refactor(user): apply chanoges to hurl tests

This commit is contained in:
Edouard Vanbelle
2026-08-21 23:19:00 +02:00
parent c583b26355
commit a8fa281a02
48 changed files with 310 additions and 244 deletions
+3 -3
View File
@@ -56,7 +56,7 @@ Content-Type: application/json
HTTP 201
[Captures]
charlie_id: jsonpath "$.id"
charlie_id: jsonpath "$.user.id"
# ─────────────────────────────────────────────────────────────
@@ -89,7 +89,7 @@ Authorization: Bearer {{charlie_token_v1}}
HTTP 200
[Asserts]
jsonpath "$.storage_quota_bytes" == 209715200
jsonpath "$.full.storage_quota_bytes" == 209715200
# ─────────────────────────────────────────────────────────────
@@ -108,7 +108,7 @@ Authorization: Bearer {{charlie_token_v1}}
HTTP 200
[Asserts]
jsonpath "$.role" == "admin"
jsonpath "$.full.user.role" == "admin"
# ─────────────────────────────────────────────────────────────
+2 -2
View File
@@ -19,7 +19,7 @@ Content-Type: application/json
HTTP 200
[Asserts]
jsonpath "$.access_token" exists
jsonpath "$.user.email" == "{{email}}"
jsonpath "$.user.full.user.email" == "{{email}}"
# ─────────────────────────────────────────────────────────────
@@ -34,7 +34,7 @@ Content-Type: application/json
HTTP 200
[Asserts]
jsonpath "$.access_token" exists
jsonpath "$.user.email" == "{{email}}"
jsonpath "$.user.full.user.email" == "{{email}}"
# ─────────────────────────────────────────────────────────────
+3 -3
View File
@@ -142,10 +142,10 @@ Authorization: Bearer {{alice_magic_access_token}}
HTTP 200
[Asserts]
jsonpath "$.email" == "{{email}}"
jsonpath "$.username" == "{{username}}"
jsonpath "$.full.user.email" == "{{email}}"
jsonpath "$.full.user.username" == "{{username}}"
[Captures]
admin_user_id: jsonpath "$.id"
admin_user_id: jsonpath "$.full.user.id"
# ─────────────────────────────────────────────────────────────
+1 -1
View File
@@ -78,7 +78,7 @@ Authorization: Bearer {{access_v2}}
HTTP 200
[Asserts]
jsonpath "$.username" == "{{username}}"
jsonpath "$.full.user.username" == "{{username}}"
# ─────────────────────────────────────────────────────────────
+9 -9
View File
@@ -52,7 +52,7 @@ Content-Type: application/json
HTTP 201
[Captures]
bob_user_id: jsonpath "$.id"
bob_user_id: jsonpath "$.user.id"
# ─────────────────────────────────────────────────────────────
@@ -73,8 +73,8 @@ Authorization: Bearer {{bob_token}}
HTTP 200
[Asserts]
jsonpath "$.is_external" == true
jsonpath "$.storage_quota_bytes" == 0
jsonpath "$.full.user.is_external" == true
jsonpath "$.full.storage_quota_bytes" == 0
# ─────────────────────────────────────────────────────────────
@@ -88,8 +88,8 @@ Content-Type: application/json
HTTP 200
[Asserts]
jsonpath "$.is_external" == false
jsonpath "$.storage_quota_bytes" > 0
jsonpath "$.full.user.is_external" == false
jsonpath "$.full.storage_quota_bytes" > 0
# ─────────────────────────────────────────────────────────────
@@ -100,8 +100,8 @@ Authorization: Bearer {{bob_token}}
HTTP 200
[Asserts]
jsonpath "$.is_external" == false
jsonpath "$.storage_quota_bytes" > 0
jsonpath "$.full.user.is_external" == false
jsonpath "$.full.storage_quota_bytes" > 0
# ─────────────────────────────────────────────────────────────
@@ -179,7 +179,7 @@ Content-Type: application/json
HTTP 201
[Captures]
carol_user_id: jsonpath "$.id"
carol_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
Content-Type: application/json
@@ -204,7 +204,7 @@ Authorization: Bearer {{carol_token}}
HTTP 200
[Asserts]
jsonpath "$.is_external" == true
jsonpath "$.full.user.is_external" == true
# ─────────────────────────────────────────────────────────────
+2 -2
View File
@@ -41,7 +41,7 @@ Content-Type: application/json
HTTP 200
[Captures]
alice_token: jsonpath "$.access_token"
alice_user_id: jsonpath "$.user.id"
alice_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
@@ -120,7 +120,7 @@ Content-Type: application/json
HTTP 200
[Captures]
bob_token: jsonpath "$.access_token"
bob_user_id: jsonpath "$.user.id"
bob_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
+2 -2
View File
@@ -24,7 +24,7 @@ Content-Type: application/json
HTTP 200
[Captures]
token: jsonpath "$.access_token"
admin_user_id: jsonpath "$.user.id"
admin_user_id: jsonpath "$.user.full.user.id"
[Asserts]
jsonpath "$.access_token" isString
jsonpath "$.token_type" == "Bearer"
@@ -344,7 +344,7 @@ Content-Type: application/json
HTTP 200
[Captures]
bob_token: jsonpath "$.access_token"
bob_user_id: jsonpath "$.user.id"
bob_user_id: jsonpath "$.user.full.user.id"
