2015-06-30 14:58:10 +00:00
|
|
|
import unittest
|
|
|
|
|
|
|
|
from app import app
|
|
|
|
|
|
|
|
from data import model
|
|
|
|
from auth import scopes
|
|
|
|
from auth.permissions import SuperUserPermission, QuayDeferredPermissionUser
|
|
|
|
from initdb import setup_database_for_testing, finished_database_for_testing
|
|
|
|
|
|
|
|
|
|
|
|
SUPER_USERNAME = 'devtable'
|
|
|
|
UNSUPER_USERNAME = 'freshuser'
|
|
|
|
|
|
|
|
|
|
|
|
class TestSuperUserOps(unittest.TestCase):
|
|
|
|
def setUp(self):
|
|
|
|
setup_database_for_testing(self)
|
2015-07-15 21:25:41 +00:00
|
|
|
self._su = model.user.get_user(SUPER_USERNAME)
|
|
|
|
self._normie = model.user.get_user(UNSUPER_USERNAME)
|
2015-06-30 14:58:10 +00:00
|
|
|
|
|
|
|
def tearDown(self):
|
|
|
|
finished_database_for_testing(self)
|
|
|
|
|
|
|
|
def test_superuser_matrix(self):
|
|
|
|
test_cases = [
|
|
|
|
(self._su, {scopes.SUPERUSER}, True),
|
|
|
|
(self._su, {scopes.DIRECT_LOGIN}, True),
|
|
|
|
(self._su, {scopes.READ_USER, scopes.SUPERUSER}, True),
|
|
|
|
(self._su, {scopes.READ_USER}, False),
|
|
|
|
(self._normie, {scopes.SUPERUSER}, False),
|
|
|
|
(self._normie, {scopes.DIRECT_LOGIN}, False),
|
|
|
|
(self._normie, {scopes.READ_USER, scopes.SUPERUSER}, False),
|
|
|
|
(self._normie, {scopes.READ_USER}, False),
|
|
|
|
]
|
|
|
|
|
|
|
|
for user_obj, scope_set, expected in test_cases:
|
|
|
|
perm_user = QuayDeferredPermissionUser.for_user(user_obj, scope_set)
|
|
|
|
has_su = perm_user.can(SuperUserPermission())
|
|
|
|
self.assertEquals(has_su, expected)
|