Skip to content

Commit e8778ac

Browse files
committed
test(dogfood): re-saving an org overlay open from before an env-wide withdrawal is refused
Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018zT8d8NpiQ1ExhuNd5TxY6
1 parent cfc55af commit e8778ac

1 file changed

Lines changed: 12 additions & 6 deletions

File tree

‎packages/qa/dogfood/test/showcase-public-form-withdrawal-layers.dogfood.test.ts‎

Lines changed: 12 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,9 @@
11
// Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license.
22
//
33
// A public form withdrawal is a kill switch, on a real showcase boot: any
4-
// metadata layer that withdraws a public form's intake closes it, and layering
5-
// may only narrow intake, never re-open it.
4+
// metadata layer whose body of the same view explicitly withdraws the form's
5+
// intake (the link kept, a switch cleared) closes it, and layering may only
6+
// narrow intake, never re-open it.
67
//
78
// The showcase ships `showcase_inquiry.contact`, a FormView open to anonymous
89
// intake at `/forms/contact-us`. The administrator saves it the way the editor
@@ -13,7 +14,8 @@
1314
// - an organization overlay that keeps the form open does not survive an
1415
// env-wide withdrawal: both anonymous doors answer `404 FORM_NOT_FOUND`
1516
// and nothing lands;
16-
// - an organization-scoped save that would re-open it is refused
17+
// - an organization-scoped save that would leave it open (a re-save of
18+
// the overlay open from before, or a re-open) is refused
1719
// (`403 NOT_OVERRIDABLE`) and the doors stay closed;
1820
// - withdrawn in the organization while open env-wide: closed;
1921
// - open at both layers (control): both doors accept.
@@ -107,10 +109,14 @@ describe('showcase: a public form withdrawal at any metadata layer holds', () =>
107109
expect(await probe()).toEqual(CLOSED);
108110
});
109111

110-
it('an organization-scoped save that would re-open it is refused, and the doors stay closed', async () => {
112+
it('an organization-scoped save that would leave it open is refused, and the doors stay closed', async () => {
111113
await scope(organizationId);
112-
// The organization overlay is still open, so withdraw it there first; the
113-
// re-open is then this write's own doing.
114+
// The organization overlay is still open from before the withdrawal:
115+
// re-saving it as it is would leave open a withdrawn form.
116+
const resave = await save(true);
117+
expect(resave.status, JSON.stringify(resave.json)).toBe(403);
118+
expect(resave.json.code ?? resave.json.error?.code).toBe('NOT_OVERRIDABLE');
119+
// Withdrawing it there is accepted; re-opening it is refused again.
114120
expect((await save(false)).status).toBe(200);
115121
const reopen = await save(true);
116122
expect(reopen.status, JSON.stringify(reopen.json)).toBe(403);

0 commit comments

Comments
 (0)