Files
planflow/tests/unit/tenant-scope.test.ts
T
Claude 92667b16b9 WP-02: locations, teams and the legal configuration register
Adds the referential models, the first database-backed settings
screens, and the register the compliance matrix requires before any
parameter is enforceable.

The register is the point of the lot. The matrix is explicit that
copying another product's configuration is not enough — each parameter
must carry its value, source, effective date, population and an
approver. Approval records the session's actor, never a form field: a
signature you can type yourself is worth nothing. The screen names the
domains that have no approved parameter yet, so the gap is visible
rather than assumed closed.

Two bugs of the same family, both now structurally impossible:

- The Prisma scoping extension read a hand-written list of models
  carrying accountId. The four models added here were missing from it,
  so writes failed with an opaque Prisma error — and a read would have
  silently returned every account's rows. The list is now derived from
  the schema itself.
- The RLS policies were likewise per-table. A new integration test
  fails if any table with an accountId column lacks forced RLS and both
  policies, which is the failure mode that hides best: nobody writes a
  wrong rule, someone forgets to write one.

An end-to-end test signs in as a manager and confirms the settings
screens refuse to render — the sidebar hiding them is a convenience,
the server check is the control.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
2026-08-07 23:04:26 +00:00

50 lines
1.6 KiB
TypeScript
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
import { Prisma } from '@prisma/client';
import { describe, expect, it } from 'vitest';
/**
* Le scoping multi-tenant se dérive du schéma Prisma.
*
* Ce test protège la dérivation elle-même : le mode de défaillance n'est pas
* d'écrire une mauvaise règle, c'est d'ajouter un modèle et d'oublier de le
* déclarer quelque part. Il a déjà été rencontré une fois — quatre modèles
* ajoutés au WP-02 échappaient au filtre.
*/
describe('modèles scopés', () => {
const scoped = Prisma.dmmf.datamodel.models.filter((model) =>
model.fields.some(
(field) => field.name === 'accountId' && field.kind === 'scalar',
),
);
it('détecte tous les modèles portant accountId', () => {
expect(scoped.length).toBeGreaterThanOrEqual(13);
});
it('couvre les modèles connus du périmètre', () => {
const names = new Set(scoped.map((model) => model.name));
for (const model of [
'Location',
'Team',
'Membership',
'Role',
'AuditLog',
'JobTitle',
'Label',
'AbsenceType',
'LegalConfigEntry',
'RetentionPolicy',
]) {
expect(names.has(model), `${model} doit être scopé`).toBe(true);
}
});
it('n’inclut pas les modèles volontairement globaux', () => {
const names = new Set(scoped.map((model) => model.name));
// Permission est un référentiel produit ; User et Session vivent avant
// qu'un compte soit connu, au moment de l'authentification.
for (const model of ['Permission', 'User', 'Session', 'Account']) {
expect(names.has(model), `${model} ne doit pas être scopé`).toBe(false);
}
});
});