* chore: upgrade Vitest to 4.0.16 and Vite to 6.4.1 - Update vitest from 2.1.9 to 4.0.16 - Update @vitest/ui from 2.1.9 to 4.0.16 - Update vitest-fetch-mock from 0.3.0 to 0.4.5 - Update vitest-mock-extended from 2.0.2 to 3.1.0 - Update vite from 4.5.14/5.4.21 to 6.4.1 across all packages - Update @vitejs/plugin-react to 5.1.2 - Update @vitejs/plugin-react-swc to 4.2.2 - Update @vitejs/plugin-basic-ssl to 2.1.0 - Update vite-plugin-dts to 4.5.4 - Rename vitest.config.ts to vitest.config.mts for ESM compatibility - Add globals: true to vitest config Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: address Vitest 4.0 and Vite 6 breaking changes - Convert arrow function mockImplementation patterns to regular functions (Vitest 4.0 breaking change: arrow functions can't be constructor mocks) - Fix CSS imports with ?inline suffix for Vite 6 compatibility - Add biome override to disable useArrowFunction rule for test files - Fix syntax errors in test files introduced by regex replacements Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: fix remaining Vitest 4.0 constructor mock patterns Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: fix more Vitest 4.0 constructor mock patterns and exclude API v2 spec files Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert more arrow function mocks to regular functions for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert more arrow function mocks to regular functions for Vitest 4.0 - Fix CrmService.integration.test.ts jsforce.Connection mock - Fix RetellSDKClient.test.ts Retell mock - Fix RetellAIService.test.ts CreditService mocks - Fix GoogleCalendarSubscriptionAdapter.test.ts CalendarAuth mock Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert Google Calendar and OAuthManager arrow function mocks for Vitest 4.0 - Fix googleapis.ts Calendar, OAuth2Client, and JWT mocks - Fix utils.ts JWT mock - Fix OAuthManager.ts defaultMockOAuthManager mock Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: add React plugin, jsdom environment, and fix more constructor mocks for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert HostRepository PrismaClient mock to regular function for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: add useOrgBranding mock to React component tests for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: update TestFunction type for Vitest 4.0 compatibility Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert listBookingReports constructor mocks to regular functions for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert UserRepository constructor mock to regular function for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert OrganizationPaymentService constructor mock to regular function for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert more constructor mocks to regular functions for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: add apps/web path aliases to vitest config Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: fix test issues for Vitest 4.0 compatibility - Fix Response constructor 204 status code issue in testUtils.ts - Fix FeaturesRepository mock persistence in handleNotificationWhenNoSlots.test.ts - Add @vitest-environment node directive to formSubmissionUtils.test.ts - Fix document.querySelector mock in embed.test.ts Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: clear EventManager spy between tests for Vitest 4.0 compatibility Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: update TeamRepository mock pattern for Vitest 4.0 compatibility Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert RoutingFormResponseRepository mock to regular function for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert more constructor mocks to regular functions for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: fix mock reset and spy clear issues for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: fix remaining test failures for Vitest 