|
3 | 3 | credential, |
4 | 4 | credentialGroup, |
5 | 5 | credentialGroupEnrollment, |
| 6 | + knowledgeBase, |
| 7 | + knowledgeConnector, |
6 | 8 | mcpServers, |
7 | 9 | member, |
8 | 10 | organization, |
@@ -30,11 +32,16 @@ import { |
30 | 32 | import { getCredentialGroup } from '@/lib/credential-groups/service' |
31 | 33 | import { SLACK_MANAGED_USER_SCOPES } from '@/lib/credential-groups/slack-managed-user-scopes' |
32 | 34 | import { createOrganizationAccountsGroup } from '@/lib/credential-groups/workspace-accounts' |
| 35 | +import { deleteConnectionCredential } from '@/lib/credentials/deletion' |
33 | 36 | import { acquireAdvisoryXactLock, tryAcquireAdvisoryXactLock } from '@/lib/db/advisory-locks' |
34 | 37 | import { |
35 | 38 | approveSearchIntegration, |
36 | 39 | listSearchIntegrations, |
37 | 40 | } from '@/lib/knowledge/application/search-integrations' |
| 41 | +import { |
| 42 | + GITHUB_INSTALLATION_PROVIDER_ID, |
| 43 | + type GitHubInstallationBinding, |
| 44 | +} from '@/lib/oauth/github-installation-types' |
38 | 45 | import { defaultLiveSearchPolicy } from '@/lib/sim-search/live/policy-schema' |
39 | 46 | import { SLACK_RTS_USER_SCOPES } from '@/lib/sim-search/live/scopes' |
40 | 47 |
|
@@ -247,6 +254,217 @@ describe('atomic organization live Search MCP setup', () => { |
247 | 254 | } |
248 | 255 | ) |
249 | 256 |
|
| 257 | + async function seedServiceSource(provider: 'google_drive' | 'github' | 'gitlab') { |
| 258 | + const knowledgeBaseId = generateId() |
| 259 | + const connectorId = generateId() |
| 260 | + const credentialId = generateId() |
| 261 | + const installation = { |
| 262 | + type: 'github_app_installation', |
| 263 | + version: 1, |
| 264 | + appId: '1', |
| 265 | + appClientId: 'fixture-github-app', |
| 266 | + installationId: '21', |
| 267 | + accountId: '11', |
| 268 | + accountType: 'Organization', |
| 269 | + accountLogin: 'fixture-owner', |
| 270 | + repositorySelection: 'selected', |
| 271 | + } satisfies GitHubInstallationBinding |
| 272 | + const encryptedInstallation = |
| 273 | + provider === 'github' ? await encryptSecret(JSON.stringify(installation)) : undefined |
| 274 | + await db.insert(knowledgeBase).values({ |
| 275 | + id: knowledgeBaseId, |
| 276 | + userId: ids.owner, |
| 277 | + organizationId: ids.organization, |
| 278 | + isSearchIndex: true, |
| 279 | + name: 'Service source fixture', |
| 280 | + }) |
| 281 | + await db.insert(credential).values({ |
| 282 | + id: credentialId, |
| 283 | + organizationId: ids.organization, |
| 284 | + type: 'service_account', |
| 285 | + providerId: provider === 'github' ? GITHUB_INSTALLATION_PROVIDER_ID : 'google-drive', |
| 286 | + ...(encryptedInstallation |
| 287 | + ? { |
| 288 | + encryptedServiceAccountKey: encryptedInstallation.encrypted, |
| 289 | + providerSubjectId: installation.installationId, |
| 290 | + providerTenantId: installation.accountId, |
| 291 | + authorizationAppId: installation.appClientId, |
| 292 | + } |
| 293 | + : {}), |
| 294 | + displayName: 'Service source fixture', |
| 295 | + createdBy: ids.owner, |
| 296 | + }) |
| 297 | + await db.insert(knowledgeConnector).values({ |
| 298 | + id: connectorId, |
| 299 | + knowledgeBaseId, |
| 300 | + connectorType: provider, |
| 301 | + credentialId, |
| 302 | + encryptedApiKey: provider === 'gitlab' ? 'synthetic-encrypted-key' : null, |
| 303 | + sourceConfig: |
| 304 | + provider === 'github' |
| 305 | + ? { repository: 'fixture-owner/repository', githubRepositoryId: '101' } |
| 306 | + : {}, |
| 307 | + accessMode: provider === 'github' ? 'members' : 'admin', |
| 308 | + status: 'active', |
| 309 | + }) |
