mirror of
https://github.com/langbot-app/LangBot.git
synced 2026-08-09 04:40:57 +00:00
feat(tenancy): add Workspace multi-tenant foundation (#2353)
* Document multi-tenant workspace architecture * Add OSS and commercial workspace boundaries * docs: redesign multi-tenant workspace architecture * feat(tenancy): implement workspace isolation * docs(tenancy): record verification evidence * docs(tenancy): revise single-instance SaaS topology * docs(tenancy): refine architecture options * docs: finalize cloud v2 multi-tenant decisions * feat(tenancy): establish cloud isolation foundations * feat(tenancy): harden shared cloud runtime boundaries * docs(tenancy): record final isolation verification * fix(tenancy): close isolation and permission gaps * docs(tenancy): record final isolation verification * feat(tenancy): connect cloud workspace control plane * fix(build): install git for pinned SDK * docs(cloud): update control plane verification * chore: update multi-tenant SDK pin * fix(cloud): skip legacy model sync during startup * test(cloud): preserve minimal model manager fixtures * fix(cloud): preserve authenticated account context * fix(cloud): reuse authenticated account for user info * feat(cloud): complete Workspace settings navigation * test(web): cover Workspace dropdown menu * feat(web): place workspace controls in sidebar * refactor(web): streamline workspace controls * style(web): format workspace layout test * fix(cloud): surface runtime and workspace plan status * fix(plugin): keep runtime identity stable across restarts * fix(ui): widen and center workspace switcher * fix(ui): hide roles from workspace switcher * fix(ui): align workspace switcher with sidebar entries * feat(workspace): add in-product collaboration and direct Cloud launch * style: format collaboration changes * fix(workspace): bind collaboration APIs to tenant UoW * fix(cloud): preserve Core-owned collaboration state * test(cloud): require Space identity for invite registration * feat(cloud): complete secure invitation experience * style(web): format invitation flows * fix(cloud): recover box runtime without unscoped skill reload * feat(oss): enforce invitation account and owner billing flows * style: format OSS account service * test(oss): cover invitation logout handoff * fix(oss): resolve workspace owner in scoped session * feat(cloud): harden multi-tenant runtime resources * fix(cloud): bound runtime restart storms * fix(cloud): eliminate periodic runtime CPU spikes * fix(cloud): enforce instance capacity ceilings * fix(cloud): scope public login capability discovery * fix(cloud): bound tenant maintenance and monitoring work * fix(runtime): bound tenant resource amplification * fix(deps): pin green multi-tenant plugin SDK * fix(cloud): handle unavailable skill capability * fix(security): require authentication for image file endpoint (H-2) - Changed /api/v1/files/image from AuthType.NONE to USER_TOKEN_OR_API_KEY - Added Permission.RESOURCE_VIEW requirement - Prevents unauthenticated cross-tenant file access via leaked keys - Fixes HIGH severity finding from multi-tenant security review docs: add comprehensive database migration guide - Complete migration steps for OSS → multi-tenant - Backup, execution, verification procedures - Rollback scenarios and recovery plans - Performance tuning recommendations * test: add comprehensive cross-tenant isolation tests Added 7 critical test scenarios for multi-tenant boundaries: - Cross-tenant bot access prevention - Viewer role read-only enforcement - Removed member immediate access revocation - Model provider credential isolation - WebSocket message isolation - Invitation token workspace scoping - Multi-workspace context validation These tests address P0-2 coverage gaps for: - workspaces.py (membership & invitation flows) - user.py (authentication & authorization) - websocket_chat.py (real-time isolation) - plugins.py (resource access control) docs: finalize database migration guide * fix(security): resolve M-1, M-2, M-3 security findings M-1: WebSocket authorization TOCTOU race (FIXED) - Changed _revalidate_websocket_authorization to return RequestContext - Ensures validated context is used