2026-08-10 20:10:49 -04:00
|
|
|
import { describe, expect, it, vi } from "vitest";
|
|
|
|
|
import type { Db } from "../db/client.js";
|
|
|
|
|
import { IdentityConflictError, upsertUserFromIdentity } from "./upsert-user.js";
|
|
|
|
|
|
|
|
|
|
function createDb(options: {
|
|
|
|
|
bySub?: Record<string, unknown> | null;
|
|
|
|
|
byEmail?: Record<string, unknown> | null;
|
2026-09-25 22:43:44 +00:00
|
|
|
}): { handle: Db; setSpy: ReturnType<typeof vi.fn> } {
|
2026-08-10 20:10:49 -04:00
|
|
|
const findFirst = vi.fn(async (_args: { where: unknown }) => {
|
|
|
|
|
// drizzle eq objects aren't introspectable here; alternate by call order.
|
|
|
|
|
if (findFirst.mock.calls.length === 1) {
|
|
|
|
|
return options.bySub ?? null;
|
|
|
|
|
}
|
|
|
|
|
return options.byEmail ?? null;
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
const returningRow = {
|
|
|
|
|
id: "11111111-1111-4111-8111-111111111111",
|
|
|
|
|
cognitoSub: "seed-sub-admin",
|
|
|
|
|
email: "admin@seahavenind.com",
|
|
|
|
|
name: "Dev Admin",
|
|
|
|
|
role: "admin" as const,
|
|
|
|
|
};
|
|
|
|
|
|
2026-09-25 22:43:44 +00:00
|
|
|
const setSpy = vi.fn((patch: Record<string, unknown>) => ({
|
|
|
|
|
where: vi.fn(() => ({
|
|
|
|
|
returning: vi.fn(async () => [
|
|
|
|
|
{ ...returningRow, ...patch, role: patch.role ?? returningRow.role },
|
|
|
|
|
]),
|
|
|
|
|
})),
|
|
|
|
|
}));
|
|
|
|
|
|
2026-08-10 20:10:49 -04:00
|
|
|
return {
|
2026-09-25 22:43:44 +00:00
|
|
|
handle: {
|
|
|
|
|
driver: "postgres",
|
|
|
|
|
pool: { end: vi.fn(async () => undefined) } as never,
|
|
|
|
|
db: {
|
|
|
|
|
query: { users: { findFirst } },
|
|
|
|
|
update: vi.fn(() => ({
|
|
|
|
|
set: setSpy,
|
|
|
|
|
})),
|
|
|
|
|
insert: vi.fn(() => ({
|
|
|
|
|
values: vi.fn(() => ({
|
2026-08-10 20:10:49 -04:00
|
|
|
returning: vi.fn(async () => [returningRow]),
|
|
|
|
|
})),
|
|
|
|
|
})),
|
2026-09-25 22:43:44 +00:00
|
|
|
} as never,
|
|
|
|
|
},
|
|
|
|
|
setSpy,
|
2026-08-10 20:10:49 -04:00
|
|
|
};
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
describe("upsertUserFromIdentity", () => {
|
|
|
|
|
it("updates an existing row matched by cognito sub", async () => {
|
2026-09-25 22:43:44 +00:00
|
|
|
const { handle } = createDb({
|
2026-08-10 20:10:49 -04:00
|
|
|
bySub: {
|
|
|
|
|
id: "11111111-1111-4111-8111-111111111111",
|
|
|
|
|
cognitoSub: "seed-sub-admin",
|
|
|
|
|
email: "admin@seahavenind.com",
|
|
|
|
|
name: "Old Name",
|
|
|
|
|
role: "admin",
|
|
|
|
|
},
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
const user = await upsertUserFromIdentity(handle, {
|
|
|
|
|
cognitoSub: "seed-sub-admin",
|
|
|
|
|
email: "admin@seahavenind.com",
|
|
|
|
|
name: "Dev Admin",
|
|
|
|
|
role: "admin",
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
expect(user.cognitoSub).toBe("seed-sub-admin");
|
|
|
|
|
expect(handle.db.update).toHaveBeenCalled();
|
|
|
|
|
});
|
|
|
|
|
|
2026-09-25 22:43:44 +00:00
|
|
|
it("preserves the stored role when the token omits a role claim", async () => {
|
|
|
|
|
const { handle, setSpy } = createDb({
|
|
|
|
|
bySub: {
|
|
|
|
|
id: "11111111-1111-4111-8111-111111111111",
|
|
|
|
|
cognitoSub: "seed-sub-admin",
|
|
|
|
|
email: "admin@seahavenind.com",
|
|
|
|
|
name: "Dev Admin",
|
|
|
|
|
role: "admin",
|
|
|
|
|
},
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
const user = await upsertUserFromIdentity(handle, {
|
|
|
|
|
cognitoSub: "seed-sub-admin",
|
|
|
|
|
email: "admin@seahavenind.com",
|
|
|
|
|
name: "Dev Admin",
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
expect(setSpy).toHaveBeenCalledWith(expect.not.objectContaining({ role: expect.anything() }));
|
|
|
|
|
expect(user.role).toBe("admin");
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("writes an explicit role claim over the stored role", async () => {
|
|
|
|
|
const { handle, setSpy } = createDb({
|
|
|
|
|
bySub: {
|
|
|
|
|
id: "11111111-1111-4111-8111-111111111111",
|
|
|
|
|
cognitoSub: "seed-sub-admin",
|
|
|
|
|
email: "admin@seahavenind.com",
|
|
|
|
|
name: "Dev Admin",
|
|
|
|
|
role: "viewer",
|
|
|
|
|
},
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
await upsertUserFromIdentity(handle, {
|
|
|
|
|
cognitoSub: "seed-sub-admin",
|
|
|
|
|
email: "admin@seahavenind.com",
|
|
|
|
|
name: "Dev Admin",
|
|
|
|
|
role: "approver",
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
expect(setSpy).toHaveBeenCalledWith(expect.objectContaining({ role: "approver" }));
|
|
|
|
|
});
|
|
|
|
|
|
2026-08-10 20:10:49 -04:00
|
|
|
it("refuses to rebind an email owned by a different cognito sub", async () => {
|
2026-09-25 22:43:44 +00:00
|
|
|
const { handle } = createDb({
|
2026-08-10 20:10:49 -04:00
|
|
|
bySub: null,
|
|
|
|
|
byEmail: {
|
|
|
|
|
id: "11111111-1111-4111-8111-111111111111",
|
|
|
|
|
cognitoSub: "other-sub",
|
|
|
|
|
email: "admin@seahavenind.com",
|
|
|
|
|
name: "Seed Admin",
|
|
|
|
|
role: "admin",
|
|
|
|
|
},
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
await expect(
|
|
|
|
|
upsertUserFromIdentity(handle, {
|
|
|
|
|
cognitoSub: "attacker-sub",
|
|
|
|
|
email: "admin@seahavenind.com",
|
|
|
|
|
name: "Attacker",
|
|
|
|
|
role: "admin",
|
|
|
|
|
}),
|
|
|
|
|
).rejects.toBeInstanceOf(IdentityConflictError);
|
|
|
|
|
});
|
|
|
|
|
});
|