fix: authorize super admins by dynamic highest rank
Remote Build and Deploy / deploy (push) Successful in 42s

This commit is contained in:
Simo committed 2026-07-11 22:35:40 +02:00
1 parent bb847176ad
commit f08e56cf53
10 files changed
+173 -65

No files matched your search

@@ -0,0 +1,18 @@
import { describe, expect, it } from "vitest";
import { decideAuthorization, isDynamicSuperAdmin } from "@/lib/admin/authorization-policy";
describe("isDynamicSuperAdmin", () => {
it.each([[7, 7], [11, 11], [2000, 2000]])("accepts highest rank %i", (rank, highest) => {
expect(isDynamicSuperAdmin(rank, highest)).toBe(true);
});
it("demotes the previous highest rank", () => expect(isDynamicSuperAdmin(2000, 2001)).toBe(false));
it("fails closed without ranks", () => expect(isDynamicSuperAdmin(1, null)).toBe(false));
});
describe("decideAuthorization", () => {
const actor = { id: 1, username: "admin", rank: 11 };
it("allows the dynamically highest rank", () => expect(decideAuthorization({ actor, highestRank: 11, permission: "admin.any", hasPermission: false }).allowed).toBe(true));
it("allows explicit ACL permission below highest", () => expect(decideAuthorization({ actor, highestRank: 12, permission: "admin.news.view", hasPermission: true }).allowed).toBe(true));
it("denies invalid ranks", () => expect(decideAuthorization({ actor: { ...actor, rank: 0 }, highestRank: 11, permission: "admin.any", hasPermission: true })).toMatchObject({ allowed: false, reason: "invalid_rank" }));
it("denies missing permission", () => expect(decideAuthorization({ actor, highestRank: 12, permission: "admin.any", hasPermission: false })).toMatchObject({ allowed: false, reason: "permission_denied" }));
});