import { describe, expect, it } from 'vitest'; import { decideAccess } from './access'; describe('decideAccess', () => { it('sends an anonymous browser to the sign-in screen', () => { expect(decideAccess({ pathname: '/admin/horaires', method: 'GET', role: undefined })).toEqual({ kind: 'redirect', }); }); it('answers an anonymous fetch with 401 rather than an HTML page', () => { expect(decideAccess({ pathname: '/api/admin/messages', method: 'GET', role: undefined })).toEqual( { kind: 'deny', status: 401, error: 'Non authentifié' }, ); }); it('lets a read-only account read pages and API routes', () => { expect(decideAccess({ pathname: '/admin', method: 'GET', role: 'viewer' })).toEqual({ kind: 'allow', }); expect(decideAccess({ pathname: '/api/admin/messages', method: 'GET', role: 'viewer' })).toEqual( { kind: 'allow' }, ); }); it('refuses a write to the API from a read-only account', () => { expect(decideAccess({ pathname: '/api/admin/messages', method: 'POST', role: 'viewer' })).toEqual( { kind: 'deny', status: 403, error: 'Compte en lecture seule' }, ); }); it('allows a write to the API from an administrator', () => { expect(decideAccess({ pathname: '/api/admin/messages', method: 'DELETE', role: 'admin' })).toEqual( { kind: 'allow' }, ); }); it('lets a read-only account POST to a page', () => { // Regression: a React server action POSTs to the URL of the page it lives // on. Gating pages by method refused every form to a viewer, sign-out // included, which showed up as "an unexpected response was received from // the server". Page writes are checked inside the action instead. expect(decideAccess({ pathname: '/admin', method: 'POST', role: 'viewer' })).toEqual({ kind: 'allow', }); expect(decideAccess({ pathname: '/admin/horaires', method: 'POST', role: 'viewer' })).toEqual({ kind: 'allow', }); }); it('still requires a session before a page POST', () => { expect(decideAccess({ pathname: '/admin', method: 'POST', role: undefined })).toEqual({ kind: 'redirect', }); }); });