52 lines
2.3 KiB
Go
52 lines
2.3 KiB
Go
package cabana
|
|
|
|
import (
|
|
"testing"
|
|
|
|
"git.golem15.com/golem15/summercms/modules/bouncer"
|
|
)
|
|
|
|
// TestAllowsFollowsWinterHasAnyAccess pins the permission check to Winter's
|
|
// User::hasAnyAccess: wildcards match on both sides and several required codes
|
|
// are an OR.
|
|
func TestAllowsFollowsWinterHasAnyAccess(t *testing.T) {
|
|
grant := func(codes ...string) *bouncer.Principal {
|
|
grants := map[string]bool{}
|
|
for _, code := range codes {
|
|
grants[code] = true
|
|
}
|
|
return &bouncer.Principal{ID: 1, Backend: true, PermissionGrants: grants}
|
|
}
|
|
tests := []struct {
|
|
name string
|
|
principal *bouncer.Principal
|
|
required []string
|
|
want bool
|
|
}{
|
|
{"nil principal", nil, []string{"a.b.c"}, false},
|
|
{"superuser", &bouncer.Principal{Backend: true, IsSuperuser: true}, []string{"a.b.c"}, true},
|
|
{"empty requirement is open", grant(), nil, true},
|
|
{"exact grant", grant("a.b.c"), []string{"a.b.c"}, true},
|
|
{"missing grant", grant("a.b.d"), []string{"a.b.c"}, false},
|
|
{"grant wildcard covers code", grant("a.b.*"), []string{"a.b.c"}, true},
|
|
{"grant wildcard other prefix", grant("a.x.*"), []string{"a.b.c"}, false},
|
|
{"required wildcard met by any grant under the prefix", grant("a.b.access_genres"), []string{"a.b.*"}, true},
|
|
{"required wildcard not met by a sibling plugin", grant("a.x.access_genres"), []string{"a.b.*"}, false},
|
|
{"required wildcard with no grants", grant(), []string{"a.b.*"}, false},
|
|
{"required wildcard met by a grant wildcard", grant("a.b.*"), []string{"a.b.*"}, true},
|
|
{"required leading wildcard", grant("a.b.access_genres"), []string{"*.access_genres"}, true},
|
|
{"required leading wildcard miss", grant("a.b.access_styles"), []string{"*.access_genres"}, false},
|
|
{"several codes are any, first grants", grant("a.b.one"), []string{"a.b.one", "a.b.two"}, true},
|
|
{"several codes are any, last grants", grant("a.b.two"), []string{"a.b.one", "a.b.two"}, true},
|
|
{"several codes are any, none grants", grant("a.b.three"), []string{"a.b.one", "a.b.two"}, false},
|
|
{"disabled grant is not a grant", &bouncer.Principal{PermissionGrants: map[string]bool{"a.b.c": false}}, []string{"a.b.c"}, false},
|
|
}
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
if got := Allows(tt.principal, tt.required); got != tt.want {
|
|
t.Fatalf("Allows(%v) = %v, want %v", tt.required, got, tt.want)
|
|
}
|
|
})
|
|
}
|
|
}
|