feat: harden data access and simplify user management
This commit is contained in:
1 parent
3dd5731751
commit
adb780bc82
51 files changed
+3239
-2121
No files matched your search
@@ -0,0 +1,43 @@
|
||||
import assert from "node:assert/strict";
|
||||
import { readFileSync } from "node:fs";
|
||||
import test from "node:test";
|
||||
|
||||
const appSource = readFileSync(new URL("../src/App.tsx", import.meta.url), "utf8");
|
||||
const panelSource = readFileSync(
|
||||
new URL("../src/panels/system/UserManagement.tsx", import.meta.url),
|
||||
"utf8",
|
||||
);
|
||||
const apiSource = readFileSync(new URL("../src/api.ts", import.meta.url), "utf8");
|
||||
const dataCenterSource = readFileSync(
|
||||
new URL("../src/panels/data-platform/DataCenterPanel.tsx", import.meta.url),
|
||||
"utf8",
|
||||
);
|
||||
|
||||
test("System keeps one focused user-management page", () => {
|
||||
assert.match(appSource, /key: "\/system\/users"[\s\S]*label: "用户管理"/);
|
||||
assert.match(appSource, /path="\/admin\/system\/users"/);
|
||||
for (const path of ["agents", "logs", "permissions"]) {
|
||||
assert.doesNotMatch(appSource, new RegExp(`/admin/system/${path}`));
|
||||
}
|
||||
});
|
||||
|
||||
test("User management exposes exactly two understandable data permissions", () => {
|
||||
for (const label of ["数据管理", "数据查看", "仅可查看和导出数据", "不能进行任何写入"]) {
|
||||
assert.match(panelSource, new RegExp(label));
|
||||
}
|
||||
assert.match(panelSource, /type DataPermission = "data_manage" \| "data_view"/);
|
||||
assert.doesNotMatch(panelSource, /listRoles|角色|权限矩阵|新增能力项|deleteUser/);
|
||||
});
|
||||
|
||||
test("User removal is replaced by reversible account disabling", () => {
|
||||
assert.match(panelSource, /确认停用该用户/);
|
||||
assert.match(panelSource, /立即失去登录权限/);
|
||||
assert.doesNotMatch(apiSource, /api\.delete\(`\/users/);
|
||||
});
|
||||
|
||||
test("Data-view accounts receive a read-only data-center surface", () => {
|
||||
assert.match(appSource, /<DataCenterPanel canManage=\{isDataManager\}/);
|
||||
assert.match(dataCenterSource, /!canManage[\s\S]*\? "只读权限"/);
|
||||
assert.match(dataCenterSource, /canManage && \(/);
|
||||
assert.match(dataCenterSource, /const canEdit = canManage && field\.editable/);
|
||||
});
|
||||
Reference in new issue
Block a user