* Add account deletion and multi-section settings page - Rename /user-profile → /settings with 301 redirect from old URL - Add multi-section settings nav (Profile, Account, API placeholder, Data & Privacy) reusing existing SettingsDesktopNav/SettingsMobileGridNav components - Implement account deletion via anonymization: wipes all PII from users row, releases team ownerships, removes commissioner records, deletes sessions/accounts - Add data export request form that emails privacy@brackt.com via Resend - Add deletedAt timestamp column to users table (migration 0100) - Add anonymizeUserAccount() to user model - Add removeAllCommissionersByUserId() to commissioner model - Tests for both new model functions - Update UserMenu "Profile" link → "Settings" at /settings https://claude.ai/code/session_017Hvmof82Xr3UwKFc3pnC4X * Address code review feedback on settings/account deletion 1. Wrap anonymizeUserAccount in a DB transaction so partial failures (e.g. session delete succeeds but user update fails) can't leave accounts in an inconsistent state 2. Escape user email and notes with escapeHtml() before interpolating into the data request email body 3. Reset AlertDialog confirmed state when dialog is dismissed via backdrop click or Escape key (onOpenChange handler) 4. Extract accounts DB query to app/models/account.ts (findLinkedAccountsByUserId) to comply with the "always query through app/models/" convention 5. Replace dynamic imports() in action handlers with static top-level imports 6. Remove the unused hard-delete deleteUser() function 7. Add lastDataRequestAt timestamp to users (migration 0101) and enforce a 30-day server-side cooldown on data export requests 8. Replace fragile actionData type casts with a proper ActionData discriminated union; narrowing now works without `as` assertions 9. Strengthen tests: verify which schema tables are passed to delete() and that operations run inside the transaction https://claude.ai/code/session_017Hvmof82Xr3UwKFc3pnC4X * Fix no-non-null-assertion lint error in PrivacySection Replace non-null assertion with optional chaining on dataRequestCooldownUntil to satisfy oxlint no-non-null-assertion rule. https://claude.ai/code/session_017Hvmof82Xr3UwKFc3pnC4X --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| autodraft.test.ts | ||
| draft-board-access.test.ts | ||
| draft-order-visibility.test.ts | ||
| draft-reconnection-sync.test.ts | ||
| draft-reset.test.ts | ||
| README.md | ||
| settings-update.test.ts | ||
| team-management.test.ts | ||
League Settings Integration Tests
Overview
This directory contains integration tests for league settings features. The tests are written using Vitest and cover the following functionality:
Team Management
- Remove Team Owner: Commissioners can remove owners from teams
- Assign Team Owner: Admins can assign users to teams via dropdown
- Authorization: Proper access control for commissioners vs admins
- Edge Cases: Handling invalid inputs and error scenarios
- Integration Scenarios: Complete workflows and multi-team operations
Draft Reset
- Admin-Only Access: Only admins can reset drafts
- Delete Operations: Clearing picks and queues
- Status Updates: Resetting season to pre_draft
- Draft Order Preservation: Ensuring draft slots remain intact
- Data Integrity: Maintaining referential integrity during reset
Test Structure
Test Files
team-management.test.ts- Team management feature testsdraft-reset.test.ts- Draft reset feature tests
Fixtures
app/test/fixtures/user.ts- Mock user data including admin and regular usersapp/test/fixtures/team.ts- Mock team dataapp/test/fixtures/league.ts- Mock league data
Running Tests
Run all tests
npm test
Run tests in watch mode
npm run dev:test
Run tests with UI
npm run test:ui
Run tests with coverage
npm run test:coverage
Run only team management tests
npm test team-management
Test Coverage
The test suite covers:
1. Remove Owner Functionality (4 tests)
- ✅ Successfully remove an owner from a team
- ✅ Handle errors when removal fails
- ✅ Allow commissioners to remove owners
- ✅ Verify proper database calls
2. Assign Owner Functionality (5 tests)
- ✅ Successfully assign an owner to a team
- ✅ Handle errors when assignment fails
- ✅ Only allow admins to assign owners
- ✅ Prevent non-admins from assigning owners
- ✅ Replace existing owner when assigning new owner
3. Admin User List (3 tests)
- ✅ Fetch all users for admin dropdown
- ✅ Only fetch users when user is admin
- ✅ Return empty array for non-admin users
4. Authorization (3 tests)
- ✅ Verify admin status before allowing assignment
- ✅ Reject assignment for non-admin users
- ✅ Allow commissioners to remove owners regardless of admin status
5. Edge Cases (6 tests)
- ✅ Prevent assigning user who already owns a team in the league
- ✅ Handle removing owner from team with no owner
- ✅ Handle assigning owner to team that already has owner
- ✅ Handle invalid team ID gracefully
- ✅ Handle invalid user ID gracefully
- ✅ Proper error messages
6. Integration Scenarios (3 tests)
- ✅ Complete workflow: assign then remove owner
- ✅ Reassigning owner from one user to another
- ✅ Handle multiple teams with different ownership states
Total: 24 tests
Draft Reset Test Coverage
1. Authorization (3 tests)
- ✅ Only allow admins to reset draft
- ✅ Reject non-admin users from resetting draft
- ✅ Reject commissioners who are not admins
2. Delete Operations (4 tests)
- ✅ Delete all draft picks for a season
- ✅ Clear all draft queues for a season
- ✅ Handle errors when deleting draft picks fails
- ✅ Handle errors when clearing queues fails
3. Season Status Update (2 tests)
- ✅ Update season status to pre_draft
- ✅ Handle errors when updating season status fails
4. Status Validation (4 tests)
- ✅ Allow reset when season status is draft
- ✅ Allow reset when season status is completed
- ✅ Allow reset when season status is active
- ✅ Not allow reset when season status is pre_draft
5. Complete Workflow (3 tests)
- ✅ Execute complete reset workflow in correct order
- ✅ Not proceed with reset if admin check fails
- ✅ Handle partial failure gracefully
6. Draft Order Preservation (2 tests)
- ✅ Not delete or modify draft slots during reset
- ✅ Preserve draft order after reset
7. Edge Cases (4 tests)
- ✅ Handle reset when no draft picks exist
- ✅ Handle reset when no draft queues exist
- ✅ Handle invalid season ID gracefully
- ✅ Handle concurrent reset attempts
8. Data Integrity (2 tests)
- ✅ Ensure all picks are deleted before updating status
- ✅ Maintain referential integrity after reset
Total: 24 tests
Key Features Tested
Commissioner Capabilities
- Remove owners from any team in their league
- No ability to assign owners (admin-only)
Admin Capabilities
- Remove owners from any team
- Assign any user to any team via dropdown
- Access to full user list for assignment
- Reset draft (admin-only, not commissioners)
- Delete all draft picks
- Clear all draft queues
- Reset season to pre_draft status
- Preserve draft order
Security
- Admin-only check enforced for assignments and draft resets
- Commissioner access verified for removals
- Proper error handling for unauthorized access
- Status validation for draft reset operations
Mocking Strategy
The tests use Vitest's mocking capabilities to:
- Mock database operations (
removeTeamOwner,assignTeamOwner) - Mock user authentication (
isUserAdmin) - Mock user data fetching (
findAllUsers) - Simulate various success and error scenarios
Future Enhancements
Potential additions to the test suite:
- Test UI component rendering
- Test form validation
- Test loading states
- Test success/error toast messages
- Test concurrent operations
- Test with real database (integration tests)
- Performance tests for large user lists