Add name resolver and Crisp verification tests

Cover gaps the connectors shipped without: the Railway and Crisp name
resolvers had no tests despite real branch logic (single vs multiple vs
zero workspaces, best-effort on error, empty-website short-circuit,
tier header), and the crispVerificationCode query was only unit-tested
at the HMAC layer, never through the live schema and authorization
stack.

Add TestRailwayNameResolver and TestCrispNameResolver alongside the
existing resolver tests, pin the Crisp driver's hardcoded MFA Unknown
and nil Active, and add an e2e TestCrispVerificationCode asserting the
code shape, determinism, organization binding, blank-input INVALID, and
viewer FORBIDDEN. The verification-code query needs no Crisp credentials
(only the always-set token secret and organization authorization), so it
runs against the default e2e deployment.

Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
Aurélien Sibiril
2026-07-11 18:41:40 +02:00
parent 5b83911269
commit d5102eac63
3 changed files with 228 additions and 0 deletions

View File

@@ -45,6 +45,10 @@ func TestCrispDriver(t *testing.T) {
assert.True(t, owner.IsAdmin)
assert.Equal(t, "Founder", owner.JobTitle)
assert.Equal(t, coredata.AccessReviewEntryAccountTypeUser, owner.AccountType)
// Crisp's operators/list exposes no MFA or account-status signal, so the
// driver hardcodes MFA Unknown and leaves Active nil for every record.
assert.Equal(t, coredata.MFAStatusUnknown, owner.MFAStatus)
assert.Nil(t, owner.Active)
member := records[1]
assert.Equal(t, "9a1f3c2e-6b4d-4f8a-bc11-7d2e9f0a1b22", member.ExternalID)
@@ -52,4 +56,6 @@ func TestCrispDriver(t *testing.T) {
assert.Equal(t, []string{"Member"}, member.Roles)
assert.False(t, member.IsAdmin)
assert.Equal(t, "Support Agent", member.JobTitle)
assert.Equal(t, coredata.MFAStatusUnknown, member.MFAStatus)
assert.Nil(t, member.Active)
}