Files
pig/packages/core/test/permissions.test.ts
karti 13dec6b4b8
CI / verify (push) Successful in 3m45s
CI / publish (push) Has been skipped
Rebuild the shell, add Calendar and Learn, and govern reads
Seven parallel agents and an adversarial verification pass. The three things
worth knowing before reading the diff:

RBAC WAS ALREADY BUILT. docs/build-plan.md marks F2 and F3 outstanding and is
stale — packages/core/src/permissions.ts and lib/mutation.ts shipped long ago.
So this does not rebuild them; it closes the gaps an audit found. The big one
is that reads were entirely ungoverned: every GET was "any authenticated
member", so a junior demand rep and a research contractor could both pull
per-block supplier cost and break-even prices from /api/capacity/margin, and
every contract's negotiated terms. For a company whose margin is the business,
that was the hole that mattered. Adds book:read / economics:read / team:read,
a readGuard middleware, and a `viewer` role below member.

THE BUTTON AND THE 403 DISAGREED — the exact thing F3 said must never happen.
Contracts.tsx never called can() at all, so its save button was always enabled
against a server requiring contract:sign; Capacity.tsx gated commitment
creation on deal:write/demand while the server wanted commitment:write/supply.

POST /api/activities was the one write bypassing executeMutation: no capability
check, and any member could mutate accounts.lastActivityAt as a side effect.
It is now a proper mutation() behind activity:write.

The shell becomes three panes — a collapsible shadcn sidebar with an account
switcher on the Piggy accent, a header with real search, and Piggy docked to
the right, page-aware and persistent across navigation. The phone keeps its
bottom tab bar, which is the thing this product already beat trycompai/crm on,
and gains the sidebar as a sheet.

Calendar is a projection over thirteen dated sources rather than a new table,
because a table would duplicate dates that already live on contracts, deals and
commitments and would drift — and one ledger answering the question is the
whole argument. It surfaces export_authorizations and compliance_artifacts,
which had indexed expires_at columns, schema comments saying they must be
alerted on, and no read endpoint or UI anywhere.

Learn carries two tracks. Concepts are members-only; the platform track can be
opened with a share code by someone with no account. The code mints a scoped
learn-only token and never a Principal — every route here resolves a principal
and then checks capabilities, so a principal-minting code would be one missing
check away from leaking the book. "Only platform-track rows may be code-visible"
is a database CHECK constraint as well as a write-path rule, and a test asserts
a valid learn token still gets 401 on /api/dashboard, /api/accounts and
/api/contracts — the same invariant scripts/deploy.sh refuses to ship without.

CD becomes tag-to-ship. CI publishes an image to the Gitea registry on a
release-* tag and cloud-2 pulls it, so no credential on the shared runner can
execute anything on production — by construction rather than by policy. Both
halves of deploy.sh's original rule survive: nothing on the runner reaches the
host, and a human still decides when it ships. deploy.sh gains a rollback and a
public-origin check, and PIG_IMAGE now reaches compose through `sudo env`,
without which sudo's env_reset silently resolved every release to pig:local.

Tests 141 -> 261.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-13 15:02:48 -07:00

