mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-09-30 04:33:15 +00:00
* feat(api): serve portal-shaped health and error envelope
Move liveness to GET /api/health { stage, sha } with a Node 24 image on 8080 so ALB probes and deploy verify do not need auth or a database ping.
* feat(api): switch live auth to host cookie BFF
Replace Bearer as the documented session path with Cognito hosted UI plus __Host-ap_* cookies so the SPA can call /api with credentials include.
* feat(web): add unused cookie SPA API client
Land a credentials-include fetch helper and hand-synced health/me types without wiring pages or domain hooks, so mocks stay the default data path.
* feat(api): add master-data OpenAPI and Hono stubs
* feat(api): add invoice, line, and document stubs
* feat(api): add approval policy, inbox, and activity stubs
* test(web): fix SPA client fetch mock types
* test(web): cast fetch mock call args for tsc
* fix(api): do not default DEV_AUTH_BYPASS outside local migrate
* fix(api): replace invoice lines in a single transaction
* fix(api): create invoices and lines in one transaction
* fix(api): inline GIT_SHA from the image build arg
* fix(api): stop PATCH from skipping the approval workflow
* fix(api): address review feedback
* fix(ci): format upsert-user test
* fix(api): document only the auth statuses the routes return
* fix(api): drop health 400 responses the routes never return
139 lines
3.9 KiB
TypeScript
139 lines
3.9 KiB
TypeScript
import { describe, expect, it, vi } from "vitest";
|
|
import type { Db } from "../db/client.js";
|
|
import { IdentityConflictError, upsertUserFromIdentity } from "./upsert-user.js";
|
|
|
|
function createDb(options: {
|
|
bySub?: Record<string, unknown> | null;
|
|
byEmail?: Record<string, unknown> | null;
|
|
}): { handle: Db; setSpy: ReturnType<typeof vi.fn> } {
|
|
const findFirst = vi.fn(async (_args: { where: unknown }) => {
|
|
// drizzle eq objects aren't introspectable here; alternate by call order.
|
|
if (findFirst.mock.calls.length === 1) {
|
|
return options.bySub ?? null;
|
|
}
|
|
return options.byEmail ?? null;
|
|
});
|
|
|
|
const returningRow = {
|
|
id: "11111111-1111-4111-8111-111111111111",
|
|
cognitoSub: "seed-sub-admin",
|
|
email: "admin@seahavenind.com",
|
|
name: "Dev Admin",
|
|
role: "admin" as const,
|
|
};
|
|
|
|
const setSpy = vi.fn((patch: Record<string, unknown>) => ({
|
|
where: vi.fn(() => ({
|
|
returning: vi.fn(async () => [
|
|
{ ...returningRow, ...patch, role: patch.role ?? returningRow.role },
|
|
]),
|
|
})),
|
|
}));
|
|
|
|
return {
|
|
handle: {
|
|
driver: "postgres",
|
|
pool: { end: vi.fn(async () => undefined) } as never,
|
|
db: {
|
|
query: { users: { findFirst } },
|
|
update: vi.fn(() => ({
|
|
set: setSpy,
|
|
})),
|
|
insert: vi.fn(() => ({
|
|
values: vi.fn(() => ({
|
|
returning: vi.fn(async () => [returningRow]),
|
|
})),
|
|
})),
|
|
} as never,
|
|
},
|
|
setSpy,
|
|
};
|
|
}
|
|
|
|
describe("upsertUserFromIdentity", () => {
|
|
it("updates an existing row matched by cognito sub", async () => {
|
|
const { handle } = createDb({
|
|
bySub: {
|
|
id: "11111111-1111-4111-8111-111111111111",
|
|
cognitoSub: "seed-sub-admin",
|
|
email: "admin@seahavenind.com",
|
|
name: "Old Name",
|
|
role: "admin",
|
|
},
|
|
});
|
|
|
|
const user = await upsertUserFromIdentity(handle, {
|
|
cognitoSub: "seed-sub-admin",
|
|
email: "admin@seahavenind.com",
|
|
name: "Dev Admin",
|
|
role: "admin",
|
|
});
|
|
|
|
expect(user.cognitoSub).toBe("seed-sub-admin");
|
|
expect(handle.db.update).toHaveBeenCalled();
|
|
});
|
|
|
|
it("preserves the stored role when the token omits a role claim", async () => {
|
|
const { handle, setSpy } = createDb({
|
|
bySub: {
|
|
id: "11111111-1111-4111-8111-111111111111",
|
|
cognitoSub: "seed-sub-admin",
|
|
email: "admin@seahavenind.com",
|
|
name: "Dev Admin",
|
|
role: "admin",
|
|
},
|
|
});
|
|
|
|
const user = await upsertUserFromIdentity(handle, {
|
|
cognitoSub: "seed-sub-admin",
|
|
email: "admin@seahavenind.com",
|
|
name: "Dev Admin",
|
|
});
|
|
|
|
expect(setSpy).toHaveBeenCalledWith(expect.not.objectContaining({ role: expect.anything() }));
|
|
expect(user.role).toBe("admin");
|
|
});
|
|
|
|
it("writes an explicit role claim over the stored role", async () => {
|
|
const { handle, setSpy } = createDb({
|
|
bySub: {
|
|
id: "11111111-1111-4111-8111-111111111111",
|
|
cognitoSub: "seed-sub-admin",
|
|
email: "admin@seahavenind.com",
|
|
name: "Dev Admin",
|
|
role: "viewer",
|
|
},
|
|
});
|
|
|
|
await upsertUserFromIdentity(handle, {
|
|
cognitoSub: "seed-sub-admin",
|
|
email: "admin@seahavenind.com",
|
|
name: "Dev Admin",
|
|
role: "approver",
|
|
});
|
|
|
|
expect(setSpy).toHaveBeenCalledWith(expect.objectContaining({ role: "approver" }));
|
|
});
|
|
|
|
it("refuses to rebind an email owned by a different cognito sub", async () => {
|
|
const { handle } = createDb({
|
|
bySub: null,
|
|
byEmail: {
|
|
id: "11111111-1111-4111-8111-111111111111",
|
|
cognitoSub: "other-sub",
|
|
email: "admin@seahavenind.com",
|
|
name: "Seed Admin",
|
|
role: "admin",
|
|
},
|
|
});
|
|
|
|
await expect(
|
|
upsertUserFromIdentity(handle, {
|
|
cognitoSub: "attacker-sub",
|
|
email: "admin@seahavenind.com",
|
|
name: "Attacker",
|
|
role: "admin",
|
|
}),
|
|
).rejects.toBeInstanceOf(IdentityConflictError);
|
|
});
|
|
});
|