import { describe, expect, it } from "vitest"; import { can, RBAC_ACTIONS, type RbacAction } from "./rbac.js"; import { USER_ROLES, type UserRole } from "../env.js"; const EXPECTED: Record = { admin: [...RBAC_ACTIONS], ap_processor: ["read:me", "read:invoices", "write:invoices"], approver: ["read:me", "read:invoices", "approve:invoices"], viewer: ["read:me", "read:invoices"], }; describe("RBAC matrix", () => { it.each(USER_ROLES)("role %s matches the foundation matrix", (role) => { for (const action of RBAC_ACTIONS) { expect(can(role, action)).toBe(EXPECTED[role].includes(action)); } }); it("denies viewer write and approve actions", () => { expect(can("viewer", "write:invoices")).toBe(false); expect(can("viewer", "approve:invoices")).toBe(false); expect(can("viewer", "admin:settings")).toBe(false); }); it("allows admin every foundation action", () => { for (const action of RBAC_ACTIONS) { expect(can("admin", action)).toBe(true); } }); });