Add internal staff IAM: named users, roles, and management permissions.
Some checks are pending
offline / test (push) Waiting to run
Some checks are pending
offline / test (push) Waiting to run
verae-staff-iam (:3028) is the people directory — owner, billing-admin, cs, sales, accounting, operator, viewer — with scrypt passwords, sessions, and an audit log. Admin console login uses it when STAFF_IAM_URL is set and hides tabs the account cannot use. CS/sales/accounting/staff/fleet check permissions such as cs.credit and fleet.operate. Shared staff key remains only as a fallback when IAM is unset.
This commit is contained in:
parent
2740d51446
commit
d299d245e8
41 changed files with 1337 additions and 52 deletions
22
packages/verae-staff-iam/test/roles.test.js
Normal file
22
packages/verae-staff-iam/test/roles.test.js
Normal file
|
|
@ -0,0 +1,22 @@
|
|||
import { test } from 'node:test';
|
||||
import assert from 'node:assert/strict';
|
||||
import { expandRoles, allows, ROLES } from '../src/roles.js';
|
||||
import { StaffIam } from '../src/store.js';
|
||||
import { verifyPassword } from '../src/passwords.js';
|
||||
|
||||
test('owner expands to all permissions', () => {
|
||||
assert.deepEqual(expandRoles(['owner']), ['*']);
|
||||
assert.equal(allows(['*'], 'cs.credit'), true);
|
||||
assert.equal(allows(expandRoles(['cs']), 'cs.credit'), true);
|
||||
assert.equal(allows(expandRoles(['cs']), 'accounting.export'), false);
|
||||
assert.ok(ROLES.sales);
|
||||
});
|
||||
|
||||
test('cannot deactivate last owner; passwords hash', () => {
|
||||
const iam = new StaffIam().seed();
|
||||
const owner = iam.findByUsername('admin');
|
||||
assert.ok(verifyPassword(process.env.ADMIN_KEY || 'admin-dev-key', owner.passwordHash));
|
||||
assert.throws(() => iam.update('admin', { active: false }, 'admin'), /last owner/);
|
||||
const cs = iam.create({ username: 'anna', password: 'anna-pass-1', name: 'Anna', roles: ['cs'], actor: 'admin' });
|
||||
assert.deepEqual(cs.roles, ['cs']);
|
||||
});
|
||||
Loading…
Add table
Add a link
Reference in a new issue