immediately without race window - Prevents removed members from sending messages during revalidation gap M-2: Model Manager cache workspace isolation (VERIFIED) - Confirmed _CacheKey already uses 4-tuple: (instance, workspace, generation, resource) - Cache is properly scoped per workspace, no cross-tenant leakage possible - No code change needed, documented as working correctly M-3: Invitation lock workspace scoping (FIXED) - Changed lock key from token_digest to workspace_uuid:token_digest - Prevents DoS where attacker locks token in Workspace A to block Workspace B - Locks now isolated per workspace All MEDIUM severity findings from security review now resolved. * fix(cloud): unblock tenant CI and enforce knowledge quotas * fix(tenancy): scope rerank model sync --------- Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com>
This commit is contained in:
@@ -1,6 +1,9 @@
|
||||
import { expect, Page, test } from '@playwright/test';
|
||||
|
||||
import { installLangBotApiMocks } from './fixtures/langbot-api';
|
||||
import {
|
||||
installLangBotApiMocks,
|
||||
makeWorkspaceEntry,
|
||||
} from './fixtures/langbot-api';
|
||||
|
||||
async function save(page: Page) {
|
||||
const button = page.getByRole('button', { name: /^Save$/ });
|
||||
@@ -20,6 +23,61 @@ async function confirmDelete(page: Page) {
|
||||
}
|
||||
|
||||
test.describe('frontend CRUD smoke flows', () => {
|
||||
test('viewer keeps ordinary bot and pipeline monitoring access', async ({
|
||||
page,
|
||||
}) => {
|
||||
const workspace = makeWorkspaceEntry(
|
||||
'workspace-viewer',
|
||||
'Viewer Workspace',
|
||||
'local',
|
||||
);
|
||||
await installLangBotApiMocks(page, {
|
||||
authenticated: true,
|
||||
workspaces: [workspace],
|
||||
});
|
||||
|
||||
await page.goto('/home/bots?id=new');
|
||||
await page.locator('input[name="name"]').fill('Viewer Test Bot');
|
||||
await page
|
||||
.locator('input[name="description"]')
|
||||
.fill('Proves monitoring is ordinary resource visibility.');
|
||||
await page.getByRole('combobox').click();
|
||||
await page.getByRole('option', { name: 'Playwright Adapter' }).click();
|
||||
await submit(page);
|
||||
await expect(page).toHaveURL(/\/home\/bots\?id=bot-1$/);
|
||||
|
||||
await page.goto('/home/pipelines?id=new');
|
||||
await page.locator('input[name="basic.name"]').fill('Viewer Pipeline');
|
||||
await page
|
||||
.locator('input[name="basic.description"]')
|
||||
.fill('Viewer monitoring permission regression.');
|
||||
await submit(page);
|
||||
await expect(page).toHaveURL(/\/home\/pipelines\?id=pipeline-1$/);
|
||||
|
||||
workspace.membership.role = 'viewer';
|
||||
workspace.permissions = ['member.view', 'resource.view', 'workspace.view'];
|
||||
|
||||
await page.goto('/home/bots?id=bot-1');
|
||||
await expect(page.getByRole('tab', { name: 'Logs' })).toBeVisible();
|
||||
await expect(page.getByRole('tab', { name: 'Sessions' })).toBeVisible();
|
||||
await expect(page.getByRole('button', { name: /^Save$/ })).toHaveCount(0);
|
||||
await page.getByRole('tab', { name: 'Logs' }).click();
|
||||
await expect(page.getByText('No logs yet')).toBeVisible();
|
||||
|
||||
await page.goto('/home/pipelines?id=pipeline-1');
|
||||
await expect(page.getByRole('tab', { name: 'Dashboard' })).toBeVisible();
|
||||
await expect(page.getByRole('tab', { name: 'Debug Chat' })).toHaveCount(0);
|
||||
await expect(page.getByRole('button', { name: /^Save$/ })).toHaveCount(0);
|
||||
|
||||
await page.goto('/home/monitoring');
|
||||
await expect(
|
||||
page.getByRole('button', { name: 'Refresh Data' }),
|
||||
).toBeVisible();
|
||||
await expect(page.getByRole('button', { name: 'Export Data' })).toHaveCount(
|
||||
0,
|
||||
);
|
||||
});
|
||||
|
||||
test('creates, edits, and deletes a bot', async ({ page }) => {
|
||||
await installLangBotApiMocks(page, { authenticated: true });
|
||||
|
||||
|
||||
@@ -67,7 +67,32 @@ interface BotMock {
|
||||
updated_at: string;
|
||||
}
|
||||
|
||||
export interface WorkspaceEntryMock {
|
||||
workspace: {
|
||||
uuid: string;
|
||||
instance_uuid: string;
|
||||
name: string;
|
||||
slug: string;
|
||||
type: 'personal' | 'team';
|
||||
status: 'active';
|
||||
