74 lines
2.2 KiB
Go
74 lines
2.2 KiB
Go
package access
|
|
|
|
import "testing"
|
|
|
|
func TestPurchaserPermissionMatrixHasNoDuplicates(t *testing.T) {
|
|
seen := map[string]bool{}
|
|
for _, permission := range AdminAPIs {
|
|
key := permission.Method + " " + permission.Path
|
|
if seen[key] {
|
|
t.Fatalf("duplicate API permission: %s", key)
|
|
}
|
|
seen[key] = true
|
|
}
|
|
}
|
|
|
|
func TestPurchaserExcludesAdministratorOperations(t *testing.T) {
|
|
denied := map[string]bool{
|
|
"POST /api/admin/v1/devices/:deviceId/disable": true,
|
|
"POST /api/admin/v1/syb-products/import": true,
|
|
"POST /api/admin/v1/collection-rules": true,
|
|
"PUT /api/admin/v1/ai-matching-settings": true,
|
|
}
|
|
for _, permission := range PurchaserAPIs() {
|
|
if denied[permission.Method+" "+permission.Path] {
|
|
t.Fatalf("administrator-only API granted to purchaser: %s %s", permission.Method, permission.Path)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestPurchaserMayOnlyReadReplacementAudit(t *testing.T) {
|
|
want := map[string]bool{
|
|
"GET /api/admin/v1/pdd-product-replacements": false,
|
|
"GET /api/admin/v1/pdd-product-replacements/:replacementId": false,
|
|
}
|
|
for _, permission := range PurchaserAPIs() {
|
|
key := permission.Method + " " + permission.Path
|
|
if _, ok := want[key]; ok {
|
|
want[key] = true
|
|
}
|
|
}
|
|
for permission, found := range want {
|
|
if !found {
|
|
t.Fatalf("missing purchaser replacement audit permission: %s", permission)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestPurchaserMayCreateStockPurchase(t *testing.T) {
|
|
for _, permission := range PurchaserAPIs() {
|
|
if permission.Method == "POST" && permission.Path == "/api/admin/v1/purchase-tasks/stock" {
|
|
return
|
|
}
|
|
}
|
|
t.Fatal("missing purchaser stock purchase permission")
|
|
}
|
|
|
|
func TestPurchaserMayRunBatchSpecMatch(t *testing.T) {
|
|
for _, permission := range PurchaserAPIs() {
|
|
if permission.Method == "POST" && permission.Path == "/api/admin/v1/purchase-tasks/batch-spec-match" {
|
|
return
|
|
}
|
|
}
|
|
t.Fatal("missing purchaser batch spec match permission")
|
|
}
|
|
|
|
func TestPurchaserMayAutoMatchShopeeProductSpecs(t *testing.T) {
|
|
for _, permission := range PurchaserAPIs() {
|
|
if permission.Method == "POST" && permission.Path == "/api/admin/v1/shopee-products/:productId/specs/mapping/auto-match" {
|
|
return
|
|
}
|
|
}
|
|
t.Fatal("missing purchaser shopee auto-match permission")
|
|
}
|