"""GET /system/jira-config must be readable by any authenticated user. Regression: it used to be admin-only, so non-admin users (e.g. red_lead) got a 403 and the frontend silently fell back to a hardcoded "https://jira.atlassian.com" base URL when building ticket links. """ def test_non_admin_can_read_jira_config(client, red_lead_headers): resp = client.get("/api/v1/system/jira-config", headers=red_lead_headers) assert resp.status_code == 200, resp.text assert "url" in resp.json() def test_non_admin_cannot_update_jira_config(client, red_lead_headers): resp = client.patch( "/api/v1/system/jira-config", json={"url": "https://evil.example.com"}, headers=red_lead_headers, ) assert resp.status_code == 403