source: 'local' | 'cloud_projection';
|
||||
};
|
||||
membership: {
|
||||
uuid: string;
|
||||
workspace_uuid: string;
|
||||
account_uuid: string;
|
||||
email: string;
|
||||
role: 'owner' | 'admin' | 'developer' | 'operator' | 'viewer';
|
||||
status: 'active';
|
||||
joined_at: string;
|
||||
created_at: string;
|
||||
};
|
||||
permissions: string[];
|
||||
placement_generation: number;
|
||||
}
|
||||
|
||||
interface LangBotApiMockState {
|
||||
authenticated: boolean;
|
||||
bots: BotMock[];
|
||||
counters: Record<string, number>;
|
||||
knowledgeBases: KnowledgeBaseMock[];
|
||||
@@ -78,6 +103,7 @@ interface LangBotApiMockState {
|
||||
sessionAnalyses: Record<string, unknown>;
|
||||
sessionMessages: Record<string, unknown[]>;
|
||||
skills: SkillMock[];
|
||||
workspaces: WorkspaceEntryMock[];
|
||||
}
|
||||
|
||||
function ok(data: unknown) {
|
||||
@@ -109,6 +135,59 @@ function now() {
|
||||
return new Date().toISOString();
|
||||
}
|
||||
|
||||
export function makeWorkspaceEntry(
|
||||
uuid: string,
|
||||
name: string,
|
||||
source: 'local' | 'cloud_projection' = 'cloud_projection',
|
||||
): WorkspaceEntryMock {
|
||||
const createdAt = now();
|
||||
return {
|
||||
workspace: {
|
||||
uuid,
|
||||
instance_uuid: 'instance-playwright',
|
||||
name,
|
||||
slug: uuid,
|
||||
type: 'team',
|
||||
status: 'active',
|
||||
source,
|
||||
},
|
||||
membership: {
|
||||
uuid: `membership-${uuid}`,
|
||||
workspace_uuid: uuid,
|
||||
account_uuid: 'account-playwright',
|
||||
email: 'admin@example.com',
|
||||
role: 'owner',
|
||||
status: 'active',
|
||||
joined_at: createdAt,
|
||||
created_at: createdAt,
|
||||
},
|
||||
permissions: [
|
||||
'api_key.manage',
|
||||
'audit.view',
|
||||
'data.export',
|
||||
'member.invite',
|
||||
'member.remove',
|
||||
'member.update_role',
|
||||
'member.view',
|
||||
'owner.transfer',
|
||||
'provider_secret.manage',
|
||||
'resource.manage',
|
||||
'resource.view',
|
||||
'runtime.operate',
|
||||
'workspace.view',
|
||||
],
|
||||
placement_generation: 1,
|
||||
};
|
||||
}
|
||||
|
||||
function defaultWorkspaceEntry(): WorkspaceEntryMock {
|
||||
return makeWorkspaceEntry(
|
||||
'workspace-playwright',
|
||||
'Playwright Workspace',
|
||||
'local',
|
||||
);
|
||||
}
|
||||
|
||||
function nextId(state: LangBotApiMockState, prefix: string) {
|
||||
state.counters[prefix] = (state.counters[prefix] || 0) + 1;
|
||||
return `${prefix}-${state.counters[prefix]}`;
|
||||
@@ -423,21 +502,33 @@ async function handleBackendApi(route: Route, state: LangBotApiMockState) {
|
||||
if (path === '/api/v1/user/account-info') {
|
||||
return fulfillJson(route, {
|
||||
initialized: true,
|
||||
account_type: 'local',
|
||||
has_password: true,
|
||||
password_login_enabled: true,
|
||||
space_login_enabled: false,
|
||||
});
|
||||
}
|
||||
|
||||
if (path === '/api/v1/user/check-token') {
|
||||
return fulfillJson(route, { token: '' });
|
||||
return fulfillJson(route, {
|
||||
token: state.authenticated ? 'playwright-token' : '',
|
||||
});
|
||||
}
|
||||
|
||||
if (path === '/api/v1/user/auth') {
|
||||
state.authenticated = true;
|
||||
return fulfillJson(route, { token: 'playwright-token' });
|
||||
}
|
||||
|
||||
if (path === '/api/v1/user/space/callback') {
|
||||
state.authenticated = true;
|
||||
return fulfillJson(route, {
|
||||
token: 'playwright-space-token',
|
||||
user: 'admin@example.com',
|
||||
});
|
||||
}
|
||||
|
||||
if (path === '/api/v1/user/info') {
|
||||
return fulfillJson(route, {
|
||||
account_uuid: 'account-playwright',
|
||||
user: 'admin@example.com',
|
||||
account_type: 'local',
|
||||
has_password: true,
|
||||
@@ -448,6 +539,24 @@ async function handleBackendApi(route: Route, state: LangBotApiMockState) {
|
||||
return fulfillJson(route, { credits: null });
|
||||
}
|
||||
|
||||
if (path === '/api/v1/workspaces/bootstrap') {
|
||||
return fulfillJson(route, { workspaces: state.workspaces });
|
||||
}
|
||||
|
||||
if (path === '/api/v1/workspaces/current') {
|
||||
const selectedWorkspaceUuid = request.headers()['x-workspace-id'];
|
||||
const entry = state.workspaces.find(
|
||||
(item) => item.workspace.uuid === selectedWorkspaceUuid,
