seahaven-ap/packages/api/src/auth/rbac.test.ts
Adam Moussa 9d3646876e
feat(api): stand up Hono Drizzle foundation with auth and Redocly (AP-14) (#12)
* feat(api): stand up Hono Drizzle foundation with auth and Redocly

* fix(api): bump drizzle-orm and hono node-server past audit highs

* fix(api): harden auth upsert and Cognito token verification
2026-08-11 00:10:49 +00:00

30 lines
1 KiB
TypeScript

import { describe, expect, it } from "vitest";
import { can, RBAC_ACTIONS, type RbacAction } from "./rbac.js";
import { USER_ROLES, type UserRole } from "../env.js";
const EXPECTED: Record<UserRole, RbacAction[]> = {
admin: [...RBAC_ACTIONS],
ap_processor: ["read:me", "read:invoices", "write:invoices"],
approver: ["read:me", "read:invoices", "approve:invoices"],
viewer: ["read:me", "read:invoices"],
};
describe("RBAC matrix", () => {
it.each(USER_ROLES)("role %s matches the foundation matrix", (role) => {
for (const action of RBAC_ACTIONS) {
expect(can(role, action)).toBe(EXPECTED[role].includes(action));
}
});
it("denies viewer write and approve actions", () => {
expect(can("viewer", "write:invoices")).toBe(false);
expect(can("viewer", "approve:invoices")).toBe(false);
expect(can("viewer", "admin:settings")).toBe(false);
});
it("allows admin every foundation action", () => {
for (const action of RBAC_ACTIONS) {
expect(can("admin", action)).toBe(true);
}
});
});