Files
probo/e2e/console/third_party_test.go
Sacha Al Himdani 6a4f124adb
Some checks failed
github / Analyze (go) (push) Has been cancelled
github / Analyze (actions) (push) Has been cancelled
github / Analyze (javascript-typescript) (push) Has been cancelled
make / build-apps (push) Has been cancelled
make / probod binary (darwin/amd64) (push) Has been cancelled
make / probod binary (freebsd/amd64) (push) Has been cancelled
make / probod binary (linux/amd64) (push) Has been cancelled
make / probod binary (openbsd/amd64) (push) Has been cancelled
make / probod binary (windows/amd64) (push) Has been cancelled
make / probod binary (darwin/arm64) (push) Has been cancelled
make / probod binary (freebsd/arm64) (push) Has been cancelled
make / probod binary (linux/arm64) (push) Has been cancelled
make / probod binary (openbsd/arm64) (push) Has been cancelled
make / probo-agent (darwin/amd64) (push) Has been cancelled
make / probo-agent (freebsd/amd64) (push) Has been cancelled
make / probo-agent (linux/amd64) (push) Has been cancelled
make / probo-agent (windows/amd64) (push) Has been cancelled
make / probo-agent (darwin/arm64) (push) Has been cancelled
make / probo-agent (freebsd/arm64) (push) Has been cancelled
make / probo-agent (linux/arm64) (push) Has been cancelled
make / probo-agent (windows/arm64) (push) Has been cancelled
make / docker (amd64) (push) Has been cancelled
make / docker (arm64) (push) Has been cancelled
make / snapshot-scan (push) Has been cancelled
make / build-probod (push) Has been cancelled
make / build-probo-agent (push) Has been cancelled
make / lint-go (push) Has been cancelled
make / lint-js (push) Has been cancelled
make / lint-swift (push) Has been cancelled
make / lint-shell (push) Has been cancelled
make / test (push) Has been cancelled
make / test-e2e (push) Has been cancelled
trufflehog / scan (push) Has been cancelled
Replace third-party owners with administrators
Migrate business and security owners into a shared administrators list across GraphQL, MCP, CLI, n8n, and the console.

Signed-off-by: Sacha Al Himdani <sacha@probo.com>
2026-07-31 16:48:36 +02:00

1127 lines
28 KiB
Go

// Copyright (c) 2025-2026 Probo Inc <hello@probo.com>.
//
// Permission is hereby granted, free of charge, to any person obtaining a copy
// of this software and associated documentation files (the "Software"), to deal
// in the Software without restriction, including without limitation the rights
// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
// copies of the Software, and to permit persons to whom the Software is
// furnished to do so, subject to the following conditions:
//
// The above copyright notice and this permission notice shall be included in
// all copies or substantial portions of the Software.
//
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
// SOFTWARE.
package console_test
import (
"maps"
"testing"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"go.probo.inc/probo/e2e/internal/factory"
"go.probo.inc/probo/e2e/internal/testutil"
)
func TestThirdParty_Create(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
t.Run("with full details", func(t *testing.T) {
const query = `
mutation($input: CreateThirdPartyInput!) {
createThirdParty(input: $input) {
thirdPartyEdge {
node {
id
name
description
}
}
}
}
`
var result struct {
CreateThirdParty struct {
ThirdPartyEdge struct {
Node struct {
ID string `json:"id"`
Name string `json:"name"`
Description *string `json:"description"`
} `json:"node"`
} `json:"thirdPartyEdge"`
} `json:"createThirdParty"`
}
err := owner.Execute(query, map[string]any{
"input": map[string]any{