# Step 17 — Bob's book listing does NOT include Alice's book.
+1 -1
View File
@@ -71,7 +71,7 @@ Content-Type: application/json
HTTP 200
[Captures]
owner_token: jsonpath "$.access_token"
owner_user_id: jsonpath "$.user.id"
owner_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
+1 -1
View File
@@ -67,7 +67,7 @@ Content-Type: application/json
HTTP 200
[Captures]
owner_token: jsonpath "$.access_token"
owner_user_id: jsonpath "$.user.id"
owner_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
+1 -1
View File
@@ -249,7 +249,7 @@ Content-Type: application/json
HTTP *
[Captures]
alice_id: jsonpath "$.id"
alice_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
+1 -1
View File
@@ -103,7 +103,7 @@ Content-Type: application/json
HTTP *
[Captures]
fresh_user_id: jsonpath "$.id"
fresh_user_id: jsonpath "$.user.id"
# ─────────────────────────────────────────────────────────────
+2 -2
View File
@@ -65,7 +65,7 @@ Content-Type: application/json
HTTP 200
[Captures]
owner_token: jsonpath "$.access_token"
owner_user_id: jsonpath "$.user.id"
owner_user_id: jsonpath "$.user.full.user.id"
# Provision `dp_intruder` — a second internal user used only to
@@ -91,7 +91,7 @@ Content-Type: application/json
HTTP 200
[Captures]
intruder_token: jsonpath "$.access_token"
intruder_user_id: jsonpath "$.user.id"
intruder_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
+1 -1
View File
@@ -60,7 +60,7 @@ Content-Type: application/json
HTTP 200
[Captures]
owner_token: jsonpath "$.access_token"
owner_user_id: jsonpath "$.user.id"
owner_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
+2 -2
View File
@@ -82,7 +82,7 @@ Content-Type: application/json
HTTP 200
[Captures]
owner_token: jsonpath "$.access_token"
owner_user_id: jsonpath "$.user.id"
owner_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
@@ -107,7 +107,7 @@ Content-Type: application/json
HTTP 200
[Captures]
target_user_id: jsonpath "$.user.id"
target_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
+3 -3
View File
@@ -31,7 +31,7 @@ Content-Type: application/json
HTTP 200
[Captures]
admin_token: jsonpath "$.access_token"
admin_user_id: jsonpath "$.user.id"
admin_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
@@ -70,7 +70,7 @@ Content-Type: application/json
HTTP 201
[Captures]
alice_user_id: jsonpath "$.id"
alice_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/admin/users
Authorization: Bearer {{admin_token}}
@@ -79,7 +79,7 @@ Content-Type: application/json
HTTP 201
[Captures]
bob_user_id: jsonpath "$.id"
bob_user_id: jsonpath "$.user.id"
# Alice's first login fires `PersonalDriveLifecycleHook::on_user_login`
+5 -5
View File
@@ -64,7 +64,7 @@ Content-Type: application/json
HTTP 200
[Captures]
admin_token: jsonpath "$.access_token"
admin_user_id: jsonpath "$.user.id"
admin_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
@@ -113,7 +113,7 @@ Content-Type: application/json
HTTP 201
[Captures]
alice_user_id: jsonpath "$.id"
alice_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
Content-Type: application/json
@@ -470,7 +470,7 @@ Content-Type: application/json
HTTP 201
[Captures]
bob_user_id: jsonpath "$.id"
bob_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
Content-Type: application/json
@@ -657,7 +657,7 @@ Content-Type: application/json
HTTP 201
[Captures]
carol_user_id: jsonpath "$.id"
carol_user_id: jsonpath "$.user.id"
