From 3d791e2e9fc69b8a3ad3744ef3ad676fdc0a6a11 Mon Sep 17 00:00:00 2001 From: Quick <31828688+Quick104@users.noreply.github.com> Date: Tue, 26 May 2026 19:41:55 -0400 Subject: [PATCH] test(auth): expand session revocation coverage --- internal/api/handlers/admin_test.go | 72 +++++++++++++++++++++++++++-- 1 file changed, 67 insertions(+), 5 deletions(-) diff --git a/internal/api/handlers/admin_test.go b/internal/api/handlers/admin_test.go index 57240e77..d434a029 100644 --- a/internal/api/handlers/admin_test.go +++ b/internal/api/handlers/admin_test.go @@ -2,10 +2,72 @@ package handlers import "testing" -func TestUpdateRequiresSessionRevocation_ForPermissions(t *testing.T) { - if !updateRequiresSessionRevocation(updateUserRequest{ - Permissions: updateStringSliceField{Set: true, Value: []string{"metadata_curation"}}, - }) { - t.Fatal("permission updates should revoke sessions") +func TestUpdateRequiresSessionRevocation(t *testing.T) { + role := "admin" + enabled := true + libraryIDs := []int{1, 2} + maxPlaybackQuality := "1080p" + password := "new-password" + username := "renamed" + maxStreams := 4 + + tests := []struct { + name string + req updateUserRequest + want bool + }{ + { + name: "permissions set", + req: updateUserRequest{Permissions: updateStringSliceField{Set: true, Value: []string{"metadata_curation"}}}, + want: true, + }, + { + name: "permissions unset", + req: updateUserRequest{Permissions: updateStringSliceField{Set: false, Value: []string{"metadata_curation"}}}, + want: false, + }, + { + name: "role", + req: updateUserRequest{Role: &role}, + want: true, + }, + { + name: "enabled", + req: updateUserRequest{Enabled: &enabled}, + want: true, + }, + { + name: "library ids", + req: updateUserRequest{LibraryIDs: updateLibraryIDsField{Set: true, Value: libraryIDs}}, + want: true, + }, + { + name: "max playback quality", + req: updateUserRequest{MaxPlaybackQuality: &maxPlaybackQuality}, + want: true, + }, + { + name: "password", + req: updateUserRequest{Password: &password}, + want: true, + }, + { + name: "non access fields", + req: updateUserRequest{Username: &username, MaxStreams: &maxStreams}, + want: false, + }, + { + name: "empty update", + req: updateUserRequest{}, + want: false, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + if got := updateRequiresSessionRevocation(tt.req); got != tt.want { + t.Fatalf("updateRequiresSessionRevocation() = %v, want %v", got, tt.want) + } + }) } }