WP-03: employee records and contracts on real data
Replaces the demo module behind the team directory and the employee record with scoped queries, and adds contracts, amendments, work permits and the forfait-jours fields. Writing the end-to-end test exposed a modelling error worth naming: first and last names lived only on User, so an employee without an application account had no name at all — the directory rendered "— Salarié E0007". Most sales staff never sign in, and the personnel register requires their name, so the name belongs to the record, not to the login. Moved to EmployeeProfile with a data migration that carries the existing names down from User. Contract rules are pure functions tested at the boundaries. The case that matters is an open-ended contract: a CDI with no end date overlaps every later period, which a naive comparison of two date pairs misses, and two overlapping active contracts would count one employee twice in payroll. The check runs inside the transaction, not only in the form. Forfait jours is refused without a written individual agreement and a dated employee consent: without them the arrangement is unenforceable, and enabling it would also switch off every weekly-duration control. Salary and bank details are not merely hidden when the capability is missing — they are never loaded. A field absent from the response cannot leak through HTML, a log or an error message. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
This commit is contained in:
18 files changed
+1667
-210
No files matched your search
@@ -19,9 +19,11 @@ test('les six écrans se chargent et affichent leur contenu', async ({ page }) =
|
||||
await page.getByRole('link', { name: 'Équipe', exact: true }).click();
|
||||
await expect(page.getByRole('heading', { name: 'Équipe' })).toBeVisible();
|
||||
|
||||
await page.getByRole('link', { name: 'Camille Ferrand' }).click();
|
||||
// La fiche est atteinte depuis l'annuaire réel, plus depuis un lien codé
|
||||
// en dur : l'identifiant est celui de la base.
|
||||
await page.getByRole('link', { name: /Camille Ferrand/ }).first().click();
|
||||
await expect(
|
||||
page.getByRole('heading', { name: 'Camille Ferrand' }),
|
||||
page.getByRole('heading', { name: /Camille Ferrand/ }),
|
||||
).toBeVisible();
|
||||
|
||||
await page.getByRole('link', { name: 'Congés' }).click();
|
||||
|
||||
@@ -58,3 +58,34 @@ test('un manager ne peut ni voir ni modifier les établissements', async ({
|
||||
page.getByRole('heading', { name: 'Établissements' }),
|
||||
).toBeHidden();
|
||||
});
|
||||
|
||||
test('un salarié sans compte applicatif est créable', async ({ page }) => {
|
||||
await signIn(page, 'direction@example.test');
|
||||
await page.goto('/equipe');
|
||||
|
||||
await expect(page.getByRole('heading', { name: 'Équipe' })).toBeVisible();
|
||||
// L'effectif vient de la base, pas du module de démonstration.
|
||||
await expect(page.getByText('E0001')).toBeVisible();
|
||||
|
||||
const matricule = `E9${Date.now() % 100000}`;
|
||||
const form = page.locator('form').filter({ hasText: 'Ajouter' });
|
||||
await form.locator('input[name="firstName"]').fill('Sans');
|
||||
await form.locator('input[name="lastName"]').fill('Compte');
|
||||
await form.locator('input[name="employeeNumber"]').fill(matricule);
|
||||
await page.getByRole('button', { name: 'Ajouter' }).click();
|
||||
await expect(page.getByText('Salarié ajouté.')).toBeVisible();
|
||||
|
||||
// Rechargement explicite : ce qui est vérifié ici est la persistance et la
|
||||
// présence dans l'annuaire, pas le moment exact où la revalidation atteint
|
||||
// le rendu courant.
|
||||
await page.reload();
|
||||
|
||||
// Un salarié sans adresse doit exister : la plupart des équipes de vente ne
|
||||
// se connectent jamais à l'outil.
|
||||
await expect(
|
||||
page.getByRole('cell', { name: matricule, exact: true }),
|
||||
).toBeVisible();
|
||||
// Le nom vit sur le dossier, pas sur le compte : un salarié sans accès
|
||||
// applicatif doit tout de même figurer nommément au registre du personnel.
