Go app for capturing and archiving HSA-eligible receipts: OIDC/PKCE auth against Authelia, SQLite storage with dual-write (filesystem + DB blob), mobile-first upload, and DB export. Adds AI receipt classification: a config.json catalog of people and categories (seeded into the DB on startup), a prompt builder that derives name-order/initial variants from the data (with same-surname ambiguity handling), and an Anthropic tool-use client behind POST /classify. Tests run against a mock endpoint; a live integration test is env-gated to the cheapest model. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
28 lines
778 B
Go
28 lines
778 B
Go
package auth
|
|
|
|
import "testing"
|
|
|
|
func TestIsAuthorized(t *testing.T) {
|
|
cases := []struct {
|
|
name string
|
|
groups []string
|
|
required string
|
|
want bool
|
|
}{
|
|
{"in group", []string{"hsa-users"}, "hsa-users", true},
|
|
{"in group among others", []string{"admins", "hsa-users", "devs"}, "hsa-users", true},
|
|
{"empty groups", []string{}, "hsa-users", false},
|
|
{"nil groups", nil, "hsa-users", false},
|
|
{"other group only", []string{"admins"}, "hsa-users", false},
|
|
{"wrong case", []string{"HSA-USERS"}, "hsa-users", false},
|
|
}
|
|
|
|
for _, tc := range cases {
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
got := IsAuthorized(tc.groups, tc.required)
|
|
if got != tc.want {
|
|
t.Errorf("IsAuthorized(%v, %q) = %v, want %v", tc.groups, tc.required, got, tc.want)
|
|
}
|
|
})
|
|
}
|
|
}
|