package services import "testing" /* `app_users` keeps identity and authorisation in one table, so a self-service profile form is one careless `Updates(&struct)` away from letting a branch user promote themselves. `PUT /users/update` already writes whatever it is handed and checks only `userid` — no tenant, no role guard — which is precisely why the store user's account page has been read-only rather than editable. */ func TestAPersonCannotPromoteOrMoveThemselves(t *testing.T) { clean, err := OwnProfileUpdate(map[string]any{ "firstname": "Suriya", "roleid": 1, "locationid": 1166, "tenantid": 9, "status": "Active", "password": "hunter2", "pin": 1234, }) if err != nil { t.Fatalf("OwnProfileUpdate: %v", err) } for _, forbidden := range []string{"roleid", "locationid", "tenantid", "status", "password", "pin"} { if _, present := clean[forbidden]; present { t.Errorf("%q survived the allowlist", forbidden) } } if clean["firstname"] != "Suriya" { t.Errorf("the legitimate change was dropped: %+v", clean) } } func TestARequestOfNothingButPrivilegeIsRefused(t *testing.T) { if _, err := OwnProfileUpdate(map[string]any{"roleid": 1, "status": "Active"}); err == nil { t.Fatal("a request that changes only privilege was accepted") } } // A form sends every field it renders. If blank meant erase, saving one change // would wipe the mobile number nobody touched. func TestABlankDoesNotEraseAField(t *testing.T) { clean, err := OwnProfileUpdate(map[string]any{"firstname": "Suriya", "contactno": " "}) if err != nil { t.Fatalf("OwnProfileUpdate: %v", err) } if _, present := clean["contactno"]; present { t.Error("a whitespace-only value was treated as a change") } }