g1t/services/projects/src/access.test.ts
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 1 | import assert from "node:assert/strict"; |
| 2 | import { test } from "node:test"; | |
| 3 | ||
| 4 | import type { User } from "@g1t/contracts"; | |
| 5 | ||
| 6 | import { can, needs, permission } from "../../../packages/contracts/src/access.ts"; | |
| 7 | import { NEEDS, repoRef } from "./access.ts"; | |
| 8 | ||
| 9 | const row = (isPrivate: boolean) => ({ repo_id: "repo_api", repo_namespace: "acme", repo_private: isPrivate ? 1 : 0 }); | |
| 10 | const person = (extra: Partial<User>): User => ({ id: "u", username: "u", kind: "user", verified: true, workspaces: [], ...extra }) as User; | |
| 11 | ||
| 12 | test("a private project is seen by those who can read its repository", () => { | |
| 13 | const none = person({ workspaces: [{ slug: "acme", role: "member", base_permission: "none" }] }); | |
| 14 | assert.equal(permission(none, repoRef(row(true))), null, "a member with no base permission does not see it"); | |
| 15 | assert.ok(permission(none, repoRef(row(false))), "but sees a public one"); | |
| 16 | const granted = person({ workspaces: [{ slug: "acme", role: "member", base_permission: "none" }], grants: [{ repo_id: "repo_api", workspace: "acme", role: "read" }] }); | |
| 17 | assert.equal(permission(granted, repoRef(row(true))), "read"); | |
| 18 | const outside = person({ grants: [{ repo_id: "repo_api", workspace: "acme", role: "read" }] }); | |
| 19 | assert.equal(permission(outside, repoRef(row(true))), "read", "an outside collaborator sees the project of a repository shared with them"); | |
| 20 | }); | |
| 21 | ||
| 22 | test("changing a project and its dependencies takes Maintain", () => { | |
| 23 | const member = person({ workspaces: [{ slug: "acme", role: "member" }] }); | |
| 24 | assert.ok(!can(member, repoRef(row(true)), NEEDS.addDependency), "Write, the default base permission, is not enough"); | |
| 25 | assert.equal(needs(NEEDS.update), "Needs the Maintain role or higher."); | |
| 26 | const maintainer = person({ grants: [{ repo_id: "repo_api", workspace: "acme", role: "maintain" }] }); | |
| 27 | for (const capability of [NEEDS.update, NEEDS.addDependency, NEEDS.removeDependency]) assert.ok(can(maintainer, repoRef(row(true)), capability)); | |
| 28 | const owner = person({ workspaces: [{ slug: "acme", role: "owner" }] }); | |
| 29 | assert.ok(can(owner, repoRef(row(true)), NEEDS.create)); | |
| 30 | }); |