feat: emit team admin role in userinfo claims when applicable

This commit is contained in:
2026-09-21 11:43:36 +02:00
parent 679a864906
commit ab7d00b35d
4 changed files with 38 additions and 1 deletions
@@ -47,6 +47,26 @@ class CrmAttributesResponseParserTest extends TestCase
self::assertContains('ROLE_CUSTOMER_EXPERT', $roles);
}
/**
* ROLE_TEAM_ADMIN is not consumed here at all — it is exported through /api/userinfo and is
* myep-team's administrative role — so the claim is the only thing standing between the CRM
* selection and that application.
*/
public function testParseAssignsTeamAdminRoleWhenSelected(): void
{
$roles = $this->parseRoles($this->selectionXml(1484, true));
self::assertContains('ROLE_TEAM_ADMIN', $roles);
self::assertNotContains('ROLE_ADMIN', $roles, 'the "Admin" selection 1292 is a different one');
}
public function testParseAssignsNoTeamAdminRoleWhenNotSelected(): void
{
$roles = $this->parseRoles($this->selectionXml(1484, false));
self::assertNotContains('ROLE_TEAM_ADMIN', $roles);
}
public function testParseAssignsNoCustomerExpertRoleWhenNotSelected(): void
{
$roles = $this->parseRoles($this->selectionXml(1483, false));
@@ -70,6 +70,21 @@ class UserinfoControllerTest extends TestCase
self::assertSame([Role::EMPLOYEE, Role::TEAMER], $claims['roles']);
}
/**
* myep-team reads its own administrative role out of this claim and revokes what the claim
* omits, so the export is asserted here rather than left to the role policy's own tests.
*/
public function testTeamAdminIsExportedOnceApproved(): void
{
$claims = $this->claims(['ROLE_OAUTH2_ROLES'], [
Role::USER,
Role::EMPLOYEE,
Role::TEAM_ADMIN,
]);
self::assertSame([Role::EMPLOYEE, Role::TEAM_ADMIN], $claims['roles']);
}
public function testUpstreamFailureIsReportedRatherThanAnswered(): void
{
$apiClient = $this->createStub(ApiClient::class);