4.0 upgrade - Fix booking-validations.test.ts: convert UserRepository mock to regular function - Fix route.test.ts: update 500 error test to mock ImageResponse instead of fetch - Fix users-public-view.test.tsx: add missing mocks for getOrgFullOrigin and useRouterQuery - Add @calcom/web path alias to vitest config Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: add vitest-mocks for generated files that don't exist in CI - Add svg-hashes.json mock for route.test.ts - Add tailwind.generated.css mock for embed.test.ts - Update vitest config to use mock files Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: update vitest config aliases for CI compatibility - Use array format for aliases to ensure proper ordering - Add @calcom/platform-constants alias to resolve from source - Add @calcom/embed-react alias to resolve from source - Ensure svg-hashes.json mock alias is matched before @calcom/web Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: add @calcom/embed-snippet alias for CI compatibility Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * Fix wrong test * fix: migrate from CLI flags to VITEST_MODE env var for Vitest 4.0 Vitest 4.0 no longer allows custom CLI flags like --packaged-embed-tests-only. This change migrates to using VITEST_MODE environment variable instead: - VITEST_MODE=packaged-embed for packaged embed tests - VITEST_MODE=integration for integration tests - VITEST_MODE=timezone for timezone-dependent tests Updated vitest.config.mts to handle mode-based include/exclude patterns. Updated CI workflows and package scripts to use the new env var approach. Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: return default include pattern instead of undefined in vitest config The getTestInclude() function was returning undefined for the default case, but Vitest 4.0 expects an array. This caused 'resolved.include is not iterable' error in CI. Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: always set INTEGRATION_TEST_MODE for jsdom environment The getBookingFields.ts file checks for INTEGRATION_TEST_MODE to allow server-side imports in the jsdom environment. Without this, tests fail with 'getBookingFields must not be imported on the client side' error. Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: support legacy CLI flags for backwards compatibility with main workflow The CI runs workflows from main branch, which uses the old CLI flag approach (yarn test -- --integrationTestsOnly). This commit adds backwards compatibility by checking both VITEST_MODE env var and process.argv for the legacy flags. Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
501 lines
15 KiB
TypeScript
501 lines
15 KiB
TypeScript
import { describe, it, expect, vi, beforeEach } from "vitest";
|
|
|
|
import type { PermissionString } from "@calcom/features/pbac/domain/types/permission-registry";
|
|
import { prisma } from "@calcom/prisma";
|
|
import type { MembershipRole } from "@calcom/prisma/enums";
|
|
|
|
import { TRPCError } from "@trpc/server";
|
|
|
|
import authedProcedure from "../../../procedures/authedProcedure";
|
|
// Import after mocks are set up
|
|
import { createWebhookPbacProcedure, webhookProcedure } from "./util";
|
|
|
|
// Mock dependencies - use factory functions to avoid hoisting issues
|
|
vi.mock("@calcom/prisma", () => ({
|
|
prisma: {
|
|
webhook: {
|
|
findUnique: vi.fn(),
|
|
},
|
|
eventType: {
|
|
findUnique: vi.fn(),
|
|
},
|
|
user: {
|
|
findUnique: vi.fn(),
|
|
},
|
|
},
|
|
}));
|
|
|
|
const mockCheckPermission = vi.fn();
|
|
|
|
vi.mock("@calcom/features/pbac/services/permission-check.service", () => ({
|
|
PermissionCheckService: vi.fn().mockImplementation(function() { return {
|
|
checkPermission: mockCheckPermission,
|
|
}; }),
|
|
}));
|
|
|
|
vi.mock("../../../procedures/authedProcedure", () => ({
|
|
default: {
|
|
input: vi.fn().mockReturnThis(),
|
|
use: vi.fn(),
|
|
},
|
|
}));
|
|
|
|
// Cast the mocked items to properly typed versions