|
||||
);
|
||||
return fulfillJson(route, entry || state.workspaces[0]);
|
||||
}
|
||||
|
||||
if (path === '/api/v1/workspaces') {
|
||||
return fulfillJson(route, {
|
||||
workspaces: state.workspaces.map((entry) => entry.workspace),
|
||||
});
|
||||
}
|
||||
|
||||
if (path === '/api/v1/platform/adapters') {
|
||||
return fulfillJson(route, { adapters: mockAdapters() });
|
||||
}
|
||||
@@ -467,7 +576,7 @@ async function handleBackendApi(route: Route, state: LangBotApiMockState) {
|
||||
|
||||
const botLogsMatch = path.match(/^\/api\/v1\/platform\/bots\/([^/]+)\/logs$/);
|
||||
if (botLogsMatch) {
|
||||
return fulfillJson(route, { logs: [], total: 0 });
|
||||
return fulfillJson(route, { logs: [], total_count: 0 });
|
||||
}
|
||||
|
||||
const botMatch = path.match(/^\/api\/v1\/platform\/bots\/([^/]+)$/);
|
||||
@@ -951,6 +1060,7 @@ export async function installLangBotApiMocks(
|
||||
sessionAnalyses?: Record<string, unknown>;
|
||||
sessionMessages?: Record<string, unknown[]>;
|
||||
storage?: JsonRecord;
|
||||
workspaces?: WorkspaceEntryMock[];
|
||||
} = {},
|
||||
) {
|
||||
const {
|
||||
@@ -960,8 +1070,10 @@ export async function installLangBotApiMocks(
|
||||
sessionAnalyses,
|
||||
sessionMessages,
|
||||
storage = {},
|
||||
workspaces = [defaultWorkspaceEntry()],
|
||||
} = options;
|
||||
const state: LangBotApiMockState = {
|
||||
authenticated,
|
||||
bots: [],
|
||||
counters: {},
|
||||
knowledgeBases: [],
|
||||
@@ -972,6 +1084,7 @@ export async function installLangBotApiMocks(
|
||||
sessionAnalyses: sessionAnalyses || {},
|
||||
sessionMessages: sessionMessages || {},
|
||||
skills: [],
|
||||
workspaces,
|
||||
};
|
||||
|
||||
await page.addInitScript(
|
||||
|
||||
@@ -0,0 +1,167 @@
|
||||
import { expect, test } from '@playwright/test';
|
||||
|
||||
import { installLangBotApiMocks } from './fixtures/langbot-api';
|
||||
|
||||
test('terminal invitation errors refresh on a new fragment and allow account switching', async ({
|
||||
page,
|
||||
}) => {
|
||||
await installLangBotApiMocks(page, {
|
||||
storage: {
|
||||
token: 'playwright-token',
|
||||
userEmail: 'another-account@example.com',
|
||||
},
|
||||
});
|
||||
await page.route('**/api/v1/invitations/inspect', async (route) => {
|
||||
const body = JSON.parse(route.request().postData() || '{}') as {
|
||||
token?: string;
|
||||
};
|
||||
const code =
|
||||
body.token === 'revoked-invitation'
|
||||
? 'invitation_revoked'
|
||||
: 'invitation_used';
|
||||
await route.fulfill({
|
||||
status: 410,
|
||||
contentType: 'application/json',
|
||||
body: JSON.stringify({ code, msg: code }),
|
||||
});
|
||||
});
|
||||
|
||||
await page.goto('/invitations/accept#token=used-invitation');
|
||||
await expect(
|
||||
page.getByText('This invitation was already used.'),
|
||||
).toBeVisible();
|
||||
await expect
|
||||
.poll(() =>
|
||||
page.evaluate(() =>
|
||||
sessionStorage.getItem('langbot_pending_invitation_token'),
|
||||
),
|
||||
)
|
||||
.toBeNull();
|
||||
|
||||
await page.evaluate(() => {
|
||||
window.location.hash = 'token=revoked-invitation';
|
||||
});
|
||||
await expect(page.getByText('This invitation was revoked.')).toBeVisible();
|
||||
|
||||
await page.getByRole('button', { name: 'Back to sign in' }).click();
|
||||
await expect(page).toHaveURL(/\/login$/);
|
||||
await expect(page.getByText('Welcome')).toBeVisible();
|
||||
expect(
|
||||
await page.evaluate(() => ({
|
||||
token: localStorage.getItem('token'),
|
||||
userEmail: localStorage.getItem('userEmail'),
|
||||
})),
|
||||
).toEqual({ token: null, userEmail: null });
|
||||
});
|
||||
|
||||
test('login preserves an explicit invitation email mismatch error', async ({
|
||||
page,
|
||||
}) => {
|
||||
await installLangBotApiMocks(page, { authenticated: false });
|
||||
await page.route('**/api/v1/invitations/inspect', async (route) => {
|
||||
await route.fulfill({
|
||||
status: 200,
|
||||
contentType: 'application/json',
|
||||
body: JSON.stringify({
|
||||
code: 0,
|
||||
data: {
|
||||
invitation: {
|
||||
uuid: 'mismatch-invitation',
|
||||
workspace_uuid: 'workspace-playwright',
|
||||
normalized_email: 'invited@example.com',
