59 lines
1.6 KiB
TypeScript
59 lines
1.6 KiB
TypeScript
import { describe, expect, it } from "vitest";
|
|
|
|
import {
|
|
isAllowedAdminRegistration,
|
|
isAuthorizedAdmin,
|
|
isConfiguredAdminEmail,
|
|
} from "./authorization";
|
|
|
|
const verified = {
|
|
id: "admin",
|
|
email: "[email protected]",
|
|
emailVerified: true,
|
|
};
|
|
|
|
describe("admin authorization", () => {
|
|
it("recognizes only the exact configured administrator email", () => {
|
|
expect(isConfiguredAdminEmail(verified.email, "[email protected]")).toBe(
|
|
true,
|
|
);
|
|
expect(isConfiguredAdminEmail(verified.email, "[email protected]")).toBe(
|
|
false,
|
|
);
|
|
expect(isConfiguredAdminEmail(verified.email, undefined)).toBe(false);
|
|
});
|
|
|
|
it("allows only credential registration for the configured administrator", () => {
|
|
expect(
|
|
isAllowedAdminRegistration(
|
|
verified.email,
|
|
"email-password",
|
|
verified.email,
|
|
),
|
|
).toBe(true);
|
|
expect(
|
|
isAllowedAdminRegistration(
|
|
"[email protected]",
|
|
"email-password",
|
|
verified.email,
|
|
),
|
|
).toBe(false);
|
|
expect(
|
|
isAllowedAdminRegistration(verified.email, "oauth", verified.email),
|
|
).toBe(false);
|
|
});
|
|
|
|
it("requires an exact verified email match", () => {
|
|
expect(isAuthorizedAdmin(verified, "[email protected]")).toBe(true);
|
|
expect(isAuthorizedAdmin(verified, "[email protected]")).toBe(false);
|
|
expect(
|
|
isAuthorizedAdmin({ ...verified, emailVerified: false }, verified.email),
|
|
).toBe(false);
|
|
});
|
|
|
|
it("denies missing users and missing configuration", () => {
|
|
expect(isAuthorizedAdmin(null, verified.email)).toBe(false);
|
|
expect(isAuthorizedAdmin(verified, undefined)).toBe(false);
|
|
});
|
|
});
|