219 lines
7.7 KiB
TypeScript
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
import { strict as assert } from 'node:assert';
import { describe, it } from 'node:test';
import { TEAM_ROLES, TEAMS, type Team, type TeamRole } from '../src/ontology';
import {
CAPABILITIES,
permissionGranted,
resolvePermissionGrants,
resolveReadPermissionGrants,
resolveWritePermissionGrants,
roleMeets,
type Capability,
type PermissionSubject,
} from '../src/permissions';
describe('role permissions', () => {
it('keeps deal writes on the side where the person is a member', () => {
const grants = resolvePermissionGrants({
isPlatformAdmin: false,
teams: [{ team: 'demand', role: 'member' }],
});
assert.equal(permissionGranted(grants, 'deal:write', 'demand'), true);
assert.equal(permissionGranted(grants, 'deal:write', 'supply'), false);
assert.equal(permissionGranted(grants, 'commitment:write', 'demand'), false);
});
it('allows supply leads to commit capacity without letting them sign contracts', () => {
const grants = resolvePermissionGrants({
isPlatformAdmin: false,
teams: [{ team: 'supply', role: 'lead' }],
});
assert.equal(permissionGranted(grants, 'commitment:write', 'supply'), true);
assert.equal(permissionGranted(grants, 'contract:sign', 'supply'), false);
});
it('keeps signing and bulk import at team-admin level', () => {
const grants = resolvePermissionGrants({
isPlatformAdmin: false,
teams: [{ team: 'demand', role: 'admin' }],
});
assert.equal(permissionGranted(grants, 'contract:sign', 'demand'), true);
assert.equal(permissionGranted(grants, 'contract:sign', 'supply'), false);
assert.equal(permissionGranted(grants, 'data:import', 'demand'), true);
assert.equal(permissionGranted(grants, 'data:import', 'research'), false);
assert.equal(permissionGranted(grants, 'settings:admin'), false);
});
it('gives platform admins global grants without synthetic team memberships', () => {
const grants = resolvePermissionGrants({ isPlatformAdmin: true, teams: [] });
assert.equal(permissionGranted(grants, 'deal:write', 'demand'), true);
assert.equal(permissionGranted(grants, 'commitment:write', 'supply'), true);
assert.equal(permissionGranted(grants, 'data:import', 'research'), true);
assert.equal(permissionGranted(grants, 'settings:admin'), true);
});
});
describe('the three authorities that used to be data:import', () => {
it('does not let a research admin rewrite a commercial book', () => {
const grants = resolvePermissionGrants({
isPlatformAdmin: false,
teams: [{ team: 'research', role: 'admin' }],
});
assert.equal(permissionGranted(grants, 'fact:review', 'research'), true);
assert.equal(permissionGranted(grants, 'data:import', 'demand'), false);
assert.equal(permissionGranted(grants, 'data:import', 'supply'), false);
});
it('does not let a commercial admin approve a claim about a person', () => {
const grants = resolvePermissionGrants({
isPlatformAdmin: false,
teams: [{ team: 'supply', role: 'admin' }],
});
assert.equal(permissionGranted(grants, 'data:import', 'supply'), true);
assert.equal(permissionGranted(grants, 'integration:connect', 'supply'), true);
// Fact review lives on research alone; being a supply admin buys nothing.
assert.equal(permissionGranted(grants, 'fact:review', 'research'), false);
});
});
describe('reads', () => {
it('resolves read grants platform-wide, never per team', () => {
const grants = resolveReadPermissionGrants({
isPlatformAdmin: false,
teams: [{ team: 'demand', role: 'member' }],
});
// A team-scoped read grant would be a promise the query layer does not
// keep: `/api/contracts` returns supply paper to a demand reader either
// way. See READ_CAPABILITIES.
assert.deepEqual(
grants,
[
{ capability: 'book:read', team: null },
{ capability: 'economics:read', team: null },
{ capability: 'team:read', team: null },
],
);
});
it('shows a research contractor the book but not what we pay for capacity', () => {
const grants = resolveReadPermissionGrants({
isPlatformAdmin: false,
teams: [{ team: 'research', role: 'lead' }],
});
assert.equal(permissionGranted(grants, 'book:read'), true);
assert.equal(permissionGranted(grants, 'team:read'), true);
assert.equal(permissionGranted(grants, 'economics:read'), false);
});
it('gives a viewer reads and no writes at all', () => {
const subject: PermissionSubject = {
isPlatformAdmin: false,
teams: [{ team: 'demand', role: 'viewer' }],
};
assert.deepEqual(resolveWritePermissionGrants(subject), []);
assert.equal(permissionGranted(resolveReadPermissionGrants(subject), 'book:read'), true);
// Cost economics are a commercial member's tool, not a reader's.
assert.equal(permissionGranted(resolveReadPermissionGrants(subject), 'economics:read'), false);
});
});
/**
* The matrix is pure data, so pinning every cell is cheap — and it is the only
* way a role added later cannot quietly inherit an authority nobody chose to
* give it. Change a rule and this table tells you exactly which cells moved.
*/
describe('the whole role × capability matrix', () => {
const EXPECTED: Readonly<Record<TeamRole, readonly Capability[]>> = {
viewer: ['book:read', 'team:read'],
member: ['book:read', 'economics:read', 'team:read', 'deal:write', 'activity:write'],
lead: [
'book:read',
'economics:read',
'team:read',
'deal:write',
'activity:write',
'commitment:write',
],
admin: [
'book:read',
'economics:read',
'team:read',
'deal:write',
'activity:write',
'commitment:write',
'contract:sign',
'data:import',
'integration:connect',
],
};
/** Held on the supply team, whose rules exercise every rank threshold. */
for (const role of TEAM_ROLES) {
it(`grants a supply ${role} exactly the expected set`, () => {
const grants = resolvePermissionGrants({
isPlatformAdmin: false,
teams: [{ team: 'supply', role }],
});
const held = CAPABILITIES.filter((capability) =>
grants.some((grant) => grant.capability === capability),
);
assert.deepEqual(new Set(held), new Set(EXPECTED[role]));
});
}
it('gives research its own shape — evidence review, no commercial reach', () => {
const grants = resolvePermissionGrants({
isPlatformAdmin: false,
teams: [{ team: 'research', role: 'admin' }],
});
const held = CAPABILITIES.filter((capability) =>
grants.some((grant) => grant.capability === capability),
);
assert.deepEqual(
new Set(held),
new Set([
'book:read',
'team:read',
'activity:write',
'data:import',
'fact:review',
'integration:connect',
]),
);
});
it('never grants a lower rank something a higher rank on the same team lacks', () => {
for (const team of TEAMS as readonly Team[]) {
let previous = new Set<Capability>();
for (const role of TEAM_ROLES) {
const held = new Set<Capability>(
resolvePermissionGrants({ isPlatformAdmin: false, teams: [{ team, role }] }).map(
(grant) => grant.capability,
),
);
for (const capability of previous) {
assert.ok(held.has(capability), `${team}/${role} lost ${capability} by promotion`);
}
previous = held;
}
}
});
it('ranks viewer below member, which is what makes it safe to add', () => {
assert.equal(roleMeets('viewer', 'member'), false);
assert.equal(roleMeets('member', 'viewer'), true);
assert.equal(roleMeets('admin', 'admin'), true);
assert.equal(TEAM_ROLES[0], 'viewer');
});
});