|
||||
await expect(page.getByRole('link', { name: /Sans Compte/ })).toBeVisible();
|
||||
});
|
||||
@@ -0,0 +1,168 @@
|
||||
import { describe, expect, it } from 'vitest';
|
||||
|
||||
import {
|
||||
findOverlaps,
|
||||
FORFAIT_JOURS_CAP,
|
||||
isHourScheduled,
|
||||
periodsOverlap,
|
||||
validateContract,
|
||||
} from '@/domain/contracts/rules';
|
||||
|
||||
const d = (iso: string) => new Date(`${iso}T00:00:00Z`);
|
||||
|
||||
describe('periodsOverlap', () => {
|
||||
it('détecte deux périodes fermées qui se recouvrent', () => {
|
||||
expect(
|
||||
periodsOverlap(
|
||||
{ startDate: d('2026-01-01'), endDate: d('2026-06-30') },
|
||||
{ startDate: d('2026-06-01'), endDate: d('2026-12-31') },
|
||||
),
|
||||
).toBe(true);
|
||||
});
|
||||
|
||||
it('accepte deux périodes qui ne se touchent pas', () => {
|
||||
expect(
|
||||
periodsOverlap(
|
||||
{ startDate: d('2026-01-01'), endDate: d('2026-05-31') },
|
||||
{ startDate: d('2026-06-01'), endDate: d('2026-12-31') },
|
||||
),
|
||||
).toBe(false);
|
||||
});
|
||||
|
||||
it('traite le jour de contact comme un chevauchement', () => {
|
||||
// Deux contrats actifs le même jour comptent le salarié deux fois en paie.
|
||||
expect(
|
||||
periodsOverlap(
|
||||
{ startDate: d('2026-01-01'), endDate: d('2026-06-01') },
|
||||
{ startDate: d('2026-06-01'), endDate: d('2026-12-31') },
|
||||
),
|
||||
).toBe(true);
|
||||
});
|
||||
|
||||
it('fait chevaucher un contrat sans terme avec tout ce qui suit', () => {
|
||||
// Le cas qu'on oublie en comparant naïvement deux couples de dates : un CDI
|
||||
// en cours n'a pas de fin, il couvre donc toute période postérieure.
|
||||
expect(
|
||||
periodsOverlap(
|
||||
{ startDate: d('2020-01-01'), endDate: null },
|
||||
{ startDate: d('2030-01-01'), endDate: d('2030-12-31') },
|
||||
),
|
||||
).toBe(true);
|
||||
});
|
||||
|
||||
it('n’étend pas un contrat sans terme vers le passé', () => {
|
||||
expect(
|
||||
periodsOverlap(
|
||||
{ startDate: d('2026-01-01'), endDate: null },
|
||||
{ startDate: d('2020-01-01'), endDate: d('2020-12-31') },
|
||||
),
|
||||
).toBe(false);
|
||||
});
|
||||
});
|
||||
|
||||
describe('findOverlaps', () => {
|
||||
const existing = [
|
||||
{ id: 'c1', startDate: d('2024-01-01'), endDate: d('2025-12-31') },
|
||||
{ id: 'c2', startDate: d('2026-01-01'), endDate: null },
|
||||
];
|
||||
|
||||
it('signale le contrat en conflit', () => {
|
||||
const conflicts = findOverlaps(
|
||||
{ startDate: d('2026-06-01'), endDate: d('2026-08-31') },
|
||||
existing,
|
||||
);
|
||||
expect(conflicts.map((c) => c.id)).toEqual(['c2']);
|
||||
});
|
||||
|
||||
it('ignore le contrat en cours de modification', () => {
|
||||
const conflicts = findOverlaps(
|
||||
{ id: 'c2', startDate: d('2026-06-01'), endDate: null },
|
||||
existing,
|
||||
);
|
||||
expect(conflicts).toEqual([]);
|
||||
});
|
||||
|
||||
it('laisse passer une période libre', () => {
|
||||
expect(
|
||||
findOverlaps(
|
||||
{ startDate: d('2023-01-01'), endDate: d('2023-06-30') },
|
||||
existing,
|
||||
),
|
||||
).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
describe('validateContract — forfait jours', () => {
|
||||
const base = {
|
||||
startDate: d('2026-01-01'),
|
||||
endDate: null,
|
||||
weeklyHours: 0,
|
||||
forfaitDaysPerYear: 218,
|
||||
forfaitAgreementRef: 'CONV-2026-001',
|
||||
forfaitAgreedAt: d('2025-12-15'),
|
||||
workTimeArrangement: 'FORFAIT_JOURS' as const,
|
||||
};
|
||||
|
||||
it('accepte un forfait complet', () => {
|
||||
expect(validateContract(base)).toEqual([]);
|
||||
});
|
||||
|
||||
it('refuse sans convention individuelle écrite', () => {
|
||||
// Sans elle le forfait est inopposable — et l'activer supprimerait au
|
||||
// passage tout contrôle de durée hebdomadaire.
