test(e2e): webdav + nextcloud full e2e test coverage
add a full coverage of Webdav and Nextcloud
purpose: prepare move to Drives and ensure no regression at all
test scenarios are in docs/plan/BASELINE_TESTS_NC_WEBDAV.md
current existing bugs identified via these tests:
┌──────────┬─────────┬────────────────────────────────────────────────────────────────────────────────────────────────────┐
│ Bug │ Surface │ Pin location │
├──────────┼─────────┼────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ G4/G5/K5 │ NC │ AlreadyExists → 500 instead of 412 (handle_move + trashbin restore) │
├──────────┼─────────┼────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ G9 │ NC │ Folder DELETE not row-recursive — orphan descendants stay live │
├──────────┼─────────┼────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ M5/M7 │ Native │ resolve_path_for_user mismatch — PUT writes, GET reads via lenient lookup, MOVE/DELETE can't find │
│ │ │ via strict │
├──────────┼─────────┼────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ M8 │ Native │ COPY discards destination filename — collides with source │
├──────────┼─────────┼────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ N2 │ Native │ LOCK creates the token, mutators don't check it — class-2 advertisement is aspirational │
└──────────┴─────────┴────────────────────────────────────────────────────────────────────────────────────────────────────┘
This commit is contained in:
@@ -0,0 +1,107 @@
|
||||
# =============================================================
|
||||
# OxiCloud — Baseline: admin views another user's OCS profile
|
||||
# =============================================================
|
||||
# C4 from BASELINE_TESTS_NC_WEBDAV.md.
|
||||
#
|
||||
# Deferred from Batch 1 because it needed the bob fixture
|
||||
# that `nc_second_user_setup.hurl` now provides. Pins the
|
||||
# behaviour of the existing rule in
|
||||
# `interfaces/nextcloud/ocs_handler.rs::user_provisioning_response`:
|
||||
#
|
||||
# if user.username != userid && user.role != "admin" {
|
||||
# return Json(ocs_err(403, ...)).into_response();
|
||||
# }
|
||||
#
|
||||
# i.e. you can read your own profile always; you can read
|
||||
# anyone's profile if you're admin. Bob is not admin, so bob
|
||||
# CANNOT read admin's profile (the symmetric assertion).
|
||||
#
|
||||
# Uses admin's app password for Basic Auth (same pattern as
|
||||
# `nc_ocs_user_info.hurl`).
|
||||
# =============================================================
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
# Setup 1 — JWT login as admin + mint NC app password.
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
POST {{base_url}}/api/auth/login
|
||||
Content-Type: application/json
|
||||
{ "username": "{{username}}", "password": "{{password}}" }
|
||||
|
||||
HTTP 200
|
||||
[Captures]
|
||||
admin_jwt: jsonpath "$.access_token"
|
||||
|
||||
POST {{base_url}}/api/auth/app-passwords
|
||||
Authorization: Bearer {{admin_jwt}}
|
||||
Content-Type: application/json
|
||||
{ "label": "nc_admin_views_other_user hurl test" }
|
||||
|
||||
HTTP 200
|
||||
[Captures]
|
||||
admin_nc_user: jsonpath "$.username"
|
||||
admin_nc_pw: jsonpath "$.password"
|
||||
admin_nc_pw_id: jsonpath "$.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
# Setup 2 — JWT login as bob + mint NC app password.
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
POST {{base_url}}/api/auth/login
|
||||
Content-Type: application/json
|
||||
{ "username": "bob", "password": "BobPassword1!" }
|
||||
|
||||
HTTP 200
|
||||
[Captures]
|
||||
bob_jwt: jsonpath "$.access_token"
|
||||
|
||||
POST {{base_url}}/api/auth/app-passwords
|
||||
Authorization: Bearer {{bob_jwt}}
|
||||
Content-Type: application/json
|
||||
{ "label": "nc_admin_views_other_user hurl test (bob)" }
|
||||
|
||||
HTTP 200
|
||||
[Captures]
|
||||
bob_nc_user: jsonpath "$.username"
|
||||
bob_nc_pw: jsonpath "$.password"
|
||||
bob_nc_pw_id: jsonpath "$.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
# C4-positive — admin CAN read bob's OCS provisioning profile
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
GET {{base_url}}/ocs/v1.php/cloud/users/bob?format=json
|
||||
[BasicAuth]
|
||||
{{admin_nc_user}}: {{admin_nc_pw}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.ocs.meta.statuscode" == 100
|
||||
jsonpath "$.ocs.data.id" == "bob"
|
||||
jsonpath "$.ocs.data.email" == "bob@example.com"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
# C4-symmetric — bob (non-admin) CANNOT read admin's profile
|
||||
# (proves the admin-only branch isn't a no-op)
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
GET {{base_url}}/ocs/v1.php/cloud/users/{{username}}?format=json
|
||||
[BasicAuth]
|
||||
{{bob_nc_user}}: {{bob_nc_pw}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.ocs.meta.statuscode" == 403
|
||||
jsonpath "$.ocs.meta.status" == "failure"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
# Teardown — revoke both app passwords.
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
DELETE {{base_url}}/api/auth/app-passwords/{{admin_nc_pw_id}}
|
||||
Authorization: Bearer {{admin_jwt}}
|
||||
HTTP 200
|
||||
|
||||
DELETE {{base_url}}/api/auth/app-passwords/{{bob_nc_pw_id}}
|
||||
Authorization: Bearer {{bob_jwt}}
|
||||
HTTP 200
|
||||
Reference in New Issue
Block a user