|
1 | 1 | /** @vitest-environment node */ |
2 | | -import { slackSearchInstallation } from '@sim/db/schema' |
| 2 | +import { credential, slackSearchInstallation, slackSearchTurn } from '@sim/db/schema' |
3 | 3 | import { dbChainMockFns, queueTableRows, resetDbChainMock } from '@sim/testing' |
4 | 4 | import { beforeEach, describe, expect, it, vi } from 'vitest' |
5 | 5 |
|
@@ -49,18 +49,86 @@ describe('Slack access revocation', () => { |
49 | 49 | expect.objectContaining({ status: 'cancelled', outcome: 'access_revoked' }) |
50 | 50 | ) |
51 | 51 | }) |
52 | | - it('invalidates member grants without disabling the bot for personal revocation', async () => { |
| 52 | + it('cancels only affected members without rotating the shared installation revision', async () => { |
| 53 | + dbChainMockFns.returning.mockResolvedValueOnce([{ providerSubjectId: 'U1' }]) |
53 | 54 | await revokeSlackSearchAccess.execute({ |
54 | 55 | principal, |
55 | | - input: { ...input, event: { type: 'tokens_revoked', tokens: { oauth: ['U1'] } } }, |
| 56 | + input: { ...input, event: { type: 'tokens_revoked', tokens: { oauth: ['U1', 'U2'] } } }, |
56 | 57 | }) |
57 | 58 | expect(dbChainMockFns.set).toHaveBeenCalledWith( |
58 | 59 | expect.objectContaining({ managedOauthStatus: 'needs_reauth' }) |
59 | 60 | ) |
60 | | - expect(dbChainMockFns.set).toHaveBeenCalledWith( |
61 | | - expect.objectContaining({ lastOutcome: 'tokens_revoked' }) |
62 | | - ) |
63 | | - expect(dbChainMockFns.set.mock.calls.some(([value]) => 'enabled' in value)).toBe(false) |
| 61 | + expect(dbChainMockFns.update.mock.calls.map(([table]) => table)).toEqual([ |
| 62 | + credential, |
| 63 | + slackSearchTurn, |
| 64 | + ]) |
| 65 | + expect(dbChainMockFns.where).toHaveBeenLastCalledWith({ |
| 66 | + type: 'and', |
| 67 | + conditions: [ |
| 68 | + { type: 'eq', left: slackSearchTurn.installationId, right: 'i1' }, |
| 69 | + { type: 'inArray', column: slackSearchTurn.status, values: ['pending', 'running'] }, |
| 70 | + { |
| 71 | + type: 'inArray', |
| 72 | + column: expect.objectContaining({ |
| 73 | + strings: ['', " #>> '{message,userId}'"], |
| 74 | + values: [slackSearchTurn.payload], |
| 75 | + }), |
| 76 | + values: ['U1'], |
| 77 | + }, |
| 78 | + ], |
| 79 | + }) |
| 80 | + expect(dbChainMockFns.where).toHaveBeenNthCalledWith(2, { |
| 81 | + type: 'and', |
| 82 | + conditions: expect.arrayContaining([ |
| 83 | + { type: 'eq', left: credential.organizationId, right: 'org' }, |
| 84 | + { type: 'eq', left: credential.authorizationAppId, right: 'slack:A1:T1' }, |
| 85 | + { type: 'inArray', column: credential.providerSubjectId, values: ['U1', 'U2'] }, |
| 86 | + { |
| 87 | + type: 'or', |
| 88 | + conditions: [ |
| 89 | + { type: 'isNull', column: credential.grantedAt }, |
| 90 | + { |
| 91 | + type: 'lte', |
| 92 | + left: credential.grantedAt, |
| 93 | + right: new Date(input.event_time * 1000), |
| 94 | + }, |
| 95 | + ], |
| 96 | + }, |
| 97 | + ]), |
| 98 | + }) |
| 99 | + }) |
| 100 | + it('does not cancel work when no current member grants were revoked', async () => { |
| 101 | + await revokeSlackSearchAccess.execute({ |
| 102 | + principal, |
| 103 | + input: { ...input, event: { type: 'tokens_revoked', tokens: { oauth: ['U1'] } } }, |
| 104 | + }) |
| 105 | + expect(dbChainMockFns.update.mock.calls.map(([table]) => table)).toEqual([credential]) |
| 106 | + }) |
| 107 | + it.each([{ bot: ['UBOT'] }, { bot: ['UBOT'], oauth: ['U1'] }])( |
| 108 | + 'cancels all installation work when its bot is revoked: %j', |
| 109 | + async (tokens) => { |
| 110 | + await revokeSlackSearchAccess.execute({ |
| 111 | + principal, |
| 112 | + input: { ...input, event: { type: 'tokens_revoked', tokens } }, |
| 113 | + }) |
| 114 | + expect(dbChainMockFns.set).toHaveBeenCalledWith( |
| 115 | + expect.objectContaining({ enabled: false, revision: expect.any(String) }) |
| 116 | + ) |
| 117 | + expect(dbChainMockFns.where).toHaveBeenLastCalledWith({ |
| 118 | + type: 'and', |
| 119 | + conditions: [ |
| 120 | + { type: 'eq', left: slackSearchTurn.installationId, right: 'i1' }, |
| 121 | + { type: 'inArray', column: slackSearchTurn.status, values: ['pending', 'running'] }, |
| 122 | + ], |
| 123 | + }) |
| 124 | + } |
| 125 | + ) |
| 126 | + it('does not invalidate the installation when a different bot token is revoked', async () => { |
| 127 | + await revokeSlackSearchAccess.execute({ |
| 128 | + principal, |
| 129 | + input: { ...input, event: { type: 'tokens_revoked', tokens: { bot: ['OTHER'] } } }, |
| 130 | + }) |
| 131 | + expect(dbChainMockFns.update).not.toHaveBeenCalled() |
64 | 132 | }) |
65 | 133 | it.each([{ appId: 'A2' }, { receivedAt: new Date(0) }, { receivedAt: new Date(Number.NaN) }])( |
66 | 134 | 'rejects invalid verified authority %#', |
|
0 commit comments