|
|
const mockPrisma = prisma as any;
|
|
const mockAuthedProcedure = authedProcedure as any;
|
|
|
|
describe("Webhook PBAC Procedures", () => {
|
|
const mockCtx = {
|
|
user: {
|
|
id: 1,
|
|
},
|
|
};
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks();
|
|
// Reset the mock to ensure clean state
|
|
mockCheckPermission.mockReset();
|
|
mockPrisma.webhook.findUnique.mockReset();
|
|
mockPrisma.eventType.findUnique.mockReset();
|
|
mockPrisma.user.findUnique.mockReset();
|
|
mockAuthedProcedure.use.mockClear();
|
|
});
|
|
|
|
describe("createWebhookPbacProcedure", () => {
|
|
const testPermission: PermissionString = "webhook.update";
|
|
const fallbackRoles: MembershipRole[] = ["ADMIN", "OWNER"];
|
|
|
|
it("should create a procedure with the specified permission", () => {
|
|
const procedure = createWebhookPbacProcedure(testPermission, fallbackRoles);
|
|
|
|
// Verify that authedProcedure methods were called
|
|
expect(mockAuthedProcedure.input).toHaveBeenCalled();
|
|
expect(mockAuthedProcedure.use).toHaveBeenCalled();
|
|
});
|
|
|
|
describe("middleware behavior", () => {
|
|
let middleware: any;
|
|
|
|
beforeEach(() => {
|
|
createWebhookPbacProcedure(testPermission, fallbackRoles);
|
|
// Get the middleware function that was passed to .use()
|
|
middleware = mockAuthedProcedure.use.mock.calls[0][0];
|
|
});
|
|
|
|
describe("when webhook ID is provided", () => {
|
|
it("should allow access when user has PBAC permission for team webhook", async () => {
|
|
const mockWebhook = {
|
|
id: "webhook-1",
|
|
teamId: 10,
|
|
userId: null,
|
|
eventTypeId: null,
|
|
user: null,
|
|
team: { id: 10 },
|
|
eventType: null,
|
|
};
|
|
|
|
mockPrisma.webhook.findUnique.mockResolvedValue(mockWebhook);
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const next = vi.fn().mockResolvedValue("success");
|
|
const result = await middleware({
|
|
ctx: mockCtx,
|
|
input: { id: "webhook-1", teamId: 10 },
|
|
next,
|
|
});
|
|
|
|
expect(result).toBe("success");
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 1,
|
|
teamId: 10,
|
|
permission: testPermission,
|
|
fallbackRoles,
|
|
});
|
|
});
|
|
|
|
it("should throw FORBIDDEN when user lacks PBAC permission for team webhook", async () => {
|
|
const mockWebhook = {
|
|
id: "webhook-1",
|
|
teamId: 10,
|
|
userId: null,
|
|
eventTypeId: null,
|
|
user: null,
|
|
team: { id: 10 },
|
|
eventType: null,
|
|
};
|
|
|
|
mockPrisma.webhook.findUnique.mockResolvedValue(mockWebhook);
|
|
mockCheckPermission.mockResolvedValue(false);
|
|
|
|
const next = vi.fn();
|
|
|
|
await expect(
|
|
middleware({
|
|
ctx: mockCtx,
|
|
input: { id: "webhook-1", teamId: 10 },
|
|
next,
|
|
})
|
|
).rejects.toThrow(
|
|
new TRPCError({
|
|
code: "FORBIDDEN",
|
|
message: `Permission required: ${testPermission}`,
|
|
})
|
|
);
|
|
});
|
|
|
|
it("should allow access for personal webhook when user is the owner", async () => {
|
|
const mockWebhook = {
|
|
id: "webhook-1",
|
|
teamId: null,
|
|
userId: 1,
|
|
eventTypeId: null,
|
|
user: { id: 1 },
|
|
team: null,
|
|
eventType: null,
|
|
};
|
|
|
|
mockPrisma.webhook.findUnique.mockResolvedValue(mockWebhook);
|
|
|
|
const next = vi.fn().mockResolvedValue("success");
|
|
const result = await middleware({
|
|
ctx: mockCtx,
|
|
input: { id: "webhook-1" },
|
|
next,
|
|
});
|
|
|
|
expect(result).toBe("success");
|
|
expect(mockCheckPermission).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("should throw FORBIDDEN for personal webhook when user is not the owner", async () => {
|
|
const mockWebhook = {
|
|
id: "webhook-1",
|
|
teamId: null,
|
|
userId: 2,
|
|
eventTypeId: null,
|
|
user: { id: 2 },
|
|
team: null,
|
|
eventType: null,
|
|
};
|
|
|
|
mockPrisma.webhook.findUnique.mockResolvedValue(mockWebhook);
|
|
|
|
const next = vi.fn();
|
|
|
|
await expect(
|
|
middleware({
|
|
ctx: mockCtx,
|
|
input: { id: "webhook-1" },
|
|
next,
|
|
})
|
|
).rejects.toThrow(
|
|
new TRPCError({
|
|
code: "FORBIDDEN",