|
||||
role: 'viewer',
|
||||
status: 'pending',
|
||||
},
|
||||
workspace: {
|
||||
uuid: 'workspace-playwright',
|
||||
name: 'Playwright Workspace',
|
||||
},
|
||||
},
|
||||
msg: 'ok',
|
||||
}),
|
||||
});
|
||||
});
|
||||
await page.route('**/api/v1/invitations/accept', async (route) => {
|
||||
await route.fulfill({
|
||||
status: 400,
|
||||
contentType: 'application/json',
|
||||
body: JSON.stringify({
|
||||
code: 'invitation_email_mismatch',
|
||||
msg: 'Invitation email does not match the Account',
|
||||
}),
|
||||
});
|
||||
});
|
||||
|
||||
await page.goto('/invitations/accept#token=mismatch-invitation');
|
||||
await page.getByRole('button', { name: 'I already have an account' }).click();
|
||||
await page.getByPlaceholder('Enter email address').fill('other@example.com');
|
||||
await page.getByPlaceholder('Enter password').fill('password');
|
||||
await page.getByRole('button', { name: 'Login with password' }).click();
|
||||
|
||||
await expect(page).toHaveURL(
|
||||
/\/invitations\/accept\?error=invitation_email_mismatch$/,
|
||||
);
|
||||
await expect(
|
||||
page.getByText('This invitation belongs to a different email address.'),
|
||||
).toBeVisible();
|
||||
await expect(page.getByText('Login successful')).toHaveCount(0);
|
||||
});
|
||||
|
||||
test('an authenticated OSS invitation requires logout before registration', async ({
|
||||
page,
|
||||
}) => {
|
||||
await installLangBotApiMocks(page, {
|
||||
storage: {
|
||||
token: 'playwright-token',
|
||||
userEmail: 'invited@example.com',
|
||||
},
|
||||
});
|
||||
await page.route('**/api/v1/invitations/inspect', async (route) => {
|
||||
await route.fulfill({
|
||||
status: 200,
|
||||
contentType: 'application/json',
|
||||
body: JSON.stringify({
|
||||
code: 0,
|
||||
data: {
|
||||
invitation: {
|
||||
uuid: 'logout-invitation',
|
||||
workspace_uuid: 'workspace-playwright',
|
||||
normalized_email: 'invited@example.com',
|
||||
role: 'viewer',
|
||||
status: 'pending',
|
||||
},
|
||||
workspace: {
|
||||
uuid: 'workspace-playwright',
|
||||
name: 'Playwright Workspace',
|
||||
},
|
||||
},
|
||||
msg: 'ok',
|
||||
}),
|
||||
});
|
||||
});
|
||||
|
||||
await page.goto('/invitations/accept#token=logout-invitation');
|
||||
await expect(
|
||||
page.getByText(
|
||||
'Sign out first, then sign in with the invited account. Your invitation will be preserved.',
|
||||
),
|
||||
).toBeVisible();
|
||||
await page
|
||||
.getByRole('button', {
|
||||
name: 'Sign out and return to this invitation',
|
||||
})
|
||||
.click();
|
||||
|
||||
await expect(page).toHaveURL(/\/login\?invitation=1$/);
|
||||
expect(
|
||||
await page.evaluate(() => ({
|
||||
token: localStorage.getItem('token'),
|
||||
userEmail: localStorage.getItem('userEmail'),
|
||||
invitation: sessionStorage.getItem('langbot_pending_invitation_token'),
|
||||
})),
|
||||
).toEqual({
|
||||
token: null,
|
||||
userEmail: null,
|
||||
invitation: 'logout-invitation',
|
||||
});
|
||||
});
|
||||
+132
-2
@@ -1,6 +1,9 @@
|
||||
import { expect, test } from '@playwright/test';
|
||||
|
||||
import { installLangBotApiMocks } from './fixtures/langbot-api';
|
||||
import {
|
||||
installLangBotApiMocks,
|
||||
makeWorkspaceEntry,
|
||||
} from './fixtures/langbot-api';
|
||||
|
||||
test('local account login reaches the authenticated home shell', async ({
|
||||
page,
|
||||
@@ -14,9 +17,136 @@ test('local account login reaches the authenticated home shell', async ({
|
||||
await page.getByPlaceholder('Enter password').fill('password');
|
||||
await page.getByRole('button', { name: 'Login with password' }).click();
|
||||
|
||||
await expect(page).toHaveURL(/\/home$/);
|
||||
await expect(page).toHaveURL(/\/home(?:\/monitoring)?$/);
|
||||
await expect(page.getByText('Home').first()).toBeVisible();
|
||||
await expect(page.getByRole('button', { name: 'Dashboard' })).toBeVisible();
|
||||
await expect(page.getByText('Total Messages').first()).toBeVisible();
|
||||
await expect(page.getByText('Unable to connect to server')).toHaveCount(0);
|
||||
});
|
||||
|
||||
test('an existing Account token bootstraps the singleton without a selector loop', async ({
|
||||
page,
|
||||
