feat: emit team admin role in userinfo claims when applicable

This commit is contained in:
2026-09-21 11:43:36 +02:00
parent 679a864906
commit ab7d00b35d
4 changed files with 38 additions and 1 deletions
@@ -18,11 +18,12 @@ Symfony roles:
| `IDSelektionsstamm` | Role |
| --- | --- |
| `1070` | `ROLE_TEAMER` |
| `1292` | `ROLE_ADMIN` (+ `ROLE_HOUSE_MANAGER`, + hotel code `SSL`) |
| `1292` | `ROLE_ADMIN` |
| `1293` | `ROLE_MANAGER` |
| `1477` | `ROLE_GROUPS_MANAGER` |
| `1478` | `ROLE_GROUPS_ADMIN` |
| `1483` | `ROLE_CUSTOMER_EXPERT` |
| `1484` | `ROLE_TEAM_ADMIN` (not consumed here — exported through `/api/userinfo` for myep-team) |
| label `Hausleitung {CODE}` | `ROLE_HOUSE_MANAGER` + hotel code `{CODE}` |
| nothing matched | `ROLE_CUSTOMER` |
@@ -40,6 +40,7 @@ class CrmAttributesResponseParser
1477 => Role::GROUPS_MANAGER,
1478 => Role::GROUPS_ADMIN,
1483 => Role::CUSTOMER_EXPERT,
1484 => Role::TEAM_ADMIN,
];
/**
@@ -47,6 +47,26 @@ class CrmAttributesResponseParserTest extends TestCase
self::assertContains('ROLE_CUSTOMER_EXPERT', $roles);
}
/**
* ROLE_TEAM_ADMIN is not consumed here at all — it is exported through /api/userinfo and is
* myep-team's administrative role — so the claim is the only thing standing between the CRM
* selection and that application.
*/
public function testParseAssignsTeamAdminRoleWhenSelected(): void
{
$roles = $this->parseRoles($this->selectionXml(1484, true));
self::assertContains('ROLE_TEAM_ADMIN', $roles);
self::assertNotContains('ROLE_ADMIN', $roles, 'the "Admin" selection 1292 is a different one');
}
public function testParseAssignsNoTeamAdminRoleWhenNotSelected(): void
{
$roles = $this->parseRoles($this->selectionXml(1484, false));
self::assertNotContains('ROLE_TEAM_ADMIN', $roles);
}
public function testParseAssignsNoCustomerExpertRoleWhenNotSelected(): void
{
$roles = $this->parseRoles($this->selectionXml(1483, false));
@@ -70,6 +70,21 @@ class UserinfoControllerTest extends TestCase
self::assertSame([Role::EMPLOYEE, Role::TEAMER], $claims['roles']);
}
/**
* myep-team reads its own administrative role out of this claim and revokes what the claim
* omits, so the export is asserted here rather than left to the role policy's own tests.
*/
public function testTeamAdminIsExportedOnceApproved(): void
{
$claims = $this->claims(['ROLE_OAUTH2_ROLES'], [
Role::USER,
Role::EMPLOYEE,
Role::TEAM_ADMIN,
]);
self::assertSame([Role::EMPLOYEE, Role::TEAM_ADMIN], $claims['roles']);
}
public function testUpstreamFailureIsReportedRatherThanAnswered(): void
{
$apiClient = $this->createStub(ApiClient::class);