Tree:
2a9c148f1d
cached-config-operations
main
revert-7033-patch-1
test_dylint
v2-registration
0.10.0
0.11.0
0.12.0
0.13.0
0.9.0
1.0.0
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.14
1.14.1
1.14.2
1.15.0
1.15.1
1.16.0
1.16.1
1.16.2
1.16.3
1.17.0
1.18.0
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.23.0
1.23.1
1.24.0
1.25.0
1.25.1
1.25.2
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.29.2
1.3.0
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.31.0
1.32.0
1.32.1
1.32.2
1.32.3
1.32.4
1.32.5
1.32.6
1.32.7
1.33.0
1.33.1
1.33.2
1.34.0
1.34.1
1.34.2
1.34.3
1.35.0
1.35.1
1.35.2
1.35.3
1.35.4
1.35.5
1.35.6
1.35.7
1.35.8
1.36.0
1.37.0
1.37.1
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.8.0
1.9.0
1.9.1
${ noResults }
2 Commits (2a9c148f1d25a25f0ca18428f91a54e9cfe50b82)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
2a9c148f1d |
Add smoke test for the Public API member and group write endpoints
Boots a throwaway instance against a seeded SQLite database and exercises every member and group write endpoint end to end, asserting on the resulting state rather than just the status code. Covers the guards that protect organization integrity: the last confirmed owner cannot be demoted, revoked or deleted; collections, groups and members from another organization are rejected; ids belonging to another organization return 404; and writes require a token. It also pins two behaviours that are easy to regress: a group update leaves member assignments alone, and every write is recorded in the event log with no acting user and no device type. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
5 days ago |
|
|
96b46c9ae9 |
Add smoke test for the organization Public API read endpoints
Boots a throwaway instance against a temporary SQLite database seeded with two organizations (each with members, groups, collections and their access associations), mints an organization API token, and asserts on every read endpoint: member/group/collection lists and details, the direct member-to-collection grant on member detail, the group-to-collection grant on group and collection detail, and that collection responses omit the encrypted name. It also asserts the organization scoping boundary (ids owned by the second organization return 404 through the first org's token) and that an unauthenticated request returns 401. The script exits non-zero if any assertion fails, so it can be run as a check. It builds the binary when one is not supplied via VW_BIN, uses a throwaway port and temp directory, and cleans up on exit. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
1 month ago |