test(perm): assert /me capabilities+bots; dry backfill token list

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
saopig1andClaude Opus 4.8 committed 2026-05-30 14:06:59 +08:00
1 parent d70664067c
commit 1ca1ca9d0c
2 files changed
+8 -1

No files matched your search

+2 -1
View File
@@ -1,4 +1,5 @@
import Database from "better-sqlite3"; import Database from "better-sqlite3";
import { CAPABILITIES, BOTS_ALL } from "./permissions.js";
export interface PlayHistoryEntry { export interface PlayHistoryEntry {
botId: string; botId: string;
@@ -196,7 +197,7 @@ export function backfillMemberPermissions(db: Database.Database): void {
if (done) return; if (done) return;
const members = db.prepare("SELECT id FROM users WHERE role = 'member'").all() as { id: string }[]; const members = db.prepare("SELECT id FROM users WHERE role = 'member'").all() as { id: string }[];
const insCap = db.prepare("INSERT OR IGNORE INTO user_permissions (userId, permission) VALUES (?, ?)"); const insCap = db.prepare("INSERT OR IGNORE INTO user_permissions (userId, permission) VALUES (?, ?)");
const tokens = ["player.control", "player.queue", "bot.manage", "platform.auth", "quality", "bots.all"]; const tokens = [...CAPABILITIES, BOTS_ALL];
const tx = db.transaction(() => { const tx = db.transaction(() => {
for (const m of members) { for (const m of members) {
for (const t of tokens) insCap.run(m.id, t); for (const t of tokens) insCap.run(m.id, t);
+6
View File
@@ -102,6 +102,12 @@ describe("session router", () => {
const me = await request(app).get("/api/session/me").set("Cookie", cookie); const me = await request(app).get("/api/session/me").set("Cookie", cookie);
expect(me.status).toBe(200); expect(me.status).toBe(200);
expect(me.body.username).toBe("alice"); expect(me.body.username).toBe("alice");
// alice is the first user (an admin), so /me exposes all capabilities and full bot access.
expect(Array.isArray(me.body.capabilities)).toBe(true);
expect(me.body.capabilities).toEqual(
expect.arrayContaining(["player.control", "player.queue", "bot.manage", "platform.auth", "quality"])
);
expect(me.body.bots).toBe("all");
const anon = await request(app).get("/api/session/me"); const anon = await request(app).get("/api/session/me");
expect(anon.status).toBe(401); expect(anon.status).toBe(401);