Skip to content

Commit

Identity's test of migration 0041 compares it with full access as it was when the migration ran, before Artifacts was offered, so tokens made then keep exactly the permissions they had and gain no artifacts scopes.

syntaqxcommitted Parent80a097bBrowse files
1 file+6−40/1 viewed
+6−4
12641264 }
12651265
12661266 /// Migration 0041 writes full access out as every permission: the
1267− /// same lists the code makes.
1267+ /// same lists the code made then, before Artifacts was offered, so
1268+ /// tokens from before keep exactly what they had.
12681269 #[test]
12691270 fn the_migration_sets_full_access_out_as_every_permission() {
1270− use g1t_contracts::scopes::{ResourceGroup, everything};
1271+ use g1t_contracts::scopes::{Resource, ResourceGroup, everything};
12711272 let sql = include_str!("../migrations/0041_one_kind_of_token.sql");
1272− assert!(sql.contains(&format!("SET scopes = '{}'", scopes_text(&everything()))));
1273− let workspace: Vec<Scope> = everything().into_iter().filter(|scope| scope.resource().group() != ResourceGroup::Account).collect();
1273+ let then: Vec<Scope> = everything().into_iter().filter(|scope| scope.resource() != Resource::Artifacts).collect();
1274+ assert!(sql.contains(&format!("SET scopes = '{}'", scopes_text(&then))));
1275+ let workspace: Vec<Scope> = then.into_iter().filter(|scope| scope.resource().group() != ResourceGroup::Account).collect();
12741276 assert!(sql.contains(&format!("SET scopes = '{}'", scopes_text(&workspace))));
12751277 let write: Vec<Scope> = workspace
12761278 .iter()