* chore: Upgrade prisma to 6.7.0 * Build fixes * type fixes Signed-off-by: Omar López <zomars@me.com> * Update schema.prisma * Patching * Revert "Update schema.prisma" This reverts commit 47d8618bf89ef4d007b30084df766f17281e21a1. * Revert "Patching" This reverts commit a1d2e3040e71690a44d4324db95d73b4d68c6adb. * Revert schema changes Signed-off-by: Omar López <zomars@me.com> * WIP Signed-off-by: Omar López <zomars@me.com> * Update getPublicEvent.ts * Update imports Signed-off-by: Omar López <zomars@me.com> * Update gitignore Signed-off-by: Omar López <zomars@me.com> * update remaining imports Signed-off-by: Omar López <zomars@me.com> * Delete .cursor/config.json * Discard changes to packages/features/eventtypes/lib/getPublicEvent.ts * Update _get.ts * Update user.ts * Update .gitignore * update * Update WorkflowStepContainer.tsx * Update next-auth-custom-adapter.ts * Update getPublicEvent.ts * Update workflow.ts * Update next-auth-custom-adapter.ts * Update next-auth-options.ts * Update bookingScenario.ts * fix missing imports * upgrades prismock Signed-off-by: Omar López <zomars@me.com> * patches prismock Signed-off-by: Omar López <zomars@me.com> * Update reschedule.test.ts * Update prisma.ts * patch prismock Signed-off-by: Omar López <zomars@me.com> * fix enums imports Signed-off-by: Omar López <zomars@me.com> * Revert "Update prisma.ts" This reverts commit 64edcf8db54171ff4456c209d563b5d431d99619. * Revert "patch prismock" This reverts commit e95819113dc9d88e7130947aa120cd42710977c8. * fix patch * Fix test that overrun the boundary, it shouldn't test too much * Move prisma import to changeSMSLockState * Bring back broken test without illegal imports * Merge with main and fix filter hosts by same round robin host * Fixed buildDryRunBooking fn tests * Fix and move ooo create or update handler test * Fix packages/features/eventtypes/lib/isCurrentlyAvailable.test.ts * Fix packages/trpc/server/routers/viewer/organizations/listMembers.handler.test.ts * Mock @calcom/prisma * Fix: verify-email.test.ts * fix: Moved WebhookService test and fixed default import mock * Fix: Added missing prisma mock, handleNewBooking uses that of course * We're not testing createContext here * fix: Prisma mock fix for listMembers.test.ts * More fixes to broken testcases * Forgot to remove borked test * Prevent the need to mock a lot of dependencies by moving out buildBaseWhereCondition to its own file * Temporarily skip getCalendarEvents, needs a rewrite * Fix: turns out you can access protected in testcases * fix further mocks * Added packages/features/insights/server/buildBaseWhereCondition.ts, types * Always great to have a mock and then not use it * And one less again. * fix: confirm.handler.test, didn't mock prisma * fix: Address minor nit by @eunjae & fix ImpersonationProvider test * Updated isPrismaAvailableCheck that doesn't crash on import * fix: Get Prisma directly from the client, it usually involves the Validator and does not need 'local' inclusion * Add zod-prisma-types without the generator enabled (commented out) * Uncomment and see what happens * Change method of import as imports did not work in Input Schemas * Remove custom 'zod' booking model, it does not belong with Prisma * Fix all other global Model imports * Rewrite most schema includes AND remove barrel file * Add bookingCreateBodySchema to features/bookings * Flurry of type fixes for compatibility with new zod gen * Refactor out the custom prisma type createEventTypeInput * Work around nullable eventTypeLocations * HandlePayment type fix * More fixes, final fix remaining is CompleteEventType * Should fix a bunch more booking related type errors * Missed one * Some props missing from BookingCreateBodySchema * Fix location type in handleChildrenEventTypes * Little bit hacky imo but it works * Final type error \o/ * Forgot to include Prisma * Do not include zod-utils in booker/types * Oops, was already including Booker/types * Fix membership type, also disallow updating createdAt/updatedAt, make part of patch/post * Fix api v1 type errors * Fix EventTypeDescription typings * Remove getParserWithGeneric, use userBodySchema with UserSchema * use centralized timeZoneSchema * Implement feedback by @zomars * Couple of WIP pushes * Fix tests * Type fixes in `handleChildrenEventTypes` test * Try and parse metadata before use * Change zod-prisma-types configuration for optimal performance * Fix prisma validator error in `prisma/selects/credential` * Disable seperate relations model, hits a bug * Import absolute - this makes rollup work in @platform/libraries * Attempt at removing resolutions override * Refactor using `Prisma.validator` to `satisfies` * Build atoms using @calcom/prisma/client * Build atoms using @calcom/prisma/client * fixes * Update eventTypeSelect.ts * Adjust `eventTypeMetaDataSchemaWithUntypedApps` from `unknown` to `record(any)` * `EventTypeDescription` rely on `descriptionAsSafeHTML` instead of `description` * Add `seatsPerTimeSlot` to event type public select * Fix typing in `users-public-view` getServerSide props * Add missing `schedulingType` to prop * chore: bump platform libraries * Function return type is illegal, not sure how this passed eslint (#21567) * Merged with main * Update updateTokenObject.ts * Update handleResponse.ts * Update index.ts * Update handleChildrenEventTypes.ts * Update booking-idempotency-key.ts * Update WebhookService.test.ts * Update events.test.ts * Update queued-response.test.ts * Update events.test.ts * Update getRoutedUrl.test.ts * fix: type checks Signed-off-by: Omar López <zomars@me.com> * fixes Signed-off-by: Omar López <zomars@me.com> * chore: bump platform libraries * Update yarn.lock * more fixes Signed-off-by: Omar López <zomars@me.com> * fixes Signed-off-by: