feat(audit): record enterprise mutations
This commit is contained in:
@@ -2,6 +2,7 @@ package v1
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
@@ -31,12 +32,13 @@ func (s *CustomRoleHandlerTestSuite) SetupSuite() {
|
||||
Logger: logger.Default.LogMode(logger.Silent),
|
||||
})
|
||||
s.Require().NoError(err)
|
||||
s.Require().NoError(db.AutoMigrate(&model.Account{}, &model.CustomRole{}))
|
||||
s.Require().NoError(db.AutoMigrate(&model.Account{}, &model.CustomRole{}, &model.Audit{}))
|
||||
s.db = db
|
||||
|
||||
repo := repository.NewCustomRoleRepo(db)
|
||||
svc := service.NewCustomRoleService(repo)
|
||||
s.handler = NewCustomRoleHandler(svc)
|
||||
auditSvc := service.NewAuditService(repository.NewAuditRepo(db))
|
||||
s.handler = NewCustomRoleHandler(svc).WithAuditService(auditSvc)
|
||||
|
||||
s.account = &model.Account{Name: "test-custom-role-account"}
|
||||
s.Require().NoError(db.Create(s.account).Error)
|
||||
@@ -53,6 +55,11 @@ func TestCustomRoleHandlerSuite(t *testing.T) {
|
||||
suite.Run(t, new(CustomRoleHandlerTestSuite))
|
||||
}
|
||||
|
||||
func (s *CustomRoleHandlerTestSuite) SetupTest() {
|
||||
s.Require().NoError(s.db.Exec("DELETE FROM audits").Error)
|
||||
s.Require().NoError(s.db.Exec("DELETE FROM custom_roles").Error)
|
||||
}
|
||||
|
||||
func (s *CustomRoleHandlerTestSuite) TestList_Success() {
|
||||
r := gin.New()
|
||||
r.GET("/api/v1/accounts/:account_id/custom_roles", s.handler.List)
|
||||
@@ -175,4 +182,64 @@ func (s *CustomRoleHandlerTestSuite) TestDelete_Success() {
|
||||
r.ServeHTTP(w, req)
|
||||
|
||||
assert.Equal(s.T(), http.StatusNoContent, w.Code)
|
||||
}
|
||||
}
|
||||
|
||||
func (s *CustomRoleHandlerTestSuite) TestMutations_WriteAuditEntries() {
|
||||
r := gin.New()
|
||||
r.POST("/api/v1/accounts/:account_id/custom_roles", withCustomRoleAuditContext(s.account.ID, 77, s.handler.Create))
|
||||
r.PUT("/api/v1/accounts/:account_id/custom_roles/:id", withCustomRoleAuditContext(s.account.ID, 77, s.handler.Update))
|
||||
r.DELETE("/api/v1/accounts/:account_id/custom_roles/:id", withCustomRoleAuditContext(s.account.ID, 77, s.handler.Delete))
|
||||
|
||||
createBody := `{"custom_role":{"name":"audit-role","permissions":{"conversation_manage":"full"}}}`
|
||||
createReq, _ := http.NewRequest("POST", fmt.Sprintf("/api/v1/accounts/%d/custom_roles", s.account.ID), bytes.NewBufferString(createBody))
|
||||
createReq.Header.Set("Content-Type", "application/json")
|
||||
createReq.Header.Set("X-Request-ID", "audit-create-req")
|
||||
createReq.RemoteAddr = "203.0.113.20:1234"
|
||||
createW := httptest.NewRecorder()
|
||||
r.ServeHTTP(createW, createReq)
|
||||
s.Require().Equal(http.StatusCreated, createW.Code)
|
||||
|
||||
var createResp struct {
|
||||
Data model.CustomRole `json:"data"`
|
||||
}
|
||||
s.Require().NoError(json.Unmarshal(createW.Body.Bytes(), &createResp))
|
||||
roleID := createResp.Data.ID
|
||||
|
||||
updateBody := `{"custom_role":{"name":"audit-role-updated","permissions":{"contact_manage":"full"}}}`
|
||||
updateReq, _ := http.NewRequest("PUT", fmt.Sprintf("/api/v1/accounts/%d/custom_roles/%d", s.account.ID, roleID), bytes.NewBufferString(updateBody))
|
||||
updateReq.Header.Set("Content-Type", "application/json")
|
||||
updateW := httptest.NewRecorder()
|
||||
r.ServeHTTP(updateW, updateReq)
|
||||
s.Require().Equal(http.StatusOK, updateW.Code)
|
||||
|
||||
deleteReq, _ := http.NewRequest("DELETE", fmt.Sprintf("/api/v1/accounts/%d/custom_roles/%d", s.account.ID, roleID), nil)
|
||||
deleteW := httptest.NewRecorder()
|
||||
r.ServeHTTP(deleteW, deleteReq)
|
||||
s.Require().Equal(http.StatusNoContent, deleteW.Code)
|
||||
|
||||
var audits []model.Audit
|
||||
s.Require().NoError(s.db.Order("id ASC").Find(&audits).Error)
|
||||
s.Require().Len(audits, 3)
|
||||
for _, audit := range audits {
|
||||
s.Equal(s.account.ID, *audit.AccountID)
|
||||
s.Equal("Account", audit.AssociatedType)
|
||||
s.Equal(s.account.ID, *audit.AssociatedID)
|
||||
s.Equal(uint(77), *audit.UserID)
|
||||
s.Equal("User", audit.UserType)
|
||||
s.Equal("CustomRole", audit.AuditableType)
|
||||
s.Equal(roleID, audit.AuditableID)
|
||||
s.NotEmpty(audit.AuditedChanges)
|
||||
}
|
||||
s.Equal("create", audits[0].Action)
|
||||
s.Equal("audit-create-req", audits[0].RequestUUID)
|
||||
s.Equal("update", audits[1].Action)
|
||||
s.Equal("destroy", audits[2].Action)
|
||||
}
|
||||
|
||||
func withCustomRoleAuditContext(accountID uint, userID uint, h gin.HandlerFunc) gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
c.Set("account_id", accountID)
|
||||
c.Set("user_id", userID)
|
||||
h(c)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user