| 1 | import assert from "node:assert/strict"; |
| 2 | import { test } from "node:test"; |
| 3 | |
| 4 | import { PERMISSIONS } from "@g1t/contracts/fine-grained"; |
| 5 | |
| 6 | import { |
| 7 | accessLabel, |
| 8 | expiryChoices, |
| 9 | fineGrainedFromForm, |
| 10 | lifetimeFromForm, |
| 11 | permissionChips, |
| 12 | permissionsFor, |
| 13 | policyNote, |
| 14 | reachSummary, |
| 15 | statusBadge, |
| 16 | } from "./fine-grained.ts"; |
| 17 | |
| 18 | function form(fields: Record<string, string | string[]>) { |
| 19 | return { |
| 20 | get: (name: string) => { |
| 21 | const value = fields[name]; |
| 22 | return Array.isArray(value) ? (value[0] ?? null) : (value ?? null); |
| 23 | }, |
| 24 | getAll: (name: string) => { |
| 25 | const value = fields[name]; |
| 26 | return value === undefined ? [] : Array.isArray(value) ? value : [value]; |
| 27 | }, |
| 28 | }; |
| 29 | } |
| 30 | |
| 31 | const policy = { allowClassic: true, allowFineGrained: true, requireApproval: true, maxLifetimeDays: null, forbidNoExpiry: false }; |
| 32 | |
| 33 | test("a workspace's token reads its form into permissions, always with metadata", () => { |
| 34 | const parsed = fineGrainedFromForm( |
| 35 | form({ |
| 36 | name: "release bot", |
| 37 | owner: "Acme", |
| 38 | expires: "30", |
| 39 | repository_selection: "selected", |
| 40 | repo: ["web", "acme/api", "web"], |
| 41 | "perm.contents": "write", |
| 42 | "perm.issues": "none", |
| 43 | "perm.workflows": "write", |
| 44 | // Not for a workspace: left out. |
| 45 | "perm.email_addresses": "write", |
| 46 | }), |
| 47 | ); |
| 48 | assert.ok(parsed.ok); |
| 49 | assert.equal(parsed.value.workspace, "acme"); |
| 50 | assert.equal(parsed.value.ttlSeconds, 30 * 86_400); |
| 51 | assert.deepEqual(parsed.value.repositories, ["web", "acme/api"]); |
| 52 | assert.deepEqual(parsed.value.permissions, { contents: "write", workflows: "write", metadata: "read" }); |
| 53 | }); |
| 54 | |
| 55 | test("your own account takes only account permissions and no repositories", () => { |
| 56 | const parsed = fineGrainedFromForm(form({ name: "inbox", owner: "", expires: "7", "perm.notifications": "write", "perm.contents": "write" })); |
| 57 | assert.ok(parsed.ok); |
| 58 | assert.equal(parsed.value.workspace, null); |
| 59 | assert.equal(parsed.value.repositorySelection, "public"); |
| 60 | assert.deepEqual(parsed.value.permissions, { notifications: "write" }); |
| 61 | assert.equal(fineGrainedFromForm(form({ name: "x", owner: "", expires: "7" })).ok, false, "at least one permission"); |
| 62 | }); |
| 63 | |
| 64 | test("mistakes are named", () => { |
| 65 | assert.match((fineGrainedFromForm(form({ owner: "acme" })) as { error: string }).error, /Name/); |
| 66 | assert.match((fineGrainedFromForm(form({ name: "x", owner: "acme", expires: "400" })) as { error: string }).error, /366/); |
| 67 | assert.match((fineGrainedFromForm(form({ name: "x", owner: "acme", expires: "30", repository_selection: "selected" })) as { error: string }).error, /repository/); |
| 68 | assert.match((fineGrainedFromForm(form({ name: "x", owner: "acme", expires: "30", "perm.workflows": "read" })) as { error: string }).error, /Workflows/); |
| 69 | }); |
| 70 | |
| 71 | test("the form offers each group to the right resource owner", () => { |
| 72 | assert.ok(permissionsFor(true).every((permission) => permission.group !== "account")); |
| 73 | assert.ok(permissionsFor(false).every((permission) => permission.group === "account")); |
| 74 | assert.equal(permissionsFor(true).length + permissionsFor(false).length, PERMISSIONS.length); |
| 75 | assert.equal(accessLabel("write", PERMISSIONS.find((p) => p.name === "workflows")), "Write"); |
| 76 | assert.equal(accessLabel("write", PERMISSIONS.find((p) => p.name === "contents")), "Read and write"); |
| 77 | }); |
| 78 | |
| 79 | test("lifetimes follow the workspace's rules", () => { |
| 80 | assert.deepEqual(expiryChoices(null), [7, 30, 60, 90, 180, 366]); |
| 81 | assert.deepEqual(expiryChoices({ ...policy, maxLifetimeDays: 90 }), [7, 30, 60, 90]); |
| 82 | assert.deepEqual(expiryChoices({ ...policy, maxLifetimeDays: 45 }), [7, 30, 45]); |
| 83 | assert.deepEqual(lifetimeFromForm(""), { ok: true, value: null }); |
| 84 | assert.deepEqual(lifetimeFromForm("90"), { ok: true, value: 90 }); |
| 85 | assert.equal(lifetimeFromForm("0").ok, false); |
| 86 | }); |
| 87 | |
| 88 | test("lists read a fine-grained token in a line", () => { |
| 89 | const token = { |
| 90 | id: "tok_1", name: "ci", createdAt: "", lastUsedAt: null, createdBy: null, scopes: [], legacy: false, expiresAt: null, |
| 91 | fineGrained: { workspace: "acme", repositorySelection: "selected" as const, repositories: ["acme/web", "acme/api"], permissions: { metadata: "read" as const, issues: "read" as const, contents: "write" as const }, status: "pending" as const }, |
| 92 | }; |
| 93 | assert.equal(reachSummary(token), "acme · 2 repositories"); |
| 94 | assert.deepEqual(permissionChips(token.fineGrained.permissions), ["Contents: write", "Issues: read"]); |
| 95 | assert.deepEqual(statusBadge("pending"), { label: "Pending approval", tone: "warn" }); |
| 96 | assert.equal(statusBadge("active"), null); |
| 97 | assert.match(policyNote("acme", policy, false) ?? "", /must approve/); |
| 98 | assert.equal(policyNote("acme", policy, true), null, "owners' own tokens never wait"); |
| 99 | assert.match(policyNote("acme", { ...policy, allowFineGrained: false }, true) ?? "", /does not allow/); |
| 100 | }); |