# 24a — Owner grants Carol Owner role (Owner-creates-Owner).
@@ -836,7 +836,7 @@ Content-Type: application/json
HTTP 201
[Captures]
dave_user_id: jsonpath "$.id"
dave_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
Content-Type: application/json
+36 -10
View File
@@ -23,7 +23,7 @@ Content-Type: application/json
HTTP 200
[Captures]
alice_token: jsonpath "$.access_token"
alice_user_id: jsonpath "$.user.id"
alice_user_id: jsonpath "$.user.full.user.id"
GET {{base_url}}/api/folders
Authorization: Bearer {{alice_token}}
@@ -226,13 +226,16 @@ Authorization: Bearer {{bob_access_token}}
HTTP 200
[Asserts]
# `/api/users/{id}` returns the slim `PublicUserDto` (9 fields) —
# id / email / username / role / image / is_external / given_name /
# family_name / is_online. Admin-visible fields like
# `email_verified_at` moved to `FullUserDto` under the three-layer
# refactor (docs/plan/userdto-refactor.md) and are checked below
# via `/api/admin/users`.
jsonpath "$.id" == "{{bob_user_id}}"
jsonpath "$.is_external" == true
jsonpath "$.email" == "bob@externalcompany.com"
jsonpath "$.username" not exists
# PR 23 — bob redeemed his invitation magic-link in Step 8, so his
# email_verified_at was stamped at that time and stays set.
jsonpath "$.email_verified_at" exists
# 11d — bob CAN look up Alice (his granter) — shared-grant relationship
# lets the external recipient resolve the sharer's display name +
@@ -244,14 +247,37 @@ HTTP 200
[Asserts]
jsonpath "$.id" == "{{alice_user_id}}"
