feat: Add Firebase security rules testing and error handling
Introduces unit tests for Firestore security rules and adds error handling to data fetching hooks. This enhances the robustness and security of the application by validating access control logic and providing feedback on data retrieval failures. Includes: - Setup for Firestore unit testing. - Basic tests for signal query and user collection access. - Error logging for `testimonials` and `notifications` data fetching. - Updates to `firestore.rules` for stricter access checks. - Adds necessary development dependencies for testing.
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
import { readFileSync } from 'fs';
|
||||
import { initializeTestEnvironment, assertFails, assertSucceeds } from '@firebase/rules-unit-testing';
|
||||
|
||||
async function main() {
|
||||
const projectId = `test-project-${Date.now()}`;
|
||||
const testEnv = await initializeTestEnvironment({
|
||||
projectId,
|
||||
firestore: {
|
||||
rules: readFileSync('firestore.rules', 'utf8'),
|
||||
},
|
||||
});
|
||||
|
||||
const alice = testEnv.authenticatedContext('alice', { email: 'alice@example.com' });
|
||||
const db = alice.firestore();
|
||||
|
||||
// Test signals query
|
||||
const signalsRef = db.collection('signals');
|
||||
const q = signalsRef.where('userId', '==', 'alice');
|
||||
|
||||
try {
|
||||
await assertSucceeds(q.get());
|
||||
console.log("SUCCESS: signals query passed");
|
||||
} catch (err) {
|
||||
console.error("FAILED: signals query failed", err);
|
||||
}
|
||||
|
||||
// Next, let's try users list
|
||||
try {
|
||||
await assertFails(db.collection('users').get());
|
||||
console.log("SUCCESS: non-admin users list correctly denied");
|
||||
} catch(err) {
|
||||
console.error("FAILED: non-admin users list passed or threw error we didn't expect", err);
|
||||
}
|
||||
}
|
||||
|
||||
main().then(() => process.exit(0)).catch(err => { console.error(err); process.exit(1); });
|
||||
Reference in New Issue
Block a user