#302: the permission matrix counts the start page
Every pond created through the api now carries one, and the matrix pond is created that way. The start page is an ordinary page with no grant of its own, so it follows the pond-wide permissions: the three member subjects each see one more, the label-restricted editor too, and the outsider — who reaches only the explicitly public page — still sees one. The 429 in the same run was the login rate limit, reached through the retries of this failure rather than on its own.
This commit is contained in:
parent
45f1925917
commit
30fd1ff53b
@ -173,10 +173,14 @@ test('page read & edit — the 404-vs-403 policy holds per subject', async () =>
|
|||||||
});
|
});
|
||||||
|
|
||||||
test('sidebar list is filtered to each subject’s visible pages', async () => {
|
test('sidebar list is filtered to each subject’s visible pages', async () => {
|
||||||
expect(await listCount(f.admin.request, f.pondId)).toBe(3);
|
// Three fixture pages plus the pond's own start page (issue #302), which
|
||||||
expect(await listCount(f.owner.request, f.pondId)).toBe(3);
|
// every pond created through the api now carries. It is an ordinary page
|
||||||
expect(await listCount(f.reader.request, f.pondId)).toBe(3);
|
// with no grant of its own, so it follows the pond-wide permissions: the
|
||||||
expect(await listCount(f.editor.request, f.pondId)).toBe(2); // secret hidden
|
// outsider, who reaches only the explicitly public page, still sees one.
|
||||||
|
expect(await listCount(f.admin.request, f.pondId)).toBe(4);
|
||||||
|
expect(await listCount(f.owner.request, f.pondId)).toBe(4);
|
||||||
|
expect(await listCount(f.reader.request, f.pondId)).toBe(4);
|
||||||
|
expect(await listCount(f.editor.request, f.pondId)).toBe(3); // secret hidden
|
||||||
expect(await listCount(f.outsider.request, f.pondId)).toBe(1); // only the public page
|
expect(await listCount(f.outsider.request, f.pondId)).toBe(1); // only the public page
|
||||||
// Anonymous cannot hit the authenticated list endpoint at all.
|
// Anonymous cannot hit the authenticated list endpoint at all.
|
||||||
expect(await listCount(f.anon, f.pondId)).toBe(401);
|
expect(await listCount(f.anon, f.pondId)).toBe(401);
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user