-
Notifications
You must be signed in to change notification settings - Fork 87
Expand file tree
/
Copy pathappAuthorization.test.ts
More file actions
124 lines (105 loc) · 3.35 KB
/
Copy pathappAuthorization.test.ts
File metadata and controls
124 lines (105 loc) · 3.35 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
import { describe, expect, test } from 'vitest';
import {
canWriteAppVersion,
getAppAuthorizationErrorMessage,
getAppAuthorizationRole,
} from './appAuthorization.js';
describe('appAuthorization', () => {
test('recognizes the app owner by stable account ID', () => {
const appInfo = {
app: {
owner: { id: 't2_owner', displayName: 'OriginalOwnerName' },
},
};
const role = getAppAuthorizationRole(appInfo, {
id: 't2_owner',
displayName: 'RenamedOwner',
});
expect(role).toBe('owner');
expect(canWriteAppVersion(role)).toBe(true);
});
test('does not fall back to a matching display name when stable IDs disagree', () => {
const appInfo = {
app: {
owner: { id: 't2_owner', displayName: 'SharedName' },
},
};
expect(
getAppAuthorizationRole(appInfo, {
id: 't2_other',
displayName: 'SharedName',
})
).toBe('unauthorized');
});
test('recognizes a maintainer from typed authorization metadata by account ID', () => {
const appInfo = {
app: {
owner: { id: 't2_owner', displayName: 'OwnerName' },
authorization: {
maintainers: [{ id: 't2_maintainer', displayName: 'MaintainerName' }],
},
},
};
const role = getAppAuthorizationRole(appInfo, {
id: 't2_maintainer',
displayName: 'RenamedMaintainer',
});
expect(role).toBe('maintainer');
expect(canWriteAppVersion(role)).toBe(true);
});
test('accepts a backend-computed current-user role', () => {
const appInfo = {
app: {
authorization: {
currentUserRole: 'maintainer',
},
},
};
expect(getAppAuthorizationRole(appInfo, '')).toBe('maintainer');
});
test('temporarily supports the prototype maintainer list by display name', () => {
const appInfo = {
app: {
owner: { displayName: 'OwnerName' },
maintainers: [{ displayName: 'MaintainerName' }],
},
};
expect(getAppAuthorizationRole(appInfo, ' maintainername ')).toBe('maintainer');
});
test('does not authorize an unrelated developer', () => {
const appInfo = {
app: {
owner: { id: 't2_owner', displayName: 'OwnerName' },
authorization: {
maintainers: [{ id: 't2_maintainer', displayName: 'MaintainerName' }],
},
},
};
const role = getAppAuthorizationRole(appInfo, {
id: 't2_other',
displayName: 'OtherDeveloper',
});
expect(role).toBe('unauthorized');
expect(canWriteAppVersion(role)).toBe(false);
});
test.each(['owner', 'maintainer'] as const)(
'allows the %s role to upload, publish, and playtest app versions',
(role) => {
expect(canWriteAppVersion(role)).toBe(true);
}
);
test('denies app-version writes when authorization metadata is missing', () => {
expect(getAppAuthorizationRole(undefined, 'OwnerName')).toBe('unauthorized');
expect(getAppAuthorizationRole({ app: null }, 'OwnerName')).toBe('unauthorized');
expect(getAppAuthorizationRole({ app: {} }, '')).toBe('unauthorized');
});
test('uses a maintainer-aware error message', () => {
expect(
getAppAuthorizationErrorMessage(
{ app: { owner: { displayName: 'OwnerName' } } },
'example-app',
'publish'
)
).toContain('owner (OwnerName) or as a designated maintainer');
});
});