mirror of
https://github.com/InvoiceShelf/InvoiceShelf.git
synced 2026-09-02 13:21:02 +00:00
* feat(modules): expose host data boundaries * feat(modules): add frontend extension surfaces * refactor(ai): remove assistant from core * chore(ai): prepare the module extraction * fix(modules): load extension styles after the host bundle * chore(modules): lock SDK 3.3.0
55 lines
2.2 KiB
PHP
55 lines
2.2 KiB
PHP
<?php
|
|
|
|
use App\Domains\Accounts\Models\Company;
|
|
use App\Domains\Accounts\Models\User;
|
|
use App\Domains\Catalog\Models\Item;
|
|
use App\Platform\Modules\Infrastructure\BouncerModuleAuthorization;
|
|
use Illuminate\Support\Facades\Artisan;
|
|
use Silber\Bouncer\BouncerFacade;
|
|
|
|
beforeEach(function () {
|
|
Artisan::call('db:seed', ['--class' => 'DatabaseSeeder', '--force' => true]);
|
|
Artisan::call('db:seed', ['--class' => 'DemoSeeder', '--force' => true]);
|
|
});
|
|
|
|
function hostGrant(User $user, int $companyId, string $ability, ?string $model = null): void
|
|
{
|
|
BouncerFacade::scope()->to($companyId);
|
|
|
|
$model === null
|
|
? BouncerFacade::allow($user)->to($ability)
|
|
: BouncerFacade::allow($user)->to($ability, $model);
|
|
}
|
|
|
|
test('module authorization resolves stable resource keys within the supplied company scope', function () {
|
|
$companyA = Company::firstOrFail();
|
|
$companyB = Company::factory()->create();
|
|
$user = User::factory()->create();
|
|
$user->companies()->attach([$companyA->id, $companyB->id]);
|
|
$authorization = new BouncerModuleAuthorization;
|
|
|
|
hostGrant($user, $companyA->id, 'view-item', Item::class);
|
|
hostGrant($user, $companyA->id, 'dashboard');
|
|
BouncerFacade::scope()->to($companyA->id);
|
|
|
|
expect($authorization->allows($user->id, $companyA->id, 'view-item', 'item'))->toBeTrue()
|
|
->and($authorization->allows($user->id, $companyA->id, 'dashboard'))->toBeTrue()
|
|
->and($authorization->allows($user->id, $companyB->id, 'view-item', 'item'))->toBeFalse()
|
|
->and($authorization->allows($user->id, $companyA->id, 'view-item', 'invoice'))->toBeFalse()
|
|
->and(BouncerFacade::scope()->appendToCacheKey('scope'))->toBe('scope-'.$companyA->id);
|
|
});
|
|
|
|
test('module authorization refuses users outside the company and unknown stable resource keys', function () {
|
|
$company = Company::firstOrFail();
|
|
$outsider = User::factory()->create();
|
|
$authorization = new BouncerModuleAuthorization;
|
|
|
|
expect($authorization->allows($outsider->id, $company->id, 'dashboard'))->toBeFalse();
|
|
|
|
$member = User::factory()->create();
|
|
$member->companies()->attach($company->id);
|
|
|
|
expect(fn () => $authorization->allows($member->id, $company->id, 'view-widget', 'widget'))
|
|
->toThrow(LogicException::class);
|
|
});
|