#302: the permission matrix counts the start page
Some checks failed
CI / Lint, typecheck, test (pull_request) Successful in 6m26s
CI / Auth e2e pack (pull_request) Failing after 6m12s
CI / Import/export fidelity gate (pull_request) Has been skipped
CI / Build container images (pull_request) Successful in 1m20s

Every pond created through the api now carries one, and the matrix pond
is created that way. The start page is an ordinary page with no grant of
its own, so it follows the pond-wide permissions: the three member
subjects each see one more, the label-restricted editor too, and the
outsider — who reaches only the explicitly public page — still sees one.

The 429 in the same run was the login rate limit, reached through the
retries of this failure rather than on its own.
This commit is contained in:
Claude Opus 5 2026-08-01 08:25:51 +02:00
parent 45f1925917
commit 30fd1ff53b

View File

@ -173,10 +173,14 @@ test('page read & edit — the 404-vs-403 policy holds per subject', async () =>
}); });
test('sidebar list is filtered to each subjects visible pages', async () => { test('sidebar list is filtered to each subjects visible pages', async () => {
expect(await listCount(f.admin.request, f.pondId)).toBe(3); // Three fixture pages plus the pond's own start page (issue #302), which
expect(await listCount(f.owner.request, f.pondId)).toBe(3); // every pond created through the api now carries. It is an ordinary page
expect(await listCount(f.reader.request, f.pondId)).toBe(3); // with no grant of its own, so it follows the pond-wide permissions: the
expect(await listCount(f.editor.request, f.pondId)).toBe(2); // secret hidden // outsider, who reaches only the explicitly public page, still sees one.
expect(await listCount(f.admin.request, f.pondId)).toBe(4);
expect(await listCount(f.owner.request, f.pondId)).toBe(4);
expect(await listCount(f.reader.request, f.pondId)).toBe(4);
expect(await listCount(f.editor.request, f.pondId)).toBe(3); // secret hidden
expect(await listCount(f.outsider.request, f.pondId)).toBe(1); // only the public page expect(await listCount(f.outsider.request, f.pondId)).toBe(1); // only the public page
// Anonymous cannot hit the authenticated list endpoint at all. // Anonymous cannot hit the authenticated list endpoint at all.
expect(await listCount(f.anon, f.pondId)).toBe(401); expect(await listCount(f.anon, f.pondId)).toBe(401);