7aac07a013
Introduces src/models/admin/, a dedicated identity and permissions module on its own nachklang_admin database, and the shared authenticator that feedback and tickets will move onto in the cutover step. Nothing swaps over yet: feedback.auth.ts and tickets.auth.ts still authenticate against the legacy calendar sessions, so production behaviour is unchanged. - better-auth 1.7 mounted at /admin/auth/*, sessions as httpOnly cookies scoped to .nachklang.art so one sign-in covers every *.nachklang.art app. - Accounts are invite-only: public sign-up is disabled, and the invitations plugin is the only code that creates users. Tokens are stored as SHA-256 hashes and travel in the request body, never in a URL. - Per-app permissions in user_app_permissions; requireAppAccess(app) queries the database on every request (no cookie cache) so disabling a user or revoking a session takes effect immediately. - ADMIN_BOOTSTRAP_EMAIL guarantees a way in on an empty database, idempotently and without crashing the API if the database is unreachable at boot. - Guards prevent an admin from removing their own admin permission, disabling themselves, or stripping the last active admin. The admin pool uses the callback-style mysql2, not mysql2/promise: Kysely's MysqlDialect drives the pool with callbacks, and the promise wrapper ignores them, so every query hangs silently. Only the integration tests caught this. Schema in sql/admin/001_init.sql, derived from getAuthTables() on the installed better-auth rather than the published CLI, which lags the library and omits account.issuer. app.ts is split into src/app.factory.ts so the integration tests drive the real middleware order rather than a copy of it. Tests: 131 unit, plus 41 integration tests against a throwaway MariaDB started by test/integration/setup.ts (docker or podman). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
92 lines
3.2 KiB
TypeScript
92 lines
3.2 KiB
TypeScript
import {vi, describe, it, expect, beforeEach, type Mock} from 'vitest';
|
|
|
|
vi.mock('../../src/models/admin/users/users.admin.service.js', () => ({
|
|
countActiveAdmins: vi.fn(),
|
|
findUserByEmail: vi.fn(),
|
|
grantPermission: vi.fn()
|
|
}));
|
|
vi.mock('../../src/models/admin/invitations/invitations.service.js', () => ({
|
|
hasOpenInvitationFor: vi.fn(),
|
|
createInvitation: vi.fn()
|
|
}));
|
|
vi.mock('../../src/models/admin/admin.mail.js', () => ({
|
|
sendInvitationMail: vi.fn()
|
|
}));
|
|
vi.mock('../../src/models/admin/admin.config.js', () => ({
|
|
ADMIN_BOOTSTRAP_EMAIL: 'boss@nachklang.art',
|
|
ADMIN_APP_URL: 'http://localhost:3002',
|
|
isProd: false
|
|
}));
|
|
|
|
import * as UsersService from '../../src/models/admin/users/users.admin.service.js';
|
|
import * as InvitationsService from '../../src/models/admin/invitations/invitations.service.js';
|
|
import {sendInvitationMail} from '../../src/models/admin/admin.mail.js';
|
|
import {bootstrapAdmin} from '../../src/models/admin/admin.bootstrap.js';
|
|
|
|
const countActiveAdmins = UsersService.countActiveAdmins as Mock;
|
|
const findUserByEmail = UsersService.findUserByEmail as Mock;
|
|
const grantPermission = UsersService.grantPermission as Mock;
|
|
const hasOpenInvitationFor = InvitationsService.hasOpenInvitationFor as Mock;
|
|
const createInvitation = InvitationsService.createInvitation as Mock;
|
|
const mockMail = sendInvitationMail as Mock;
|
|
|
|
beforeEach(() => {
|
|
countActiveAdmins.mockReset();
|
|
findUserByEmail.mockReset();
|
|
grantPermission.mockReset();
|
|
hasOpenInvitationFor.mockReset();
|
|
createInvitation.mockReset();
|
|
mockMail.mockReset();
|
|
mockMail.mockResolvedValue(true);
|
|
createInvitation.mockResolvedValue({id: 1, token: 'raw-token', expiresAt: new Date()});
|
|
});
|
|
|
|
describe('bootstrapAdmin', () => {
|
|
it('does nothing when an active admin already exists', async () => {
|
|
countActiveAdmins.mockResolvedValue(1);
|
|
|
|
await bootstrapAdmin();
|
|
|
|
expect(createInvitation).not.toHaveBeenCalled();
|
|
expect(grantPermission).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it('grants admin directly when the bootstrap address is already a user', async () => {
|
|
countActiveAdmins.mockResolvedValue(0);
|
|
findUserByEmail.mockResolvedValue({id: 'u9', email: 'boss@nachklang.art'});
|
|
|
|
await bootstrapAdmin();
|
|
|
|
expect(grantPermission).toHaveBeenCalledWith('u9', 'admin', null);
|
|
expect(createInvitation).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it('does not re-invite (or re-mail) while an open invitation exists', async () => {
|
|
countActiveAdmins.mockResolvedValue(0);
|
|
findUserByEmail.mockResolvedValue(null);
|
|
hasOpenInvitationFor.mockResolvedValue(true);
|
|
|
|
await bootstrapAdmin();
|
|
|
|
expect(createInvitation).not.toHaveBeenCalled();
|
|
expect(mockMail).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it('invites with the admin permission when there is nothing to work with', async () => {
|
|
countActiveAdmins.mockResolvedValue(0);
|
|
findUserByEmail.mockResolvedValue(null);
|
|
hasOpenInvitationFor.mockResolvedValue(false);
|
|
|
|
await bootstrapAdmin();
|
|
|
|
expect(createInvitation).toHaveBeenCalledWith('boss@nachklang.art', 'Nachklang Admin', ['admin'], null);
|
|
expect(mockMail).toHaveBeenCalled();
|
|
});
|
|
|
|
it('never throws when the database is unreachable at boot', async () => {
|
|
countActiveAdmins.mockRejectedValue(new Error('connect ECONNREFUSED'));
|
|
|
|
await expect(bootstrapAdmin()).resolves.toBeUndefined();
|
|
});
|
|
});
|