|
Four tests covering the two new endpoints added in the previous commit:
POST /auth/system/administration/resources/<id>/assign-owner
POST /auth/system/administration/resources/<id>/revoke-owner
Tests:
- assign-owner returns 401 when no Authorization header is sent
- revoke-owner returns 401 when no Authorization header is sent
- assign-owner returns 403 for a user without system:resource:assign-owner
- revoke-owner returns 403 for a user without system:resource:assign-owner
The 401 tests exercise the @require_oauth decorator directly. The 403 tests
mock require_oauth.acquire (same pattern as test_admin_user_roles.py) and use
unaff@iliated.user (TEST_USERS[3]) who has no roles and therefore no
system:resource:assign-owner privilege on the system resource.
Reviewed-By: Frederick M. Muriithi <fredmanglis@gmail.com>
|