|
||||
const issues = validateContract({ ...base, forfaitAgreementRef: '' });
|
||||
expect(issues.map((i) => i.field)).toContain('forfaitAgreementRef');
|
||||
});
|
||||
|
||||
it('refuse sans accord daté du salarié', () => {
|
||||
const issues = validateContract({ ...base, forfaitAgreedAt: null });
|
||||
expect(issues.map((i) => i.field)).toContain('forfaitAgreedAt');
|
||||
});
|
||||
|
||||
it('refuse au-delà du plafond conventionnel', () => {
|
||||
const issues = validateContract({
|
||||
...base,
|
||||
forfaitDaysPerYear: FORFAIT_JOURS_CAP + 1,
|
||||
});
|
||||
expect(issues[0]?.message).toContain('218');
|
||||
});
|
||||
|
||||
it('accepte exactement le plafond', () => {
|
||||
expect(
|
||||
validateContract({ ...base, forfaitDaysPerYear: FORFAIT_JOURS_CAP }),
|
||||
).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
describe('validateContract — horaire', () => {
|
||||
const base = {
|
||||
startDate: d('2026-01-01'),
|
||||
endDate: null,
|
||||
weeklyHours: 35,
|
||||
workTimeArrangement: 'HOURLY' as const,
|
||||
};
|
||||
|
||||
it('accepte un contrat horaire', () => {
|
||||
expect(validateContract(base)).toEqual([]);
|
||||
});
|
||||
|
||||
it('refuse une durée nulle', () => {
|
||||
expect(validateContract({ ...base, weeklyHours: 0 })).toHaveLength(1);
|
||||
});
|
||||
|
||||
it('refuse une fin antérieure au début', () => {
|
||||
const issues = validateContract({ ...base, endDate: d('2025-01-01') });
|
||||
expect(issues.map((i) => i.field)).toContain('endDate');
|
||||
});
|
||||
|
||||
it('n’exige aucune convention de forfait', () => {
|
||||
expect(validateContract(base)).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
describe('isHourScheduled', () => {
|
||||
it('exclut le forfait jours du décompte horaire', () => {
|
||||
expect(isHourScheduled('HOURLY')).toBe(true);
|
||||
expect(isHourScheduled('FORFAIT_JOURS')).toBe(false);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,76 @@
|
||||
import { describe, expect, it } from 'vitest';
|
||||
|
||||
process.env.DATABASE_URL ??= 'postgresql://user:pass@localhost:5432/planflow';
|
||||
process.env.ENCRYPTION_KEY ??= Buffer.alloc(32, 3).toString('base64');
|
||||
|
||||
const crypto = await import('@/server/crypto');
|
||||
|
||||
describe('chiffrement des colonnes sensibles', () => {
|
||||
it('fait un aller-retour fidèle', () => {
|
||||
const nir = '1 85 04 44 109 123 45';
|
||||
expect(crypto.decrypt(crypto.encrypt(nir))).toBe(nir);
|
||||
});
|
||||
|
||||
it('préserve les accents et les caractères non latins', () => {
|
||||
const value = 'Rémi Chartier — 电子';
|
||||
expect(crypto.decrypt(crypto.encrypt(value))).toBe(value);
|
||||
});
|
||||
|
||||
it('produit un chiffré différent à chaque appel', () => {
|
||||
// Un IV constant ferait apparaître deux salariés au même IBAN comme
|
||||
// identiques dans la base, sans jamais déchiffrer quoi que ce soit.