"organizationId": owner.GetOrganizationID().String(),
"name": "AWS",
"description": "Amazon Web Services - Cloud Provider",
"websiteUrl": "https://aws.amazon.com",
},
}, &result)
require.NoError(t, err)
assert.NotEmpty(t, result.CreateThirdParty.ThirdPartyEdge.Node.ID)
assert.Equal(t, "AWS", result.CreateThirdParty.ThirdPartyEdge.Node.Name)
assert.Equal(t, "Amazon Web Services - Cloud Provider", *result.CreateThirdParty.ThirdPartyEdge.Node.Description)
})
t.Run("with all optional fields", func(t *testing.T) {
const query = `
mutation($input: CreateThirdPartyInput!) {
createThirdParty(input: $input) {
thirdPartyEdge {
node {
id
name
legalName
headquarterAddress
privacyPolicyUrl
termsOfServiceUrl
certifications
}
}
}
}
`
var result struct {
CreateThirdParty struct {
ThirdPartyEdge struct {
Node struct {
ID string `json:"id"`
Name string `json:"name"`
LegalName *string `json:"legalName"`
HeadquarterAddress *string `json:"headquarterAddress"`
PrivacyPolicyUrl *string `json:"privacyPolicyUrl"`
TermsOfServiceUrl *string `json:"termsOfServiceUrl"`
Certifications []string `json:"certifications"`
} `json:"node"`
} `json:"thirdPartyEdge"`
} `json:"createThirdParty"`
}
err := owner.Execute(query, map[string]any{
"input": map[string]any{
"organizationId": owner.GetOrganizationID().String(),
"name": "Stripe",
"legalName": "Stripe, Inc.",
"headquarterAddress": "354 Oyster Point Blvd, South San Francisco, CA",
"privacyPolicyUrl": "https://stripe.com/privacy",
"termsOfServiceUrl": "https://stripe.com/legal",
"certifications": []string{"SOC 2", "PCI DSS"},
},
}, &result)
require.NoError(t, err)
assert.Equal(t, "Stripe", result.CreateThirdParty.ThirdPartyEdge.Node.Name)
assert.Equal(t, "Stripe, Inc.", *result.CreateThirdParty.ThirdPartyEdge.Node.LegalName)
assert.Contains(t, result.CreateThirdParty.ThirdPartyEdge.Node.Certifications, "SOC 2")
})
}
func TestThirdParty_Update(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
thirdPartyID := factory.CreateThirdParty(owner, factory.Attrs{
"name": "ThirdParty to Update",
"description": "Original description",
})
const query = `
mutation($input: UpdateThirdPartyInput!) {
updateThirdParty(input: $input) {
thirdParty {
id
name
}
}
}
`
var result struct {
UpdateThirdParty struct {
ThirdParty struct {
ID string `json:"id"`
Name string `json:"name"`
} `json:"thirdParty"`
} `json:"updateThirdParty"`
}
err := owner.Execute(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"name": "Updated ThirdParty Name",
"description": "Updated description",
},
}, &result)
require.NoError(t, err)
assert.Equal(t, thirdPartyID, result.UpdateThirdParty.ThirdParty.ID)
assert.Equal(t, "Updated ThirdParty Name", result.UpdateThirdParty.ThirdParty.Name)
}
func TestThirdParty_Delete(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
thirdPartyID := factory.CreateThirdParty(owner, factory.Attrs{
"name": "ThirdParty to Delete",
})
const query = `
mutation($input: DeleteThirdPartyInput!) {
deleteThirdParty(input: $input) {
deletedThirdPartyId
}
}
`
var result struct {
DeleteThirdParty struct {
DeletedThirdPartyID string `json:"deletedThirdPartyId"`
} `json:"deleteThirdParty"`
}
err := owner.Execute(query, map[string]any{
"input": map[string]any{
"thirdPartyId": thirdPartyID,
},
}, &result)
require.NoError(t, err)
assert.Equal(t, thirdPartyID, result.DeleteThirdParty.DeletedThirdPartyID)
}
func TestThirdParty_List(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
// Create multiple thirdParties
thirdPartyNames := []string{"GitHub", "Slack", "Datadog"}
for _, name := range thirdPartyNames {
factory.CreateThirdParty(owner, factory.Attrs{"name": name})
