implementation from the prompt
This commit is contained in:
@@ -0,0 +1,71 @@
|
||||
const test = require('node:test')
|
||||
const assert = require('node:assert/strict')
|
||||
|
||||
const { tenantFilter } = require('../worker_tenant')
|
||||
const cloningService = require('../voice-cloning-job-handler/voice_cloning/voice_cloning_service')
|
||||
const cloningProfileService = require('../voice-cloning-job-handler/user_audio_profile/user_audio_profile_service')
|
||||
const synthProfileService = require('../voice-synthsizer-job-handler/user_audio_profile/user_audio_profile_service')
|
||||
const salutationService = require('../voice-synthsizer-job-handler/salutation/salutation_service')
|
||||
const jobService = require('../voice-synthsizer-job-handler/job/job_service')
|
||||
|
||||
const userId = '507f1f77bcf86cd799439011'
|
||||
const otherUserId = '507f191e810c19729de860ea'
|
||||
const recordId = '507f1f77bcf86cd799439012'
|
||||
|
||||
function fakeModel() {
|
||||
const calls = []
|
||||
return {
|
||||
calls,
|
||||
findOne: async (filter) => { calls.push(['findOne', filter]); return null },
|
||||
find: async (filter) => { calls.push(['find', filter]); return [] },
|
||||
findOneAndUpdate: async (filter, update) => {
|
||||
calls.push(['findOneAndUpdate', filter, update])
|
||||
return null
|
||||
},
|
||||
updateMany: async (filter, update) => {
|
||||
calls.push(['updateMany', filter, update])
|
||||
return { modifiedCount: 0 }
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
test('tenant filter requires a valid user ID and keeps it in the query', () => {
|
||||
assert.throws(() => tenantFilter({ _id: recordId }), /userId/)
|
||||
assert.throws(() => tenantFilter({ _id: recordId, userId: { $ne: otherUserId } }), /userId/)
|
||||
assert.equal(String(tenantFilter({ _id: recordId, userId }).userId), userId)
|
||||
})
|
||||
|
||||
for (const [name, factory] of [
|
||||
['cloning record', cloningService],
|
||||
['cloning profile', cloningProfileService],
|
||||
['synthesis profile', synthProfileService],
|
||||
['synthesis job', jobService],
|
||||
]) {
|
||||
test(`${name} reads and writes require matching tenant`, async () => {
|
||||
const model = fakeModel()
|
||||
const service = factory(model)
|
||||
await service.read({ _id: recordId, userId })
|
||||
await service.find({ userId })
|
||||
await service.update({ _id: recordId, userId, status: 'processing' })
|
||||
await service.remove({ _id: recordId, userId })
|
||||
await service.removeMany({ userId })
|
||||
for (const [, filter] of model.calls) {
|
||||
assert.equal(String(filter.userId), userId)
|
||||
}
|
||||
const update = model.calls.find(([method]) => method === 'findOneAndUpdate')
|
||||
assert.equal(update[1]._id, recordId)
|
||||
assert.deepEqual(update[2], { $set: { status: 'processing' } })
|
||||
assert.equal(update[1].deleted, false)
|
||||
await assert.rejects(service.update({ _id: recordId, status: 'processing' }), /userId/)
|
||||
})
|
||||
}
|
||||
|
||||
test('salutation updates cannot change ownership', async () => {
|
||||
const model = fakeModel()
|
||||
const service = salutationService(model)
|
||||
await service.update({ _id: recordId, userId: otherUserId, salutationVideo: 'url' }, userId)
|
||||
const [, filter, update] = model.calls[0]
|
||||
assert.equal(String(filter.userId), userId)
|
||||
assert.deepEqual(update, { $set: { salutationVideo: 'url' } })
|
||||
await assert.rejects(service.read({ _id: recordId }), /userId/)
|
||||
})
|
||||
Reference in New Issue
Block a user