forked from EduCraft/curriculum-project-hub
feat: auto-join scoped Feishu OAuth users
This commit is contained in:
@@ -267,9 +267,6 @@ describe("admin auth + org API guards", () => {
|
||||
openId: "ou_scoped_user",
|
||||
displayName: "Invited User",
|
||||
});
|
||||
await prisma.organizationMembership.create({
|
||||
data: { organizationId: DEFAULT_ORG_ID, userId: identity.userId, role: "ADMIN" },
|
||||
});
|
||||
await seedTestOrganization("org_scoped_other", "scoped-other");
|
||||
await prisma.organizationMembership.create({
|
||||
data: { organizationId: "org_scoped_other", userId: identity.userId, role: "ADMIN" },
|
||||
@@ -317,7 +314,7 @@ describe("admin auth + org API guards", () => {
|
||||
expect(me.statusCode).toBe(200);
|
||||
expect(me.json()).toMatchObject({
|
||||
user: { id: identity.userId, displayName: "Scoped User" },
|
||||
organizations: [expect.objectContaining({ slug: "test-default", role: "ADMIN" })],
|
||||
organizations: [expect.objectContaining({ slug: "test-default", role: "MEMBER" })],
|
||||
});
|
||||
expect((me.json() as { organizations: unknown[] }).organizations).toHaveLength(1);
|
||||
const crossOrganization = await app.inject({
|
||||
@@ -331,6 +328,13 @@ describe("admin auth + org API guards", () => {
|
||||
where: { id: identity.identityId },
|
||||
select: { unionId: true },
|
||||
})).resolves.toEqual({ unionId: "on_scoped_union" });
|
||||
await expect(prisma.auditEntry.count({
|
||||
where: {
|
||||
organizationId: DEFAULT_ORG_ID,
|
||||
actorUserId: identity.userId,
|
||||
action: "organization_member.oauth_auto_joined",
|
||||
},
|
||||
})).resolves.toBe(1);
|
||||
|
||||
await connections.disable({ organizationId: DEFAULT_ORG_ID, actorUserId: "scoped-owner" });
|
||||
const revoked = await app.inject({ method: "GET", url: "/api/me", headers: { cookie: sessionCookie } });
|
||||
@@ -340,6 +344,65 @@ describe("admin auth + org API guards", () => {
|
||||
}
|
||||
});
|
||||
|
||||
it("does not restore a revoked Organization membership during scoped OAuth", async () => {
|
||||
await seedUser("revoked-owner", "legacy_revoked_owner", "OWNER");
|
||||
const connections = new FeishuApplicationConnectionService(prisma, testSecretEnvelope, async () => {});
|
||||
const connection = await connections.rotateCustomerApplication({
|
||||
organizationId: DEFAULT_ORG_ID,
|
||||
actorUserId: "revoked-owner",
|
||||
appId: "cli_revoked_oauth",
|
||||
appSecret: "revoked-oauth-secret",
|
||||
botOpenId: "ou_revoked_bot",
|
||||
});
|
||||
const identity = await upsertScopedFeishuIdentity(prisma, {
|
||||
connectionId: connection.id,
|
||||
openId: "ou_revoked_user",
|
||||
displayName: "Revoked User",
|
||||
});
|
||||
await prisma.organizationMembership.create({
|
||||
data: {
|
||||
organizationId: DEFAULT_ORG_ID,
|
||||
userId: identity.userId,
|
||||
role: "MEMBER",
|
||||
revokedAt: new Date(),
|
||||
},
|
||||
});
|
||||
const fetchImpl = vi.fn(async (input: RequestInfo | URL) => {
|
||||
const url = String(input);
|
||||
if (url.includes("/oauth/token")) {
|
||||
return Response.json({ code: 0, access_token: "revoked-user-token" });
|
||||
}
|
||||
if (url.includes("/user_info")) {
|
||||
return Response.json({
|
||||
code: 0,
|
||||
data: { open_id: "ou_revoked_user", name: "Revoked User" },
|
||||
});
|
