fix(09): WR-01 match wildcard required permissions and treat several codes as any, like Winter
This commit is contained in:
51
modules/cabana/permissions_test.go
Normal file
51
modules/cabana/permissions_test.go
Normal file
@@ -0,0 +1,51 @@
|
||||
package cabana
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"git.golem15.com/golem15/summercms/modules/bouncer"
|
||||
)
|
||||
|
||||
// TestAllowsFollowsWinterHasAnyAccess pins the permission check to Winter's
|
||||
// User::hasAnyAccess: wildcards match on both sides and several required codes
|
||||
// are an OR.
|
||||
func TestAllowsFollowsWinterHasAnyAccess(t *testing.T) {
|
||||
grant := func(codes ...string) *bouncer.Principal {
|
||||
grants := map[string]bool{}
|
||||
for _, code := range codes {
|
||||
grants[code] = true
|
||||
}
|
||||
return &bouncer.Principal{ID: 1, Backend: true, PermissionGrants: grants}
|
||||
}
|
||||
tests := []struct {
|
||||
name string
|
||||
principal *bouncer.Principal
|
||||
required []string
|
||||
want bool
|
||||
}{
|
||||
{"nil principal", nil, []string{"a.b.c"}, false},
|
||||
{"superuser", &bouncer.Principal{Backend: true, IsSuperuser: true}, []string{"a.b.c"}, true},
|
||||
{"empty requirement is open", grant(), nil, true},
|
||||
{"exact grant", grant("a.b.c"), []string{"a.b.c"}, true},
|
||||
{"missing grant", grant("a.b.d"), []string{"a.b.c"}, false},
|
||||
{"grant wildcard covers code", grant("a.b.*"), []string{"a.b.c"}, true},
|
||||
{"grant wildcard other prefix", grant("a.x.*"), []string{"a.b.c"}, false},
|
||||
{"required wildcard met by any grant under the prefix", grant("a.b.access_genres"), []string{"a.b.*"}, true},
|
||||
{"required wildcard not met by a sibling plugin", grant("a.x.access_genres"), []string{"a.b.*"}, false},
|
||||
{"required wildcard with no grants", grant(), []string{"a.b.*"}, false},
|
||||
{"required wildcard met by a grant wildcard", grant("a.b.*"), []string{"a.b.*"}, true},
|
||||
{"required leading wildcard", grant("a.b.access_genres"), []string{"*.access_genres"}, true},
|
||||
{"required leading wildcard miss", grant("a.b.access_styles"), []string{"*.access_genres"}, false},
|
||||
{"several codes are any, first grants", grant("a.b.one"), []string{"a.b.one", "a.b.two"}, true},
|
||||
{"several codes are any, last grants", grant("a.b.two"), []string{"a.b.one", "a.b.two"}, true},
|
||||
{"several codes are any, none grants", grant("a.b.three"), []string{"a.b.one", "a.b.two"}, false},
|
||||
{"disabled grant is not a grant", &bouncer.Principal{PermissionGrants: map[string]bool{"a.b.c": false}}, []string{"a.b.c"}, false},
|
||||
}
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
if got := Allows(tt.principal, tt.required); got != tt.want {
|
||||
t.Fatalf("Allows(%v) = %v, want %v", tt.required, got, tt.want)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user