Omar López <zomars@me.com> * biuld fixes * chore: bump platform libraries * Update conferencing.repository.ts * Update conferencing.repository.ts * Update getCalendarsEvents.test.ts * Update vite.config.js * chore: bump platform libraries * Update users.ts * Discard changes to docs/api-reference/v2/openapi.json * Update vite.config.ts * updated platform libraries * Update get.handler.test.ts * Update get.handler.test.ts * Update schema.prisma * Discard changes to docs/api-reference/v2/openapi.json * Update next-auth-custom-adapter.ts * Update team.ts * Flurry of type fixes * Fix majority of insight related type errors * Type fixes for unlink of account * Make user nullable again * Fixed a bunch of unit tests and one type error * Attempted mock fix * Attempted fix for Attribute type * Ensure default import becomes prisma, but not direct usage * Import default as prisma in prisma.module * Add attributeOption to attribute type * Fix calcom/prisma mock * Refactor Prisma client imports to @calcom/prisma/client Updated all imports from '@prisma/client' to '@calcom/prisma/client' across tests and repository files for consistency and to use the correct Prisma client package. This change improves maintainability and ensures the correct client is referenced throughout the codebase. * Undo removal of max-warnings=0 to get main to merge * Remove unit tests for e2e fixtures, provide new prisma mock * Mock @calcom/prisma in event manager * Mock @calcom/prisma in event manager * Add correct format even with --no-verify * Mock prisma in CalendarManager * Add mock for permission-check.service * Better injection in PrismaApiKeyRepository imports * More mock fixes :) * Fix listMembers.handler.test * Fix User import * Appropriately adjust all types to be imported as types, there were a lot of types imported as normal deps * Why was this a thing? * Strictly speaking; Not using prismock anymore * Ditched patch file for prismock * Fix output.service.ts platform type imports, need concrete for plainToClass * Better typing and tests for unlinkConnectedAccount.handler * Small type fix * Disable calendar cache tests as they are dependent on prismock * chore: bump platform lib * getRoutedUrl test remove of unused import * Extract select to external const on getEventTypesFromDB * Direct select of userSelect from selects/user * fix type error from merging 23653 * Fixed integration tests by removing hardcoded values that were possible due to mocking, but as its now directly hitting the db no longer * fix: vite config atoms prisma client type location * revert: example app prisma client * revert: example app prisma client * bump platform libs * fix: use class instead of type for DI of PlatformBookingsService * update platform libs * remove unused variable * chore: generate prisma client for api v2 * fix: api v2 e2e * fix: atoms e2e * fix: atoms e2e * fix: atoms e2e * fix: api v2 e2e * fix: tsconfig apiv2 enums * publish libraries * Simplify check for existence teamId --------- Signed-off-by: Omar López <zomars@me.com> Co-authored-by: Alex van Andel <me@alexvanandel.com> Co-authored-by: Joe Au-Yeung <j.auyeung419@gmail.com> Co-authored-by: supalarry <laurisskraucis@gmail.com> Co-authored-by: cal.com <morgan@cal.com> Co-authored-by: Morgan <33722304+ThyMinimalDev@users.noreply.github.com> Co-authored-by: Benny Joo <sldisek783@gmail.com>
402 lines
11 KiB
TypeScript
402 lines
11 KiB
TypeScript
import { prisma } from "@calcom/prisma/__mocks__/prisma";
|
|
|
|
import { describe, it, expect, vi, beforeEach } from "vitest";
|
|
|
|
import { PermissionCheckService } from "@calcom/features/pbac/services/permission-check.service";
|
|
|
|
import { isAuthorized } from "./util";
|
|
|
|
vi.mock("@calcom/features/pbac/services/permission-check.service");
|
|
|
|
vi.mock("@calcom/prisma", () => ({
|
|
prisma,
|
|
}));
|
|
|
|
describe("isAuthorized", () => {
|
|
const mockPermissionCheckService = vi.mocked(PermissionCheckService);
|
|
let mockCheckPermission: ReturnType<typeof vi.fn>;
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks();
|
|
mockCheckPermission = vi.fn();
|
|
mockPermissionCheckService.mockImplementation(
|
|
() =>
|
|
({
|
|
checkPermission: mockCheckPermission,
|
|
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
|
} as any)
|
|
);
|
|
});
|
|
|
|
describe("null workflow", () => {
|
|
it("should return false when workflow is null", async () => {
|
|
const result = await isAuthorized(null, 123);
|
|
expect(result).toBe(false);
|
|
});
|
|
});
|
|
|
|
describe("personal workflows (no teamId)", () => {
|
|
it("should return true when user owns the personal workflow", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: null,
|
|
userId: 123,
|
|
};
|
|
|
|
const result = await isAuthorized(workflow, 123);
|
|
expect(result).toBe(true);
|
|
expect(mockPermissionCheckService).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("should return false when user does not own the personal workflow", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: null,
|
|
userId: 456,
|
|
};
|
|
|
|
const result = await isAuthorized(workflow, 123);
|
|
expect(result).toBe(false);
|
|
expect(mockPermissionCheckService).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("should ignore permission parameter for personal workflows", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: null,
|
|
userId: 123,
|
|
};
|
|
|
|
const readResult = await isAuthorized(workflow, 123, "workflow.read");
|
|
const updateResult = await isAuthorized(workflow, 123, "workflow.update");
|
|
const deleteResult = await isAuthorized(workflow, 123, "workflow.delete");
|
|
|
|
expect(readResult).toBe(true);
|
|
expect(updateResult).toBe(true);
|
|
expect(deleteResult).toBe(true);
|
|
expect(mockPermissionCheckService).not.toHaveBeenCalled();
