feat(frontend): expose owned session scopes
This commit is contained in:
@@ -54,6 +54,9 @@ beforeEach(() => {
|
||||
window.matchMedia = vi.fn().mockReturnValue({ matches: true, addEventListener: vi.fn(), removeEventListener: vi.fn() });
|
||||
useSessionStore.getState().resetSession();
|
||||
server.use(
|
||||
http.get("http://localhost:8787/me", () =>
|
||||
HttpResponse.json({ issuer: "portal", subject: "alice", displayName: "Alice", isAdmin: false }),
|
||||
),
|
||||
http.get("http://localhost:8787/sessions", () => HttpResponse.json(LIST)),
|
||||
http.get("http://localhost:8787/sessions/:id/documents", () => HttpResponse.json([
|
||||
{ phase: "—", key: "question", title: "Domanda originale", format: "text", content: "Attiva uno" },
|
||||
@@ -62,6 +65,91 @@ beforeEach(() => {
|
||||
);
|
||||
});
|
||||
|
||||
test("regular users load only their sessions and never see administrator controls", async () => {
|
||||
let scope: string | null = null;
|
||||
server.use(http.get("http://localhost:8787/sessions", ({ request }) => {
|
||||
scope = new URL(request.url).searchParams.get("scope");
|
||||
return HttpResponse.json(LIST);
|
||||
}));
|
||||
wrap();
|
||||
await screen.findByText("Attiva uno");
|
||||
expect(scope).toBe("mine");
|
||||
expect(screen.queryByRole("button", { name: "All sessions" })).not.toBeInTheDocument();
|
||||
expect(screen.queryByText(/administrator view/i)).not.toBeInTheDocument();
|
||||
});
|
||||
|
||||
test("administrators can explicitly switch to all sessions and see owners", async () => {
|
||||
let scope = "";
|
||||
server.use(
|
||||
http.get("http://localhost:8787/me", () =>
|
||||
HttpResponse.json({ issuer: "portal", subject: "alice", displayName: "Alice", isAdmin: true }),
|
||||
),
|
||||
http.get("http://localhost:8787/sessions", ({ request }) => {
|
||||
scope = new URL(request.url).searchParams.get("scope") ?? "";
|
||||
return HttpResponse.json([
|
||||
{ ...LIST[0], author: "Alice" },
|
||||
{ ...LIST[1], id: "s3", question: "Another owner's session", archived: false, author: "Bob" },
|
||||
]);
|
||||
}),
|
||||
);
|
||||
wrap();
|
||||
await screen.findByRole("button", { name: "All sessions" });
|
||||
await userEvent.click(screen.getByRole("button", { name: "All sessions" }));
|
||||
await waitFor(() => expect(scope).toBe("all"));
|
||||
expect(await screen.findByText("Administrator view: all sessions")).toBeInTheDocument();
|
||||
expect(screen.getByText("Owner: Bob")).toBeInTheDocument();
|
||||
});
|
||||
|
||||
test("administrator confirms before deleting another owner's session", async () => {
|
||||
let deletes = 0;
|
||||
server.use(
|
||||
http.get("http://localhost:8787/me", () =>
|
||||
HttpResponse.json({ issuer: "portal", subject: "alice", displayName: "Alice", isAdmin: true }),
|
||||
),
|
||||
http.get("http://localhost:8787/sessions", () => HttpResponse.json([
|
||||
{ ...LIST[0], author: "Bob" },
|
||||
])),
|
||||
http.delete("http://localhost:8787/sessions/:id", () => {
|
||||
deletes += 1;
|
||||
return new HttpResponse(null, { status: 204 });
|
||||
}),
|
||||
);
|
||||
wrap();
|
||||
await userEvent.click(await screen.findByRole("button", { name: "All sessions" }));
|
||||
await screen.findByText("Owner: Bob");
|
||||
await userEvent.click(screen.getByRole("checkbox", { name: "Select Attiva uno" }));
|
||||
await userEvent.click(screen.getByRole("button", { name: "Delete 1 selected sessions" }));
|
||||
expect(deletes).toBe(0);
|
||||
expect(await screen.findByRole("heading", { name: "Delete permanently" })).toBeInTheDocument();
|
||||
await userEvent.click(screen.getByRole("button", { name: "Delete" }));
|
||||
await waitFor(() => expect(deletes).toBe(1));
|
||||
});
|
||||
|
||||
test("administrator confirms before archiving another owner's session", async () => {
|
||||
let archives = 0;
|
||||
const confirm = vi.spyOn(window, "confirm").mockReturnValue(false);
|
||||
server.use(
|
||||
http.get("http://localhost:8787/me", () =>
|
||||
HttpResponse.json({ issuer: "portal", subject: "alice", displayName: "Alice", isAdmin: true }),
|
||||
),
|
||||
http.get("http://localhost:8787/sessions", () => HttpResponse.json([
|
||||
{ ...LIST[0], author: "Bob" },
|
||||
])),
|
||||
http.post("http://localhost:8787/sessions/:id/archive", () => {
|
||||
archives += 1;
|
||||
return new HttpResponse(null, { status: 204 });
|
||||
}),
|
||||
);
|
||||
wrap();
|
||||
await userEvent.click(await screen.findByRole("button", { name: "All sessions" }));
|
||||
await screen.findByText("Owner: Bob");
|
||||
await userEvent.click(screen.getByRole("button", { name: "Session actions" }));
|
||||
await userEvent.click(await screen.findByText("Archive"));
|
||||
expect(confirm).toHaveBeenCalledWith("Archive Bob's session?");
|
||||
expect(archives).toBe(0);
|
||||
confirm.mockRestore();
|
||||
});
|
||||
|
||||
test("active list shows group header and hides archived sessions", async () => {
|
||||
wrap();
|
||||
expect(await screen.findByText("Attiva uno")).toBeInTheDocument();
|
||||
|
||||
Reference in New Issue
Block a user