xpeditis2.0/apps/backend/src/application/services/notification.security.spec.ts
2026-09-14 11:19:29 +02:00

39 lines
1.8 KiB
TypeScript

import { NotificationService } from './notification.service';
import { NotificationRepository } from '@domain/ports/out/notification.repository';
import { TypeOrmNotificationRepository } from '@infrastructure/persistence/typeorm/repositories/typeorm-notification.repository';
import { NotificationOrmEntity } from '@infrastructure/persistence/typeorm/entities/notification.orm-entity';
import { Repository } from 'typeorm';
describe('notification mutation boundary', () => {
const owner = 'bd223f0d-89be-4f98-aaf4-0ab1353594e1';
const other = 'bd223f0d-89be-4f98-aaf4-0ab1353594e2';
const id = 'bd223f0d-89be-4f98-aaf4-0ab1353594e3';
it.each([{ read: false }, [], null, '', 'invalid'])(
'rejects malformed notification criteria %j',
async value => {
const markAsRead = jest.fn();
const service = new NotificationService({ markAsRead } as unknown as NotificationRepository);
await expect(service.markAsRead(value as unknown as string, owner)).rejects.toThrow();
expect(markAsRead).not.toHaveBeenCalled();
}
);
it('restricts an update to the authenticated recipient', async () => {
const row = { id, user_id: owner, read: false };
const update = jest.fn(async (criteria: { id: string; user_id: string }) => {
if (row.id === criteria.id && row.user_id === criteria.user_id) row.read = true;
});
const repository = new TypeOrmNotificationRepository({
update,
} as unknown as Repository<NotificationOrmEntity>);
const service = new NotificationService(repository);
await service.markAsRead(id, other);
expect(row.read).toBe(false);
expect(update).toHaveBeenLastCalledWith(
{ id, user_id: other },
expect.objectContaining({ read: true })
);
await service.markAsRead(id, owner);
expect(row.read).toBe(true);
});
});