Files
calendar/packages/features/routing-forms/lib/isAuthorizedToViewForm.test.ts
T
Hariom BalharaandGitHub 06d8b98b15 fix: 404 on the public form page for a sub-team form when the owner itself was removed from the org (#18495)
* wip

* fix: 404 for a form of a member that has been removed.

- Moved existing authorization check to isAuthorizedToViewFormOnOrgDomain function to handle form access control
- Add comprehensive test suite for org domain authorization scenarios
- Refactor getServerSideProps to use the new authorization function
- Improve code organization by separating domain-specific authorization logic

Test Coverage:
- Non-org domain access
- Org member's form access
- Sub-team form access within org
- Access denial for non-org members/teams
2025-01-07 12:13:19 +00:00

114 lines
3.0 KiB
TypeScript

import { describe, it, expect } from "vitest";
import { isAuthorizedToViewFormOnOrgDomain } from "./isAuthorizedToViewForm";
const _createUser = (overrides = {}) => ({
username: "testuser",
metadata: {},
movedToProfileId: null,
id: 1,
...overrides,
});
/**
* Creates a regular user without organization membership
*/
const createRegularUser = (overrides = {}) => ({
..._createUser(overrides),
profile: {
organization: null,
},
});
/**
* Creates a user that is a member of an organization
*/
const createOrgMemberUser = ({
orgSlug,
requestedSlug,
}: {
orgSlug: string;
requestedSlug: string | null;
}) => ({
..._createUser({
profile: {
organization: { slug: orgSlug, requestedSlug: requestedSlug },
},
}),
});
const _createTeam = (overrides = {}) => ({
parent: null,
...overrides,
});
/**
* Creates a regular team without organization association
*/
const createRegularTeam = (overrides = {}) => _createTeam(overrides);
/**
* Creates a sub-team that belongs to an organization
*/
const createSubTeam = (orgSlug: string, overrides = {}) =>
_createTeam({
parent: {
slug: orgSlug,
},
...overrides,
});
describe("isAuthorizedToViewFormOnOrgDomain", () => {
it("should allow viewing any form (user or team form) when not on org domain", () => {
const result = isAuthorizedToViewFormOnOrgDomain({
user: createRegularUser(),
currentOrgDomain: null,
team: createRegularTeam(),
});
expect(result).toBe(true);
});
it("should allow viewing org member's form when user belongs to the current org domain", () => {
const result = isAuthorizedToViewFormOnOrgDomain({
user: createOrgMemberUser({ orgSlug: "test-org", requestedSlug: null }),
currentOrgDomain: "test-org",
});
expect(result).toBe(true);
});
it("should allow viewing sub-team form when the sub team belongs to the current org domain", () => {
const result = isAuthorizedToViewFormOnOrgDomain({
user: createRegularUser(),
currentOrgDomain: "test-org",
team: createSubTeam("test-org"),
});
expect(result).toBe(true);
});
it("should deny viewing form when on org domain but neither user nor sub team belongs to it", () => {
const result = isAuthorizedToViewFormOnOrgDomain({
user: createOrgMemberUser("different-org"),
currentOrgDomain: "test-org",
team: createSubTeam("another-org"),
});
expect(result).toBe(false);
});
it("should handle undefined team parameter on org domain", () => {
const result = isAuthorizedToViewFormOnOrgDomain({
user: createRegularUser(),
currentOrgDomain: "test-org",
team: undefined,
});
expect(result).toBe(false);
});
it("should allow access when user has pending org membership request", () => {
const result = isAuthorizedToViewFormOnOrgDomain({
user: createOrgMemberUser({ orgSlug: "test-org", requestedSlug: "test-org" }),
currentOrgDomain: "test-org",
});
expect(result).toBe(true);
});
});