seahaven-ap/packages/api/src/auth/upsert-user.test.ts
Adam Moussa 864531b51e
feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64)
* feat(api): serve portal-shaped health and error envelope

Move liveness to GET /api/health { stage, sha } with a Node 24 image on 8080 so ALB probes and deploy verify do not need auth or a database ping.

* feat(api): switch live auth to host cookie BFF

Replace Bearer as the documented session path with Cognito hosted UI plus __Host-ap_* cookies so the SPA can call /api with credentials include.

* feat(web): add unused cookie SPA API client

Land a credentials-include fetch helper and hand-synced health/me types without wiring pages or domain hooks, so mocks stay the default data path.

* feat(api): add master-data OpenAPI and Hono stubs

* feat(api): add invoice, line, and document stubs

* feat(api): add approval policy, inbox, and activity stubs

* test(web): fix SPA client fetch mock types

* test(web): cast fetch mock call args for tsc

* fix(api): do not default DEV_AUTH_BYPASS outside local migrate

* fix(api): replace invoice lines in a single transaction

* fix(api): create invoices and lines in one transaction

* fix(api): inline GIT_SHA from the image build arg

* fix(api): stop PATCH from skipping the approval workflow

* fix(api): address review feedback

* fix(ci): format upsert-user test

* fix(api): document only the auth statuses the routes return

* fix(api): drop health 400 responses the routes never return
2026-09-25 22:43:44 +00:00

139 lines
3.9 KiB
TypeScript

import { describe, expect, it, vi } from "vitest";
import type { Db } from "../db/client.js";
import { IdentityConflictError, upsertUserFromIdentity } from "./upsert-user.js";
function createDb(options: {
bySub?: Record<string, unknown> | null;
byEmail?: Record<string, unknown> | null;
}): { handle: Db; setSpy: ReturnType<typeof vi.fn> } {
const findFirst = vi.fn(async (_args: { where: unknown }) => {
// drizzle eq objects aren't introspectable here; alternate by call order.
if (findFirst.mock.calls.length === 1) {
return options.bySub ?? null;
}
return options.byEmail ?? null;
});
const returningRow = {
id: "11111111-1111-4111-8111-111111111111",
cognitoSub: "seed-sub-admin",
email: "admin@seahavenind.com",
name: "Dev Admin",
role: "admin" as const,
};
const setSpy = vi.fn((patch: Record<string, unknown>) => ({
where: vi.fn(() => ({
returning: vi.fn(async () => [
{ ...returningRow, ...patch, role: patch.role ?? returningRow.role },
]),
})),
}));
return {
handle: {
driver: "postgres",
pool: { end: vi.fn(async () => undefined) } as never,
db: {
query: { users: { findFirst } },
update: vi.fn(() => ({
set: setSpy,
})),
insert: vi.fn(() => ({
values: vi.fn(() => ({
returning: vi.fn(async () => [returningRow]),
})),
})),
} as never,
},
setSpy,
};
}
describe("upsertUserFromIdentity", () => {
it("updates an existing row matched by cognito sub", async () => {
const { handle } = createDb({
bySub: {
id: "11111111-1111-4111-8111-111111111111",
cognitoSub: "seed-sub-admin",
email: "admin@seahavenind.com",
name: "Old Name",
role: "admin",
},
});
const user = await upsertUserFromIdentity(handle, {
cognitoSub: "seed-sub-admin",
email: "admin@seahavenind.com",
name: "Dev Admin",
role: "admin",
});
expect(user.cognitoSub).toBe("seed-sub-admin");
expect(handle.db.update).toHaveBeenCalled();
});
it("preserves the stored role when the token omits a role claim", async () => {
const { handle, setSpy } = createDb({
bySub: {
id: "11111111-1111-4111-8111-111111111111",
cognitoSub: "seed-sub-admin",
email: "admin@seahavenind.com",
name: "Dev Admin",
role: "admin",
},
});
const user = await upsertUserFromIdentity(handle, {
cognitoSub: "seed-sub-admin",
email: "admin@seahavenind.com",
name: "Dev Admin",
});
expect(setSpy).toHaveBeenCalledWith(expect.not.objectContaining({ role: expect.anything() }));
expect(user.role).toBe("admin");
});
it("writes an explicit role claim over the stored role", async () => {
const { handle, setSpy } = createDb({
bySub: {
id: "11111111-1111-4111-8111-111111111111",
cognitoSub: "seed-sub-admin",
email: "admin@seahavenind.com",
name: "Dev Admin",
role: "viewer",
},
});
await upsertUserFromIdentity(handle, {
cognitoSub: "seed-sub-admin",
email: "admin@seahavenind.com",
name: "Dev Admin",
role: "approver",
});
expect(setSpy).toHaveBeenCalledWith(expect.objectContaining({ role: "approver" }));
});
it("refuses to rebind an email owned by a different cognito sub", async () => {
const { handle } = createDb({
bySub: null,
byEmail: {
id: "11111111-1111-4111-8111-111111111111",
cognitoSub: "other-sub",
email: "admin@seahavenind.com",
name: "Seed Admin",
role: "admin",
},
});
await expect(
upsertUserFromIdentity(handle, {
cognitoSub: "attacker-sub",
email: "admin@seahavenind.com",
name: "Attacker",
role: "admin",
}),
).rejects.toBeInstanceOf(IdentityConflictError);
});
});