fix(frontend): restrict management controls to admins
This commit is contained in:
@@ -22,9 +22,9 @@ beforeEach(() => {
|
||||
setAuthState({
|
||||
issuer: "test",
|
||||
subject: "test",
|
||||
roles: ["user"],
|
||||
permissions: ["session.use", "workspace.manage"],
|
||||
isAdmin: false,
|
||||
roles: ["admin"],
|
||||
permissions: ["session.use", "workspace.manage", "workspace.secrets.manage", "pi.manage"],
|
||||
isAdmin: true,
|
||||
csrfToken: null,
|
||||
session: null,
|
||||
});
|
||||
@@ -37,7 +37,7 @@ beforeEach(() => {
|
||||
issuer: "test",
|
||||
subject: "test",
|
||||
displayName: "Test",
|
||||
isAdmin: false,
|
||||
isAdmin: true,
|
||||
})),
|
||||
http.get("/api/sessions", () => HttpResponse.json([])),
|
||||
http.get("/api/settings", () => HttpResponse.json({
|
||||
@@ -122,7 +122,7 @@ test("keeps a live core session connected and returns when that session is opene
|
||||
expect(FakeEventSource.instances).toHaveLength(1);
|
||||
});
|
||||
|
||||
test("shows database management entry to authenticated users without workspace management permission", () => {
|
||||
test("hides all management entries from non-admin users", () => {
|
||||
clearAuthState();
|
||||
setAuthState({
|
||||
issuer: "test",
|
||||
@@ -136,5 +136,7 @@ test("shows database management entry to authenticated users without workspace m
|
||||
|
||||
renderShell();
|
||||
|
||||
expect(screen.getByRole("button", { name: "Database management" })).toBeInTheDocument();
|
||||
expect(screen.queryByRole("button", { name: "Workspace management" })).not.toBeInTheDocument();
|
||||
expect(screen.queryByRole("button", { name: "Database management" })).not.toBeInTheDocument();
|
||||
expect(screen.queryByRole("button", { name: "Pi management" })).not.toBeInTheDocument();
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user