Something went wrong. Try again.
[READ-ONLY] Mirror of https://github.com/openstatusHQ/openstatus. ๐ซ Status page with uptime monitoring & API monitoring as code ๐ซ openstatus.dev
bun drizzle-orm monitoring monitoring-as-code nextjs observability on-call open-source shadcn-ui status-page statuspage synthetic-monitoring tinybird turso uptime uptime-checker uptime-monitor
Something went wrong. Try again.
TypeScript
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108import { expect } from "@std/expect";import { describe, test } from "@std/testing/bdd";
import type { Actor, ServiceContext } from "../../context";import { ForbiddenError } from "../../errors";import { requireScope } from "../require-scope";
const workspace = { id: 1, name: "test", slug: "test",} as unknown as ServiceContext["workspace"];
function makeCtx(actor: Actor): ServiceContext { return { workspace, actor };}
describe("requireScope", () => { test("read-only apiKey + 'write' requirement โ ForbiddenError", () => { const ctx = makeCtx({ type: "apiKey", keyId: "k1", scopes: ["read"], }); expect(() => requireScope(ctx, "write")).toThrow(ForbiddenError); });
test("read-only apiKey + 'read' requirement โ passes", () => { const ctx = makeCtx({ type: "apiKey", keyId: "k1", scopes: ["read"], }); expect(() => requireScope(ctx, "read")).not.toThrow(); });
test("write apiKey passes 'read' and 'write'", () => { const ctx = makeCtx({ type: "apiKey", keyId: "k1", scopes: ["write"], }); expect(() => requireScope(ctx, "read")).not.toThrow(); expect(() => requireScope(ctx, "write")).not.toThrow(); });
test("super-admin '*' apiKey passes any required", () => { const ctx = makeCtx({ type: "apiKey", keyId: "k1", scopes: ["*"], }); expect(() => requireScope(ctx, "read")).not.toThrow(); expect(() => requireScope(ctx, "write")).not.toThrow(); });
test("read-only mcp actor enforced same as apiKey", () => { const ctx = makeCtx({ type: "mcp", keyId: "k1", scopes: ["read"], }); expect(() => requireScope(ctx, "write")).toThrow(ForbiddenError); expect(() => requireScope(ctx, "read")).not.toThrow(); });
test("user actor is no-op (member-role enforcement is a separate project)", () => { const ctx = makeCtx({ type: "user", userId: 42 }); expect(() => requireScope(ctx, "write")).not.toThrow(); expect(() => requireScope(ctx, "read")).not.toThrow(); });
test("system actor is no-op", () => { const ctx = makeCtx({ type: "system", job: "checker" }); expect(() => requireScope(ctx, "write")).not.toThrow(); });
test("slack actor is no-op", () => { const ctx = makeCtx({ type: "slack", teamId: "T1", slackUserId: "U1", userId: 1, }); expect(() => requireScope(ctx, "write")).not.toThrow(); });
test("webhook actor is no-op", () => { const ctx = makeCtx({ type: "webhook", source: "stripe" }); expect(() => requireScope(ctx, "write")).not.toThrow(); });
test("subscriber actor is no-op", () => { const ctx = makeCtx({ type: "subscriber", subscriberId: 7 }); expect(() => requireScope(ctx, "write")).not.toThrow(); });
test("apiKey with empty scopes fails closed", () => { const ctx = makeCtx({ type: "apiKey", keyId: "k1", scopes: [], }); expect(() => requireScope(ctx, "read")).toThrow(ForbiddenError); expect(() => requireScope(ctx, "write")).toThrow(ForbiddenError); });});