import { revalidatePath } from "next/cache"; import { beforeEach, expect, it, vi } from "vitest"; import { requirePermission } from "@/lib/admin/guard"; import { addBlacklist, addWhitelist, deleteBlacklist, deleteWhitelist, } from "./admin-ip"; const { execute } = vi.hoisted(() => ({ execute: vi.fn() })); vi.mock("@/features/housekeeping/domains/people/services/mutations", () => ({ createPeopleMutationInvocation: vi.fn((staff, correlationId) => ({ expectedActorId: staff.id, correlationId, legacy: true, })), peopleMutationService: { execute }, })); vi.mock("@/lib/admin/guard", () => ({ requirePermission: vi.fn() })); vi.mock("@/lib/permissions", () => ({ PERMS: { SETTINGS_EDIT: "admin.settings.edit" }, })); vi.mock("next/cache", () => ({ revalidatePath: vi.fn() })); const staff = { id: 1, rank: 7, username: "admin" }; const form = (data: Record) => ({ get: (key: string) => data[key] ?? null }) as FormData; beforeEach(() => { vi.clearAllMocks(); vi.mocked(requirePermission).mockResolvedValue(staff as never); execute.mockResolvedValue({ ok: true, data: { before: null, after: {} }, correlationId: "ip", }); }); it("preserves all four IP actions and /admin revalidation", async () => { await addWhitelist(form({ ipAddress: "192.0.2.1", asn: "AS1" })); await addBlacklist(form({ ipAddress: "198.51.100.1" })); await deleteWhitelist(form({ id: "42" })); await deleteBlacklist(form({ id: "99" })); expect(execute.mock.calls.map((call) => [call[1], call[2]])).toEqual([ [ "ip.action", { action: "add-whitelist", ipAddress: "192.0.2.1", asn: "AS1" }, ], [ "ip.action", { action: "add-blacklist", ipAddress: "198.51.100.1", asn: "" }, ], ["ip.action", { action: "delete-whitelist", id: "42" }], ["ip.action", { action: "delete-blacklist", id: "99" }], ]); expect(revalidatePath).toHaveBeenCalledTimes(4); }); it("keeps empty IP input as a no-op after authorization", async () => { await addWhitelist(form({ ipAddress: "" })); expect(requirePermission).toHaveBeenCalledWith("admin.settings.edit"); expect(execute).not.toHaveBeenCalled(); }); it("preserves an IP rule ID above Number.MAX_SAFE_INTEGER", async () => { await deleteBlacklist(form({ id: "9007199254740993" })); expect(execute).toHaveBeenCalledWith(expect.anything(), "ip.action", { action: "delete-blacklist", id: "9007199254740993", }); });