|
1 | 1 | import { describe, expect, test } from "bun:test" |
2 | | -import { compareRole, type ProjectRoleName } from "./permissions" |
| 2 | +import { randomBytes } from "node:crypto" |
| 3 | +import { sql } from "drizzle-orm" |
| 4 | +import { db } from "../db" |
| 5 | +import { projects, projectMembers, user } from "../db/schema" |
| 6 | +import { compareRole, requireProjectRoleByUser, type ProjectRoleName } from "./permissions" |
3 | 7 |
|
4 | 8 | describe("compareRole", () => { |
5 | 9 | const roles: ProjectRoleName[] = ["viewer", "manager", "developer", "owner"] |
@@ -31,3 +35,65 @@ describe("compareRole", () => { |
31 | 35 | expect(compareRole("viewer", "owner")).toBe(false) |
32 | 36 | }) |
33 | 37 | }) |
| 38 | + |
| 39 | +test("requireProjectRoleByUser — returns role when member meets minimum", async () => { |
| 40 | + await db.execute(sql`TRUNCATE project_members, projects, "user" RESTART IDENTITY CASCADE`) |
| 41 | + const userId = randomBytes(16).toString("hex") |
| 42 | + const projectId = crypto.randomUUID() |
| 43 | + await db.insert(user).values({ |
| 44 | + id: userId, |
| 45 | + email: `t-${userId}@example.com`, |
| 46 | + name: "t", |
| 47 | + emailVerified: true, |
| 48 | + role: "member", |
| 49 | + status: "active", |
| 50 | + createdAt: new Date(), |
| 51 | + updatedAt: new Date(), |
| 52 | + }) |
| 53 | + await db.insert(projects).values({ id: projectId, name: "p", createdBy: userId }) |
| 54 | + await db.insert(projectMembers).values({ projectId, userId, role: "developer" }) |
| 55 | + |
| 56 | + const role = await requireProjectRoleByUser(userId, projectId, "manager") |
| 57 | + expect(role).toBe("developer") |
| 58 | +}) |
| 59 | + |
| 60 | +test("requireProjectRoleByUser — throws 403 when role too low", async () => { |
| 61 | + await db.execute(sql`TRUNCATE project_members, projects, "user" RESTART IDENTITY CASCADE`) |
| 62 | + const userId = randomBytes(16).toString("hex") |
| 63 | + const projectId = crypto.randomUUID() |
| 64 | + await db.insert(user).values({ |
| 65 | + id: userId, |
| 66 | + email: `t-${userId}@example.com`, |
| 67 | + name: "t", |
| 68 | + emailVerified: true, |
| 69 | + role: "member", |
| 70 | + status: "active", |
| 71 | + createdAt: new Date(), |
| 72 | + updatedAt: new Date(), |
| 73 | + }) |
| 74 | + await db.insert(projects).values({ id: projectId, name: "p", createdBy: userId }) |
| 75 | + await db.insert(projectMembers).values({ projectId, userId, role: "viewer" }) |
| 76 | + |
| 77 | + await expect(requireProjectRoleByUser(userId, projectId, "developer")).rejects.toThrow( |
| 78 | + /insufficient/i, |
| 79 | + ) |
| 80 | +}) |
| 81 | + |
| 82 | +test("requireProjectRoleByUser — throws 404 when not a member", async () => { |
| 83 | + await db.execute(sql`TRUNCATE project_members, projects, "user" RESTART IDENTITY CASCADE`) |
| 84 | + const userId = randomBytes(16).toString("hex") |
| 85 | + const projectId = crypto.randomUUID() |
| 86 | + await db.insert(user).values({ |
| 87 | + id: userId, |
| 88 | + email: `t-${userId}@example.com`, |
| 89 | + name: "t", |
| 90 | + emailVerified: true, |
| 91 | + role: "member", |
| 92 | + status: "active", |
| 93 | + createdAt: new Date(), |
| 94 | + updatedAt: new Date(), |
| 95 | + }) |
| 96 | + await db.insert(projects).values({ id: projectId, name: "p", createdBy: userId }) |
| 97 | + |
| 98 | + await expect(requireProjectRoleByUser(userId, projectId, "viewer")).rejects.toThrow(/not found/i) |
| 99 | +}) |
0 commit comments