| 310 | + await db.insert(organizationSearchIntegration).values({ |
| 311 | + organizationId: ids.organization, |
| 312 | + connectorType: provider, |
| 313 | + approved: true, |
| 314 | + }) |
| 315 | + await db |
| 316 | + .update(organization) |
| 317 | + .set({ |
| 318 | + metadata: { |
| 319 | + liveSearchPolicies: { |
| 320 | + [provider]: { |
| 321 | + ...defaultLiveSearchPolicy(provider), |
| 322 | + accessMode: 'service_account', |
| 323 | + ...(provider === 'google_drive' ? { sourceId: connectorId } : {}), |
| 324 | + }, |
| 325 | + }, |
| 326 | + }, |
| 327 | + }) |
| 328 | + .where(eq(organization.id, ids.organization)) |
| 329 | + return { knowledgeBaseId, connectorId, credentialId } |
| 330 | + } |
| 331 | + |
| 332 | + async function integrationStatus(provider: string) { |
| 333 | + const data = await listSearchIntegrations.execute({ |
| 334 | + principal: createSessionPrincipal({ userId: ids.member, sessionId: generateId() }), |
| 335 | + input: { organizationId: ids.organization }, |
| 336 | + }) |
| 337 | + return listSearchIntegrationsContract.response.schema |
| 338 | + .parse({ success: true, data }) |
| 339 | + .data.find((entry) => entry.connectorType === provider) |
| 340 | + } |
| 341 | + |
| 342 | + it.each(['google_drive', 'github', 'gitlab'] as const)( |
| 343 | + 'reports a configured %s service source without requiring a member account', |
| 344 | + async (provider) => { |
| 345 | + const source = await seedServiceSource(provider) |
| 346 | + expect((await snapshot()).groups).toEqual([]) |
| 347 | + expect(await integrationStatus(provider)).toMatchObject({ configuredServiceSource: true }) |
| 348 | + await db |
| 349 | + .update(knowledgeConnector) |
| 350 | + .set({ status: 'disabled' }) |
| 351 | + .where(eq(knowledgeConnector.id, source.connectorId)) |
| 352 | + expect(await integrationStatus(provider)).toMatchObject({ configuredServiceSource: false }) |
| 353 | + await db |
| 354 | + .update(knowledgeConnector) |
| 355 | + .set({ status: 'active', archivedAt: new Date() }) |
| 356 | + .where(eq(knowledgeConnector.id, source.connectorId)) |
| 357 | + expect(await integrationStatus(provider)).toMatchObject({ configuredServiceSource: false }) |
| 358 | + await db |
| 359 | + .update(knowledgeConnector) |
| 360 | + .set({ archivedAt: null }) |
| 361 | + .where(eq(knowledgeConnector.id, source.connectorId)) |
| 362 | + await db |
| 363 | + .update(knowledgeBase) |
| 364 | + .set({ deletedAt: new Date() }) |
| 365 | + .where(eq(knowledgeBase.id, source.knowledgeBaseId)) |
| 366 | + expect(await integrationStatus(provider)).toMatchObject({ configuredServiceSource: false }) |
| 367 | + await db |
| 368 | + .update(knowledgeBase) |
| 369 | + .set({ deletedAt: null }) |
| 370 | + .where(eq(knowledgeBase.id, source.knowledgeBaseId)) |
| 371 | + await db |
| 372 | + .update(organizationSearchIntegration) |
| 373 | + .set({ approved: false }) |
| 374 | + .where(eq(organizationSearchIntegration.organizationId, ids.organization)) |
| 375 | + expect(await integrationStatus(provider)).toMatchObject({ configuredServiceSource: false }) |
| 376 | + } |
| 377 | + ) |
| 378 | + |
| 379 | + it('stops reporting a service source as configured after its credential is deleted', async () => { |
| 380 | + const source = await seedServiceSource('google_drive') |
| 381 | + expect(await integrationStatus('google_drive')).toMatchObject({ configuredServiceSource: true }) |
| 382 | + await deleteConnectionCredential({ |
| 383 | + credentialId: source.credentialId, |
| 384 | + organizationId: ids.organization, |
| 385 | + reason: 'user_delete', |
| 386 | + }) |
| 387 | + expect(await integrationStatus('google_drive')).toMatchObject({ |
