g1t/apps/web/app/lib/chrome.test.ts
| 1 | import assert from "node:assert/strict"; |
| 2 | import { test } from "node:test"; |
| 3 | |
| 4 | import { VISITOR_LINKS, projectPages, usesAppShell } from "./chrome.ts"; |
| 5 | |
| 6 | test("someone signed in always gets the sidebar", () => { |
| 7 | for (const path of ["/", "/pricing", "/acme/web", "/explore", "/does/not/exist"]) { |
| 8 | assert.equal(usesAppShell(path, true), true, path); |
| 9 | } |
| 10 | }); |
| 11 | |
| 12 | test("a visitor gets the sidebar on app pages", () => { |
| 13 | for (const path of [ |
| 14 | "/acme/web", |
| 15 | "/acme/web/code", |
| 16 | "/acme/web/issues/4", |
| 17 | "/explore", |
| 18 | "/search", |
| 19 | "/u/ada", |
| 20 | "/acme", |
| 21 | "/nothing/here/at/all", |
| 22 | ]) { |
| 23 | assert.equal(usesAppShell(path, false), true, path); |
| 24 | } |
| 25 | }); |
| 26 | |
| 27 | test("a visitor gets the marketing frame on the front, pricing and sign-in pages", () => { |
| 28 | for (const path of ["/", "/pricing", "/pricing/", "/login", "/register", "/verify", "/forgot", "/reset", "/device", "/oauth/authorize"]) { |
| 29 | assert.equal(usesAppShell(path, false), false, path); |
| 30 | } |
| 31 | }); |
| 32 | |
| 33 | test("a visitor reads the policies, security, support and status in the marketing frame", () => { |
| 34 | for (const path of ["/policies", "/policies/terms", "/policies/privacy/", "/security", "/support", "/status"]) { |
| 35 | assert.equal(usesAppShell(path, false), false, path); |
| 36 | } |
| 37 | // A workspace's own security page is still the app's. |
| 38 | assert.equal(usesAppShell("/acme/-/security", false), true); |
| 39 | }); |
| 40 | |
| 41 | test("a visitor's sidebar offers Explore and Search", () => { |
| 42 | assert.deepEqual(VISITOR_LINKS.map((link) => link.to), ["/explore", "/search"]); |
| 43 | }); |
| 44 | |
| 45 | test("a project's menu hides member-only pages from everyone else", () => { |
| 46 | const visitor = projectPages(false); |
| 47 | assert.deepEqual(visitor.slice(0, 5), ["code", "issues", "pulls", "agents", "actions"]); |
| 48 | for (const page of ["security", "settings"] as const) { |
| 49 | assert.ok(!visitor.includes(page), page); |
| 50 | assert.ok(projectPages(true).includes(page), page); |
| 51 | } |
| 52 | // Security needs push once the role is known: Read and Triage do not see it. |
| 53 | assert.ok(!projectPages(true, { push: false }).includes("security")); |
| 54 | assert.ok(projectPages(true, { push: true }).includes("security")); |
| 55 | // Anyone who can read a repository sees its deployments. |
| 56 | assert.ok(visitor.includes("deployments") && projectPages(true).includes("deployments")); |
| 57 | }); |