Skip to content
⌘K
Explore
Docs
Sign in
Sign up
flagon-io
/
g1t
public
Star
0
Overview
Code
Issues
5
Pull requests
1
Agents
Workflows
Deployments
Insights
Files
Commits
Branches
Tags
Releases
Compare
Commit
Identity's test of migration 0041 compares it with full access as it was when the migration ran, before Artifacts was offered, so tokens made then keep exactly the permissions they had and gain no artifacts scopes.
syntaqx
committed
19h ago
Parent
80a097b
Browse files
0612e697e3c2
1
file
+6
−4
0/1 viewed
Collapse all
Unified
Split
services/identity/src/token_reach.rs
+6
−4
View
Blame
Viewed
1264
1264
}
1265
1265
1266
1266
/// Migration 0041 writes full access out as every permission: the
1267
−
/// same lists the code makes.
1267
+
/// same lists the code made then, before Artifacts was offered, so
1268
+
/// tokens from before keep exactly what they had.
1268
1269
#[test]
1269
1270
fn the_migration_sets_full_access_out_as_every_permission() {
1270
−
use g1t_contracts::scopes::{ResourceGroup, everything};
1271
+
use g1t_contracts::scopes::{Resource, ResourceGroup, everything};
1271
1272
let sql = include_str!("../migrations/0041_one_kind_of_token.sql");
1272
−
assert!(sql.contains(&format!("SET scopes = '{}'", scopes_text(&everything()))));
1273
−
let workspace: Vec<Scope> = everything().into_iter().filter(|scope| scope.resource().group() != ResourceGroup::Account).collect();
1273
+
let then: Vec<Scope> = everything().into_iter().filter(|scope| scope.resource() != Resource::Artifacts).collect();
1274
+
assert!(sql.contains(&format!("SET scopes = '{}'", scopes_text(&then))));
1275
+
let workspace: Vec<Scope> = then.into_iter().filter(|scope| scope.resource().group() != ResourceGroup::Account).collect();
1274
1276
assert!(sql.contains(&format!("SET scopes = '{}'", scopes_text(&workspace))));
1275
1277
let write: Vec<Scope> = workspace
1276
1278
.iter()