Files
accounted/app/api/customers/__tests__/viewer.test.ts
T
Mattsson a1a816b4a5 Delete features (#218)
* Implement company and account deletion features

- Add event types for company and account deletion to CoreEvent.
- Enhance Supabase middleware to handle company context resolution and cookie management for archived companies.
- Create API routes for deleting accounts and companies, including necessary validations and event emissions.
- Implement tests for account and company deletion endpoints to ensure proper functionality and error handling.
- Add retention notice component to inform users about bookkeeping data retention during destructive actions.
- Create database migrations to support soft deletion of companies and anonymization of user accounts, ensuring compliance with retention laws.

* feat: enhance account deletion process and update user notifications

* Add service client for onboarding completion check and update escape hatch visibility

* Enhance invite flow and email handling for company members

* Refactor company context and RLS policies for active company isolation

- Update `switchCompany` to remove unnecessary revalidation as client handles navigation.
- Revise `getActiveCompanyId` to prioritize `user_preferences` and validate against non-archived memberships.
- Modify `setActiveCompany` to ensure `user_preferences` is the authoritative source while maintaining cookie compatibility.
- Enhance middleware to resolve active company using `user_preferences` and fallback to first non-archived membership.
- Introduce new API route `/api/company/current` to fetch the active company ID for cross-tab synchronization.
- Implement `CompanyTabSync` component for real-time active company enforcement across tabs.
- Create migration for RLS policies to enforce single-active-company isolation using `current_active_company_id()`.

* feat: implement viewer role enforcement for write permissions

- Added `useCanWrite` hook to determine if the current user has write permissions based on their role in the active company.
- Updated various components (JournalEntryForm, CustomerForm, DeadlineForm, etc.) to disable write actions and show a lock icon with a tooltip for users without write permissions.
- Introduced `requireWritePermission` function to enforce write permissions at the API level, returning a 403 response for viewers.
- Created tests to verify the behavior of the viewer role and write permissions.
- Added database migration to enforce read-only access for viewers at the database level.
2026-04-11 17:06:32 +02:00

88 lines
2.6 KiB
TypeScript

/**
* Representative viewer-403 test.
*
* Verifies that POST /api/customers returns 403 when the caller's
* requireWritePermission check returns an error response. This is a
* canary test — if it breaks, the wiring between mutating routes and
* requireWritePermission has drifted.
*
* The full per-role behavior of requireWritePermission itself is
* covered in lib/auth/__tests__/require-write.test.ts.
*/
import { describe, it, expect, vi, beforeEach } from 'vitest'
import { NextResponse } from 'next/server'
import { createMockRequest, parseJsonResponse } from '@/tests/helpers'
const mockAuthGetUser = vi.fn()
const mockFrom = vi.fn()
const mockSupabase = {
auth: { getUser: mockAuthGetUser },
from: mockFrom,
}
vi.mock('@/lib/supabase/server', () => ({
createClient: () => Promise.resolve(mockSupabase),
}))
vi.mock('@/lib/init', () => ({
ensureInitialized: vi.fn(),
}))
vi.mock('@/lib/company/context', () => ({
requireCompanyId: vi.fn().mockResolvedValue('company-1'),
getActiveCompanyId: vi.fn().mockResolvedValue('company-1'),
}))
const requireWritePermissionMock = vi.fn()
vi.mock('@/lib/auth/require-write', () => ({
requireWritePermission: (...args: unknown[]) => requireWritePermissionMock(...args),
}))
import { POST } from '../route'
describe('POST /api/customers — viewer role gate', () => {
const mockUser = { id: 'user-1', email: 'viewer@test.se' }
beforeEach(() => {
vi.clearAllMocks()
mockAuthGetUser.mockResolvedValue({ data: { user: mockUser } })
})
it('returns 403 with Swedish message when requireWritePermission rejects', async () => {
requireWritePermissionMock.mockResolvedValue({
ok: false,
response: NextResponse.json(
{ error: 'Du har endast läsbehörighet i detta företag.' },
{ status: 403 },
),
})
const request = createMockRequest('/api/customers', {
method: 'POST',
body: { name: 'Test customer', customer_type: 'company' },
})
const response = await POST(request)
const { status, body } = await parseJsonResponse<{ error: string }>(response)
expect(status).toBe(403)
expect(body.error).toContain('läsbehörighet')
})
it('calls requireWritePermission with the authenticated user id', async () => {
requireWritePermissionMock.mockResolvedValue({
ok: false,
response: NextResponse.json({ error: 'blocked' }, { status: 403 }),
})
const request = createMockRequest('/api/customers', {
method: 'POST',
body: { name: 'Test customer', customer_type: 'company' },
})
await POST(request)
expect(requireWritePermissionMock).toHaveBeenCalledWith(mockSupabase, 'user-1')
})
})