feat: add role-based permission system

This commit is contained in:
2026-03-26 11:54:24 -05:00
parent 22f0ded88f
commit fdc27584c9
2 changed files with 99 additions and 0 deletions
+43
View File
@@ -0,0 +1,43 @@
import { describe, it, expect } from 'vitest';
import { hasPermission, canViewPets, type Role, type Permission } from '$lib/roles';
describe('roles', () => {
it('sysadmin has all permissions', () => {
const perms: Permission[] = [
'dashboard', 'pets', 'pets_view', 'applications', 'sponsors',
'donations', 'expenses', 'vets', 'medical', 'events', 'content',
'volunteers', 'users', 'shop', 'import', 'system'
];
for (const perm of perms) {
expect(hasPermission('sysadmin', perm)).toBe(true);
}
});
it('director has all except system', () => {
expect(hasPermission('director', 'pets')).toBe(true);
expect(hasPermission('director', 'system')).toBe(false);
});
it('foster has only dashboard', () => {
expect(hasPermission('foster', 'dashboard')).toBe(true);
expect(hasPermission('foster', 'pets')).toBe(false);
expect(hasPermission('foster', 'users')).toBe(false);
});
it('viewer has only dashboard', () => {
expect(hasPermission('viewer', 'dashboard')).toBe(true);
expect(hasPermission('viewer', 'pets')).toBe(false);
});
it('applications_manager can view pets but not edit', () => {
expect(hasPermission('applications_manager', 'applications')).toBe(true);
expect(hasPermission('applications_manager', 'pets_view')).toBe(true);
expect(hasPermission('applications_manager', 'pets')).toBe(false);
});
it('canViewPets returns true for roles with pets or pets_view', () => {
expect(canViewPets('sysadmin')).toBe(true);
expect(canViewPets('applications_manager')).toBe(true);
expect(canViewPets('viewer')).toBe(false);
});
});