", () => {
|
||||
it.each([
|
||||
[7, 7],
|
||||
[11, 11],
|
||||
[2000, 2000],
|
||||
])("accepts highest rank %i", (rank, highest) => {
|
||||
expect(isDynamicSuperAdmin(rank, highest)).toBe(true);
|
||||
});
|
||||
it("demotes the previous highest rank", () => expect(isDynamicSuperAdmin(2000, 2001)).toBe(false));
|
||||
it("fails closed without ranks", () => expect(isDynamicSuperAdmin(1, null)).toBe(false));
|
||||
it.each([
|
||||
[7, 7],
|
||||
[11, 11],
|
||||
[2000, 2000],
|
||||
])("accepts highest rank %i", (rank, highest) => {
|
||||
expect(isDynamicSuperAdmin(rank, highest)).toBe(true);
|
||||
});
|
||||
it("demotes the previous highest rank", () =>
|
||||
expect(isDynamicSuperAdmin(2000, 2001)).toBe(false));
|
||||
it("fails closed without ranks", () =>
|
||||
expect(isDynamicSuperAdmin(1, null)).toBe(false));
|
||||
});
|
||||
|
||||
describe("decideAuthorization", () => {
|
||||
const actor = { id: 1, username: "admin", rank: 11 };
|
||||
it("allows the dynamically highest rank", () =>
|
||||
expect(
|
||||
decideAuthorization({ actor, highestRank: 11, permission: "admin.any", hasPermission: false }).allowed,
|
||||
).toBe(true));
|
||||
it("allows explicit ACL permission below highest", () =>
|
||||
expect(
|
||||
decideAuthorization({ actor, highestRank: 12, permission: "admin.news.view", hasPermission: true })
|
||||
.allowed,
|
||||
).toBe(true));
|
||||
it("denies invalid ranks", () =>
|
||||
expect(
|
||||
decideAuthorization({
|
||||
actor: { ...actor, rank: 0 },
|
||||
highestRank: 11,
|
||||
permission: "admin.any",
|
||||
hasPermission: true,
|
||||
}),
|
||||
).toMatchObject({ allowed: false, reason: "invalid_rank" }));
|
||||
it("denies missing permission", () =>
|
||||
expect(
|
||||
decideAuthorization({ actor, highestRank: 12, permission: "admin.any", hasPermission: false }),
|
||||
).toMatchObject({ allowed: false, reason: "permission_denied" }));
|
||||
const actor = { id: 1, username: "admin", rank: 11 };
|
||||
it("allows the dynamically highest rank", () =>
|
||||
expect(
|
||||
decideAuthorization({
|
||||
actor,
|
||||
highestRank: 11,
|
||||
permission: "admin.any",
|
||||
hasPermission: false,
|
||||
}).allowed,
|
||||
).toBe(true));
|
||||
it("allows explicit ACL permission below highest", () =>
|
||||
expect(
|
||||
decideAuthorization({
|
||||
actor,
|
||||
highestRank: 12,
|
||||
permission: "admin.news.view",
|
||||
hasPermission: true,
|
||||
}).allowed,
|
||||
).toBe(true));
|
||||
it("denies invalid ranks", () =>
|
||||
expect(
|
||||
decideAuthorization({
|
||||
actor: { ...actor, rank: 0 },
|
||||
highestRank: 11,
|
||||
permission: "admin.any",
|
||||
hasPermission: true,
|
||||
}),
|
||||
).toMatchObject({ allowed: false, reason: "invalid_rank" }));
|
||||
it("denies missing permission", () =>
|
||||
expect(
|
||||
decideAuthorization({
|
||||
actor,
|
||||
highestRank: 12,
|
||||
permission: "admin.any",
|
||||
hasPermission: false,
|
||||
}),
|
||||
).toMatchObject({ allowed: false, reason: "permission_denied" }));
|
||||
});
|
||||
Reference in new issue
Block a user