dify/web/service/access-control/__tests__/use-app-access-control.spec.tsx
Wu Tianwei 33edf97f81
feat: RBAC (#37107)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: fatelei <fatelei@gmail.com>
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: 盐粒 Yanli <yanli@dify.ai>
Co-authored-by: Charles Yao <chongbinyao33@gmail.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: yunlu.wen <yunlu.wen@dify.ai>
Co-authored-by: yyh <92089059+lyzno1@users.noreply.github.com>
Co-authored-by: Jingyi <jingyi.qi@dify.ai>
Co-authored-by: yyh <yuanyouhuilyz@gmail.com>
Co-authored-by: Joel <iamjoel007@gmail.com>
Co-authored-by: hjlarry <hjlarry@163.com>
Co-authored-by: Asuka Minato <i@asukaminato.eu.org>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Xiyuan Chen <52963600+GareArc@users.noreply.github.com>
Co-authored-by: gigglewang <gigglewang@dify.ai>
Co-authored-by: chariri <w@chariri.moe>
Co-authored-by: Evan <2869018789@qq.com>
Co-authored-by: zyssyz123 <916125788@qq.com>
2026-06-18 16:35:29 +00:00

109 lines
3.2 KiB
TypeScript

import type { ReactNode } from 'react'
import { QueryClient, QueryClientProvider, queryOptions } from '@tanstack/react-query'
import { renderHook, waitFor } from '@testing-library/react'
import { get } from '@/service/base'
import { getUserCanAccess } from '@/service/share'
import {
useAppWhiteListSubjects,
useGetUserCanAccessApp,
useSearchForWhiteListCandidates,
} from '../use-app-access-control'
const mockSystemFeatures = vi.hoisted(() => ({
webappAuthEnabled: false,
}))
vi.mock('@/service/base', () => ({
get: vi.fn(),
request: vi.fn(),
}))
vi.mock('@/service/share', () => ({
getUserCanAccess: vi.fn(),
}))
vi.mock('@/features/system-features/client', () => ({
systemFeaturesQueryOptions: () => queryOptions({
queryKey: ['system-features'],
queryFn: () => Promise.resolve({
webapp_auth: {
enabled: mockSystemFeatures.webappAuthEnabled,
},
}),
}),
}))
const createWrapper = () => {
const queryClient = new QueryClient({
defaultOptions: {
queries: { retry: false },
mutations: { retry: false },
},
})
return ({ children }: { children: ReactNode }) => (
<QueryClientProvider client={queryClient}>{children}</QueryClientProvider>
)
}
describe('use-app-access-control', () => {
beforeEach(() => {
vi.clearAllMocks()
mockSystemFeatures.webappAuthEnabled = false
vi.mocked(get).mockResolvedValue({ groups: [], members: [] })
vi.mocked(getUserCanAccess).mockResolvedValue({ result: true })
})
// Queries build the enterprise whitelist endpoints from app and filter inputs.
describe('Queries', () => {
it('should fetch app whitelist subjects when enabled', async () => {
renderHook(() => useAppWhiteListSubjects('app-1', true), { wrapper: createWrapper() })
await waitFor(() => {
expect(get).toHaveBeenCalledWith('/enterprise/webapp/app/subjects?appId=app-1')
})
})
it('should search whitelist candidates with encoded query params', async () => {
vi.mocked(get).mockResolvedValue({
currPage: 1,
totalPages: 1,
subjects: [],
hasMore: false,
})
renderHook(
() => useSearchForWhiteListCandidates({
keyword: 'team one',
groupId: 'group-1',
resultsPerPage: 20,
}, true),
{ wrapper: createWrapper() },
)
await waitFor(() => {
expect(get).toHaveBeenCalledWith('/enterprise/webapp/app/subject/search?keyword=team+one&groupId=group-1&resultsPerPage=20&pageNumber=1')
})
})
it('should return public access when webapp auth is disabled', async () => {
const { result } = renderHook(() => useGetUserCanAccessApp({ appId: 'app-1' }), { wrapper: createWrapper() })
await waitFor(() => {
expect(result.current.data).toEqual({ result: true })
})
expect(getUserCanAccess).not.toHaveBeenCalled()
})
it('should call share access check when webapp auth is enabled', async () => {
mockSystemFeatures.webappAuthEnabled = true
renderHook(() => useGetUserCanAccessApp({ appId: 'app-1', isInstalledApp: false }), { wrapper: createWrapper() })
await waitFor(() => {
expect(getUserCanAccess).toHaveBeenCalledWith('app-1', false)
})
})
})
})