||||
}
|
||||
throw new Error(`unexpected ${url}`);
|
||||
});
|
||||
const app = await buildApp(fetchImpl as unknown as typeof fetch);
|
||||
try {
|
||||
const start = await app.inject({ method: "GET", url: "/auth/feishu/test-default" });
|
||||
const authorize = new URL(String(start.headers.location));
|
||||
const state = authorize.searchParams.get("state");
|
||||
expect(state).not.toBeNull();
|
||||
const callback = await app.inject({
|
||||
method: "GET",
|
||||
url: `/auth/feishu/callback?code=ok&state=${encodeURIComponent(state!)}`,
|
||||
headers: { cookie: cookiePair(start.headers["set-cookie"], OAUTH_STATE_COOKIE_NAME) },
|
||||
});
|
||||
expect(callback.statusCode).toBe(302);
|
||||
await expect(prisma.organizationMembership.count({
|
||||
where: { organizationId: DEFAULT_ORG_ID, userId: identity.userId, revokedAt: null },
|
||||
})).resolves.toBe(0);
|
||||
await expect(prisma.auditEntry.count({
|
||||
where: { action: "organization_member.oauth_auto_joined", actorUserId: identity.userId },
|
||||
})).resolves.toBe(0);
|
||||
} finally {
|
||||
await app.close();
|
||||
}
|
||||
});
|
||||
|
||||
it("unknown org slug returns 404 for admin", async () => {
|
||||
await seedUser("u-admin", "ou_admin", "ADMIN");
|
||||
const app = await buildApp();
|
||||
|
||||
@@ -662,8 +662,8 @@ describe("trigger full lifecycle (integration)", () => {
|
||||
await trigger(makeEvent("chat-bound-unknown", "@_user_1 写教案", "ou_bound_unknown"), rt);
|
||||
|
||||
expect(rt.sentTexts).toContain(
|
||||
"请先通过飞书登录建立身份:https://educraft.example.test/auth/feishu/test-default\n" +
|
||||
"登录后仍需由组织管理员将你加入组织。",
|
||||
"请先通过飞书登录并加入组织:https://educraft.example.test/auth/feishu/test-default\n" +
|
||||
"完成后返回群聊重试。",
|
||||
);
|
||||
expect(rt.sentTexts).not.toContain("无权限触发。");
|
||||
expect(runAgentCalls).toHaveLength(0);
|
||||
@@ -684,7 +684,7 @@ describe("trigger full lifecycle (integration)", () => {
|
||||
await trigger(makeEvent("chat-bound-non-member", "@_user_1 写教案", "ou_bound_non_member"), rt);
|
||||
|
||||
expect(rt.sentTexts).toContain(
|
||||
"你已完成飞书登录,但尚未加入该组织。请联系组织管理员为你开通成员权限。",
|
||||
"你尚未加入该组织,或成员资格已被移除。请联系组织管理员。",
|
||||
);
|
||||
expect(rt.sentTexts).not.toContain("无权限触发。");
|
||||
expect(runAgentCalls).toHaveLength(0);
|
||||
@@ -1011,8 +1011,8 @@ describe("trigger full lifecycle (integration)", () => {
|
||||
await trigger(makeEvent("chat-UNKNOWN", "@_user_1 写教案", "ou_unknown_user"), rt);
|
||||
|
||||
expect(rt.sentTexts).toContain(
|
||||
"请先通过飞书登录建立身份:https://educraft.example.test/auth/feishu/test-default\n" +
|
||||
"登录后仍需由组织管理员将你加入组织。",
|
||||
"请先通过飞书登录并加入组织:https://educraft.example.test/auth/feishu/test-default\n" +
|
||||
"完成后返回群聊重试。",
|
||||
);
|
||||
expect(rt.sentCards).toHaveLength(0);
|
||||
const runs = await prisma.agentRun.findMany();
|
||||
@@ -1033,7 +1033,7 @@ describe("trigger full lifecycle (integration)", () => {
|
||||
await trigger(makeEvent("chat-unbound", "@_user_1 写教案", "ou_logged_in_not_member"), rt);
|
||||
|
||||
expect(rt.sentTexts).toContain(
|
||||
"你已完成飞书登录,但尚未加入该组织。请联系组织管理员为你开通成员权限。",
|
||||
"你尚未加入该组织,或成员资格已被移除。请联系组织管理员。",
|
||||
);
|
||||
expect(rt.sentTexts.join("\n")).not.toContain("/auth/feishu/");
|
||||
await expect(prisma.agentRun.count()).resolves.toBe(0);
|
||||
|
||||
Reference in New Issue
Block a user