Scope workspace roots per account
This commit is contained in:
@@ -5,10 +5,11 @@ from __future__ import annotations
|
||||
import tempfile
|
||||
import unittest
|
||||
import os
|
||||
import json
|
||||
from pathlib import Path
|
||||
from unittest.mock import patch
|
||||
|
||||
from app import workspace
|
||||
from app import auth, workspace
|
||||
|
||||
|
||||
class WorkspaceChangeTests(unittest.TestCase):
|
||||
@@ -99,10 +100,49 @@ class WorkspaceChangeTests(unittest.TestCase):
|
||||
{"SOVEREIGNAI_ALLOWED_WORKSPACES": str(allowed)},
|
||||
clear=False,
|
||||
):
|
||||
with self.assertRaisesRegex(ValueError, "خارج مجلدات المشاريع"):
|
||||
with self.assertRaisesRegex(ValueError, "خارج مساحة العمل"):
|
||||
workspace.selected_root(str(outside))
|
||||
self.assertEqual(workspace.selected_root(str(nested)), nested.resolve())
|
||||
|
||||
def test_account_workspaces_are_separate_and_admin_config_must_not_overlap(self) -> None:
|
||||
allowed = self.root / "accounts"
|
||||
first_root = allowed / "first"
|
||||
second_root = allowed / "second"
|
||||
first_root.mkdir(parents=True)
|
||||
second_root.mkdir()
|
||||
config = {
|
||||
"first@example.test": [str(first_root)],
|
||||
"second@example.test": [str(second_root)],
|
||||
}
|
||||
with (
|
||||
patch.dict(
|
||||
os.environ,
|
||||
{
|
||||
"SOVEREIGNAI_ALLOWED_WORKSPACES": str(allowed),
|
||||
"SOVEREIGNAI_USER_WORKSPACES": json.dumps(config),
|
||||
},
|
||||
clear=False,
|
||||
),
|
||||
patch.object(
|
||||
auth,
|
||||
"account_email",
|
||||
side_effect=lambda user_id: {
|
||||
"user-first": "first@example.test",
|
||||
"user-second": "second@example.test",
|
||||
}.get(user_id),
|
||||
),
|
||||
):
|
||||
self.assertEqual(
|
||||
workspace.selected_root(str(first_root), user_id="user-first"),
|
||||
first_root.resolve(),
|
||||
)
|
||||
with self.assertRaisesRegex(ValueError, "خارج مساحة العمل"):
|
||||
workspace.selected_root(str(second_root), user_id="user-first")
|
||||
config["second@example.test"] = [str(allowed)]
|
||||
os.environ["SOVEREIGNAI_USER_WORKSPACES"] = json.dumps(config)
|
||||
with self.assertRaisesRegex(ValueError, "متداخلة"):
|
||||
workspace.selected_root(str(first_root), user_id="user-first")
|
||||
|
||||
def test_rejects_create_overwrite_and_update_of_missing_file(self) -> None:
|
||||
target = self.root / "src" / "existing.py"
|
||||
target.write_text("value = 1\n", encoding="utf-8")
|
||||
|
||||
Reference in New Issue
Block a user