File size: 1,216 Bytes
46252cd
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
import { Reflector } from '@nestjs/core';
import { PluginsController } from './plugins.controller';
import { REQUIRED_ROLE_KEY } from '../auth/decorators/auth.decorators';
import { ApiKeyRole } from '../auth/entities/api-key.entity';

describe('PluginsController authorization', () => {
  const reflector = new Reflector();

  // Plugin reads expose installed versions, non-secret config, and health/error text — privileged
  // inventory on par with the ADMIN-gated write routes and the InfraController convention. A
  // VIEWER/OPERATOR key (or a session-scoped key) must not be able to enumerate it via the raw API.
  const adminOnly = [
    'findAll',
    'findOne',
    'healthCheck',
    'enable',
    'disable',
    'updateConfig',
    'getConfigUi',
    'updateSessionConfig',
  ] as const;

  it.each(adminOnly)('%s requires the ADMIN role', method => {
    // Metadata lookup key, never invoked — see the same note in infra.controller.spec.ts.
    // eslint-disable-next-line @typescript-eslint/unbound-method
    const handler = PluginsController.prototype[method];
    const role = reflector.get<ApiKeyRole | undefined>(REQUIRED_ROLE_KEY, handler);
    expect(role).toBe(ApiKeyRole.ADMIN);
  });
});