fix(frontend): harden owner action confirmation

This commit is contained in:
User
2026-07-16 18:51:02 +02:00
parent 58e0884df1
commit c6a74c9ccb
3 changed files with 32 additions and 11 deletions
@@ -82,7 +82,7 @@ test("administrators can explicitly switch to all sessions and see owners", asyn
let scope = "";
server.use(
http.get("http://localhost:8787/me", () =>
HttpResponse.json({ issuer: "portal", subject: "alice", displayName: "Alice", isAdmin: true }),
HttpResponse.json({ issuer: "portal", subject: "alice-id", displayName: "Alice", isAdmin: true }),
),
http.get("http://localhost:8787/sessions", ({ request }) => {
scope = new URL(request.url).searchParams.get("scope") ?? "";
@@ -94,20 +94,25 @@ test("administrators can explicitly switch to all sessions and see owners", asyn
);
wrap();
await screen.findByRole("button", { name: "All sessions" });
expect(screen.getByRole("button", { name: "My sessions" })).toHaveAttribute("aria-pressed", "true");
expect(screen.getByRole("button", { name: "All sessions" })).toHaveAttribute("aria-pressed", "false");
await userEvent.click(screen.getByRole("button", { name: "All sessions" }));
await waitFor(() => expect(scope).toBe("all"));
expect(screen.getByRole("button", { name: "My sessions" })).toHaveAttribute("aria-pressed", "false");
expect(screen.getByRole("button", { name: "All sessions" })).toHaveAttribute("aria-pressed", "true");
expect(await screen.findByText("Administrator view: all sessions")).toBeInTheDocument();
expect(screen.getByText("Owner: Bob")).toBeInTheDocument();
});
test("administrator confirms before deleting another owner's session", async () => {
test("administrator confirms before deleting a same-named user's session", async () => {
let deletes = 0;
server.use(
http.get("http://localhost:8787/me", () =>
HttpResponse.json({ issuer: "portal", subject: "alice", displayName: "Alice", isAdmin: true }),
HttpResponse.json({ issuer: "portal", subject: "alice-id", displayName: "Alice", isAdmin: true }),
),
http.get("http://localhost:8787/sessions", () => HttpResponse.json([
{ ...LIST[0], author: "Bob" },
{ ...LIST[0], author: "Alice" },
{ ...LIST[1], id: "s3", question: "Second session", archived: false, author: "Bob" },
])),
http.delete("http://localhost:8787/sessions/:id", () => {
deletes += 1;
@@ -116,7 +121,7 @@ test("administrator confirms before deleting another owner's session", async ()
);
wrap();
await userEvent.click(await screen.findByRole("button", { name: "All sessions" }));
await screen.findByText("Owner: Bob");
await screen.findByText("Owner: Alice");
await userEvent.click(screen.getByRole("checkbox", { name: "Select Attiva uno" }));
await userEvent.click(screen.getByRole("button", { name: "Delete 1 selected sessions" }));
expect(deletes).toBe(0);
@@ -125,15 +130,15 @@ test("administrator confirms before deleting another owner's session", async ()
await waitFor(() => expect(deletes).toBe(1));
});
test("administrator confirms before archiving another owner's session", async () => {
test("administrator confirms before archiving a same-named user's session", async () => {
let archives = 0;
const confirm = vi.spyOn(window, "confirm").mockReturnValue(false);
server.use(
http.get("http://localhost:8787/me", () =>
HttpResponse.json({ issuer: "portal", subject: "alice", displayName: "Alice", isAdmin: true }),
HttpResponse.json({ issuer: "portal", subject: "alice-id", displayName: "Alice", isAdmin: true }),
),
http.get("http://localhost:8787/sessions", () => HttpResponse.json([
{ ...LIST[0], author: "Bob" },
{ ...LIST[0], author: "Alice" },
])),
http.post("http://localhost:8787/sessions/:id/archive", () => {
archives += 1;
@@ -142,10 +147,10 @@ test("administrator confirms before archiving another owner's session", async ()
);
wrap();
await userEvent.click(await screen.findByRole("button", { name: "All sessions" }));
await screen.findByText("Owner: Bob");
await screen.findByText("Owner: Alice");
await userEvent.click(screen.getByRole("button", { name: "Session actions" }));
await userEvent.click(await screen.findByText("Archive"));
expect(confirm).toHaveBeenCalledWith("Archive Bob's session?");
expect(confirm).toHaveBeenCalledWith("Archive Alice's session?");
expect(archives).toBe(0);
confirm.mockRestore();
});