}
const query = `
query($orgId: ID!) {
node(id: $orgId) {
... on Organization {
thirdParties(first: 10) {
edges {
node {
id
name
}
}
totalCount
}
}
}
}
`
var result struct {
Node struct {
ThirdParties struct {
Edges []struct {
Node struct {
ID string `json:"id"`
Name string `json:"name"`
} `json:"node"`
} `json:"edges"`
TotalCount int `json:"totalCount"`
} `json:"thirdParties"`
} `json:"node"`
}
err := owner.Execute(query, map[string]any{
"orgId": owner.GetOrganizationID().String(),
}, &result)
require.NoError(t, err)
assert.GreaterOrEqual(t, result.Node.ThirdParties.TotalCount, 3)
}
func TestThirdParty_CreateContact(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
thirdPartyID := factory.CreateThirdParty(owner, factory.Attrs{"name": "ThirdParty With Contact"})
const query = `
mutation($input: CreateThirdPartyContactInput!) {
createThirdPartyContact(input: $input) {
thirdPartyContactEdge {
node {
id
fullName
email
role
}
}
}
}
`
var result struct {
CreateThirdPartyContact struct {
ThirdPartyContactEdge struct {
Node struct {
ID string `json:"id"`
FullName string `json:"fullName"`
Email string `json:"email"`
Role *string `json:"role"`
} `json:"node"`
} `json:"thirdPartyContactEdge"`
} `json:"createThirdPartyContact"`
}
err := owner.Execute(query, map[string]any{
"input": map[string]any{
"thirdPartyId": thirdPartyID,
"fullName": "John Contact",
"email": "john@thirdParty.com",
"role": "Account Manager",
},
}, &result)
require.NoError(t, err)
assert.NotEmpty(t, result.CreateThirdPartyContact.ThirdPartyContactEdge.Node.ID)
assert.Equal(t, "John Contact", result.CreateThirdPartyContact.ThirdPartyContactEdge.Node.FullName)
}
func TestThirdParty_RequiredFields(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
tests := []struct {
name string
input map[string]any
skipOrganization bool
wantErrorContains string
}{
{
name: "missing organizationId",
input: map[string]any{
"name": "Test ThirdParty",
},
skipOrganization: true,
wantErrorContains: "organizationId",
},
{
name: "missing name",
input: map[string]any{},
wantErrorContains: "name",
},
{
name: "empty name",
input: map[string]any{
"name": "",
},
wantErrorContains: "name",
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
query := `
mutation CreateThirdParty($input: CreateThirdPartyInput!) {
createThirdParty(input: $input) {
thirdPartyEdge {
node {
id
}
}
}
}
`
input := make(map[string]any)
if !tt.skipOrganization {
input["organizationId"] = owner.GetOrganizationID().String()
}
maps.Copy(input, tt.input)
_, err := owner.Do(query, map[string]any{"input": input})
require.Error(t, err)
assert.Contains(t, err.Error(), tt.wantErrorContains)
})
}
}
func TestThirdParty_CategoryEnum(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
categories := []string{
"ANALYTICS",
"CLOUD_PROVIDER",
"COLLABORATION",
}
for _, category := range categories {
t.Run("create with category "+category, func(t *testing.T) {
thirdPartyID := factory.NewThirdParty(owner).
WithName("Category Test " + category).
WithCategory(category).
Create()
query := `
query($id: ID!) {
node(id: $id) {
... on ThirdParty {
id
category
}
}
}
`
var result struct {
Node struct {
ID string `json:"id"`
Category *string `json:"category"`
} `json:"node"`
}
err := owner.Execute(query, map[string]any{"id": thirdPartyID}, &result)
require.NoError(t, err)
require.NotNil(t, result.Node.Category)
assert.Equal(t, category, *result.Node.Category)
})
}
}
func TestThirdParty_SubResolvers(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
thirdPartyID := factory.NewThirdParty(owner).
WithName("SubResolver Test ThirdParty").
