Put the feedback and tickets admin areas behind the shared identity (#13)
Jenkins Production Deployment
Jenkins Production Deployment
Reviewed-on: #13 Co-authored-by: Patrick Müller <mail@pmueller.me> Co-committed-by: Patrick Müller <mail@pmueller.me>
This commit was merged in pull request #13.
This commit is contained in:
@@ -221,16 +221,32 @@ describe('requireAppAccess', () => {
|
||||
expect(Array.isArray(res.body)).toBe(true);
|
||||
});
|
||||
|
||||
// Step 2 deliberately does NOT swap the feedback and tickets authenticators:
|
||||
// they still authenticate against the legacy calendar sessions, so an admin
|
||||
// cookie means nothing to them yet. This asserts that boundary rather than
|
||||
// the end state - when step 4 lands, these two expectations become 200/403
|
||||
// and this comment goes away.
|
||||
it('leaves the feedback and tickets admin areas on their legacy authenticator', async () => {
|
||||
// The step 4 cutover (2026-09-06): the feedback and tickets admin areas now
|
||||
// sit behind this same gate, so one sign-in reaches every app the user has a
|
||||
// permission for - and reaches no further. Until step 4 these two returned
|
||||
// 401 for an admin cookie, because each module still ran its own header
|
||||
// session against the calendar users table.
|
||||
it('lets an admin cookie into the feedback and tickets admin areas', async () => {
|
||||
const user = await createAndAcceptInvitation(app, 'o@nachklang.art', 'O', ['feedback', 'tickets']);
|
||||
|
||||
expect((await user.agent.get('/feedback/admin/me')).status).toBe(401);
|
||||
expect((await user.agent.get('/tickets/admin/me')).status).toBe(401);
|
||||
expect((await user.agent.get('/feedback/admin/me')).status).toBe(200);
|
||||
expect((await user.agent.get('/tickets/admin/me')).status).toBe(200);
|
||||
});
|
||||
|
||||
it('403s each app separately for a user who only holds the other one', async () => {
|
||||
const user = await createAndAcceptInvitation(app, 'q@nachklang.art', 'Q', ['feedback']);
|
||||
|
||||
expect((await user.agent.get('/feedback/admin/me')).status).toBe(200);
|
||||
expect((await user.agent.get('/tickets/admin/me')).status).toBe(403);
|
||||
});
|
||||
|
||||
it('401s the feedback and tickets admin areas for a legacy header session', async () => {
|
||||
const res = await request(app)
|
||||
.get('/feedback/admin/me')
|
||||
.set('X-Session-Id', '1')
|
||||
.set('X-Session-Key', 'whatever');
|
||||
|
||||
expect(res.status).toBe(401);
|
||||
});
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user