profile name change
This commit is contained in:
@@ -130,3 +130,39 @@ func TestAllowingTheShopTypeDidNotAllowItsStanding(t *testing.T) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// The person who runs the shop.
|
||||
//
|
||||
// `tenants.firstname` was collected by no form and permitted by no allowlist,
|
||||
// so every merchant read came back with it empty and the store profile printed
|
||||
// "—" for Store admin. It is the business's own contact person, not its
|
||||
// standing on the platform.
|
||||
func TestTenantProfileUpdateAllowsStoreAdmin(t *testing.T) {
|
||||
clean, err := TenantProfileUpdate(map[string]any{
|
||||
"tenantid": 1147,
|
||||
"firstname": "Ravi Kumar",
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("TenantProfileUpdate: %v", err)
|
||||
}
|
||||
if clean["firstname"] != "Ravi Kumar" {
|
||||
t.Fatalf("firstname should survive the allowlist, got %v", clean["firstname"])
|
||||
}
|
||||
if _, ok := clean["tenantid"]; ok {
|
||||
t.Fatal("tenantid names the row and is never a value to write")
|
||||
}
|
||||
}
|
||||
|
||||
// The guard that makes the allowlist worth having: a merchant must not be able
|
||||
// to approve themselves or move under another partner by sending the field.
|
||||
func TestTenantProfileUpdateStillRefusesPlatformFields(t *testing.T) {
|
||||
_, err := TenantProfileUpdate(map[string]any{
|
||||
"tenantid": 1147,
|
||||
"approved": 1,
|
||||
"partnerid": 9,
|
||||
"status": "Active",
|
||||
})
|
||||
if err == nil {
|
||||
t.Fatal("nothing in that request is editable, so it must not report success")
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user