@@ -146,7 +146,7 @@ describe('Slack access revocation', () => {
146146 } )
147147 it . each ( [
148148 { type : 'app_uninstalled' as const } ,
149- { type : 'tokens_revoked' as const , tokens : { bot : [ 'UBOT' ] , oauth : [ 'U1' ] } } ,
149+ { type : 'tokens_revoked' as const , tokens : { bot : [ 'UBOT' ] } } ,
150150 ] ) ( 'ignores stale installation-wide revocations before any writes: %j' , async ( event ) => {
151151 resetDbChainMock ( )
152152 queueTableRows ( slackSearchInstallation , [
@@ -162,26 +162,43 @@ describe('Slack access revocation', () => {
162162 await revokeSlackSearchAccess . execute ( { principal, input : { ...input , event } } )
163163 expect ( dbChainMockFns . update ) . not . toHaveBeenCalled ( )
164164 } )
165- it ( 'still revokes matching personal grants when only the installation is newer' , async ( ) => {
166- resetDbChainMock ( )
167- queueTableRows ( slackSearchInstallation , [
168- {
169- id : 'i1' ,
170- organizationId : 'org' ,
171- appId : 'A1' ,
172- teamId : 'T1' ,
173- botUserId : 'UBOT' ,
174- updatedAt : new Date ( input . event_time * 1000 + 1000 ) ,
175- } ,
176- ] )
177- dbChainMockFns . returning . mockResolvedValueOnce ( [ { providerSubjectId : 'U1' } ] )
178- await revokeSlackSearchAccess . execute ( {
179- principal,
180- input : { ...input , event : { type : 'tokens_revoked' , tokens : { oauth : [ 'U1' ] } } } ,
181- } )
182- expect ( dbChainMockFns . update . mock . calls . map ( ( [ table ] ) => table ) ) . toEqual ( [
183- credential ,
184- slackSearchTurn ,
185- ] )
186- } )
165+ it . each ( [ { oauth : [ 'U1' ] } , { oauth : [ 'U1' ] , bot : [ 'UBOT' ] } ] ) (
166+ 'revokes matching member grants independently of a newer bot installation: %j' ,
167+ async ( tokens ) => {
168+ resetDbChainMock ( )
169+ queueTableRows ( slackSearchInstallation , [
170+ {
171+ id : 'i1' ,
172+ organizationId : 'org' ,
173+ appId : 'A1' ,
174+ teamId : 'T1' ,
175+ botUserId : 'UBOT' ,
176+ updatedAt : new Date ( input . event_time * 1000 + 1000 ) ,
177+ } ,
178+ ] )
179+ dbChainMockFns . returning . mockResolvedValueOnce ( [ { providerSubjectId : 'U1' } ] )
180+ await revokeSlackSearchAccess . execute ( {
181+ principal,
182+ input : { ...input , event : { type : 'tokens_revoked' , tokens } } ,
183+ } )
184+ expect ( dbChainMockFns . update . mock . calls . map ( ( [ table ] ) => table ) ) . toEqual ( [
185+ credential ,
186+ slackSearchTurn ,
187+ ] )
188+ expect ( dbChainMockFns . where ) . toHaveBeenLastCalledWith (
189+ expect . objectContaining ( {
190+ conditions : expect . arrayContaining ( [
191+ {
192+ type : 'inArray' ,
193+ column : expect . objectContaining ( {
194+ strings : [ '' , " #>> '{message,userId}'" ] ,
195+ values : [ slackSearchTurn . payload ] ,
196+ } ) ,
197+ values : [ 'U1' ] ,
198+ } ,
199+ ] ) ,
200+ } )
201+ )
202+ }
203+ )
187204} )
0 commit comments