Fix tests
This commit is contained in:
@@ -51,7 +51,7 @@ func ValidateOnCreate(ctx context.Context, obj *iamv0alpha1.ServiceAccount) erro
|
||||
if !requester.HasRole(requestedRole) {
|
||||
return apierrors.NewForbidden(iamv0alpha1.ServiceAccountResourceInfo.GroupResource(),
|
||||
obj.Name,
|
||||
fmt.Errorf("can not assign a role higher than user's role"))
|
||||
fmt.Errorf("cannot assign a role higher than user's role"))
|
||||
}
|
||||
|
||||
return nil
|
||||
|
||||
@@ -77,7 +77,7 @@ func TestValidateOnCreate(t *testing.T) {
|
||||
OrgRole: identity.RoleViewer,
|
||||
},
|
||||
expectError: true,
|
||||
errorContains: "can not assign a role higher than user's role",
|
||||
errorContains: "cannot assign a role higher than user's role",
|
||||
},
|
||||
{
|
||||
name: "external service account - valid",
|
||||
|
||||
@@ -110,7 +110,7 @@ func NewMapperRegistry() MapperRegistry {
|
||||
"folders": newResourceTranslation("folders", "uid", true, false),
|
||||
},
|
||||
"iam.grafana.app": {
|
||||
"serviceaccounts": newResourceTranslation("serviceaccounts", "uid", false),
|
||||
"serviceaccounts": newResourceTranslation("serviceaccounts", "uid", false, true),
|
||||
// Teams is a special case. We translate user permissions from id to uid based.
|
||||
"teams": newResourceTranslation("teams", "uid", false, true),
|
||||
// No need to skip scope on create for roles because we translate `permissions:type:delegate` to `roles:*``
|
||||
|
||||
@@ -94,6 +94,10 @@ func (s *SQLPermissionsStore) GetUserPermissions(ctx context.Context, ns types.N
|
||||
if err := res.Scan(&perm.Kind, &perm.Attribute, &perm.Identifier, &perm.Scope); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
// TODO: Why is the Scope set to '::' when it should be empty in the DB?
|
||||
if perm.Scope == "::" {
|
||||
perm.Scope = ""
|
||||
}
|
||||
perms = append(perms, perm)
|
||||
}
|
||||
|
||||
|
||||
@@ -154,9 +154,8 @@ func doServiceAccountCRUDTestsUsingTheNewAPIs(t *testing.T, helper *apis.K8sTest
|
||||
})
|
||||
|
||||
saClient := helper.GetResourceClient(apis.ResourceClientArgs{
|
||||
User: editorWithSACreate,
|
||||
Namespace: helper.Namespacer(editorWithSACreate.Identity.GetOrgID()),
|
||||
GVR: gvrServiceAccounts,
|
||||
User: editorWithSACreate,
|
||||
GVR: gvrServiceAccounts,
|
||||
})
|
||||
|
||||
saToCreate := helper.LoadYAMLOrJSONFile("testdata/serviceaccount-test-higher-role-v0.yaml")
|
||||
@@ -166,7 +165,7 @@ func doServiceAccountCRUDTestsUsingTheNewAPIs(t *testing.T, helper *apis.K8sTest
|
||||
var statusErr *errors.StatusError
|
||||
require.ErrorAs(t, err, &statusErr)
|
||||
require.Equal(t, int32(403), statusErr.ErrStatus.Code)
|
||||
require.Contains(t, statusErr.ErrStatus.Message, "can not assign a role higher than user's role")
|
||||
require.Contains(t, statusErr.ErrStatus.Message, "cannot assign a role higher than user's role")
|
||||
})
|
||||
|
||||
t.Run("should not be able to create service account without a title", func(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user