-
Notifications
You must be signed in to change notification settings - Fork 2
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat(permissions): list body members with permission
- Loading branch information
1 parent
cbd2eb1
commit 4988337
Showing
2 changed files
with
221 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,168 @@ | ||
const { startServer, stopServer } = require('../../lib/server.js'); | ||
const { request } = require('../scripts/helpers'); | ||
const generator = require('../scripts/generator'); | ||
|
||
describe('Memberships list wth permission', () => { | ||
beforeAll(async () => { | ||
await startServer(); | ||
}); | ||
|
||
afterAll(async () => { | ||
await stopServer(); | ||
}); | ||
|
||
afterEach(async () => { | ||
await generator.clearAll(); | ||
}); | ||
|
||
test('should fail if no view:member permission', async () => { | ||
const user = await generator.createUser(); | ||
const token = await generator.createAccessToken({}, user); | ||
|
||
const body = await generator.createBody(); | ||
await generator.createBodyMembership(body, user); | ||
|
||
const res = await request({ | ||
uri: '/bodies/' + body.id + '/members', | ||
method: 'GET', | ||
qs: { holds_permission: { action: 'action', object: 'object' } }, | ||
headers: { 'X-Auth-Token': token.value } | ||
}); | ||
|
||
expect(res.statusCode).toEqual(403); | ||
expect(res.body.success).toEqual(false); | ||
expect(res.body).toHaveProperty('message'); | ||
expect(res.body).not.toHaveProperty('data'); | ||
}); | ||
|
||
test('should complain if no action is specified', async () => { | ||
const user = await generator.createUser({ superadmin: true }); | ||
const token = await generator.createAccessToken({}, user); | ||
|
||
const body = await generator.createBody(); | ||
await generator.createBodyMembership(body, user); | ||
|
||
await generator.createPermission({ scope: 'global', action: 'view_member', object: 'body' }); | ||
|
||
const res = await request({ | ||
uri: '/bodies/' + body.id + '/members', | ||
method: 'GET', | ||
qs: { holds_permission: { object: 'object' } }, | ||
headers: { 'X-Auth-Token': token.value } | ||
}); | ||
|
||
expect(res.statusCode).toEqual(400); | ||
expect(res.body.success).toEqual(false); | ||
expect(res.body).toHaveProperty('message'); | ||
expect(res.body).not.toHaveProperty('data'); | ||
}); | ||
|
||
test('should complain if no object is specified', async () => { | ||
const user = await generator.createUser({ superadmin: true }); | ||
const token = await generator.createAccessToken({}, user); | ||
|
||
const body = await generator.createBody(); | ||
await generator.createBodyMembership(body, user); | ||
|
||
await generator.createPermission({ scope: 'global', action: 'view_member', object: 'body' }); | ||
|
||
const res = await request({ | ||
uri: '/bodies/' + body.id + '/members', | ||
method: 'GET', | ||
qs: { holds_permission: { action: 'action' } }, | ||
headers: { 'X-Auth-Token': token.value } | ||
}); | ||
|
||
expect(res.statusCode).toEqual(400); | ||
expect(res.body.success).toEqual(false); | ||
expect(res.body).toHaveProperty('message'); | ||
expect(res.body).not.toHaveProperty('data'); | ||
}); | ||
|
||
test('should fail if no permission found', async () => { | ||
const user = await generator.createUser({ superadmin: true }); | ||
const token = await generator.createAccessToken({}, user); | ||
|
||
const body = await generator.createBody(); | ||
await generator.createBodyMembership(body, user); | ||
|
||
await generator.createPermission({ scope: 'global', action: 'view_member', object: 'body' }); | ||
|
||
const res = await request({ | ||
uri: '/bodies/' + body.id + '/members', | ||
method: 'GET', | ||
qs: { holds_permission: { action: 'action', object: 'object' } }, | ||
headers: { 'X-Auth-Token': token.value } | ||
}); | ||
|
||
expect(res.statusCode).toEqual(404); | ||
expect(res.body.success).toEqual(false); | ||
expect(res.body).toHaveProperty('message'); | ||
expect(res.body).not.toHaveProperty('data'); | ||
}); | ||
|
||
test('should list member who got this permission from a bound circle directly', async () => { | ||
const user = await generator.createUser({ superadmin: true }); | ||
const token = await generator.createAccessToken({}, user); | ||
|
||
await generator.createPermission({ scope: 'global', action: 'view_member', object: 'body' }); | ||
|
||
const body = await generator.createBody(); | ||
const permission = await generator.createPermission({ scope: 'local', action: 'action', object: 'object' }); | ||
const circle = await generator.createCircle({ body_id: body.id }); | ||
const otherUser = await generator.createUser(); | ||
await generator.createBodyMembership(body, otherUser); | ||
await generator.createCircleMembership(circle, otherUser); | ||
await generator.createCirclePermission(circle, permission); | ||
|
||
const res = await request({ | ||
uri: '/bodies/' + body.id + '/members', | ||
method: 'GET', | ||
qs: { holds_permission: { action: 'action', object: 'object' } }, | ||
headers: { 'X-Auth-Token': token.value } | ||
}); | ||
|
||
expect(res.statusCode).toEqual(200); | ||
expect(res.body.success).toEqual(true); | ||
expect(res.body).toHaveProperty('data'); | ||
expect(res.body).not.toHaveProperty('errors'); | ||
|
||
expect(res.body.data.length).toEqual(1); | ||
expect(res.body.data[0].user.id).toEqual(otherUser.id); | ||
}); | ||
|
||
test('should list member who got this permission from a bound circle indirectly', async () => { | ||
const user = await generator.createUser({ superadmin: true }); | ||
const token = await generator.createAccessToken({}, user); | ||
|
||
await generator.createPermission({ scope: 'global', action: 'view_member', object: 'body' }); | ||
|
||
const body = await generator.createBody(); | ||
const permission = await generator.createPermission({ scope: 'local', action: 'action', object: 'object' }); | ||
|
||
|
||
const firstCircle = await generator.createCircle(); | ||
const secondCircle = await generator.createCircle({ parent_circle_id: firstCircle.id }); | ||
const thirdCircle = await generator.createCircle({ parent_circle_id: secondCircle.id, body_id: body.id }); | ||
|
||
const otherUser = await generator.createUser(); | ||
await generator.createBodyMembership(body, otherUser); | ||
await generator.createCircleMembership(thirdCircle, otherUser); | ||
await generator.createCirclePermission(firstCircle, permission); | ||
|
||
const res = await request({ | ||
uri: '/bodies/' + body.id + '/members', | ||
method: 'GET', | ||
qs: { holds_permission: { action: 'action', object: 'object' } }, | ||
headers: { 'X-Auth-Token': token.value } | ||
}); | ||
|
||
expect(res.statusCode).toEqual(200); | ||
expect(res.body.success).toEqual(true); | ||
expect(res.body).toHaveProperty('data'); | ||
expect(res.body).not.toHaveProperty('errors'); | ||
|
||
expect(res.body.data.length).toEqual(1); | ||
expect(res.body.data[0].user.id).toEqual(otherUser.id); | ||
}); | ||
}); |