mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-10-01 05:03:19 +00:00
* feat(api): stand up Hono Drizzle foundation with auth and Redocly * fix(api): bump drizzle-orm and hono node-server past audit highs * fix(api): harden auth upsert and Cognito token verification
30 lines
1 KiB
TypeScript
30 lines
1 KiB
TypeScript
import { describe, expect, it } from "vitest";
|
|
import { can, RBAC_ACTIONS, type RbacAction } from "./rbac.js";
|
|
import { USER_ROLES, type UserRole } from "../env.js";
|
|
|
|
const EXPECTED: Record<UserRole, RbacAction[]> = {
|
|
admin: [...RBAC_ACTIONS],
|
|
ap_processor: ["read:me", "read:invoices", "write:invoices"],
|
|
approver: ["read:me", "read:invoices", "approve:invoices"],
|
|
viewer: ["read:me", "read:invoices"],
|
|
};
|
|
|
|
describe("RBAC matrix", () => {
|
|
it.each(USER_ROLES)("role %s matches the foundation matrix", (role) => {
|
|
for (const action of RBAC_ACTIONS) {
|
|
expect(can(role, action)).toBe(EXPECTED[role].includes(action));
|
|
}
|
|
});
|
|
|
|
it("denies viewer write and approve actions", () => {
|
|
expect(can("viewer", "write:invoices")).toBe(false);
|
|
expect(can("viewer", "approve:invoices")).toBe(false);
|
|
expect(can("viewer", "admin:settings")).toBe(false);
|
|
});
|
|
|
|
it("allows admin every foundation action", () => {
|
|
for (const action of RBAC_ACTIONS) {
|
|
expect(can("admin", action)).toBe(true);
|
|
}
|
|
});
|
|
});
|