Put the feedback and tickets admin areas behind the shared identity (#13)
Jenkins Production Deployment

Reviewed-on: #13
Co-authored-by: Patrick Müller <mail@pmueller.me>
Co-committed-by: Patrick Müller <mail@pmueller.me>
This commit was merged in pull request #13.
This commit is contained in:
2026-09-06 19:06:30 +00:00
committed by Patrick Müller
parent bf7be65b03
commit 3c892d02ed
20 changed files with 457 additions and 309 deletions
+24 -8
View File
@@ -221,16 +221,32 @@ describe('requireAppAccess', () => {
expect(Array.isArray(res.body)).toBe(true);
});
// Step 2 deliberately does NOT swap the feedback and tickets authenticators:
// they still authenticate against the legacy calendar sessions, so an admin
// cookie means nothing to them yet. This asserts that boundary rather than
// the end state - when step 4 lands, these two expectations become 200/403
// and this comment goes away.
it('leaves the feedback and tickets admin areas on their legacy authenticator', async () => {
// The step 4 cutover (2026-09-06): the feedback and tickets admin areas now
// sit behind this same gate, so one sign-in reaches every app the user has a
// permission for - and reaches no further. Until step 4 these two returned
// 401 for an admin cookie, because each module still ran its own header
// session against the calendar users table.
it('lets an admin cookie into the feedback and tickets admin areas', async () => {
const user = await createAndAcceptInvitation(app, 'o@nachklang.art', 'O', ['feedback', 'tickets']);
expect((await user.agent.get('/feedback/admin/me')).status).toBe(401);
expect((await user.agent.get('/tickets/admin/me')).status).toBe(401);
expect((await user.agent.get('/feedback/admin/me')).status).toBe(200);
expect((await user.agent.get('/tickets/admin/me')).status).toBe(200);
});
it('403s each app separately for a user who only holds the other one', async () => {
const user = await createAndAcceptInvitation(app, 'q@nachklang.art', 'Q', ['feedback']);
expect((await user.agent.get('/feedback/admin/me')).status).toBe(200);
expect((await user.agent.get('/tickets/admin/me')).status).toBe(403);
});
it('401s the feedback and tickets admin areas for a legacy header session', async () => {
const res = await request(app)
.get('/feedback/admin/me')
.set('X-Session-Id', '1')
.set('X-Session-Key', 'whatever');
expect(res.status).toBe(401);
});
});