diff --git a/deploy/expense_tax.sql b/deploy/expense_tax.sql new file mode 100644 index 0000000..bea1879 --- /dev/null +++ b/deploy/expense_tax.sql @@ -0,0 +1,33 @@ +-- Deploy numerus:expense_tax to pg +-- requires: schema_numerus +-- requires: expense +-- requires: tax +-- requires: tax_rate + +begin; + +set search_path to numerus, public; + +create table expense_tax ( + expense_id integer not null references expense, + tax_id integer not null references tax, + tax_rate tax_rate not null, + primary key (expense_id, tax_id) +); + +grant select, insert, update, delete on table expense_tax to invoicer; +grant select, insert, update, delete on table expense_tax to admin; + +alter table expense_tax enable row level security; + +create policy company_policy +on expense_tax +using ( + exists( + select 1 + from expense + where expense.expense_id = expense_tax.expense_id + ) +); + +commit; diff --git a/revert/expense_tax.sql b/revert/expense_tax.sql new file mode 100644 index 0000000..5f16baa --- /dev/null +++ b/revert/expense_tax.sql @@ -0,0 +1,7 @@ +-- Revert numerus:expense_tax from pg + +begin; + +drop table if exists numerus.expense_tax; + +commit; diff --git a/sqitch.plan b/sqitch.plan index 8baf8f1..55669a5 100644 --- a/sqitch.plan +++ b/sqitch.plan @@ -71,3 +71,4 @@ edit_invoice [schema_numerus invoice currency parse_price edited_invoice_product add_contact [schema_numerus extension_vat email extension_pg_libphonenumber extension_uri country_code tag_name contact] 2023-03-25T22:32:37Z jordi fita mas # Add function to create new contacts edit_contact [schema_numerus email extension_uri country_code tag_name contact extension_vat extension_pg_libphonenumber] 2023-03-25T23:20:27Z jordi fita mas # Add function to edit contacts expense [schema_numerus contact company currency_code currency tag_name] 2023-04-30T13:46:36Z jordi fita mas # Add the expense relation +expense_tax [schema_numerus expense tax tax_rate] 2023-05-01T14:08:33Z jordi fita mas # Add relation of expense taxes diff --git a/test/expense_tax.sql b/test/expense_tax.sql new file mode 100644 index 0000000..188fdf6 --- /dev/null +++ b/test/expense_tax.sql @@ -0,0 +1,142 @@ +-- Test expense_tax +set client_min_messages to warning; +create extension if not exists pgtap; +reset client_min_messages; + +begin; + +select plan(27); + +set search_path to numerus, auth, public; + +select has_table('expense_tax'); +select has_pk('expense_tax' ); +select col_is_pk('expense_tax', array['expense_id', 'tax_id']); +select table_privs_are('expense_tax', 'guest', array []::text[]); +select table_privs_are('expense_tax', 'invoicer', array ['SELECT', 'INSERT', 'UPDATE', 'DELETE']); +select table_privs_are('expense_tax', 'admin', array ['SELECT', 'INSERT', 'UPDATE', 'DELETE']); +select table_privs_are('expense_tax', 'authenticator', array []::text[]); + +select has_column('expense_tax', 'expense_id'); +select col_is_fk('expense_tax', 'expense_id'); +select fk_ok('expense_tax', 'expense_id', 'expense', 'expense_id'); +select col_type_is('expense_tax', 'expense_id', 'integer'); +select col_not_null('expense_tax', 'expense_id'); +select col_hasnt_default('expense_tax', 'expense_id'); + +select has_column('expense_tax', 'tax_id'); +select col_is_fk('expense_tax', 'tax_id'); +select fk_ok('expense_tax', 'tax_id', 'tax', 'tax_id'); +select col_type_is('expense_tax', 'tax_id', 'integer'); +select col_not_null('expense_tax', 'tax_id'); +select col_hasnt_default('expense_tax', 'tax_id'); + +select has_column('expense_tax', 'tax_rate'); +select col_type_is('expense_tax', 'tax_rate', 'tax_rate'); +select col_not_null('expense_tax', 'tax_rate'); +select col_hasnt_default('expense_tax', 'tax_rate'); + + +set client_min_messages to warning; +truncate expense_tax cascade; +truncate expense cascade; +truncate invoice