Initial import of verae-staff-iam from zapier monorepo
This commit is contained in:
commit
84fd73fe95
14 changed files with 969 additions and 0 deletions
57
test/health.test.js
Normal file
57
test/health.test.js
Normal file
|
|
@ -0,0 +1,57 @@
|
|||
import { test } from 'node:test';
|
||||
import assert from 'node:assert/strict';
|
||||
import { spawn } from 'node:child_process';
|
||||
import fs from 'node:fs';
|
||||
import os from 'node:os';
|
||||
import path from 'node:path';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
|
||||
const root = path.join(path.dirname(fileURLToPath(import.meta.url)), '..');
|
||||
|
||||
test('iam login, permission check, user CRUD', async () => {
|
||||
const port = 18028;
|
||||
const dir = fs.mkdtempSync(path.join(os.tmpdir(), 'iam-'));
|
||||
const child = spawn(process.execPath, ['src/server.js'], {
|
||||
cwd: root,
|
||||
env: { ...process.env, PORT: String(port), STAFF_IAM_PATH: path.join(dir, 'iam.json') },
|
||||
stdio: ['ignore', 'pipe', 'pipe'],
|
||||
});
|
||||
await new Promise((r) => setTimeout(r, 500));
|
||||
try {
|
||||
const h = await (await fetch(`http://127.0.0.1:${port}/health`)).json();
|
||||
assert.equal(h.role, 'verae-staff-iam');
|
||||
const login = await fetch(`http://127.0.0.1:${port}/login`, {
|
||||
method: 'POST',
|
||||
headers: { 'content-type': 'application/json' },
|
||||
body: JSON.stringify({ username: 'admin', password: 'admin-dev-key' }),
|
||||
});
|
||||
assert.equal(login.status, 200);
|
||||
const { token, user } = await login.json();
|
||||
assert.ok(user.permissions.includes('*'));
|
||||
const hdr = { authorization: `Bearer ${token}`, 'content-type': 'application/json' };
|
||||
const ok = await fetch(`http://127.0.0.1:${port}/check?permission=cs.credit`, { headers: hdr });
|
||||
assert.equal(ok.status, 200);
|
||||
const csLogin = await fetch(`http://127.0.0.1:${port}/login`, {
|
||||
method: 'POST',
|
||||
headers: { 'content-type': 'application/json' },
|
||||
body: JSON.stringify({ username: 'cs', password: 'cs-dev-key' }),
|
||||
});
|
||||
const cs = await csLogin.json();
|
||||
const deny = await fetch(`http://127.0.0.1:${port}/check?permission=accounting.export`, {
|
||||
headers: { authorization: `Bearer ${cs.token}` },
|
||||
});
|
||||
assert.equal(deny.status, 403);
|
||||
const created = await fetch(`http://127.0.0.1:${port}/users`, {
|
||||
method: 'POST',
|
||||
headers: hdr,
|
||||
body: JSON.stringify({ username: 'pat', password: 'pat-pass-99', name: 'Pat', roles: ['sales'] }),
|
||||
});
|
||||
assert.equal(created.status, 201);
|
||||
const body = await created.json();
|
||||
assert.deepEqual(body.roles, ['sales']);
|
||||
const list = await (await fetch(`http://127.0.0.1:${port}/users`, { headers: hdr })).json();
|
||||
assert.ok(list.users.some((u) => u.username === 'pat'));
|
||||
} finally {
|
||||
child.kill('SIGTERM');
|
||||
}
|
||||
});
|
||||
31
test/roles.test.js
Normal file
31
test/roles.test.js
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
import { test } from 'node:test';
|
||||
import assert from 'node:assert/strict';
|
||||
import { expandRoles, allows, ROLES } from '../src/roles.js';
|
||||
import { StaffIam } from '../src/store.js';
|
||||
import { verifyPassword } from '../src/passwords.js';
|
||||
|
||||
test('owner expands to all permissions', () => {
|
||||
assert.deepEqual(expandRoles(['owner']), ['*']);
|
||||
assert.equal(allows(['*'], 'cs.credit'), true);
|
||||
assert.equal(allows(expandRoles(['cs']), 'cs.credit'), true);
|
||||
assert.equal(allows(expandRoles(['cs']), 'accounting.export'), false);
|
||||
assert.ok(ROLES.sales);
|
||||
});
|
||||
|
||||
test('sessions persist in dump/load', () => {
|
||||
const iam = new StaffIam().seed();
|
||||
const u = iam.findByUsername('cs');
|
||||
const tok = iam.issueSession(u.id);
|
||||
const raw = iam.dump();
|
||||
const b = new StaffIam().load(raw);
|
||||
assert.equal(b.getSession(tok).userId, u.id);
|
||||
});
|
||||
|
||||
test('cannot deactivate last owner; passwords hash', () => {
|
||||
const iam = new StaffIam().seed();
|
||||
const owner = iam.findByUsername('admin');
|
||||
assert.ok(verifyPassword(process.env.ADMIN_KEY || 'admin-dev-key', owner.passwordHash));
|
||||
assert.throws(() => iam.update('admin', { active: false }, 'admin'), /last owner/);
|
||||
const cs = iam.create({ username: 'anna', password: 'anna-pass-1', name: 'Anna', roles: ['cs'], actor: 'admin' });
|
||||
assert.deepEqual(cs.roles, ['cs']);
|
||||
});
|
||||
Loading…
Add table
Add a link
Reference in a new issue