jsonpath "$.is_external" == false
# Setup admin is auto-verified at creation. `setup_create_admin` stamps
# 11c/d/verify — admin (alice) observes email_verified_at on both
# users via `GET /api/admin/users/{id}` — returns `FullUserDto`
# (public identity in `.user` + admin-visible extras at top level).
#
# `email_verified_at` lives on `FullUserDto` (admin+self-visible),
# not on `PublicUserDto` — peer views via `/api/users/{id}` never
# expose it. The admin single-user endpoint is the correct
# observation surface. See `docs/plan/userdto-refactor.md` for the
# three-layer split.
#
# Setup admin auto-verified rationale: `setup_create_admin` stamps
# `email_verified_at = NOW()` — admin fiat counts as verification,
# matching the OIDC-JIT convention. Rationale: an operator running the
# first-run wizard is authoritative by construction (they set the
# password at the console on a fresh install). Without this, flipping
# matching the OIDC-JIT convention. An operator running the first-run
# wizard is authoritative by construction. Without this, flipping
# `OXICLOUD_REQUIRE_VERIFIED_EMAIL=true` on an existing deployment
# would lock the sole admin out of their own instance. The admin login
# exemption is a second layer of defense; this stamp is the primary.
# would lock the sole admin out of their own instance.
GET {{base_url}}/api/admin/users/{{bob_user_id}}
Authorization: Bearer {{alice_token}}
HTTP 200
[Asserts]
jsonpath "$.user.id" == "{{bob_user_id}}"
jsonpath "$.email_verified_at" exists
GET {{base_url}}/api/admin/users/{{alice_user_id}}
Authorization: Bearer {{alice_token}}
HTTP 200
[Asserts]
jsonpath "$.user.id" == "{{alice_user_id}}"
jsonpath "$.email_verified_at" exists
# 11e — bob CANNOT enumerate unrelated users. A random UUID returns 404
+2 -2
View File
@@ -19,11 +19,11 @@ Content-Type: application/json
HTTP 200
[Captures]
token: jsonpath "$.access_token"
admin_user_id: jsonpath "$.user.id"
admin_user_id: jsonpath "$.user.full.user.id"
[Asserts]
jsonpath "$.access_token" isString
jsonpath "$.token_type" == "Bearer"
jsonpath "$.user.id" isString
jsonpath "$.user.full.user.id" isString
# ─────────────────────────────────────────────────────────────
+2 -2
View File
@@ -29,7 +29,7 @@ Content-Type: application/json
HTTP 200
[Captures]
alice_token: jsonpath "$.access_token"
alice_user_id: jsonpath "$.user.id"
alice_user_id: jsonpath "$.user.full.user.id"
GET {{base_url}}/api/folders
@@ -57,7 +57,7 @@ Content-Type: application/json
HTTP 201
[Captures]
mallory_user_id: jsonpath "$.id"
mallory_user_id: jsonpath "$.user.id"
# ─────────────────────────────────────────────────────────────
+5 -5
View File
@@ -23,7 +23,7 @@ Content-Type: application/json
HTTP 200
[Captures]
alice_token: jsonpath "$.access_token"
alice_user_id: jsonpath "$.user.id"
alice_user_id: jsonpath "$.user.full.user.id"
GET {{base_url}}/api/folders
Authorization: Bearer {{alice_token}}
@@ -45,7 +45,7 @@ Content-Type: application/json
HTTP 201
[Captures]
dave_user_id: jsonpath "$.id"
dave_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/admin/users
Authorization: Bearer {{alice_token}}
@@ -54,7 +54,7 @@ Content-Type: application/json
HTTP 201
[Captures]
eve_user_id: jsonpath "$.id"
eve_user_id: jsonpath "$.user.id"
# ─────────────────────────────────────────────────────────────
@@ -371,7 +371,7 @@ Content-Type: application/json
HTTP 201
[Captures]
adam_user_id: jsonpath "$.id"
adam_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
Content-Type: application/json
@@ -1044,7 +1044,7 @@ Content-Type: application/json
HTTP 201
[Captures]
frank_user_id: jsonpath "$.id"
frank_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
Content-Type: application/json
+1 -1
View File
@@ -44,7 +44,7 @@ Content-Type: application/json
HTTP 201
[Captures]
henry_user_id: jsonpath "$.id"
henry_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
Content-Type: application/json
+1 -1
View File
@@ -76,7 +76,7 @@ Content-Type: application/json
HTTP 201
[Captures]
dora_id: jsonpath "$.id"
dora_id: jsonpath "$.user.id"
# ─────────────────────────────────────────────────────────────
+1 -1
View File
@@ -48,7 +48,7 @@ Content-Type: application/json
HTTP 200
[Captures]
admin_token: jsonpath "$.access_token"
admin_user_id: jsonpath "$.user.id"
admin_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
+1 -1
View File
@@ -45,7 +45,7 @@ Content-Type: application/json
HTTP 200
[Captures]
jwt: jsonpath "$.access_token"
admin_user_id: jsonpath "$.user.id"
admin_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