cascade; +truncate tax cascade; +truncate tax_class cascade; +truncate contact cascade; +truncate company_user cascade; +truncate payment_method cascade; +truncate company cascade; +truncate auth."user" cascade; +reset client_min_messages; + +insert into auth."user" (user_id, email, name, password, role, cookie, cookie_expires_at) +values (1, 'demo@tandem.blog', 'Demo', 'test', 'invoicer', '44facbb30d8a419dfd4bfbc44a4b5539d4970148dfc84bed0e', current_timestamp + interval '1 month') + , (5, 'admin@tandem.blog', 'Demo', 'test', 'admin', '12af4c88b528c2ad4222e3740496ecbc58e76e26f087657524', current_timestamp + interval '1 month') +; + +set constraints "company_default_payment_method_id_fkey" deferred; + +insert into company (company_id, business_name, vatin, trade_name, phone, email, web, address, city, province, postal_code, country_code, currency_code, default_payment_method_id) +values (2, 'Company 2', 'XX123', '', '555-555-555', 'a@a', '', '', '', '', '', 'ES', 'EUR', 222) + , (4, 'Company 4', 'XX234', '', '666-666-666', 'b@b', '', '', '', '', '', 'FR', 'USD', 444) +; + +insert into payment_method (payment_method_id, company_id, name, instructions) +values (444, 4, 'cash', 'cash') + , (222, 2, 'cash', 'cash') +; + +set constraints "company_default_payment_method_id_fkey" immediate; + +insert into company_user (company_id, user_id) +values (2, 1) + , (4, 5) +; + +insert into tax_class (tax_class_id, company_id, name) +values (22, 2, 'vat') + , (44, 4, 'vat') +; + +insert into tax (tax_id, company_id, tax_class_id, name, rate) +values (3, 2, 22, 'IVA 21 %', 0.21) + , (6, 4, 44, 'IVA 10 %', 0.10) +; + +insert into contact (contact_id, company_id, business_name, vatin, trade_name, phone, email, web, address, city, province, postal_code, country_code) +values ( 9, 2, 'Customer 1', 'XX555', '', '777-777-777', 'c1@e', '', '', '', '', '', 'ES') + , (10, 4, 'Customer 2', 'XX666', '', '888-888-888', 'c2@e', '', '', '', '', '', 'ES') +; + +insert into expense (expense_id, company_id, invoice_number, contact_id, invoice_date, amount, currency_code) +values (13, 2, 'INV001', 9, '2011-01-11', 111, 'EUR') + , (14, 4, 'INV002', 10, '2022-02-22', 222, 'EUR') +; + +insert into expense_tax (expense_id, tax_id, tax_rate) +values (13, 3, 0.10) + , (14, 6, -0.15) +; + +prepare expense_tax_data as +select expense_id, tax_id +from expense_tax +order by expense_id, tax_id; + +set role invoicer; +select is_empty('expense_tax_data', 'Should show no data when cookie is not set yet'); +reset role; + +select set_cookie('44facbb30d8a419dfd4bfbc44a4b5539d4970148dfc84bed0e/demo@tandem.blog'); +select bag_eq( + 'expense_tax_data', + $$ values (13, 3) + $$, + 'Should only list tax of products of the companies where demo@tandem.blog is user of' +); +reset role; + +select set_cookie('12af4c88b528c2ad4222e3740496ecbc58e76e26f087657524/admin@tandem.blog'); +select bag_eq( + 'expense_tax_data', + $$ values (14, 6) + $$, + 'Should only list tax of products of the companies where admin@tandem.blog is user of' +); +reset role; + +select set_cookie('not-a-cookie'); +select throws_ok( + 'expense_tax_data', + '42501', 'permission denied for table expense_tax', + 'Should not allow select to guest users' +); +reset role; + + +select * +from finish(); + +rollback; + diff --git a/verify/expense_tax.sql b/verify/expense_tax.sql new file mode 100644 index 0000000..d9acd55 --- /dev/null +++ b/verify/expense_tax.sql @@ -0,0 +1,14 @@ +-- Verify numerus:expense_tax on pg + +begin; + +select expense_id + , tax_id + , tax_rate +from numerus.expense_tax +where false; + +select 1 / count(*) from pg_class where oid = 'numerus.expense_tax'::regclass and relrowsecurity; +select 1 / count(*) from pg_policy where polname = 'company_policy' and polrelid = 'numerus.expense_tax'::regclass; + +rollback;