Fix tests

This commit is contained in:
Mihaly Gyongyosi
2025-09-12 17:01:49 +02:00
parent 928853f867
commit 5fb8871c7b
5 changed files with 10 additions and 7 deletions
@@ -51,7 +51,7 @@ func ValidateOnCreate(ctx context.Context, obj *iamv0alpha1.ServiceAccount) erro
if !requester.HasRole(requestedRole) {
return apierrors.NewForbidden(iamv0alpha1.ServiceAccountResourceInfo.GroupResource(),
obj.Name,
fmt.Errorf("can not assign a role higher than user's role"))
fmt.Errorf("cannot assign a role higher than user's role"))
}
return nil
@@ -77,7 +77,7 @@ func TestValidateOnCreate(t *testing.T) {
OrgRole: identity.RoleViewer,
},
expectError: true,
errorContains: "can not assign a role higher than user's role",
errorContains: "cannot assign a role higher than user's role",
},
{
name: "external service account - valid",
+1 -1
View File
@@ -110,7 +110,7 @@ func NewMapperRegistry() MapperRegistry {
"folders": newResourceTranslation("folders", "uid", true, false),
},
"iam.grafana.app": {
"serviceaccounts": newResourceTranslation("serviceaccounts", "uid", false),
"serviceaccounts": newResourceTranslation("serviceaccounts", "uid", false, true),
// Teams is a special case. We translate user permissions from id to uid based.
"teams": newResourceTranslation("teams", "uid", false, true),
// No need to skip scope on create for roles because we translate `permissions:type:delegate` to `roles:*``
@@ -94,6 +94,10 @@ func (s *SQLPermissionsStore) GetUserPermissions(ctx context.Context, ns types.N
if err := res.Scan(&perm.Kind, &perm.Attribute, &perm.Identifier, &perm.Scope); err != nil {
return nil, err
}
// TODO: Why is the Scope set to '::' when it should be empty in the DB?
if perm.Scope == "::" {
perm.Scope = ""
}
perms = append(perms, perm)
}
@@ -154,9 +154,8 @@ func doServiceAccountCRUDTestsUsingTheNewAPIs(t *testing.T, helper *apis.K8sTest
})
saClient := helper.GetResourceClient(apis.ResourceClientArgs{
User: editorWithSACreate,
Namespace: helper.Namespacer(editorWithSACreate.Identity.GetOrgID()),
GVR: gvrServiceAccounts,
User: editorWithSACreate,
GVR: gvrServiceAccounts,
})
saToCreate := helper.LoadYAMLOrJSONFile("testdata/serviceaccount-test-higher-role-v0.yaml")
@@ -166,7 +165,7 @@ func doServiceAccountCRUDTestsUsingTheNewAPIs(t *testing.T, helper *apis.K8sTest
var statusErr *errors.StatusError
require.ErrorAs(t, err, &statusErr)
require.Equal(t, int32(403), statusErr.ErrStatus.Code)
require.Contains(t, statusErr.ErrStatus.Message, "can not assign a role higher than user's role")
require.Contains(t, statusErr.ErrStatus.Message, "cannot assign a role higher than user's role")
})
t.Run("should not be able to create service account without a title", func(t *testing.T) {