Create()
t.Run("thirdParty node query", func(t *testing.T) {
query := `
query GetThirdParty($id: ID!) {
node(id: $id) {
... on ThirdParty {
id
name
description
websiteUrl
}
}
}
`
var result struct {
Node struct {
ID string `json:"id"`
Name string `json:"name"`
Description *string `json:"description"`
WebsiteUrl *string `json:"websiteUrl"`
} `json:"node"`
}
err := owner.Execute(query, map[string]any{"id": thirdPartyID}, &result)
require.NoError(t, err)
assert.Equal(t, thirdPartyID, result.Node.ID)
assert.Equal(t, "SubResolver Test ThirdParty", result.Node.Name)
})
t.Run("organization sub-resolver", func(t *testing.T) {
query := `
query($id: ID!) {
node(id: $id) {
... on ThirdParty {
id
organization {
id
name
}
}
}
}
`
var result struct {
Node struct {
ID string `json:"id"`
Organization struct {
ID string `json:"id"`
Name string `json:"name"`
} `json:"organization"`
} `json:"node"`
}
err := owner.Execute(query, map[string]any{"id": thirdPartyID}, &result)
require.NoError(t, err)
assert.Equal(t, owner.GetOrganizationID().String(), result.Node.Organization.ID)
assert.NotEmpty(t, result.Node.Organization.Name)
})
t.Run("services sub-resolver (empty)", func(t *testing.T) {
query := `
query($id: ID!) {
node(id: $id) {
... on ThirdParty {
id
services(first: 10) {
edges {
node {
id
name
}
}
}
}
}
}
`
var result struct {
Node struct {
ID string `json:"id"`
Services struct {
Edges []struct {
Node struct {
ID string `json:"id"`
Name string `json:"name"`
} `json:"node"`
} `json:"edges"`
} `json:"services"`
} `json:"node"`
}
err := owner.Execute(query, map[string]any{"id": thirdPartyID}, &result)
require.NoError(t, err)
assert.NotNil(t, result.Node.Services.Edges)
})
t.Run("administrators sub-resolver (empty)", func(t *testing.T) {
query := `
query($id: ID!) {
node(id: $id) {
... on ThirdParty {
id
administrators {
id
fullName
}
}
}
}
`
var result struct {
Node struct {
ID string `json:"id"`
Administrators []struct {
ID string `json:"id"`
FullName string `json:"fullName"`
} `json:"administrators"`
} `json:"node"`
}
err := owner.Execute(query, map[string]any{"id": thirdPartyID}, &result)
require.NoError(t, err)
assert.Empty(t, result.Node.Administrators)
})
}
func TestThirdParty_InvalidID(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
t.Run("update with invalid ID", func(t *testing.T) {
query := `
mutation UpdateThirdParty($input: UpdateThirdPartyInput!) {
updateThirdParty(input: $input) {
thirdParty {
id
}
}
}
`
_, err := owner.Do(query, map[string]any{
"input": map[string]any{
"id": "invalid-id-format",
"name": "Test",
},
})
require.Error(t, err)
assert.Contains(t, err.Error(), "base64")
})
t.Run("delete with invalid ID", func(t *testing.T) {
query := `
mutation DeleteThirdParty($input: DeleteThirdPartyInput!) {
deleteThirdParty(input: $input) {
deletedThirdPartyId
}
}
`
_, err := owner.Do(query, map[string]any{
"input": map[string]any{
"thirdPartyId": "invalid-id-format",
},
})
require.Error(t, err)
assert.Contains(t, err.Error(), "base64")
})
t.Run("query with non-existent ID", func(t *testing.T) {
query := `
query GetThirdParty($id: ID!) {
node(id: $id) {
... on ThirdParty {
id
name
}
}
}
`
err := owner.ExecuteShouldFail(query, map[string]any{
"id": "V0wtM0tMNmJBQ1lBQUFBQUFackhLSTJfbXJJRUFZVXo",
})
require.Error(t, err, "Non-existent ID should return error")
})
}
func TestThirdParty_OmittableDescription(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
thirdPartyID := factory.NewThirdParty(owner).
WithName("Description Test ThirdParty").
WithDescription("Initial description").
