shoc-backend/SeaHavenIndustries.Tests/WorkOrderAccountTestHelpers.cs
Arthur Bassi 1edcf479ae fix(work-orders): apply account scope across create and reads [SH-221]
Stamp WorkOrder.AccountId on all create paths and filter board/list/search/detail by server-derived account claims so scoped callers cannot cross accounts.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-11 10:45:37 -03:00

68 lines
2.2 KiB
C#

using System.Security.Claims;
using Data.SeaHavenIndustries;
using Microsoft.EntityFrameworkCore;
using SeaHaven.DataServices.Implementation;
using SeaHaven.Services.Helpers;
using SeaHaven.Services.Implementation;
using SeaHaven.Services.Interfaces;
namespace SeaHavenIndustries.Tests;
internal static class WorkOrderAccountTestHelpers
{
public static IWorkOrderAccountResolver Resolver(ApplicationDbContext context)
=> new WorkOrderAccountResolver(new AccountDataService(context));
public static ClaimsPrincipal AccountUser(
string userId = "actor-1",
int accountId = 1,
params string[] roles)
{
var effectiveRoles = roles.Length == 0 ? new[] { "Admin" } : roles;
var claims = new List<Claim>
{
new(ClaimTypes.NameIdentifier, userId),
new(SeaHavenClaimTypes.AccountId, accountId.ToString())
};
claims.AddRange(effectiveRoles.Select(r => new Claim(ClaimTypes.Role, r)));
return new ClaimsPrincipal(new ClaimsIdentity(claims, authenticationType: "test"));
}
public static ClaimsPrincipal OrgWideAdmin(string userId = "actor-1")
{
var claims = new List<Claim>
{
new(ClaimTypes.NameIdentifier, userId),
new(ClaimTypes.Role, "Admin"),
new(SeaHavenClaimTypes.OrgScope, SeaHavenClaimTypes.OrgScopeAll)
};
return new ClaimsPrincipal(new ClaimsIdentity(claims, authenticationType: "test"));
}
public static ClaimsPrincipal MissingScope(string userId = "actor-1", string role = "Dispatcher")
{
var claims = new List<Claim>
{
new(ClaimTypes.NameIdentifier, userId),
new(ClaimTypes.Role, role)
};
return new ClaimsPrincipal(new ClaimsIdentity(claims, authenticationType: "test"));
}
public static async Task EnsureAccountAsync(
ApplicationDbContext context,
int id = 1,
string name = "Acme Corp")
{
if (await context.Accounts.AnyAsync(a => a.Id == id))
return;
context.Accounts.Add(new Accounts
{
Id = id,
Name = name,
IsDeleted = false
});
await context.SaveChangesAsync();
}
}