}) => {
|
||||
const bootstrapWorkspaceHeaders: Array<string | undefined> = [];
|
||||
page.on('request', (request) => {
|
||||
if (new URL(request.url()).pathname === '/api/v1/workspaces/bootstrap') {
|
||||
bootstrapWorkspaceHeaders.push(request.headers()['x-workspace-id']);
|
||||
}
|
||||
});
|
||||
|
||||
await installLangBotApiMocks(page, { authenticated: true });
|
||||
await page.goto('/login');
|
||||
|
||||
await expect(page).toHaveURL(/\/home(?:\/monitoring)?$/);
|
||||
await expect(page.getByRole('button', { name: 'Dashboard' })).toBeVisible();
|
||||
expect(bootstrapWorkspaceHeaders.length).toBeGreaterThan(0);
|
||||
expect(bootstrapWorkspaceHeaders.every((header) => !header)).toBe(true);
|
||||
});
|
||||
|
||||
test('multi-Workspace login waits for an explicit selection', async ({
|
||||
page,
|
||||
}) => {
|
||||
const accountScopedRequests: { path: string; workspace?: string }[] = [];
|
||||
const selectedWorkspaceHeaders: string[] = [];
|
||||
page.on('request', (request) => {
|
||||
const path = new URL(request.url()).pathname;
|
||||
const workspace = request.headers()['x-workspace-id'];
|
||||
if (
|
||||
path === '/api/v1/user/auth' ||
|
||||
path === '/api/v1/user/check-token' ||
|
||||
path === '/api/v1/workspaces/bootstrap'
|
||||
) {
|
||||
accountScopedRequests.push({ path, workspace });
|
||||
}
|
||||
if (path === '/api/v1/workspaces/current' && workspace) {
|
||||
selectedWorkspaceHeaders.push(workspace);
|
||||
}
|
||||
});
|
||||
|
||||
await installLangBotApiMocks(page, {
|
||||
storage: {
|
||||
langbot_active_workspace_uuid: 'workspace-from-another-account',
|
||||
},
|
||||
workspaces: [
|
||||
makeWorkspaceEntry('workspace-alpha', 'Alpha Workspace'),
|
||||
makeWorkspaceEntry('workspace-beta', 'Beta Workspace'),
|
||||
],
|
||||
});
|
||||
|
||||
await page.goto('/login');
|
||||
await page.getByPlaceholder('Enter email address').fill('admin@example.com');
|
||||
await page.getByPlaceholder('Enter password').fill('password');
|
||||
await page.getByRole('button', { name: 'Login with password' }).click();
|
||||
|
||||
await expect(page).toHaveURL(/\/workspaces\/select/);
|
||||
await expect(
|
||||
page.getByRole('heading', { name: 'Choose a Workspace' }),
|
||||
).toBeVisible();
|
||||
await expect(page.getByText('Alpha Workspace')).toBeVisible();
|
||||
await expect(page.getByText('Beta Workspace')).toBeVisible();
|
||||
|
||||
await page.getByRole('button', { name: /Beta Workspace/ }).click();
|
||||
|
||||
await expect(page).toHaveURL(/\/home(?:\/monitoring)?$/);
|
||||
const workspaceSwitcher = page
|
||||
.getByRole('button', {
|
||||
name: /Switch Workspace/,
|
||||
})
|
||||
.first();
|
||||
await expect(workspaceSwitcher).toBeVisible();
|
||||
await workspaceSwitcher.click();
|
||||
await expect(
|
||||
page.getByRole('menuitem', { name: 'Workspace Settings' }),
|
||||
).toBeVisible();
|
||||
expect(selectedWorkspaceHeaders).toContain('workspace-beta');
|
||||
expect(accountScopedRequests.length).toBeGreaterThan(0);
|
||||
expect(accountScopedRequests.every((request) => !request.workspace)).toBe(
|
||||
true,
|
||||
);
|
||||
});
|
||||
|
||||
test('Space OAuth bootstraps a singleton before entering home', async ({
|
||||
page,
|
||||
}) => {
|
||||
const selectedWorkspaceHeaders: string[] = [];
|
||||
page.on('request', (request) => {
|
||||
const path = new URL(request.url()).pathname;
|
||||
const workspace = request.headers()['x-workspace-id'];
|
||||
if (path === '/api/v1/workspaces/current' && workspace) {
|
||||
selectedWorkspaceHeaders.push(workspace);
|
||||
}
|
||||
});
|
||||
|
||||
await installLangBotApiMocks(page);
|
||||
await page.goto('/auth/space/callback?code=oauth-code&state=oauth-state');
|
||||
|
||||
await expect(page).toHaveURL(/\/home(?:\/monitoring)?$/, {
|
||||
timeout: 5_000,
|
||||
});
|
||||
expect(selectedWorkspaceHeaders).toContain('workspace-playwright');
|
||||
});
|
||||
|
||||
test('Space OAuth sends a multi-Workspace Account to the chooser', async ({
|
||||
page,
|
||||
}) => {
|
||||
const bootstrapWorkspaceHeaders: Array<string | undefined> = [];
|
||||
page.on('request', (request) => {
|
||||
