role id solved
This commit is contained in:
58
src/auth/roles.test.ts
Normal file
58
src/auth/roles.test.ts
Normal file
@@ -0,0 +1,58 @@
|
||||
/**
|
||||
* Which workspace a roleid lands in — and the one that has been mislabelled on
|
||||
* every shop since the platform started.
|
||||
*
|
||||
* `app_roles` calls roleid 1 "Super admin", and tenant onboarding wrote 1 for a
|
||||
* merchant's own administrator. So every shop's Users & access screen listed
|
||||
* its owner as a platform operator. It never WAS one — platform access is
|
||||
* `app_users.issuperadmin`, a separate column checked first — but the label is
|
||||
* the sort of thing somebody eventually acts on.
|
||||
*
|
||||
* New tenants get roleid 3 ("Admin"). Existing ones keep 1, and must keep
|
||||
* working: nine shops were provisioned with it.
|
||||
*/
|
||||
import assert from 'node:assert/strict';
|
||||
import { test } from 'node:test';
|
||||
import { resolveRole } from './roles';
|
||||
|
||||
test('platform access comes from issuperadmin, never from a roleid', () => {
|
||||
assert.equal(resolveRole({ roleid: 0, issuperadmin: true }), 'nearle-admin');
|
||||
// The point of the whole fix: roleid 1 is a merchant, not a platform operator.
|
||||
assert.equal(resolveRole({ roleid: 1, issuperadmin: false }), 'store-admin');
|
||||
});
|
||||
|
||||
test('a merchant administrator reaches the Store Admin workspace', () => {
|
||||
// 3 is what new tenants get; 1 is what every existing tenant has.
|
||||
assert.equal(resolveRole({ roleid: 3, issuperadmin: false }), 'store-admin');
|
||||
assert.equal(resolveRole({ roleid: 1, issuperadmin: false }), 'store-admin');
|
||||
});
|
||||
|
||||
/*
|
||||
Existing merchants must not be locked out. Nine shops were provisioned with
|
||||
roleid 1 before this changed, and dropping it from the store-admin set would
|
||||
shut every one of their owners out of their own console.
|
||||
*/
|
||||
test('roleid 1 keeps working, so no existing merchant is locked out', () => {
|
||||
assert.notEqual(resolveRole({ roleid: 1, issuperadmin: false }), 'store-manager');
|
||||
});
|
||||
|
||||
test('a manager is pinned to one shop', () => {
|
||||
// 4 is "Manager" in app_roles, and what the old console gave rmartuser.
|
||||
assert.equal(resolveRole({ roleid: 4, issuperadmin: false }), 'store-manager');
|
||||
});
|
||||
|
||||
// The auto-spawned branch login carries roleid 0 — Go's zero value, and the
|
||||
// branch-user role. It must land in the shop workspace, not the merchant's.
|
||||
test('the branch login lands in the store workspace', () => {
|
||||
assert.equal(resolveRole({ roleid: 0, issuperadmin: false }), 'store-manager');
|
||||
});
|
||||
|
||||
/*
|
||||
Till accounts must never reach a back-office workspace. They are excluded in the
|
||||
backend's queries too — a cashier is "not found" rather than "refused" — but a
|
||||
roleid arriving from anywhere else must not resolve upward.
|
||||
*/
|
||||
test('till roles never resolve to a merchant workspace', () => {
|
||||
assert.equal(resolveRole({ roleid: 7, issuperadmin: false }), 'store-manager');
|
||||
assert.equal(resolveRole({ roleid: 8, issuperadmin: false }), 'store-manager');
|
||||
});
|
||||
@@ -182,7 +182,6 @@ function Problem({ message }: { message: string }) {
|
||||
const STAFF_ROLES = [
|
||||
{ id: 3, label: 'Administrator — runs the whole business' },
|
||||
{ id: 4, label: 'Manager — one shop' },
|
||||
{ id: 5, label: 'Staff — one shop' },
|
||||
];
|
||||
|
||||
export function PersonDrawer({
|
||||
|
||||
Reference in New Issue
Block a user