Files
summercms/modules/cabana/permissions_test.go

52 lines
2.3 KiB
Go

package cabana
import (
"testing"
"git.golem15.com/golem15/summercms/modules/bouncer"
)
// TestAllowsFollowsWinterHasAnyAccess pins the permission check to Winter's
// User::hasAnyAccess: wildcards match on both sides and several required codes
// are an OR.
func TestAllowsFollowsWinterHasAnyAccess(t *testing.T) {
grant := func(codes ...string) *bouncer.Principal {
grants := map[string]bool{}
for _, code := range codes {
grants[code] = true
}
return &bouncer.Principal{ID: 1, Backend: true, PermissionGrants: grants}
}
tests := []struct {
name string
principal *bouncer.Principal
required []string
want bool
}{
{"nil principal", nil, []string{"a.b.c"}, false},
{"superuser", &bouncer.Principal{Backend: true, IsSuperuser: true}, []string{"a.b.c"}, true},
{"empty requirement is open", grant(), nil, true},
{"exact grant", grant("a.b.c"), []string{"a.b.c"}, true},
{"missing grant", grant("a.b.d"), []string{"a.b.c"}, false},
{"grant wildcard covers code", grant("a.b.*"), []string{"a.b.c"}, true},
{"grant wildcard other prefix", grant("a.x.*"), []string{"a.b.c"}, false},
{"required wildcard met by any grant under the prefix", grant("a.b.access_genres"), []string{"a.b.*"}, true},
{"required wildcard not met by a sibling plugin", grant("a.x.access_genres"), []string{"a.b.*"}, false},
{"required wildcard with no grants", grant(), []string{"a.b.*"}, false},
{"required wildcard met by a grant wildcard", grant("a.b.*"), []string{"a.b.*"}, true},
{"required leading wildcard", grant("a.b.access_genres"), []string{"*.access_genres"}, true},
{"required leading wildcard miss", grant("a.b.access_styles"), []string{"*.access_genres"}, false},
{"several codes are any, first grants", grant("a.b.one"), []string{"a.b.one", "a.b.two"}, true},
{"several codes are any, last grants", grant("a.b.two"), []string{"a.b.one", "a.b.two"}, true},
{"several codes are any, none grants", grant("a.b.three"), []string{"a.b.one", "a.b.two"}, false},
{"disabled grant is not a grant", &bouncer.Principal{PermissionGrants: map[string]bool{"a.b.c": false}}, []string{"a.b.c"}, false},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
if got := Allows(tt.principal, tt.required); got != tt.want {
t.Fatalf("Allows(%v) = %v, want %v", tt.required, got, tt.want)
}
})
}
}