Create()
t.Run("set description", func(t *testing.T) {
query := `
mutation UpdateThirdParty($input: UpdateThirdPartyInput!) {
updateThirdParty(input: $input) {
thirdParty {
id
description
}
}
}
`
var result struct {
UpdateThirdParty struct {
ThirdParty struct {
ID string `json:"id"`
Description *string `json:"description"`
} `json:"thirdParty"`
} `json:"updateThirdParty"`
}
err := owner.Execute(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"description": "Updated description",
},
}, &result)
require.NoError(t, err)
require.NotNil(t, result.UpdateThirdParty.ThirdParty.Description)
assert.Equal(t, "Updated description", *result.UpdateThirdParty.ThirdParty.Description)
})
t.Run("clear description with null", func(t *testing.T) {
query := `
mutation UpdateThirdParty($input: UpdateThirdPartyInput!) {
updateThirdParty(input: $input) {
thirdParty {
id
description
}
}
}
`
var result struct {
UpdateThirdParty struct {
ThirdParty struct {
ID string `json:"id"`
Description *string `json:"description"`
} `json:"thirdParty"`
} `json:"updateThirdParty"`
}
err := owner.Execute(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"description": nil,
},
}, &result)
require.NoError(t, err)
assert.Nil(t, result.UpdateThirdParty.ThirdParty.Description)
})
t.Run("update without description preserves value", func(t *testing.T) {
// First set a description
setQuery := `
mutation UpdateThirdParty($input: UpdateThirdPartyInput!) {
updateThirdParty(input: $input) {
thirdParty {
id
}
}
}
`
err := owner.Execute(setQuery, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"description": "Should persist",
},
}, nil)
require.NoError(t, err)
// Update only name
query := `
mutation UpdateThirdParty($input: UpdateThirdPartyInput!) {
updateThirdParty(input: $input) {
thirdParty {
id
name
description
}
}
}
`
var result struct {
UpdateThirdParty struct {
ThirdParty struct {
ID string `json:"id"`
Name string `json:"name"`
Description *string `json:"description"`
} `json:"thirdParty"`
} `json:"updateThirdParty"`
}
err = owner.Execute(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"name": "Updated Name",
},
}, &result)
require.NoError(t, err)
require.NotNil(t, result.UpdateThirdParty.ThirdParty.Description)
assert.Equal(t, "Should persist", *result.UpdateThirdParty.ThirdParty.Description)
})
}
func TestThirdParty_Administrators(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
profileID := factory.CreateUser(owner)
thirdPartyID := factory.NewThirdParty(owner).
WithName("Administrators Test ThirdParty").
Create()
t.Run("set administrators", func(t *testing.T) {
query := `
mutation UpdateThirdParty($input: UpdateThirdPartyInput!) {
updateThirdParty(input: $input) {
thirdParty {
id
administrators {
id
fullName
}
}
}
}
`
var result struct {
UpdateThirdParty struct {
ThirdParty struct {
ID string `json:"id"`
Administrators []struct {
ID string `json:"id"`
FullName string `json:"fullName"`
} `json:"administrators"`
} `json:"thirdParty"`
} `json:"updateThirdParty"`
}
err := owner.Execute(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"administratorIds": []string{profileID},
},
}, &result)
require.NoError(t, err)
require.Len(t, result.UpdateThirdParty.ThirdParty.Administrators, 1)
assert.Equal(t, profileID, result.UpdateThirdParty.ThirdParty.Administrators[0].ID)
})
t.Run("clear administrators with empty list", func(t *testing.T) {
query := `
mutation UpdateThirdParty($input: UpdateThirdPartyInput!) {
updateThirdParty(input: $input) {
thirdParty {
id
administrators {
id
}
}
}
}
`
var result struct {
UpdateThirdParty struct {
ThirdParty struct {
ID string `json:"id"`
Administrators []struct {
ID string `json:"id"`
} `json:"administrators"`
} `json:"thirdParty"`
} `json:"updateThirdParty"`
}
err := owner.Execute(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"administratorIds": []string{},
},
}, &result)
require.NoError(t, err)
assert.Empty(t, result.UpdateThirdParty.ThirdParty.Administrators)
})
}
func TestThirdParty_OmittableWebsiteUrl(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
thirdPartyID := factory.NewThirdParty(owner).
WithName("WebsiteUrl Test ThirdParty").
WithWebsiteUrl("https://example.com").
