import { describe, expect, it } from 'vitest'; import { authorize } from './authorize'; describe('authorize', () => { it('refuses anyone without a session', () => { expect(authorize(undefined, 'GET')).toEqual({ ok: false, status: 401, error: 'Non authentifié', }); expect(authorize(undefined, 'POST')).toMatchObject({ status: 401 }); }); it('lets any signed-in account read', () => { for (const method of ['GET', 'HEAD', 'OPTIONS', 'get', 'head']) { expect(authorize('viewer', method)).toEqual({ ok: true }); expect(authorize('admin', method)).toEqual({ ok: true }); } }); it('refuses a write from a read-only account', () => { for (const method of ['POST', 'PUT', 'PATCH', 'DELETE']) { expect(authorize('viewer', method)).toEqual({ ok: false, status: 403, error: 'Compte en lecture seule', }); } }); it('allows a write from an administrator', () => { for (const method of ['POST', 'PUT', 'PATCH', 'DELETE', 'post']) { expect(authorize('admin', method)).toEqual({ ok: true }); } }); it('treats an unknown method as a write', () => { // New verbs should arrive locked, not open. expect(authorize('viewer', 'PURGE')).toMatchObject({ status: 403 }); expect(authorize('admin', 'PURGE')).toEqual({ ok: true }); }); it('checks the session before the method', () => { // A read-only method must not turn a missing session into a 403; the // caller has to know they are signed out, not under-privileged. expect(authorize(undefined, 'GET')).toMatchObject({ status: 401 }); }); });