* fix: align checkBookingAccessWithPBAC with listing logic for personal event types
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: align permission strings with doesUserIdHaveAccessToBooking granular permissions
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* change implementation
* remove unused code
* test: add getBookingDetails tests for personal event type booking access
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: remove unused MembershipRole import
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* test: convert BookingDetailsService tests to integration tests
Replace unit tests with mocks by integration tests using real database.
Tests verify org/team admin access to personal event type bookings.
- Org admin viewing team member's personal event booking (fails on main, passes on PR)
- Team admin viewing team member's personal event booking (fails on main, passes on PR)
- Non-admin denied access (passes on both)
- Owner viewing own booking (passes on both)
- Non-existent booking returns Forbidden (passes on both)
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* test: refactor integration tests to use repositories instead of direct prisma calls
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* test: replace direct prisma usage with TestXXXRepository pattern in integration tests
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* test: use production repositories (OrganizationRepository, BookingRepository, UserRepository) instead of test repos for setup
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* test: inline test repository logic into integration test file
The TestXXXRepository classes were thin wrappers around single prisma
calls with barely any logic, so the indirection wasn't justified.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>