Create()
t.Run("set websiteUrl", func(t *testing.T) {
query := `
mutation UpdateThirdParty($input: UpdateThirdPartyInput!) {
updateThirdParty(input: $input) {
thirdParty {
id
websiteUrl
}
}
}
`
var result struct {
UpdateThirdParty struct {
ThirdParty struct {
ID string `json:"id"`
WebsiteUrl *string `json:"websiteUrl"`
} `json:"thirdParty"`
} `json:"updateThirdParty"`
}
err := owner.Execute(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"websiteUrl": "https://updated.example.com",
},
}, &result)
require.NoError(t, err)
require.NotNil(t, result.UpdateThirdParty.ThirdParty.WebsiteUrl)
assert.Equal(t, "https://updated.example.com", *result.UpdateThirdParty.ThirdParty.WebsiteUrl)
})
t.Run("clear websiteUrl with null", func(t *testing.T) {
query := `
mutation UpdateThirdParty($input: UpdateThirdPartyInput!) {
updateThirdParty(input: $input) {
thirdParty {
id
websiteUrl
}
}
}
`
var result struct {
UpdateThirdParty struct {
ThirdParty struct {
ID string `json:"id"`
WebsiteUrl *string `json:"websiteUrl"`
} `json:"thirdParty"`
} `json:"updateThirdParty"`
}
err := owner.Execute(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"websiteUrl": nil,
},
}, &result)
require.NoError(t, err)
assert.Nil(t, result.UpdateThirdParty.ThirdParty.WebsiteUrl)
})
}
// TestThirdParty_Vet exercises the vetThirdParty mutation through authorization
// and tenant-isolation paths without running the real LLM/browser pipeline to
// completion. The e2e config sets OPENAI_API_KEY and inherits the default
// agent provider, so authorized calls enqueue vetting and return the third
// party. Request validation is covered by unit tests in pkg/thirdparty.
func TestThirdParty_Vet(t *testing.T) {
t.Parallel()
const query = `
mutation VetThirdParty($input: VetThirdPartyInput!) {
vetThirdParty(input: $input) {
thirdParty {
id
}
}
}
`
type resultShape struct {
VetThirdParty struct {
ThirdParty struct {
ID string `json:"id"`
} `json:"thirdParty"`
} `json:"vetThirdParty"`
}
t.Run("owner call enqueues vetting", func(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
thirdPartyID := factory.NewThirdParty(owner).WithName("Unconfigured vet").Create()
var result resultShape
err := owner.Execute(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"websiteUrl": "https://thirdParty.example.com",
},
}, &result)
require.NoError(t, err)
assert.Equal(t, thirdPartyID, result.VetThirdParty.ThirdParty.ID)
})
t.Run("admin call enqueues vetting", func(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
admin := testutil.NewClientInOrg(t, testutil.RoleAdmin, owner)
thirdPartyID := factory.NewThirdParty(owner).WithName("Admin-vetted thirdParty").Create()
var result resultShape
err := admin.Execute(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"websiteUrl": "https://admin.example.com",
},
}, &result)
require.NoError(t, err)
assert.Equal(t, thirdPartyID, result.VetThirdParty.ThirdParty.ID)
})
t.Run("viewer cannot vet a thirdParty", func(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
viewer := testutil.NewClientInOrg(t, testutil.RoleViewer, owner)
thirdPartyID := factory.NewThirdParty(owner).WithName("Viewer attempt").Create()
var result resultShape
err := viewer.Execute(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"websiteUrl": "https://viewer.example.com",
},
}, &result)
testutil.RequireForbiddenError(t, err)
})
t.Run("cannot vet thirdParty from another organization", func(t *testing.T) {
t.Parallel()
org1Owner := testutil.NewClient(t, testutil.RoleOwner)
org2Owner := testutil.NewClient(t, testutil.RoleOwner)
thirdPartyID := factory.NewThirdParty(org1Owner).WithName("Org1 thirdParty").Create()
var result resultShape
err := org2Owner.Execute(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"websiteUrl": "https://cross-tenant.example.com",
},
}, &result)
require.Error(t, err, "thirdParty vet must not cross tenant boundaries")
