guide changes
This commit is contained in:
54
services/ownProfile_test.go
Normal file
54
services/ownProfile_test.go
Normal file
@@ -0,0 +1,54 @@
|
||||
package services
|
||||
|
||||
import "testing"
|
||||
|
||||
/*
|
||||
`app_users` keeps identity and authorisation in one table, so a self-service
|
||||
profile form is one careless `Updates(&struct)` away from letting a branch user
|
||||
promote themselves.
|
||||
|
||||
`PUT /users/update` already writes whatever it is handed and checks only
|
||||
`userid` — no tenant, no role guard — which is precisely why the store user's
|
||||
account page has been read-only rather than editable.
|
||||
*/
|
||||
|
||||
func TestAPersonCannotPromoteOrMoveThemselves(t *testing.T) {
|
||||
clean, err := OwnProfileUpdate(map[string]any{
|
||||
"firstname": "Suriya",
|
||||
"roleid": 1,
|
||||
"locationid": 1166,
|
||||
"tenantid": 9,
|
||||
"status": "Active",
|
||||
"password": "hunter2",
|
||||
"pin": 1234,
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("OwnProfileUpdate: %v", err)
|
||||
}
|
||||
for _, forbidden := range []string{"roleid", "locationid", "tenantid", "status", "password", "pin"} {
|
||||
if _, present := clean[forbidden]; present {
|
||||
t.Errorf("%q survived the allowlist", forbidden)
|
||||
}
|
||||
}
|
||||
if clean["firstname"] != "Suriya" {
|
||||
t.Errorf("the legitimate change was dropped: %+v", clean)
|
||||
}
|
||||
}
|
||||
|
||||
func TestARequestOfNothingButPrivilegeIsRefused(t *testing.T) {
|
||||
if _, err := OwnProfileUpdate(map[string]any{"roleid": 1, "status": "Active"}); err == nil {
|
||||
t.Fatal("a request that changes only privilege was accepted")
|
||||
}
|
||||
}
|
||||
|
||||
// A form sends every field it renders. If blank meant erase, saving one change
|
||||
// would wipe the mobile number nobody touched.
|
||||
func TestABlankDoesNotEraseAField(t *testing.T) {
|
||||
clean, err := OwnProfileUpdate(map[string]any{"firstname": "Suriya", "contactno": " "})
|
||||
if err != nil {
|
||||
t.Fatalf("OwnProfileUpdate: %v", err)
|
||||
}
|
||||
if _, present := clean["contactno"]; present {
|
||||
t.Error("a whitespace-only value was treated as a change")
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user