From 0eb6320faa4a9811d21bfed256493deb0927c5d2 Mon Sep 17 00:00:00 2001 From: Ruben Fiszel Date: Sat, 3 Oct 2026 09:42:09 +0200 Subject: [PATCH] test: make the import refusal reach the handler guard (#11502) Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL Co-authored-by: Claude Opus 5.5 (1M context) --- backend/tests/job_token_scopes.rs | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/backend/tests/job_token_scopes.rs b/backend/tests/job_token_scopes.rs index 8129fe2b3e..580dc1e8e2 100644 --- a/backend/tests/job_token_scopes.rs +++ b/backend/tests/job_token_scopes.rs @@ -163,7 +163,7 @@ async fn test_restricted_job_token_is_confined(db: Pool) -> anyhow::Re "INSERT INTO job_perms (job_id, email, username, is_admin, is_operator, folders, groups, workspace_id, job_token_scopes) VALUES ($1, 'test@windmill.dev', 'test-user', true, false, '{}', '{}', 'test-workspace', - '{jobs:run}')", + '{jobs:write,jobs:run}')", ) .bind(admin_job) .execute(&db) @@ -186,7 +186,8 @@ async fn test_restricted_job_token_is_confined(db: Pool) -> anyhow::Re .json(&json!([])) .send() .await?; - assert_eq!(resp.status(), StatusCode::FORBIDDEN, "{}", resp.text().await?); + assert_eq!(resp.status(), StatusCode::FORBIDDEN); + assert!(resp.text().await?.contains("cannot import")); // Nor can it, even an admin's, place a child in an unrelated run: the flow-run routes // trust that lineage. let resp = client