})
t.Run("procedure is accepted on the input", func(t *testing.T) {
t.Parallel()
owner := testutil.NewClient(t, testutil.RoleOwner)
thirdPartyID := factory.NewThirdParty(owner).WithName("Procedure test").Create()
var result resultShape
err := owner.Execute(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"websiteUrl": "https://procedure.example.com",
"procedure": "Focus on SOC 2 controls and data residency",
},
}, &result)
require.NoError(t, err)
assert.Equal(t, thirdPartyID, result.VetThirdParty.ThirdParty.ID)
})
}
func TestThirdParty_TenantIsolation(t *testing.T) {
t.Parallel()
org1Owner := testutil.NewClient(t, testutil.RoleOwner)
org2Owner := testutil.NewClient(t, testutil.RoleOwner)
thirdPartyID := factory.NewThirdParty(org1Owner).WithName("Org1 ThirdParty").Create()
t.Run("cannot read thirdParty from another organization", func(t *testing.T) {
query := `
query($id: ID!) {
node(id: $id) {
... on ThirdParty {
id
name
}
}
}
`
var result struct {
Node *struct {
ID string `json:"id"`
Name string `json:"name"`
} `json:"node"`
}
err := org2Owner.Execute(query, map[string]any{"id": thirdPartyID}, &result)
testutil.AssertNodeNotAccessible(t, err, result.Node == nil, "thirdParty")
})
t.Run("cannot update thirdParty from another organization", func(t *testing.T) {
query := `
mutation UpdateThirdParty($input: UpdateThirdPartyInput!) {
updateThirdParty(input: $input) {
thirdParty { id }
}
}
`
_, err := org2Owner.Do(query, map[string]any{
"input": map[string]any{
"id": thirdPartyID,
"name": "Hijacked ThirdParty",
},
})
require.Error(t, err, "Should not be able to update thirdParty from another org")
})
t.Run("cannot delete thirdParty from another organization", func(t *testing.T) {
query := `
mutation DeleteThirdParty($input: DeleteThirdPartyInput!) {
deleteThirdParty(input: $input) {
deletedThirdPartyId
}
}
`
_, err := org2Owner.Do(query, map[string]any{
"input": map[string]any{
"thirdPartyId": thirdPartyID,
},
})
require.Error(t, err, "Should not be able to delete thirdParty from another org")
})
t.Run("cannot create thirdParty referencing an administrator from another organization", func(t *testing.T) {
org2ProfileID := factory.CreateUser(org2Owner)
_, err := org1Owner.Do(`
mutation($input: CreateThirdPartyInput!) {
createThirdParty(input: $input) {
thirdPartyEdge { node { id } }
}
}
`, map[string]any{
"input": map[string]any{
"organizationId": org1Owner.GetOrganizationID().String(),
"name": factory.SafeName("ThirdParty"),
"administratorIds": []string{org2ProfileID},
},
})
require.Error(t, err, "must not accept an administratorId belonging to another organization")
})
t.Run("cannot update thirdParty to reference an administrator from another organization", func(t *testing.T) {
org2ProfileID := factory.CreateUser(org2Owner)
otherThirdPartyID := factory.NewThirdParty(org1Owner).WithName("Org1 ThirdParty for Administrators").Create()
_, err := org1Owner.Do(`
mutation($input: UpdateThirdPartyInput!) {
updateThirdParty(input: $input) {
thirdParty { id }
}
}
`, map[string]any{
"input": map[string]any{
"id": otherThirdPartyID,
"administratorIds": []string{org2ProfileID},
},
})
require.Error(t, err, "must not accept an administratorId belonging to another organization")
})
t.Run("cannot create thirdParty referencing a parent thirdParty from another organization", func(t *testing.T) {
org2ParentID := factory.NewThirdParty(org2Owner).WithName("Org2 Parent ThirdParty").Create()
_, err := org1Owner.Do(`
mutation($input: CreateThirdPartyInput!) {
createThirdParty(input: $input) {
thirdPartyEdge { node { id } }
}
}
`, map[string]any{
"input": map[string]any{
"organizationId": org1Owner.GetOrganizationID().String(),
"name": factory.SafeName("ThirdParty"),
"parentThirdPartyId": org2ParentID,
},
})
require.Error(t, err, "must not accept a parentThirdPartyId belonging to another organization")
})
}