f32f636f05
GET /system/jira-config was admin-only, so non-admin users hit a 403
and the frontend silently fell back to a hardcoded jira.atlassian.com
base URL when building /browse/{key} links. Opened it to any
authenticated user (still no secrets returned).
Also drops the redundant 'security-test' Jira label, and adds a
page-size selector (10/25/50/100) and a 'no existing test yet' filter
to the Test Catalog.
22 lines
763 B
Python
22 lines
763 B
Python
"""GET /system/jira-config must be readable by any authenticated user.
|
|
|
|
Regression: it used to be admin-only, so non-admin users (e.g. red_lead)
|
|
got a 403 and the frontend silently fell back to a hardcoded
|
|
"https://jira.atlassian.com" base URL when building ticket links.
|
|
"""
|
|
|
|
|
|
def test_non_admin_can_read_jira_config(client, red_lead_headers):
|
|
resp = client.get("/api/v1/system/jira-config", headers=red_lead_headers)
|
|
assert resp.status_code == 200, resp.text
|
|
assert "url" in resp.json()
|
|
|
|
|
|
def test_non_admin_cannot_update_jira_config(client, red_lead_headers):
|
|
resp = client.patch(
|
|
"/api/v1/system/jira-config",
|
|
json={"url": "https://evil.example.com"},
|
|
headers=red_lead_headers,
|
|
)
|
|
assert resp.status_code == 403
|