68 lines
2.4 KiB
TypeScript
68 lines
2.4 KiB
TypeScript
import { ForbiddenException, NotFoundException } from '@nestjs/common';
|
|
import { Organization, OrganizationType } from '@domain/entities/organization.entity';
|
|
import { OrganizationRepository } from '@domain/ports/out/organization.repository';
|
|
import { UserRepository } from '@domain/ports/out/user.repository';
|
|
import { OrganizationsController } from './organizations.controller';
|
|
import { NotificationService } from '../services/notification.service';
|
|
import { UserPayload } from '../decorators/current-user.decorator';
|
|
|
|
describe('OrganizationsController tenant authorization', () => {
|
|
const actor = (role: string): UserPayload => ({
|
|
id: 'user-id',
|
|
email: 'manager@example.org',
|
|
role,
|
|
organizationId: 'own-org',
|
|
firstName: 'Test',
|
|
lastName: 'User',
|
|
});
|
|
const makeOrganization = (id: string) =>
|
|
Organization.create({
|
|
id,
|
|
name: 'Original',
|
|
type: OrganizationType.FREIGHT_FORWARDER,
|
|
address: { street: '1 rue Test', city: 'Paris', postalCode: '75001', country: 'FR' },
|
|
documents: [],
|
|
isActive: true,
|
|
});
|
|
const findById = jest.fn();
|
|
const save = jest.fn(async (organization: Organization) => organization);
|
|
const controller = new OrganizationsController(
|
|
{ findById, save } as unknown as OrganizationRepository,
|
|
{} as UserRepository,
|
|
{} as NotificationService
|
|
);
|
|
|
|
beforeEach(() => jest.clearAllMocks());
|
|
|
|
it.each(['MANAGER', 'manager', 'USER', 'VIEWER'])(
|
|
'rejects foreign organization for %s',
|
|
async role => {
|
|
const target = makeOrganization('other-org');
|
|
findById.mockResolvedValue(target);
|
|
await expect(
|
|
controller.updateOrganization(target.id, { name: 'Changed' }, actor(role))
|
|
).rejects.toBeInstanceOf(ForbiddenException);
|
|
expect(target.name).toBe('Original');
|
|
expect(save).not.toHaveBeenCalled();
|
|
}
|
|
);
|
|
|
|
it.each([
|
|
['MANAGER', 'own-org'],
|
|
['ADMIN', 'other-org'],
|
|
])('allows %s to update %s', async (role, id) => {
|
|
findById.mockResolvedValue(makeOrganization(id));
|
|
const result = await controller.updateOrganization(id, { name: 'Changed' }, actor(role));
|
|
expect(result.name).toBe('Changed');
|
|
expect(save).toHaveBeenCalledTimes(1);
|
|
});
|
|
|
|
it('preserves missing organization response', async () => {
|
|
findById.mockResolvedValue(null);
|
|
await expect(
|
|
controller.updateOrganization('missing', {}, actor('ADMIN'))
|
|
).rejects.toBeInstanceOf(NotFoundException);
|
|
expect(save).not.toHaveBeenCalled();
|
|
});
|
|
});
|