|
1 | 1 | // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. |
2 | 2 | // |
3 | 3 | // A public form withdrawal is a kill switch, on a real showcase boot: any |
4 | | -// metadata layer that withdraws a public form's intake closes it, and layering |
5 | | -// may only narrow intake, never re-open it. |
| 4 | +// metadata layer whose body of the same view explicitly withdraws the form's |
| 5 | +// intake (the link kept, a switch cleared) closes it, and layering may only |
| 6 | +// narrow intake, never re-open it. |
6 | 7 | // |
7 | 8 | // The showcase ships `showcase_inquiry.contact`, a FormView open to anonymous |
8 | 9 | // intake at `/forms/contact-us`. The administrator saves it the way the editor |
|
13 | 14 | // - an organization overlay that keeps the form open does not survive an |
14 | 15 | // env-wide withdrawal: both anonymous doors answer `404 FORM_NOT_FOUND` |
15 | 16 | // and nothing lands; |
16 | | -// - an organization-scoped save that would re-open it is refused |
| 17 | +// - an organization-scoped save that would leave it open (a re-save of |
| 18 | +// the overlay open from before, or a re-open) is refused |
17 | 19 | // (`403 NOT_OVERRIDABLE`) and the doors stay closed; |
18 | 20 | // - withdrawn in the organization while open env-wide: closed; |
19 | 21 | // - open at both layers (control): both doors accept. |
@@ -107,10 +109,14 @@ describe('showcase: a public form withdrawal at any metadata layer holds', () => |
107 | 109 | expect(await probe()).toEqual(CLOSED); |
108 | 110 | }); |
109 | 111 |
|
110 | | - it('an organization-scoped save that would re-open it is refused, and the doors stay closed', async () => { |
| 112 | + it('an organization-scoped save that would leave it open is refused, and the doors stay closed', async () => { |
111 | 113 | await scope(organizationId); |
112 | | - // The organization overlay is still open, so withdraw it there first; the |
113 | | - // re-open is then this write's own doing. |
| 114 | + // The organization overlay is still open from before the withdrawal: |
| 115 | + // re-saving it as it is would leave open a withdrawn form. |
| 116 | + const resave = await save(true); |
| 117 | + expect(resave.status, JSON.stringify(resave.json)).toBe(403); |
| 118 | + expect(resave.json.code ?? resave.json.error?.code).toBe('NOT_OVERRIDABLE'); |
| 119 | + // Withdrawing it there is accepted; re-opening it is refused again. |
114 | 120 | expect((await save(false)).status).toBe(200); |
115 | 121 | const reopen = await save(true); |
116 | 122 | expect(reopen.status, JSON.stringify(reopen.json)).toBe(403); |
|
0 commit comments