package cabana import ( "testing" "git.golem15.com/golem15/summercms/modules/bouncer" ) // TestAllowsFollowsWinterHasAnyAccess pins the permission check to Winter's // User::hasAnyAccess: wildcards match on both sides and several required codes // are an OR. func TestAllowsFollowsWinterHasAnyAccess(t *testing.T) { grant := func(codes ...string) *bouncer.Principal { grants := map[string]bool{} for _, code := range codes { grants[code] = true } return &bouncer.Principal{ID: 1, Backend: true, PermissionGrants: grants} } tests := []struct { name string principal *bouncer.Principal required []string want bool }{ {"nil principal", nil, []string{"a.b.c"}, false}, {"superuser", &bouncer.Principal{Backend: true, IsSuperuser: true}, []string{"a.b.c"}, true}, {"empty requirement is open", grant(), nil, true}, {"exact grant", grant("a.b.c"), []string{"a.b.c"}, true}, {"missing grant", grant("a.b.d"), []string{"a.b.c"}, false}, {"grant wildcard covers code", grant("a.b.*"), []string{"a.b.c"}, true}, {"grant wildcard other prefix", grant("a.x.*"), []string{"a.b.c"}, false}, {"required wildcard met by any grant under the prefix", grant("a.b.access_genres"), []string{"a.b.*"}, true}, {"required wildcard not met by a sibling plugin", grant("a.x.access_genres"), []string{"a.b.*"}, false}, {"required wildcard with no grants", grant(), []string{"a.b.*"}, false}, {"required wildcard met by a grant wildcard", grant("a.b.*"), []string{"a.b.*"}, true}, {"required leading wildcard", grant("a.b.access_genres"), []string{"*.access_genres"}, true}, {"required leading wildcard miss", grant("a.b.access_styles"), []string{"*.access_genres"}, false}, {"several codes are any, first grants", grant("a.b.one"), []string{"a.b.one", "a.b.two"}, true}, {"several codes are any, last grants", grant("a.b.two"), []string{"a.b.one", "a.b.two"}, true}, {"several codes are any, none grants", grant("a.b.three"), []string{"a.b.one", "a.b.two"}, false}, {"disabled grant is not a grant", &bouncer.Principal{PermissionGrants: map[string]bool{"a.b.c": false}}, []string{"a.b.c"}, false}, } for _, tt := range tests { t.Run(tt.name, func(t *testing.T) { if got := Allows(tt.principal, tt.required); got != tt.want { t.Fatalf("Allows(%v) = %v, want %v", tt.required, got, tt.want) } }) } }