bbf9274d37
* chore: upgrade Vitest to 4.0.16 and Vite to 6.4.1 - Update vitest from 2.1.9 to 4.0.16 - Update @vitest/ui from 2.1.9 to 4.0.16 - Update vitest-fetch-mock from 0.3.0 to 0.4.5 - Update vitest-mock-extended from 2.0.2 to 3.1.0 - Update vite from 4.5.14/5.4.21 to 6.4.1 across all packages - Update @vitejs/plugin-react to 5.1.2 - Update @vitejs/plugin-react-swc to 4.2.2 - Update @vitejs/plugin-basic-ssl to 2.1.0 - Update vite-plugin-dts to 4.5.4 - Rename vitest.config.ts to vitest.config.mts for ESM compatibility - Add globals: true to vitest config Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: address Vitest 4.0 and Vite 6 breaking changes - Convert arrow function mockImplementation patterns to regular functions (Vitest 4.0 breaking change: arrow functions can't be constructor mocks) - Fix CSS imports with ?inline suffix for Vite 6 compatibility - Add biome override to disable useArrowFunction rule for test files - Fix syntax errors in test files introduced by regex replacements Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: fix remaining Vitest 4.0 constructor mock patterns Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: fix more Vitest 4.0 constructor mock patterns and exclude API v2 spec files Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert more arrow function mocks to regular functions for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert more arrow function mocks to regular functions for Vitest 4.0 - Fix CrmService.integration.test.ts jsforce.Connection mock - Fix RetellSDKClient.test.ts Retell mock - Fix RetellAIService.test.ts CreditService mocks - Fix GoogleCalendarSubscriptionAdapter.test.ts CalendarAuth mock Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert Google Calendar and OAuthManager arrow function mocks for Vitest 4.0 - Fix googleapis.ts Calendar, OAuth2Client, and JWT mocks - Fix utils.ts JWT mock - Fix OAuthManager.ts defaultMockOAuthManager mock Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: add React plugin, jsdom environment, and fix more constructor mocks for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert HostRepository PrismaClient mock to regular function for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: add useOrgBranding mock to React component tests for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: update TestFunction type for Vitest 4.0 compatibility Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert listBookingReports constructor mocks to regular functions for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert UserRepository constructor mock to regular function for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert OrganizationPaymentService constructor mock to regular function for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert more constructor mocks to regular functions for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: add apps/web path aliases to vitest config Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: fix test issues for Vitest 4.0 compatibility - Fix Response constructor 204 status code issue in testUtils.ts - Fix FeaturesRepository mock persistence in handleNotificationWhenNoSlots.test.ts - Add @vitest-environment node directive to formSubmissionUtils.test.ts - Fix document.querySelector mock in embed.test.ts Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: clear EventManager spy between tests for Vitest 4.0 compatibility Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: update TeamRepository mock pattern for Vitest 4.0 compatibility Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert RoutingFormResponseRepository mock to regular function for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: convert more constructor mocks to regular functions for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: fix mock reset and spy clear issues for Vitest 4.0 Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: fix remaining test failures for Vitest 4.0 upgrade - Fix booking-validations.test.ts: convert UserRepository mock to regular function - Fix route.test.ts: update 500 error test to mock ImageResponse instead of fetch - Fix users-public-view.test.tsx: add missing mocks for getOrgFullOrigin and useRouterQuery - Add @calcom/web path alias to vitest config Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: add vitest-mocks for generated files that don't exist in CI - Add svg-hashes.json mock for route.test.ts - Add tailwind.generated.css mock for embed.test.ts - Update vitest config to use mock files Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: update vitest config aliases for CI compatibility - Use array format for aliases to ensure proper ordering - Add @calcom/platform-constants alias to resolve from source - Add @calcom/embed-react alias to resolve from source - Ensure svg-hashes.json mock alias is matched before @calcom/web Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: add @calcom/embed-snippet alias for CI compatibility Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * Fix wrong test * fix: migrate from CLI flags to VITEST_MODE env var for Vitest 4.0 Vitest 4.0 no longer allows custom CLI flags like --packaged-embed-tests-only. This change migrates to using VITEST_MODE environment variable instead: - VITEST_MODE=packaged-embed for packaged embed tests - VITEST_MODE=integration for integration tests - VITEST_MODE=timezone for timezone-dependent tests Updated vitest.config.mts to handle mode-based include/exclude patterns. Updated CI workflows and package scripts to use the new env var approach. Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: return default include pattern instead of undefined in vitest config The getTestInclude() function was returning undefined for the default case, but Vitest 4.0 expects an array. This caused 'resolved.include is not iterable' error in CI. Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: always set INTEGRATION_TEST_MODE for jsdom environment The getBookingFields.ts file checks for INTEGRATION_TEST_MODE to allow server-side imports in the jsdom environment. Without this, tests fail with 'getBookingFields must not be imported on the client side' error. Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> * fix: support legacy CLI flags for backwards compatibility with main workflow The CI runs workflows from main branch, which uses the old CLI flag approach (yarn test -- --integrationTestsOnly). This commit adds backwards compatibility by checking both VITEST_MODE env var and process.argv for the legacy flags. Co-Authored-By: Volnei Munhoz <volnei.munhoz@gmail.com> --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
400 lines
11 KiB
TypeScript
400 lines
11 KiB
TypeScript
import { prisma } from "@calcom/prisma/__mocks__/prisma";
|
|
|
|
import { describe, it, expect, vi, beforeEach } from "vitest";
|
|
|
|
import { isAuthorized } from "@calcom/features/ee/workflows/lib/isAuthorized";
|
|
import { PermissionCheckService } from "@calcom/features/pbac/services/permission-check.service";
|
|
|
|
vi.mock("@calcom/features/pbac/services/permission-check.service");
|
|
|
|
vi.mock("@calcom/prisma", () => ({
|
|
prisma,
|
|
}));
|
|
|
|
describe("isAuthorized", () => {
|
|
const mockPermissionCheckService = vi.mocked(PermissionCheckService);
|
|
let mockCheckPermission: ReturnType<typeof vi.fn>;
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks();
|
|
mockCheckPermission = vi.fn();
|
|
mockPermissionCheckService.mockImplementation(function () {
|
|
return {
|
|
checkPermission: mockCheckPermission,
|
|
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
|
} as any;
|
|
});
|
|
});
|
|
|
|
describe("null workflow", () => {
|
|
it("should return false when workflow is null", async () => {
|
|
const result = await isAuthorized(null, 123);
|
|
expect(result).toBe(false);
|
|
});
|
|
});
|
|
|
|
describe("personal workflows (no teamId)", () => {
|
|
it("should return true when user owns the personal workflow", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: null,
|
|
userId: 123,
|
|
};
|
|
|
|
const result = await isAuthorized(workflow, 123);
|
|
expect(result).toBe(true);
|
|
expect(mockPermissionCheckService).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("should return false when user does not own the personal workflow", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: null,
|
|
userId: 456,
|
|
};
|
|
|
|
const result = await isAuthorized(workflow, 123);
|
|
expect(result).toBe(false);
|
|
expect(mockPermissionCheckService).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("should ignore permission parameter for personal workflows", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: null,
|
|
userId: 123,
|
|
};
|
|
|
|
const readResult = await isAuthorized(workflow, 123, "workflow.read");
|
|
const updateResult = await isAuthorized(workflow, 123, "workflow.update");
|
|
const deleteResult = await isAuthorized(workflow, 123, "workflow.delete");
|
|
|
|
expect(readResult).toBe(true);
|
|
expect(updateResult).toBe(true);
|
|
expect(deleteResult).toBe(true);
|
|
expect(mockPermissionCheckService).not.toHaveBeenCalled();
|
|
});
|
|
});
|
|
|
|
describe("team workflows with PBAC", () => {
|
|
describe("read operations", () => {
|
|
it("should use workflow.read permission by default with all roles as fallback", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123);
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockPermissionCheckService).toHaveBeenCalledTimes(1);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.read",
|
|
fallbackRoles: ["ADMIN", "OWNER", "MEMBER"],
|
|
});
|
|
});
|
|
|
|
it("should use workflow.read permission when explicitly passed", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.read");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.read",
|
|
fallbackRoles: ["ADMIN", "OWNER", "MEMBER"],
|
|
});
|
|
});
|
|
|
|
it("should return false when PBAC denies read permission", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(false);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.read");
|
