Restructures into apps/ssp + apps/behandelportal (two Angular projects) plus libs/shared + libs/beheer (cross-app libraries), replacing WP-61's separate sibling repo. That split had already produced real drift: a hand-vendored copy of the backend's OpenAPI doc, a shared/ui+layout tree forked and silently diverging (7 files), and beheer + the styles.scss token bridge duplicated byte-for-byte across both repos. - git mv the SSP's src/app/* into apps/ssp/; fold shared/, beheer/, environments/, the Storybook docs/*.mdx, and styles.scss into libs/shared + libs/beheer (all confirmed identical between the two repos before merging). auth stays deliberately duplicated per ADR-0002 (actor-specific, expected to diverge) - amended there. - One generated API client (libs/shared), no more vendored swagger.json. - .dependency-cruiser split into a base factory + one config per app, and Storybook into .storybook-ssp/.storybook-behandelportal - both forced by the @auth/* alias resolving to different directories per app. - SiteHeaderComponent/ShellComponent gained HEADER_NAV_ITEMS/ HEADER_ADMIN_LINKS/DEBUG_PANEL injection tokens so each app supplies its own nav/admin-links/dev-panel instead of one being hardcoded. - CLAUDE.md, ARCHITECTURE.md, dependencies.md, and ADR-0002 updated; WP-67 backlog entry documents the full decision trail. npm run ci green (lint, dep:check x2, 360 tests across ssp/ behandelportal/shared/beheer, both localized builds, backend tests, snippet + api-client drift); both dev servers, both Storybook instances, and docker compose verified working. The old sibling repo (/home/eho/repos/behandelportal) is left untouched, not deleted. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
55 lines
2.0 KiB
TypeScript
55 lines
2.0 KiB
TypeScript
import { describe, it, expect, beforeEach, afterEach } from 'vitest';
|
|
import { roleInterceptor } from './role.interceptor';
|
|
|
|
// currentRole() reads window.location.search; set it via the real URL rather than
|
|
// vi.mock (the Angular unit-test system forbids mocking relative imports).
|
|
beforeEach(() => window.history.replaceState({}, '', '/?role=admin'));
|
|
afterEach(() => {
|
|
window.history.replaceState({}, '', '/');
|
|
sessionStorage.clear(); // currentRole() now persists the dev role; don't leak across tests
|
|
});
|
|
|
|
// Minimal stand-in for HttpRequest — the interceptor only reads `url` and calls
|
|
// `clone({ setHeaders })`. Avoids importing @angular/common/http (its XHR chunk needs
|
|
// the JIT compiler under vitest).
|
|
function fakeReq(url: string) {
|
|
const make = (headers: Map<string, string>) => ({
|
|
url,
|
|
headers,
|
|
clone(opts: { setHeaders: Record<string, string> }) {
|
|
const next = new Map(headers);
|
|
for (const [k, v] of Object.entries(opts.setHeaders)) next.set(k, v);
|
|
return make(next);
|
|
},
|
|
});
|
|
return make(new Map());
|
|
}
|
|
|
|
/** Run the interceptor and return the request it forwarded to `next`. */
|
|
function forward(url: string) {
|
|
let seen!: ReturnType<typeof fakeReq>;
|
|
const next = (r: ReturnType<typeof fakeReq>) => {
|
|
seen = r;
|
|
return undefined;
|
|
};
|
|
// Cast: the fake matches the shape the interceptor actually touches.
|
|
(roleInterceptor as unknown as (req: unknown, next: unknown) => unknown)(fakeReq(url), next);
|
|
return seen;
|
|
}
|
|
|
|
describe('roleInterceptor', () => {
|
|
it.each([
|
|
'/api/v1/brief',
|
|
'/api/v1/admin/org-template',
|
|
'/api/v1/stamdata', // WP-29: the admin stamdata reads 403 without X-Role
|
|
'/api/v1/stamdata/professions?peildatum=1999-01-01',
|
|
'/api/v1/me',
|
|
])('stamps X-Role on the role-aware endpoint %s', (url) => {
|
|
expect(forward(url).headers.get('X-Role')).toBe('admin');
|
|
});
|
|
|
|
it('leaves an unrelated endpoint untouched', () => {
|
|
expect(forward('/api/v1/duo/diplomas').headers.has('X-Role')).toBe(false);
|
|
});
|
|
});
|