if (new URL(request.url()).pathname === '/api/v1/workspaces/bootstrap') {
|
||||
bootstrapWorkspaceHeaders.push(request.headers()['x-workspace-id']);
|
||||
}
|
||||
});
|
||||
|
||||
await installLangBotApiMocks(page, {
|
||||
workspaces: [
|
||||
makeWorkspaceEntry('workspace-alpha', 'Alpha Workspace'),
|
||||
makeWorkspaceEntry('workspace-beta', 'Beta Workspace'),
|
||||
],
|
||||
});
|
||||
await page.goto('/auth/space/callback?code=oauth-code&state=oauth-state');
|
||||
|
||||
await expect(page).toHaveURL(/\/workspaces\/select/, { timeout: 5_000 });
|
||||
await expect(page.getByText('Alpha Workspace')).toBeVisible();
|
||||
await expect(page.getByText('Beta Workspace')).toBeVisible();
|
||||
expect(bootstrapWorkspaceHeaders.length).toBeGreaterThan(0);
|
||||
expect(bootstrapWorkspaceHeaders.every((header) => !header)).toBe(true);
|
||||
});
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
import assert from 'node:assert/strict';
|
||||
import fs from 'node:fs';
|
||||
import path from 'node:path';
|
||||
import test from 'node:test';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
|
||||
const root = path.resolve(
|
||||
path.dirname(fileURLToPath(import.meta.url)),
|
||||
'../..',
|
||||
);
|
||||
const read = (file) => fs.readFileSync(path.join(root, file), 'utf8');
|
||||
|
||||
test('invited local registration returns to login instead of authenticating', () => {
|
||||
const source = read('src/app/invitations/accept/page.tsx');
|
||||
assert.doesNotMatch(
|
||||
source,
|
||||
/beginAuthenticatedSession\([\s\S]{0,120}response\.token/,
|
||||
);
|
||||
assert.match(source, /navigate\('\/login\?invitation=1'/);
|
||||
});
|
||||
|
||||
test('authenticated invitation page offers logout while retaining invitation', () => {
|
||||
const source = read('src/app/invitations/accept/page.tsx');
|
||||
assert.match(source, /workspace\.logoutAndReturn/);
|
||||
assert.match(source, /setPendingInvitationToken\(token\)/);
|
||||
});
|
||||
|
||||
test('Space OAuth callback distinguishes unknown and unbound accounts by stable codes', () => {
|
||||
const source = read('src/app/auth/space/callback/page.tsx');
|
||||
assert.match(source, /space_account_not_registered/);
|
||||
assert.match(source, /space_account_binding_required/);
|
||||
});
|
||||
|
||||
test('models panel derives LangBot Models billing state from workspace owner', () => {
|
||||
const source = read('src/app/home/components/models-dialog/ModelsPanel.tsx');
|
||||
assert.match(source, /getWorkspaceSpaceBilling/);
|
||||
assert.doesNotMatch(source, /getSpaceCredits\(\)/);
|
||||
assert.match(source, /membership\.role === 'owner'/);
|
||||
});
|
||||
|
||||
test('provider card represents owner and member owner-bound states explicitly', () => {
|
||||
const source = read(
|
||||
'src/app/home/components/models-dialog/components/ProviderCard.tsx',
|
||||
);
|
||||
assert.match(source, /isWorkspaceOwner/);
|
||||
assert.match(source, /ownerSpaceBound/);
|
||||
assert.match(source, /models\.ownerMustBindSpace/);
|
||||
assert.match(source, /models\.usesOwnerSpaceBilling/);
|
||||
});
|
||||
@@ -0,0 +1,114 @@
|
||||
import assert from 'node:assert/strict';
|
||||
import fs from 'node:fs';
|
||||
import path from 'node:path';
|
||||
import test from 'node:test';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
|
||||
const currentDirectory = path.dirname(fileURLToPath(import.meta.url));
|
||||
const webRoot = path.resolve(currentDirectory, '../..');
|
||||
|
||||
function readSource(relativePath) {
|
||||
return fs.readFileSync(path.join(webRoot, relativePath), 'utf8');
|
||||
}
|
||||
|
||||
const homeLayoutSource = readSource('src/app/home/layout.tsx');
|
||||
const homeSidebarSource = readSource(
|
||||
'src/app/home/components/home-sidebar/HomeSidebar.tsx',
|
||||
);
|
||||
const workspaceSettingsPanelSource = readSource(
|
||||
'src/app/home/components/workspace-settings/WorkspaceSettingsPanel.tsx',
|
||||
);
|
||||
const workspaceSwitcherSource = readSource(
|
||||
'src/app/home/components/workspace-settings/WorkspaceSwitcher.tsx',
|
||||
);
|
||||
|
||||
test('renders WorkspaceSwitcher only from HomeSidebar', () => {
|
||||
assert.doesNotMatch(homeLayoutSource, /<WorkspaceSwitcher\b/);
