Files
Ruben FiszelandClaude Opus 5.5 3eaf2888c0 fix: scope workspace dependencies create to the path workspace (#11385)
* fix: scope workspace dependencies create to the path workspace

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs: state the workspace_id must-match contract in the spec and struct

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-28 18:15:10 +02:00

58 lines
1.9 KiB
Rust

use serde_json::json;
use sqlx::{Pool, Postgres};
#[allow(unused_imports)]
use windmill_test_utils::*;
/// An admin of one workspace must not be able to write dependency files into another
/// by naming it in the request body.
#[sqlx::test(migrations = "../migrations", fixtures("base"))]
async fn test_create_rejects_body_workspace_other_than_path(
db: Pool<Postgres>,
) -> anyhow::Result<()> {
initialize_tracing().await;
// test-user-2 is a plain user of test-workspace and an admin of its own workspace.
sqlx::query("INSERT INTO workspace (id, name, owner) VALUES ('own-workspace', 'own-workspace', 'test-user-2')")
.execute(&db)
.await?;
sqlx::query("INSERT INTO usr (workspace_id, email, username, is_admin, role) VALUES ('own-workspace', 'test2@windmill.dev', 'test-user-2', true, 'Admin')")
.execute(&db)
.await?;
let (_client, port, _server) = init_client(db.clone()).await;
let resp = reqwest::Client::new()
.post(format!(
"http://localhost:{port}/api/w/own-workspace/workspace_dependencies/create"
))
.header("Authorization", "Bearer SECRET_TOKEN_2")
.json(&json!({
"workspace_id": "test-workspace",
"language": "python3",
"content": "requests==2.28.0"
}))
.send()
.await?;
let status = resp.status().as_u16();
let body = resp.text().await?;
assert_eq!(
status, 400,
"expected the mismatched body to be rejected, got {body}"
);
assert!(
body.contains("does not match"),
"expected the workspace mismatch rejection, got {body}"
);
let written: i64 = sqlx::query_scalar("SELECT count(*) FROM workspace_dependencies")
.fetch_one(&db)
.await?;
assert_eq!(
written, 0,
"no dependency file may be written in either workspace"
);
Ok(())
}