feat(M02-C): 建立RBAC与门店数据范围
This commit is contained in:
@@ -0,0 +1,31 @@
|
||||
import assert from 'node:assert/strict';
|
||||
import { RbacRepository, roleCodes } from '../dist/auth/rbac-repository.js';
|
||||
|
||||
assert.deepEqual(roleCodes, [
|
||||
'CUSTOMER', 'CLEANER', 'STAFF', 'STORE_ADMIN', 'TENANT_ADMIN', 'PLATFORM_ADMIN'
|
||||
]);
|
||||
|
||||
const calls = [];
|
||||
const repository = new RbacRepository({
|
||||
async execute(sql, params) {
|
||||
calls.push([sql, params]);
|
||||
if (sql.includes('SELECT DISTINCT r.code')) return [[{ code: 'CUSTOMER' }], []];
|
||||
if (sql.includes('SELECT DISTINCT p.code')) {
|
||||
return [[{ code: 'order.self.read' }, { code: 'profile.read' }], []];
|
||||
}
|
||||
if (sql.includes('SELECT DISTINCT store_id')) return [[{ storeId: 11 }], []];
|
||||
return [{ affectedRows: 1 }, []];
|
||||
}
|
||||
});
|
||||
assert.deepEqual(await repository.getAccessProfile('7', '21'), {
|
||||
roles: ['CUSTOMER'],
|
||||
capabilities: ['order.self.read', 'profile.read'],
|
||||
storeIds: ['11']
|
||||
});
|
||||
assert.equal(await repository.grantStore({
|
||||
tenantId: '7', userId: '21', storeId: '11', scopeType: 'STAFF'
|
||||
}), true);
|
||||
assert.match(calls.at(-1)[0], /s\.tenant_id = \?/);
|
||||
assert.match(calls.at(-1)[0], /u\.tenant_id = \?/);
|
||||
|
||||
console.log('PASS: M02-C roles, capabilities and tenant-scoped store grants are present.');
|
||||
Reference in New Issue
Block a user