feat(auth): replace Google login with credentials
This commit is contained in:
@@ -1,6 +1,10 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
|
||||
import { isAuthorizedAdmin } from "./authorization";
|
||||
import {
|
||||
isAllowedAdminRegistration,
|
||||
isAuthorizedAdmin,
|
||||
isConfiguredAdminEmail,
|
||||
} from "./authorization";
|
||||
|
||||
const verified = {
|
||||
id: "admin",
|
||||
@@ -9,6 +13,36 @@ const verified = {
|
||||
};
|
||||
|
||||
describe("admin authorization", () => {
|
||||
it("recognizes only the exact configured administrator email", () => {
|
||||
expect(isConfiguredAdminEmail(verified.email, "[email protected]")).toBe(
|
||||
true,
|
||||
);
|
||||
expect(isConfiguredAdminEmail(verified.email, "[email protected]")).toBe(
|
||||
false,
|
||||
);
|
||||
expect(isConfiguredAdminEmail(verified.email, undefined)).toBe(false);
|
||||
});
|
||||
|
||||
it("allows only credential registration for the configured administrator", () => {
|
||||
expect(
|
||||
isAllowedAdminRegistration(
|
||||
verified.email,
|
||||
"email-password",
|
||||
verified.email,
|
||||
),
|
||||
).toBe(true);
|
||||
expect(
|
||||
isAllowedAdminRegistration(
|
||||
"[email protected]",
|
||||
"email-password",
|
||||
verified.email,
|
||||
),
|
||||
).toBe(false);
|
||||
expect(
|
||||
isAllowedAdminRegistration(verified.email, "oauth", verified.email),
|
||||
).toBe(false);
|
||||
});
|
||||
|
||||
it("requires an exact verified email match", () => {
|
||||
expect(isAuthorizedAdmin(verified, "[email protected]")).toBe(true);
|
||||
expect(isAuthorizedAdmin(verified, "[email protected]")).toBe(false);
|
||||
|
||||
Reference in New Issue
Block a user