Files
Aegis/backend/tests/test_jira_config_endpoint.py
kitos f32f636f05 fix(jira): expose non-admin jira-config, drop security-test label; catalog paging
GET /system/jira-config was admin-only, so non-admin users hit a 403
and the frontend silently fell back to a hardcoded jira.atlassian.com
base URL when building /browse/{key} links. Opened it to any
authenticated user (still no secrets returned).

Also drops the redundant 'security-test' Jira label, and adds a
page-size selector (10/25/50/100) and a 'no existing test yet' filter
to the Test Catalog.
2026-07-10 10:24:13 +02:00

22 lines
763 B
Python

"""GET /system/jira-config must be readable by any authenticated user.
Regression: it used to be admin-only, so non-admin users (e.g. red_lead)
got a 403 and the frontend silently fell back to a hardcoded
"https://jira.atlassian.com" base URL when building ticket links.
"""
def test_non_admin_can_read_jira_config(client, red_lead_headers):
resp = client.get("/api/v1/system/jira-config", headers=red_lead_headers)
assert resp.status_code == 200, resp.text
assert "url" in resp.json()
def test_non_admin_cannot_update_jira_config(client, red_lead_headers):
resp = client.patch(
"/api/v1/system/jira-config",
json={"url": "https://evil.example.com"},
headers=red_lead_headers,
)
assert resp.status_code == 403