hsa-app/internal/auth/authz_test.go
Jean-Michel Tremblay 8b7252dad4 Initial commit: HSA receipt tracker
Go app for capturing and archiving HSA-eligible receipts: OIDC/PKCE auth
against Authelia, SQLite storage with dual-write (filesystem + DB blob),
mobile-first upload, and DB export.

Adds AI receipt classification: a config.json catalog of people and
categories (seeded into the DB on startup), a prompt builder that derives
name-order/initial variants from the data (with same-surname ambiguity
handling), and an Anthropic tool-use client behind POST /classify. Tests
run against a mock endpoint; a live integration test is env-gated to the
cheapest model.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-17 21:40:12 -04:00

28 lines
778 B
Go

package auth
import "testing"
func TestIsAuthorized(t *testing.T) {
cases := []struct {
name string
groups []string
required string
want bool
}{
{"in group", []string{"hsa-users"}, "hsa-users", true},
{"in group among others", []string{"admins", "hsa-users", "devs"}, "hsa-users", true},
{"empty groups", []string{}, "hsa-users", false},
{"nil groups", nil, "hsa-users", false},
{"other group only", []string{"admins"}, "hsa-users", false},
{"wrong case", []string{"HSA-USERS"}, "hsa-users", false},
}
for _, tc := range cases {
t.Run(tc.name, func(t *testing.T) {
got := IsAuthorized(tc.groups, tc.required)
if got != tc.want {
t.Errorf("IsAuthorized(%v, %q) = %v, want %v", tc.groups, tc.required, got, tc.want)
}
})
}
}