aravind changes
This commit is contained in:
@@ -314,6 +314,50 @@ func mustCreate(t *testing.T, r *rbac, act actor, path string, body map[string]a
|
||||
|
||||
/* ── 3. Mass assignment ─────────────────────────────────────────────────── */
|
||||
|
||||
// The other half of a talent-only derivation: what an OPERATOR must supply.
|
||||
//
|
||||
// The server fills these columns from the session for a talent caller and for
|
||||
// nobody else — an operator filing an application or logging evidence is
|
||||
// writing about somebody who is not them. Treating the column as
|
||||
// server-supplied for every role let an operator's request past validation and
|
||||
// into SQL, where it came back as a not-null violation instead of the
|
||||
// required-field message the contract promises. The two halves have to agree:
|
||||
// what the repository will derive, and what validation stops asking for.
|
||||
func TestTalentOnlyDerivedFieldsAreRequiredOfOperators(t *testing.T) {
|
||||
r := newRBAC(t)
|
||||
|
||||
cases := []struct {
|
||||
name, path, column string
|
||||
body map[string]any
|
||||
}{
|
||||
{"job_applications.email", "/api/v1/job-applications", "email",
|
||||
map[string]any{"job_posting_id": r.activePosting, "applicant_name": "Nameless"}},
|
||||
{"evidence.worker_email", "/api/v1/evidence", "worker_email",
|
||||
map[string]any{"type": "photo_identify"}},
|
||||
}
|
||||
|
||||
for _, tc := range cases {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
got := r.as(r.admin, "POST", tc.path, tc.body)
|
||||
if got.code != http.StatusUnprocessableEntity {
|
||||
t.Fatalf("operator create without %s: got %d, want 422 (%v)",
|
||||
tc.column, got.code, got.body)
|
||||
}
|
||||
details, _ := got.body["error"].(map[string]any)["details"].(map[string]any)
|
||||
if details[tc.column] != "required" {
|
||||
t.Errorf("details = %v, want %s: required", details, tc.column)
|
||||
}
|
||||
|
||||
// The same body from a talent caller is complete, because the
|
||||
// server is about to fill the column in from their session.
|
||||
if got := r.as(r.talA, "POST", tc.path, tc.body); got.code != http.StatusCreated {
|
||||
t.Errorf("talent create without %s: got %d, want 201 (%v)",
|
||||
tc.column, got.code, got.body)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// Identity a caller supplies is ignored; identity the server derives wins.
|
||||
//
|
||||
// This is the test that makes the ownership predicates above mean anything. If
|
||||
|
||||
Reference in New Issue
Block a user