feat: enforce per-user module access in Makelore

This commit is contained in:
2026-08-17 08:51:15 +08:00
parent f7171a471a
commit d16922f18c
12 changed files with 457 additions and 35 deletions

View File

@@ -1,4 +1,4 @@
import { render, waitFor } from '@testing-library/react';
import { render, screen, waitFor } from '@testing-library/react';
import { beforeEach, describe, expect, it, vi } from 'vitest';
import { MemoryRouter, Outlet } from 'react-router-dom';
import App from '@/App';
@@ -23,6 +23,10 @@ vi.mock('@/pages/Chat', () => ({
Chat: () => <div>Programming workspace</div>,
}));
vi.mock('@/pages/ModuleSelection', () => ({
ModuleSelection: () => <div>Module chooser</div>,
}));
describe('App programming provider initialization gate', () => {
const initProviders = vi.fn();
@@ -45,6 +49,12 @@ describe('App programming provider initialization gate', () => {
deptId: null,
authorities: [],
},
moduleAccess: {
programming: true,
design: true,
learning: true,
robot: true,
},
init: vi.fn(),
});
useUserSyncStore.setState({ bootstrap: vi.fn().mockResolvedValue(undefined) });
@@ -73,4 +83,28 @@ describe('App programming provider initialization gate', () => {
await waitFor(() => expect(initProviders).toHaveBeenCalledTimes(1));
});
it.each([
['/opencode-chat', 'programming'],
['/image-canvas', 'design'],
['/learning', 'learning'],
['/ai-hardware', 'robot'],
] as const)('redirects disabled %s routes before mounting their module', async (pathname, accessKey) => {
useAuthStore.setState({
moduleAccess: {
programming: true,
design: true,
learning: true,
robot: true,
[accessKey]: false,
},
});
await renderAt(pathname);
expect(await screen.findByText('Module chooser')).toBeInTheDocument();
if (accessKey === 'programming') {
expect(initProviders).not.toHaveBeenCalled();
}
});
});