1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
|
"""Tests for system admin resource-ownership endpoints.
Covers POST /auth/system/administration/resources/<id>/assign-owner
and POST /auth/system/administration/resources/<id>/revoke-owner.
"""
import pytest
from tests.unit.auth import conftest
from tests.unit.auth.fixtures.resource_fixtures import TEST_RESOURCES
# Arbitrary target resource for the endpoint path — the privilege check fires
# before any resource lookup, so the resource need not exist for 401/403 tests.
_TARGET_RESOURCE = str(TEST_RESOURCES[0].resource_id)
# Minimal body for both endpoints (the target user for ownership change).
_BODY = {"user_id": str(conftest.TEST_USERS[3].user_id)}
_ASSIGN_URL = f"/auth/system/administration/resources/{_TARGET_RESOURCE}/assign-owner"
_REVOKE_URL = f"/auth/system/administration/resources/{_TARGET_RESOURCE}/revoke-owner"
_NON_SYSADMIN = conftest.TEST_USERS[3] # unaff@iliated.user — no roles at all
def _mock_token(mocker, user, clients):
"""Patch require_oauth.acquire in the admin resources module."""
mocker.patch(
"gn_auth.auth.system.admin.resources.require_oauth.acquire",
conftest.get_tokeniser(
user,
tuple(c for c in clients if c.user == user)[0]))
# ---------------------------------------------------------------------------
# No-token tests (401)
# ---------------------------------------------------------------------------
@pytest.mark.unit_test
def test_assign_owner_no_token_returns_401(fxtr_app):
"""
GIVEN: no Authorization header
WHEN: POST .../assign-owner
THEN: 401 is returned
"""
with fxtr_app.test_client() as http:
res = http.post(_ASSIGN_URL, json=_BODY)
assert res.status_code == 401
@pytest.mark.unit_test
def test_revoke_owner_no_token_returns_401(fxtr_app):
"""
GIVEN: no Authorization header
WHEN: POST .../revoke-owner
THEN: 401 is returned
"""
with fxtr_app.test_client() as http:
res = http.post(_REVOKE_URL, json=_BODY)
assert res.status_code == 401
# ---------------------------------------------------------------------------
# Non-sysadmin tests (403)
# ---------------------------------------------------------------------------
@pytest.mark.unit_test
def test_assign_owner_non_sysadmin_returns_403(fxtr_app, mocker, fxtr_oauth2_clients):
"""
GIVEN: a valid token for a user without system:resource:assign-owner
WHEN: POST .../assign-owner
THEN: 403 is returned
"""
_conn, clients = fxtr_oauth2_clients
_mock_token(mocker, _NON_SYSADMIN, clients)
with fxtr_app.test_client() as http:
res = http.post(
_ASSIGN_URL, json=_BODY,
headers={"Authorization": "Bearer some-mocked-token"})
assert res.status_code == 403
@pytest.mark.unit_test
def test_revoke_owner_non_sysadmin_returns_403(fxtr_app, mocker, fxtr_oauth2_clients):
"""
GIVEN: a valid token for a user without system:resource:assign-owner
WHEN: POST .../revoke-owner
THEN: 403 is returned
"""
_conn, clients = fxtr_oauth2_clients
_mock_token(mocker, _NON_SYSADMIN, clients)
with fxtr_app.test_client() as http:
res = http.post(
_REVOKE_URL, json=_BODY,
headers={"Authorization": "Bearer some-mocked-token"})
assert res.status_code == 403
|