Scope workspace roots per account

This commit is contained in:
Hamza Ayed
2026-10-03 01:44:00 +03:00
parent 1b56f70aa6
commit 4345e43e29
10 changed files with 250 additions and 54 deletions
@@ -5,10 +5,11 @@ from __future__ import annotations
import tempfile
import unittest
import os
import json
from pathlib import Path
from unittest.mock import patch
from app import workspace
from app import auth, workspace
class WorkspaceChangeTests(unittest.TestCase):
@@ -99,10 +100,49 @@ class WorkspaceChangeTests(unittest.TestCase):
{"SOVEREIGNAI_ALLOWED_WORKSPACES": str(allowed)},
clear=False,
):
with self.assertRaisesRegex(ValueError, "خارج مجلدات المشاريع"):
with self.assertRaisesRegex(ValueError, "خارج مساحة العمل"):
workspace.selected_root(str(outside))
self.assertEqual(workspace.selected_root(str(nested)), nested.resolve())
def test_account_workspaces_are_separate_and_admin_config_must_not_overlap(self) -> None:
allowed = self.root / "accounts"
first_root = allowed / "first"
second_root = allowed / "second"
first_root.mkdir(parents=True)
second_root.mkdir()
config = {
"first@example.test": [str(first_root)],
"second@example.test": [str(second_root)],
}
with (
patch.dict(
os.environ,
{
"SOVEREIGNAI_ALLOWED_WORKSPACES": str(allowed),
"SOVEREIGNAI_USER_WORKSPACES": json.dumps(config),
},
clear=False,
),
patch.object(
auth,
"account_email",
side_effect=lambda user_id: {
"user-first": "first@example.test",
"user-second": "second@example.test",
}.get(user_id),
),
):
self.assertEqual(
workspace.selected_root(str(first_root), user_id="user-first"),
first_root.resolve(),
)
with self.assertRaisesRegex(ValueError, "خارج مساحة العمل"):
workspace.selected_root(str(second_root), user_id="user-first")
config["second@example.test"] = [str(allowed)]
os.environ["SOVEREIGNAI_USER_WORKSPACES"] = json.dumps(config)
with self.assertRaisesRegex(ValueError, "متداخلة"):
workspace.selected_root(str(first_root), user_id="user-first")
def test_rejects_create_overwrite_and_update_of_missing_file(self) -> None:
target = self.root / "src" / "existing.py"
target.write_text("value = 1\n", encoding="utf-8")