| 136 | // Only session authentication is served; membership is read from the mirror, |
| 137 | // so any other WorkOS call fails the test. |
| 138 | const stubWorkOS = (userId: string) => |
| 139 | Layer.succeed( |
| 140 | WorkOSClient, |
| 141 | new Proxy({} as WorkOSClientService, { |
| 142 | get: (_target, prop) => { |
| 143 | if (prop === "authenticateRequest") { |
| 144 | return () => |
| 145 | Effect.succeed({ |
| 146 | userId, |
| 147 | email: `${userId}@placeholder.test`, |
| 148 | organizationId: null, |
| 149 | }); |
| 150 | } |
| 151 | return () => Effect.die(`unexpected WorkOSClient.${String(prop)} call`); |
| 152 | }, |
| 153 | }), |
| 154 | ); |
| 155 | |
| 156 | const authorizeAs = (userId: string) => |
| 157 | authorizeTenant( |