|
|
|
expect(result).toBe(false);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.read",
|
|
fallbackRoles: ["ADMIN", "OWNER", "MEMBER"],
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("update operations", () => {
|
|
it("should use workflow.update permission with admin/owner roles as fallback", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.update");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockPermissionCheckService).toHaveBeenCalledTimes(1);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.update",
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
|
|
it("should return false when PBAC denies update permission", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(false);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.update");
|
|
|
|
expect(result).toBe(false);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.update",
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("delete operations", () => {
|
|
it("should use workflow.delete permission with admin/owner roles as fallback", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.delete");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.delete",
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
|
|
it("should return false when PBAC denies delete permission", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(false);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.delete");
|
|
|
|
expect(result).toBe(false);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.delete",
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("other permissions", () => {
|
|
it("should use workflow.create permission with admin/owner roles as fallback", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.create");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.create",
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
|
|
it("should use workflow.manage permission with admin/owner roles as fallback", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.manage");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 456,
|
|
permission: "workflow.manage",
|
|
fallbackRoles: ["ADMIN", "OWNER"],
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("permission service integration", () => {
|
|
it("should create a new PermissionCheckService instance for each call", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
await isAuthorized(workflow, 123, "workflow.read");
|
|
await isAuthorized(workflow, 123, "workflow.update");
|
|
|
|
expect(mockPermissionCheckService).toHaveBeenCalledTimes(2);
|
|
});
|
|
|
|
it("should handle permission service errors gracefully", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockRejectedValue(new Error("Permission service error"));
|
|
|
|
await expect(isAuthorized(workflow, 123, "workflow.read")).rejects.toThrow(
|
|
"Permission service error"
|
|
);
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("edge cases", () => {
|
|
it("should handle workflow with teamId 0 as personal workflow", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 0,
|
|
userId: 123,
|
|
};
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.delete");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockPermissionCheckService).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("should handle workflow with positive teamId as team workflow", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 1,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.read");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 123,
|
|
teamId: 1,
|
|
permission: "workflow.read",
|
|
fallbackRoles: ["ADMIN", "OWNER", "MEMBER"],
|
|
});
|
|
});
|
|
|
|
it("should handle different user IDs correctly", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 789, "workflow.read");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockCheckPermission).toHaveBeenCalledWith({
|
|
userId: 789,
|
|
teamId: 456,
|
|
permission: "workflow.read",
|
|
fallbackRoles: ["ADMIN", "OWNER", "MEMBER"],
|
|
});
|
|
});
|
|
|
|
it("should handle workflow with undefined teamId as personal workflow", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
|
teamId: undefined as any,
|
|
userId: 123,
|
|
};
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.delete");
|
|
|
|
expect(result).toBe(true);
|
|
expect(mockPermissionCheckService).not.toHaveBeenCalled();
|
|
});
|
|
});
|
|
|
|
describe("type safety", () => {
|
|
it("should work with minimal workflow object", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: null,
|
|
userId: 123,
|
|
};
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.read");
|
|
expect(result).toBe(true);
|
|
});
|
|
|
|
it("should work with workflow object containing extra properties", async () => {
|
|
const workflow = {
|
|
id: 1,
|
|
teamId: 456,
|
|
userId: 123,
|
|
name: "Test Workflow",
|
|
createdAt: new Date(),
|
|
updatedAt: new Date(),
|
|
};
|
|
|
|
mockCheckPermission.mockResolvedValue(true);
|
|
|
|
const result = await isAuthorized(workflow, 123, "workflow.update");
|
|
expect(result).toBe(true);
|
|
});
|
|
});
|
|
});
|