feat(profile): align account permissions

This commit is contained in:
2026-06-06 02:07:09 +08:00
parent 706c706ee4
commit 0fb4e6c500
3 changed files with 43 additions and 9 deletions
@@ -56,6 +56,7 @@ func (s *ProfileHandlerTestSuite) SetupSuite() {
&model.Account{},
&model.User{},
&model.AccountUser{},
&model.CustomRole{},
&model.AccessToken{},
))
s.db = db
@@ -140,9 +141,12 @@ func (s *ProfileHandlerTestSuite) SetupTest() {
"pubsub_token": "pubsub-profile-user",
})
s.db.Model(&model.AccountUser{}).Where("account_id = ? AND user_id = ?", s.accountID, s.userID).Updates(map[string]interface{}{
"availability": "offline",
"auto_offline": true,
"role": "administrator",
"custom_role_id": 0,
"availability": "offline",
"auto_offline": true,
})
s.db.Unscoped().Where("account_id = ?", s.accountID).Delete(&model.CustomRole{})
s.db.Unscoped().Where("owner_type = ? AND owner_id = ?", model.AccessTokenOwnerTypeUser, s.userID).Delete(&model.AccessToken{})
s.Require().NoError(s.db.Create(&model.AccessToken{OwnerType: model.AccessTokenOwnerTypeUser, OwnerID: s.userID, Token: "profile-token-1", TokenPrefix: "profile-", Name: "Personal Access Token"}).Error)
}
@@ -187,9 +191,36 @@ func (s *ProfileHandlerTestSuite) TestGet_Success() {
assert.Equal(s.T(), "offline", account["availability"])
assert.Equal(s.T(), "offline", account["availability_status"])
assert.Equal(s.T(), true, account["auto_offline"])
assert.Equal(s.T(), []interface{}{"administrator"}, account["permissions"])
}
}
func (s *ProfileHandlerTestSuite) TestGet_CustomRolePermissions() {
role := &model.CustomRole{AccountID: s.accountID, Name: "Support Lead"}
s.Require().NoError(role.SetPermissionKeys([]model.PermissionDimension{
model.DimensionConversationManage,
model.DimensionContactManage,
}))
s.Require().NoError(s.db.Create(role).Error)
s.Require().NoError(s.db.Model(&model.AccountUser{}).
Where("account_id = ? AND user_id = ?", s.accountID, s.userID).
Updates(map[string]interface{}{"role": "agent", "custom_role_id": role.ID}).Error)
req, _ := http.NewRequest("GET", "/api/v1/profile", nil)
w := httptest.NewRecorder()
s.router.ServeHTTP(w, req)
assert.Equal(s.T(), http.StatusOK, w.Code)
payload := s.decodeProfileBody(w)
account := s.firstAccountFromProfile(payload)
assert.Equal(s.T(), "agent", account["role"])
assert.Equal(s.T(), []interface{}{"conversation_manage", "contact_manage", "custom_role"}, account["permissions"])
assert.Equal(s.T(), float64(role.ID), account["custom_role_id"])
customRole := account["custom_role"].(map[string]interface{})
assert.Equal(s.T(), "Support Lead", customRole["name"])
assert.Equal(s.T(), []interface{}{"conversation_manage", "contact_manage"}, customRole["permissions"])
}
func (s *ProfileHandlerTestSuite) TestGet_Unauthorized() {
// Create router without auth middleware — user_id will be 0
r := gin.New()
+3 -2
View File
@@ -407,7 +407,8 @@ func profileAccountResponse(accountUser model.AccountUser) ProfileAccountRespons
activeAt := timeStringPtr(accountUser.ActiveAt)
availability := defaultString(accountUser.Availability, "offline")
status := defaultString(accountUser.Account.Status, "active")
permissions := []string{}
role := defaultString(accountUser.Role, "agent")
permissions := []string{role}
var customRole any
var customRoleID *uint
if accountUser.CustomRole != nil && accountUser.CustomRoleID > 0 {
@@ -434,7 +435,7 @@ func profileAccountResponse(accountUser model.AccountUser) ProfileAccountRespons
Status: status,
OnboardingStep: accountUser.Account.OnboardingStep,
ActiveAt: activeAt,
Role: accountUser.Role,
Role: role,
Permissions: permissions,
Availability: availability,
AvailabilityStatus: availability,