|
|
});
|
|
});
|
|
|
|
describe("team workflows with PBAC", () => {
|
|
describe("read operations", () => {
|
|
it("should use workflow.read permission by default with all roles as fallback", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123);
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockPermissionCheckService).toHaveBeenCalledTimes(1);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.read",
|
|
fallbackRoles: ["ADMIN", "OWNER", "MEMBER"],
|
|
});
|
|
});
|
|
|
|
it("should use workflow.read permission when explicitly passed", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.read");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.read",
|
|
fallbackRoles: ["ADMIN", "OWNER", "MEMBER"],
|
|
});
|
|
});
|
|
|
|
it("should return false when PBAC denies read permission", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(false);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.read");
|
|
|
|
expect(result).toBe(false);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.read",
|
|
fallbackRoles: ["ADMIN", "OWNER", "MEMBER"],
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("update operations", () => {
|
|
it("should use workflow.update permission with admin/owner roles as fallback", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.update");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockPermissionCheckService).toHaveBeenCalledTimes(1);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.update",
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
|
|
it("should return false when PBAC denies update permission", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(false);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.update");
|
|
|
|
expect(result).toBe(false);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.update",
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("delete operations", () => {
|
|
it("should use workflow.delete permission with admin/owner roles as fallback", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.delete");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.delete",
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
|
|
it("should return false when PBAC denies delete permission", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(false);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.delete");
|
|
|
|
expect(result).toBe(false);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.delete",
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("other permissions", () => {
|
|
it("should use workflow.create permission with admin/owner roles as fallback", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.create");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.create",
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
|
|
it("should use workflow.manage permission with admin/owner roles as fallback", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.manage");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.manage",
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("permission service integration", () => {
|
|
it("should create a new PermissionCheckService instance for each call", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
await isAuthorized(workflow, 123, "workflow.read");
|
|
await isAuthorized(workflow, 123, "workflow.update");
|
|
|
|
expect(mockPermissionCheckService).toHaveBeenCalledTimes(2);
|
|
});
|
|
|
|
it("should handle permission service errors gracefully", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockRejectedValue(new Error("Permission service error"));
|
|
|
|
await expect(isAuthorized(workflow, 123, "workflow.read")).rejects.toThrow(
|
|
"Permission service error"
|
|
);
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("edge cases", () => {
|
|
it("should handle workflow with teamId 0 as personal workflow", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 0,
|
|
userId: 123,
|
|
};
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.delete");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockPermissionCheckService).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("should handle workflow with positive teamId as team workflow", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 1,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.read");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 1,
|
|
permission: "workflow.read",
|
|
fallbackRoles: ["ADMIN", "OWNER", "MEMBER"],
|
|
});
|
|
});
|
|
|
|
it("should handle different user IDs correctly", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 789, "workflow.read");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 789,
|
|
teamId: 456,
|
|
permission: "workflow.read",
|
|
fallbackRoles: ["ADMIN", "OWNER", "MEMBER"],
|
|
});
|
|
});
|
|
|
|
it("should handle workflow with undefined teamId as personal workflow", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
|
teamId: undefined as any,
|
|
userId: 123,
|
|
};
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.delete");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockPermissionCheckService).not.toHaveBeenCalled();
|
|
});
|
|
});
|
|
|
|
describe("type safety", () => {
|
|
it("should work with minimal workflow object", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: null,
|
|
userId: 123,
|
|
};
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.read");
|
|
expect(result).toBe(true);
|
|
});
|
|
|
|
it("should work with workflow object containing extra properties", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
name: "Test Workflow",
|
|
createdAt: new Date(),
|
|
updatedAt: new Date(),
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.update");
|
|
expect(result).toBe(true);
|
|
});
|
|
});
|
|
});
|