|
||||
assert.doesNotMatch(workspaceSettingsPanelSource, /<WorkspaceSwitcher\b/);
|
||||
assert.equal(homeSidebarSource.match(/<WorkspaceSwitcher\b/g)?.length, 1);
|
||||
});
|
||||
|
||||
test('places WorkspaceSwitcher between the sidebar header and Home navigation', () => {
|
||||
const headerEnd = homeSidebarSource.indexOf('</SidebarHeader>');
|
||||
const switcher = homeSidebarSource.indexOf('<WorkspaceSwitcher');
|
||||
const contentStart = homeSidebarSource.indexOf('<SidebarContent');
|
||||
const homeGroup = homeSidebarSource.indexOf(
|
||||
"<SidebarGroupLabel>{t('sidebar.home')}</SidebarGroupLabel>",
|
||||
);
|
||||
|
||||
assert.notEqual(headerEnd, -1);
|
||||
assert.notEqual(switcher, -1);
|
||||
assert.notEqual(contentStart, -1);
|
||||
assert.notEqual(homeGroup, -1);
|
||||
assert.ok(
|
||||
headerEnd < switcher,
|
||||
'WorkspaceSwitcher must follow SidebarHeader',
|
||||
);
|
||||
assert.ok(
|
||||
switcher < contentStart && switcher < homeGroup,
|
||||
'WorkspaceSwitcher must precede SidebarContent and the Home group',
|
||||
);
|
||||
});
|
||||
|
||||
test('shows WorkspaceSwitcher for a current Cloud or OSS workspace even when it is the only workspace', () => {
|
||||
assert.match(
|
||||
workspaceSwitcherSource,
|
||||
/if \(!currentWorkspace\) return null;/,
|
||||
);
|
||||
assert.doesNotMatch(workspaceSwitcherSource, /workspaces\.length\s*<=\s*1/);
|
||||
assert.doesNotMatch(
|
||||
homeSidebarSource,
|
||||
/currentWorkspace\?\.workspace\.source\s*===\s*'cloud_projection'[\s\S]{0,200}<WorkspaceSwitcher/,
|
||||
);
|
||||
});
|
||||
|
||||
test('keeps Cloud workspace member management in Workspace Settings', () => {
|
||||
assert.match(workspaceSettingsPanelSource, /workspace\.inviteMember/);
|
||||
assert.doesNotMatch(workspaceSettingsPanelSource, /#workspace-members/);
|
||||
assert.doesNotMatch(workspaceSettingsPanelSource, /cloudMembersURL/);
|
||||
assert.doesNotMatch(workspaceSettingsPanelSource, /canManageCloudMembers/);
|
||||
});
|
||||
|
||||
test('keeps workspace plan and settings controls on the workspace row', () => {
|
||||
assert.match(workspaceSwitcherSource, /entry\.plan_name/);
|
||||
assert.match(
|
||||
workspaceSwitcherSource,
|
||||
/aria-label=\{t\('workspace\.settings'\)\}/,
|
||||
);
|
||||
assert.match(workspaceSwitcherSource, /className="size-8"/);
|
||||
assert.doesNotMatch(workspaceSwitcherSource, /workspace\.currentPlan/);
|
||||
assert.doesNotMatch(workspaceSwitcherSource, /workspace\.upgradePlan/);
|
||||
assert.doesNotMatch(workspaceSwitcherSource, /workspace\.roles/);
|
||||
assert.doesNotMatch(workspaceSwitcherSource, /entry\.membership\.role/);
|
||||
});
|
||||
|
||||
test('moves Cloud plan upgrades into Workspace Settings', () => {
|
||||
assert.match(workspaceSettingsPanelSource, /workspace\.upgradePlan/);
|
||||
assert.match(workspaceSettingsPanelSource, /cloudPortalURL/);
|
||||
assert.match(workspaceSettingsPanelSource, /step=plan/);
|
||||
assert.match(workspaceSettingsPanelSource, /systemInfo\.cloud_service_url/);
|
||||
});
|
||||
|
||||
test('aligns the workspace trigger with navigation entries on both sides and truncates long names', () => {
|
||||
assert.match(
|
||||
homeSidebarSource,
|
||||
/<div className="px-2[^>]*>[\s\S]*<WorkspaceSwitcher className="w-full/,
|
||||
);
|
||||
assert.doesNotMatch(
|
||||
homeSidebarSource,
|
||||
/WorkspaceSwitcher className="[^"]*w-4\/5/,
|
||||
);
|
||||
assert.match(workspaceSwitcherSource, /h-9/);
|
||||
assert.match(workspaceSwitcherSource, /w-64/);
|
||||
assert.doesNotMatch(workspaceSwitcherSource, /min-w-80/);
|
||||
assert.match(workspaceSwitcherSource, /max-w-\[7rem\][^>]*truncate/);
|
||||
});
|
||||
|
||||
test('uses an infrastructure-level Box health endpoint in monitoring', () => {
|
||||
const statusCardSource = readSource(
|
||||
'src/app/home/monitoring/components/overview-cards/SystemStatusCards.tsx',
|
||||
);
|
||||
const backendClientSource = readSource('src/app/infra/http/BackendClient.ts');
|
||||
assert.match(backendClientSource, /getBoxRuntimeStatus/);
|
||||
assert.match(statusCardSource, /getBoxRuntimeStatus/);
|
||||
});
|
||||
Reference in New Issue
Block a user