import { env, exports } from "cloudflare:workers"; import { beforeAll, describe, expect, it } from "vitest"; const SELF = exports.default; import { makeAuth } from "@/worker/auth"; import { ISSUER, signInForCookie, testHeaders } from "./helpers"; // tessera owns the user-management surface and does not expose the full // Better Auth admin plugin. The allowlist middleware in // `src/worker/middleware/admin-allowlist.ts` only lets list-users, // set-role, and unban-user reach Better Auth; ban-user is a tessera // handler. Everything else under /api/auth/admin/* must 404 — this // preserves the invite-only invariant (no create-user) and forbids // destructive actions tessera's UI never surfaces. describe("admin route allowlist", () => { const adminCred = { email: "allowlist-admin@example.com", password: "correct-horse-battery-staple", name: "Allowlist Admin", }; let cookie: string; beforeAll(async () => { const auth = makeAuth(env, { baseURL: ISSUER, issuer: ISSUER }); await auth.api.signUpEmail({ body: adminCred, asResponse: false }); await env.DB.prepare("UPDATE users SET role = ? WHERE email = ?").bind("admin", adminCred.email).run(); cookie = await signInForCookie(adminCred.email, adminCred.password, "10.40.0.1"); }); const blockedRoutes: Array<[string, string, Record?]> = [ ["POST", "/api/auth/admin/create-user", { email: "x@example.com", password: "a-twelve-char", name: "X" }], ["POST", "/api/auth/admin/set-user-password", { userId: "anything", newPassword: "another-twelve" }], ["POST", "/api/auth/admin/impersonate-user", { userId: "anything" }], ["POST", "/api/auth/admin/stop-impersonating", {}], ["POST", "/api/auth/admin/remove-user", { userId: "anything" }], ["POST", "/api/auth/admin/revoke-user-session", { sessionToken: "x" }], ["POST", "/api/auth/admin/revoke-user-sessions", { userId: "anything" }], ]; for (const [method, path, body] of blockedRoutes) { it(`blocks ${method} ${path} with 404`, async () => { const res = await SELF.fetch(`${ISSUER}${path}`, { method, headers: testHeaders({ cookie }), body: body ? JSON.stringify(body) : undefined, }); expect(res.status).toBe(404); }); } it("allows GET /api/auth/admin/list-users (passthrough to Better Auth)", async () => { const res = await SELF.fetch(`${ISSUER}/api/auth/admin/list-users?limit=5`, { headers: { cookie } }); expect(res.status).toBe(200); const body = (await res.json()) as { users: unknown[] }; expect(Array.isArray(body.users)).toBe(true); }); it("allows POST /api/auth/admin/set-role on another user (passthrough)", async () => { const targetCred = { email: "allowlist-target@example.com", password: "correct-horse-battery-staple", name: "Target", }; const auth = makeAuth(env, { baseURL: ISSUER, issuer: ISSUER }); await auth.api.signUpEmail({ body: targetCred, asResponse: false }); const targetId = ( await env.DB.prepare("SELECT id FROM users WHERE email = ?").bind(targetCred.email).first<{ id: string }>() )?.id; expect(targetId).toBeTruthy(); // `origin` is required by Better Auth's CSRF gate for state-changing // auth endpoints. const res = await SELF.fetch(`${ISSUER}/api/auth/admin/set-role`, { method: "POST", headers: testHeaders({ cookie }), body: JSON.stringify({ userId: targetId, role: "admin" }), }); expect(res.status).toBe(200); }); });