|
|
message: `Permission required: ${testPermission}`,
|
|
})
|
|
);
|
|
});
|
|
|
|
it("should check team permissions for team event type webhook", async () => {
|
|
const mockWebhook = {
|
|
id: "webhook-1",
|
|
teamId: null,
|
|
userId: null,
|
|
eventTypeId: 100,
|
|
user: null,
|
|
team: null,
|
|
eventType: { id: 100, teamId: 10, userId: 2 },
|
|
};
|
|
|
|
const mockEventType = {
|
|
id: 100,
|
|
teamId: 10,
|
|
userId: 2,
|
|
team: { id: 10 },
|
|
};
|
|
|
|
mockPrisma.webhook.findUnique.mockResolvedValue(mockWebhook);
|
|
mockPrisma.eventType.findUnique.mockResolvedValue(mockEventType);
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const next = vi.fn().mockResolvedValue("success");
|
|
const result = await middleware({
|
|
ctx: mockCtx,
|
|
input: { id: "webhook-1", eventTypeId: 100 },
|
|
next,
|
|
});
|
|
|
|
expect(result).toBe("success");
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 1,
|
|
teamId: 10,
|
|
permission: testPermission,
|
|
fallbackRoles,
|
|
});
|
|
});
|
|
|
|
it("should throw NOT_FOUND when webhook doesn't exist", async () => {
|
|
mockPrisma.webhook.findUnique.mockResolvedValue(null);
|
|
|
|
const next = vi.fn();
|
|
|
|
await expect(
|
|
middleware({
|
|
ctx: mockCtx,
|
|
input: { id: "webhook-1" },
|
|
next,
|
|
})
|
|
).rejects.toThrow(new TRPCError({ code: "NOT_FOUND" }));
|
|
});
|
|
|
|
it("should throw UNAUTHORIZED when teamId doesn't match webhook teamId", async () => {
|
|
const mockWebhook = {
|
|
id: "webhook-1",
|
|
teamId: 10,
|
|
userId: null,
|
|
eventTypeId: null,
|
|
user: null,
|
|
team: { id: 10 },
|
|
eventType: null,
|
|
};
|
|
|
|
mockPrisma.webhook.findUnique.mockResolvedValue(mockWebhook);
|
|
|
|
const next = vi.fn();
|
|
|
|
await expect(
|
|
middleware({
|
|
ctx: mockCtx,
|
|
input: { id: "webhook-1", teamId: 20 },
|
|
next,
|
|
})
|
|
).rejects.toThrow(new TRPCError({ code: "UNAUTHORIZED" }));
|
|
});
|
|
});
|
|
|
|
describe("when creating new webhook (no ID provided)", () => {
|
|
it("should allow creation with team PBAC permission", async () => {
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const next = vi.fn().mockResolvedValue("success");
|
|
const result = await middleware({
|
|
ctx: mockCtx,
|
|
input: { teamId: 10 },
|
|
next,
|
|
});
|
|
|
|
expect(result).toBe("success");
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 1,
|
|
teamId: 10,
|
|
permission: testPermission,
|
|
fallbackRoles,
|
|
});
|
|
});
|
|
|
|
it("should throw FORBIDDEN when lacking team PBAC permission", async () => {
|
|
mockCheckPermission.mockResolvedValue(false);
|
|
|
|
const next = vi.fn();
|
|
|
|
await expect(
|
|
middleware({
|
|
ctx: mockCtx,
|
|
input: { teamId: 10 },
|
|
next,
|
|
})
|
|
).rejects.toThrow(
|
|
new TRPCError({
|
|
code: "FORBIDDEN",
|
|
message: `Permission required: ${testPermission}`,
|
|
})
|
|
);
|
|
});
|
|
|
|
it("should check team permissions for team event type creation", async () => {
|
|
const mockEventType = {
|
|
id: 100,
|
|
teamId: 10,
|
|
userId: 2,
|
|
team: { id: 10 },
|
|
};
|
|
|
|
mockPrisma.eventType.findUnique.mockResolvedValue(mockEventType);
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const next = vi.fn().mockResolvedValue("success");
|
|
const result = await middleware({
|
|
ctx: mockCtx,
|
|
input: { eventTypeId: 100 },
|
|
next,
|
|
});
|
|
|
|
expect(result).toBe("success");
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 1,
|
|
teamId: 10,
|
|
permission: testPermission,
|
|
fallbackRoles,
|
|
});
|
|
});
|
|
|
|
it("should allow personal event type webhook creation for owner", async () => {
|
|
const mockEventType = {
|
|
id: 100,
|
|
teamId: null,
|
|
userId: 1,
|
|
team: null,
|
|
};
|
|
|
|
mockPrisma.eventType.findUnique.mockResolvedValue(mockEventType);
|
|
|
|
const next = vi.fn().mockResolvedValue("success");
|
|
const result = await middleware({
|
|
ctx: mockCtx,
|
|
input: { eventTypeId: 100 },
|
|
next,
|
|
});
|
|
|
|
