|
| 1 | +import { |
| 2 | + Permission, |
| 3 | + AuthActionVerb, |
| 4 | + AuthPossession, |
| 5 | + PermissionData, |
| 6 | + AuthZGuard, |
| 7 | + BatchApproval |
| 8 | +} from '../src'; |
| 9 | + |
| 10 | +describe('@AuthZGuard()', () => { |
| 11 | + const policies = [ |
| 12 | + ['user1', 'resourceType1', 'id1', AuthActionVerb.READ], |
| 13 | + ['user1', 'resourceType1', 'id2', AuthActionVerb.READ], |
| 14 | + ['user1', 'resourceType1', 'id3', AuthActionVerb.READ], |
| 15 | + ['user2', 'resourceType1', 'id1', AuthActionVerb.READ], |
| 16 | + ['user2', 'resourceType1', 'id3', AuthActionVerb.READ], |
| 17 | + ]; |
| 18 | + |
| 19 | + const mockEnforcer: any = { |
| 20 | + enforce: (userId: string, resource: any, action: string) => { |
| 21 | + return policies.some((p) => p[0] === userId && p[1] === resource.type && p[2] === resource.id && p[3] === action); |
| 22 | + }, |
| 23 | + batchEnforce: (checks: string[][]) => { |
| 24 | + return checks.map((res: any) => { |
| 25 | + return policies.some((p) => p[0] === res[0] && p[1] === res[1].type && p[2] === res[1].id && p[3] === res[2]) |
| 26 | + }); |
| 27 | + }, |
| 28 | + }; |
| 29 | + |
| 30 | + const mockOptions: any = { |
| 31 | + userFromContext: (ctx: any) => ctx.user.id, |
| 32 | + } |
| 33 | + |
| 34 | + const getMockContext = (user: string, resources: any): any => ({ |
| 35 | + getHandler: () => null, |
| 36 | + data: {id: resources}, |
| 37 | + user: {id: user} |
| 38 | + }); |
| 39 | + |
| 40 | + const getMockReflector = (permissions: Permission[]): any => ({ |
| 41 | + get: (meta: any, handler: any) => permissions, |
| 42 | + }); |
| 43 | + |
| 44 | + it('should enforce specific resource', async () => { |
| 45 | + const permission: Permission[] = [ |
| 46 | + { |
| 47 | + resource: 'resourceType1', |
| 48 | + action: AuthActionVerb.READ, |
| 49 | + resourceFromContext: (ctx: any, perm: PermissionData) => ({type: perm.resource, id: ctx.data.id}) |
| 50 | + }, |
| 51 | + ]; |
| 52 | + |
| 53 | + const guard = new AuthZGuard(getMockReflector(permission), mockEnforcer, mockOptions); |
| 54 | + |
| 55 | + expect(guard.canActivate(getMockContext('user1', 'id1'))).resolves.toEqual(true); |
| 56 | + expect(guard.canActivate(getMockContext('user2', 'id1'))).resolves.toEqual(true); |
| 57 | + expect(guard.canActivate(getMockContext('user2', 'id2'))).resolves.toEqual(false); |
| 58 | + }); |
| 59 | + |
| 60 | + it('should batch enforce ALL specific resources', async () => { |
| 61 | + const permission2: Permission[] = [ |
| 62 | + { |
| 63 | + resource: 'resourceType1', |
| 64 | + action: AuthActionVerb.READ, |
| 65 | + resourceFromContext: (ctx: any, perm: PermissionData) => { |
| 66 | + return ctx.data.id.map((id: string) => ({type: perm.resource, id})) |
| 67 | + } |
| 68 | + }, |
| 69 | + ]; |
| 70 | + |
| 71 | + const guard = new AuthZGuard(getMockReflector(permission2), mockEnforcer, mockOptions); |
| 72 | + |
| 73 | + expect(guard.canActivate(getMockContext('user1', ['id1', 'id2', 'id3']))).resolves.toEqual(true); |
| 74 | + expect(guard.canActivate(getMockContext('user2', ['id1', 'id3']))).resolves.toEqual(true); |
| 75 | + expect(guard.canActivate(getMockContext('user2', ['id1', 'id2', 'id3']))).resolves.toEqual(false); |
| 76 | + }); |
| 77 | + |
| 78 | + it('should batch enforce ANY specific resources', async () => { |
| 79 | + const permission2: Permission[] = [ |
| 80 | + { |
| 81 | + resource: 'resourceType1', |
| 82 | + action: AuthActionVerb.READ, |
| 83 | + resourceFromContext: (ctx: any, perm: PermissionData) => { |
| 84 | + return ctx.data.id.map((id: string) => ({type: perm.resource, id})) |
| 85 | + }, |
| 86 | + batchApproval: BatchApproval.ANY, |
| 87 | + }, |
| 88 | + ]; |
| 89 | + |
| 90 | + const guard = new AuthZGuard(getMockReflector(permission2), mockEnforcer, mockOptions); |
| 91 | + |
| 92 | + expect(guard.canActivate(getMockContext('user2', ['id1', 'id2', 'id3']))).resolves.toEqual(true); |
| 93 | + }); |
| 94 | +}); |
0 commit comments