| 388 | + configuredServiceSource: false, |
| 389 | + }) |
| 390 | + }) |
| 391 | + |
| 392 | + it('requires the selected service source to belong to this organization and provider', async () => { |
| 393 | + const source = await seedServiceSource('google_drive') |
| 394 | + const otherOrganizationId = generateId() |
| 395 | + await db.insert(organization).values({ |
| 396 | + id: otherOrganizationId, |
| 397 | + name: 'Other service fixture', |
| 398 | + slug: otherOrganizationId, |
| 399 | + }) |
| 400 | + try { |
| 401 | + await db |
| 402 | + .update(knowledgeBase) |
| 403 | + .set({ organizationId: otherOrganizationId }) |
| 404 | + .where(eq(knowledgeBase.id, source.knowledgeBaseId)) |
| 405 | + expect(await integrationStatus('google_drive')).toMatchObject({ |
| 406 | + configuredServiceSource: false, |
| 407 | + }) |
| 408 | + await db |
| 409 | + .update(knowledgeBase) |
| 410 | + .set({ organizationId: ids.organization }) |
| 411 | + .where(eq(knowledgeBase.id, source.knowledgeBaseId)) |
| 412 | + await db |
| 413 | + .update(knowledgeConnector) |
| 414 | + .set({ connectorType: 'confluence' }) |
| 415 | + .where(eq(knowledgeConnector.id, source.connectorId)) |
| 416 | + expect(await integrationStatus('google_drive')).toMatchObject({ |
| 417 | + configuredServiceSource: false, |
| 418 | + }) |
| 419 | + await db |
| 420 | + .update(knowledgeConnector) |
| 421 | + .set({ connectorType: 'google_drive' }) |
| 422 | + .where(eq(knowledgeConnector.id, source.connectorId)) |
| 423 | + await db |
| 424 | + .update(organization) |
| 425 | + .set({ |
| 426 | + metadata: { |
| 427 | + liveSearchPolicies: { |
| 428 | + google_drive: { |
| 429 | + ...defaultLiveSearchPolicy(), |
| 430 | + accessMode: 'service_account', |
| 431 | + sourceId: generateId(), |
| 432 | + }, |
| 433 | + }, |
| 434 | + }, |
| 435 | + }) |
| 436 | + .where(eq(organization.id, ids.organization)) |
| 437 | + expect(await integrationStatus('google_drive')).toMatchObject({ |
| 438 | + configuredServiceSource: false, |
| 439 | + }) |
| 440 | + } finally { |
| 441 | + await db.delete(organization).where(eq(organization.id, otherOrganizationId)) |
| 442 | + } |
| 443 | + }) |
| 444 | + |
| 445 | + it('does not count a GitHub member source without its active installation credential', async () => { |
| 446 | + const source = await seedServiceSource('github') |
| 447 | + await db |
| 448 | + .update(credential) |
| 449 | + .set({ revokedAt: new Date() }) |
| 450 | + .where(eq(credential.id, source.credentialId)) |
| 451 | + expect(await integrationStatus('github')).toMatchObject({ configuredServiceSource: false }) |
| 452 | + await db |
| 453 | + .update(credential) |
| 454 | + .set({ revokedAt: null }) |
| 455 | + .where(eq(credential.id, source.credentialId)) |
| 456 | + await db |
| 457 | + .update(knowledgeConnector) |
| 458 | + .set({ memberSyncStatus: 'disabled' }) |
| 459 | + .where(eq(knowledgeConnector.id, source.connectorId)) |
| 460 | + expect(await integrationStatus('github')).toMatchObject({ configuredServiceSource: false }) |
| 461 | + await db |
| 462 | + .update(knowledgeConnector) |
| 463 | + .set({ memberSyncStatus: 'idle', sourceConfig: {} }) |
| 464 | + .where(eq(knowledgeConnector.id, source.connectorId)) |
| 465 | + expect(await integrationStatus('github')).toMatchObject({ configuredServiceSource: false }) |
| 466 | + }) |
| 467 | + |
250 | 468 | it('keeps disabled Zoom approvals visible and removable without permitting reapproval', async () => { |
251 | 469 | const connectorType = 'zoom' |
252 | 470 | await db.insert(organizationSearchIntegration).values({ |
|
0 commit comments