expect(result).toBe("success");
|
|
expect(mockCheckPermission).not.toHaveBeenCalled();
|
|
});
|
|
});
|
|
|
|
describe("when no input is provided", () => {
|
|
it("should call next() directly", async () => {
|
|
const next = vi.fn().mockResolvedValue("success");
|
|
const result = await middleware({
|
|
ctx: mockCtx,
|
|
input: undefined,
|
|
next,
|
|
});
|
|
|
|
expect(result).toBe("success");
|
|
expect(next).toHaveBeenCalled();
|
|
expect(mockPrisma.webhook.findUnique).not.toHaveBeenCalled();
|
|
expect(mockPrisma.eventType.findUnique).not.toHaveBeenCalled();
|
|
});
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("webhookProcedure (legacy wrapper)", () => {
|
|
it("should work as expected", () => {
|
|
// The legacy webhookProcedure uses createWebhookPbacProcedure internally
|
|
// This is verified by the functional tests above
|
|
expect(createWebhookPbacProcedure).toBeDefined();
|
|
});
|
|
});
|
|
|
|
describe("Different permission scenarios", () => {
|
|
const permissions: { permission: PermissionString; operation: string }[] = [
|
|
{ permission: "webhook.read", operation: "read" },
|
|
{ permission: "webhook.create", operation: "create" },
|
|
{ permission: "webhook.update", operation: "update" },
|
|
{ permission: "webhook.delete", operation: "delete" },
|
|
];
|
|
|
|
permissions.forEach(({ permission, operation }) => {
|
|
it(`should use ${permission} for ${operation} operations`, async () => {
|
|
createWebhookPbacProcedure(permission);
|
|
const middleware =
|
|
mockAuthedProcedure.use.mock.calls[mockAuthedProcedure.use.mock.calls.length - 1][0];
|
|
|
|
const mockWebhook = {
|
|
id: "webhook-1",
|
|
teamId: 10,
|
|
userId: null,
|
|
eventTypeId: null,
|
|
user: null,
|
|
team: { id: 10 },
|
|
eventType: null,
|
|
};
|
|
|
|
mockPrisma.webhook.findUnique.mockResolvedValue(mockWebhook);
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const next = vi.fn().mockResolvedValue("success");
|
|
await middleware({
|
|
ctx: mockCtx,
|
|
input: { id: "webhook-1" },
|
|
next,
|
|
});
|
|
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 1,
|
|
teamId: 10,
|
|
permission,
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("Fallback role behavior", () => {
|
|
it("should use custom fallback roles when provided", async () => {
|
|
const customFallback: MembershipRole[] = ["OWNER"];
|
|
createWebhookPbacProcedure("webhook.delete", customFallback);
|
|
const middleware = mockAuthedProcedure.use.mock.calls[mockAuthedProcedure.use.mock.calls.length - 1][0];
|
|
|
|
const mockWebhook = {
|
|
id: "webhook-1",
|
|
teamId: 10,
|
|
userId: null,
|
|
eventTypeId: null,
|
|
user: null,
|
|
team: { id: 10 },
|
|
eventType: null,
|
|
};
|
|
|
|
mockPrisma.webhook.findUnique.mockResolvedValue(mockWebhook);
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const next = vi.fn().mockResolvedValue("success");
|
|
await middleware({
|
|
ctx: mockCtx,
|
|
input: { id: "webhook-1" },
|
|
next,
|
|
});
|
|
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 1,
|
|
teamId: 10,
|
|
permission: "webhook.delete",
|
|
fallbackRoles: customFallback,
|
|
});
|
|
});
|
|
|
|
it("should use default fallback roles when not provided", async () => {
|
|
createWebhookPbacProcedure("webhook.update");
|
|
const middleware = mockAuthedProcedure.use.mock.calls[mockAuthedProcedure.use.mock.calls.length - 1][0];
|
|
|
|
const mockWebhook = {
|
|
id: "webhook-1",
|
|
teamId: 10,
|
|
userId: null,
|
|
eventTypeId: null,
|
|
user: null,
|
|
team: { id: 10 },
|
|
eventType: null,
|
|
};
|
|
|
|
mockPrisma.webhook.findUnique.mockResolvedValue(mockWebhook);
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const next = vi.fn().mockResolvedValue("success");
|
|
await middleware({
|
|
ctx: mockCtx,
|
|
input: { id: "webhook-1" },
|
|
next,
|
|
});
|
|
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 1,
|
|
teamId: 10,
|
|
permission: "webhook.update",
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
});
|
|
});
|