|
||||
const a = crypto.encrypt('FR7630006000011234567890189');
|
||||
const b = crypto.encrypt('FR7630006000011234567890189');
|
||||
expect(a.equals(b)).toBe(false);
|
||||
});
|
||||
|
||||
it('rejette un chiffré modifié', () => {
|
||||
// GCM authentifie : une altération est détectée au lieu de produire du
|
||||
// clair corrompu qu'on prendrait pour une donnée valide.
|
||||
const payload = crypto.encrypt('FR7630006000011234567890189');
|
||||
const last = payload.length - 1;
|
||||
payload.writeUInt8(payload.readUInt8(last) ^ 0xff, last);
|
||||
expect(() => crypto.decrypt(payload)).toThrow();
|
||||
});
|
||||
|
||||
it('rejette un chiffré tronqué', () => {
|
||||
const payload = crypto.encrypt('valeur');
|
||||
expect(() => crypto.decrypt(payload.subarray(0, 8))).toThrow(/trop court/);
|
||||
});
|
||||
|
||||
it('accepte un Uint8Array, comme le renvoie Prisma', () => {
|
||||
const payload = crypto.encrypt('valeur');
|
||||
const asArray = new Uint8Array(payload);
|
||||
expect(crypto.decrypt(asArray)).toBe('valeur');
|
||||
});
|
||||
|
||||
it('gère les valeurs absentes sans lever', () => {
|
||||
expect(crypto.encryptOptional(null)).toBeNull();
|
||||
expect(crypto.encryptOptional('')).toBeNull();
|
||||
expect(crypto.decryptOptional(null)).toBeNull();
|
||||
});
|
||||
});
|
||||
|
||||
describe('jetons', () => {
|
||||
it('produit des jetons uniques et suffisamment longs', () => {
|
||||
const tokens = new Set(
|
||||
Array.from({ length: 200 }, () => crypto.generateToken()),
|
||||
);
|
||||
expect(tokens.size).toBe(200);
|
||||
for (const token of tokens) expect(token.length).toBeGreaterThanOrEqual(40);
|
||||
});
|
||||
|
||||
it('ne stocke jamais le jeton en clair', () => {
|
||||
const token = crypto.generateToken();
|
||||
const hash = crypto.hashToken(token);
|
||||
expect(hash).not.toContain(token);
|
||||
expect(hash).toHaveLength(64);
|
||||
expect(crypto.hashToken(token)).toBe(hash);
|
||||
});
|
||||
|
||||
it('compare à temps constant sans se tromper', () => {
|
||||
expect(crypto.safeEqual('abc', 'abc')).toBe(true);
|
||||
expect(crypto.safeEqual('abc', 'abd')).toBe(false);
|
||||
expect(crypto.safeEqual('abc', 'abcd')).toBe(false);
|
||||
});
|
||||
});
|
||||
@@ -27,10 +27,11 @@ describe('matches', () => {
|
||||
|
||||
describe('activeItem', () => {
|
||||
it('retient la correspondance la plus spécifique', () => {
|
||||
// Sur une fiche, « Membres » (/equipe) et « Fiche salarié » correspondent
|
||||
// tous deux ; c'est la fiche qui doit s'allumer.
|
||||
expect(activeItem('/equipe/camille-ferrand')?.id).toBe('fiche');
|
||||
// Une fiche salarié est un détail de « Membres » : c'est cette entrée qui
|
||||
// reste allumée, et non un lien codé en dur vers un salarié particulier.
|
||||
expect(activeItem('/equipe/cm123abc')?.id).toBe('membres');
|
||||
expect(activeItem('/equipe')?.id).toBe('membres');
|
||||
expect(activeItem('/reglages/registre')?.id).toBe('registre');
|
||||
});
|
||||
|
||||
it('ne renvoie rien pour une route hors navigation', () => {
|
||||
@@ -47,7 +48,7 @@ describe('isActive', () => {
|
||||
typeof href === 'string' && !href.includes('#'),
|
||||
);
|
||||
|
||||
for (const pathname of [...targets, '/equipe/sarah-lemoine']) {
|
||||
for (const pathname of [...targets, '/equipe/cm123abc']) {
|
||||
const lit = NAVIGATION.flatMap((section) => section.items).filter(
|
||||
(item) => item.href && isActive(item.href, pathname),
|
||||
);
|
||||
|
||||
Reference in new issue
Block a user