+2 -2
View File
@@ -50,5 +50,5 @@ Content-Type: application/json
HTTP 200
[Asserts]
jsonpath "$.access_token" exists
jsonpath "$.user.username" == "bob"
jsonpath "$.user.email" == "bob@example.com"
jsonpath "$.user.full.user.username" == "bob"
jsonpath "$.user.full.user.email" == "bob@example.com"
+5 -5
View File
@@ -45,7 +45,7 @@ Content-Type: application/json
HTTP 200
[Captures]
admin_jwt: jsonpath "$.access_token"
admin_user_id: jsonpath "$.user.id"
admin_user_id: jsonpath "$.user.full.user.id"
# ═════════════════════════════════════════════════════════════
@@ -71,7 +71,7 @@ Content-Type: application/json
HTTP 201
[Captures]
editor_user_id: jsonpath "$.id"
editor_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/admin/users
Authorization: Bearer {{admin_jwt}}
@@ -85,7 +85,7 @@ Content-Type: application/json
HTTP 201
[Captures]
viewer_user_id: jsonpath "$.id"
viewer_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/admin/users
Authorization: Bearer {{admin_jwt}}
@@ -99,7 +99,7 @@ Content-Type: application/json
HTTP 201
[Captures]
outsider_user_id: jsonpath "$.id"
outsider_user_id: jsonpath "$.user.id"
# ─────────────────────────────────────────────────────────────
@@ -434,7 +434,7 @@ Content-Type: application/json
HTTP 201
[Captures]
quota_owner_id: jsonpath "$.id"
quota_owner_id: jsonpath "$.user.id"
PUT {{base_url}}/api/admin/users/{{quota_owner_id}}/quota
+4 -4
View File
@@ -40,7 +40,7 @@ Content-Type: application/json
HTTP 200
[Captures]
admin_jwt: jsonpath "$.access_token"
admin_user_id: jsonpath "$.user.id"
admin_user_id: jsonpath "$.user.full.user.id"
# ═════════════════════════════════════════════════════════════
@@ -65,7 +65,7 @@ Content-Type: application/json
HTTP 201
[Captures]
editor_user_id: jsonpath "$.id"
editor_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/admin/users
Authorization: Bearer {{admin_jwt}}
@@ -79,7 +79,7 @@ Content-Type: application/json
HTTP 201
[Captures]
viewer_user_id: jsonpath "$.id"
viewer_user_id: jsonpath "$.user.id"
# ─────────────────────────────────────────────────────────────
@@ -351,7 +351,7 @@ Content-Type: application/json
HTTP 201
[Captures]
quota_owner_id: jsonpath "$.id"
quota_owner_id: jsonpath "$.user.id"
PUT {{base_url}}/api/admin/users/{{quota_owner_id}}/quota
+1 -1
View File
@@ -85,7 +85,7 @@ Content-Type: application/json
HTTP 200
[Captures]
ncq_owner_jwt: jsonpath "$.access_token"
ncq_owner_id: jsonpath "$.user.id"
ncq_owner_id: jsonpath "$.user.full.user.id"
POST {{base_url}}/api/auth/app-passwords
Authorization: Bearer {{ncq_owner_jwt}}
+2 -2
View File
@@ -45,7 +45,7 @@ Content-Type: application/json
HTTP 200
[Captures]
alice_token: jsonpath "$.access_token"
alice_user_id: jsonpath "$.user.id"
alice_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
@@ -126,7 +126,7 @@ Content-Type: application/json
HTTP 200
[Captures]
bob_token: jsonpath "$.access_token"
bob_user_id: jsonpath "$.user.id"
bob_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
+18 -18
View File
@@ -55,7 +55,7 @@ Content-Type: application/json
HTTP 200
[Captures]
charlie_token: jsonpath "$.access_token"
charlie_user_id: jsonpath "$.user.id"
charlie_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
@@ -139,16 +139,16 @@ Authorization: Bearer {{pr18_access_token}}
HTTP 200
[Asserts]
jsonpath "$.email" == "pr18-emailonly@example.com"
jsonpath "$.is_external" == false
jsonpath "$.username" not exists
jsonpath "$.full.user.email" == "pr18-emailonly@example.com"
jsonpath "$.full.user.is_external" == false
jsonpath "$.full.user.username" not exists
# PR 23 — the user redeemed the welcome magic-link in Step 5b, so
# email_verified_at is stamped (the click IS the proof of inbox
# control, regardless of whether the redemption went through the
# direct or cross-browser-confirm path).
jsonpath "$.email_verified_at" exists
jsonpath "$.full.email_verified_at" exists
[Captures]
pr18_user_id: jsonpath "$.id"
pr18_user_id: jsonpath "$.full.user.id"
# ─────────────────────────────────────────────────────────────
@@ -162,9 +162,9 @@ Content-Type: application/json
HTTP 200
[Asserts]
jsonpath "$.id" == "{{pr18_user_id}}"
jsonpath "$.username" not exists
jsonpath "$.given_name" not exists
jsonpath "$.full.user.id" == "{{pr18_user_id}}"
jsonpath "$.full.user.username" not exists
jsonpath "$.full.user.given_name" not exists
# ─────────────────────────────────────────────────────────────
@@ -178,9 +178,9 @@ Content-Type: application/json
HTTP 200
[Asserts]
jsonpath "$.given_name" == "Pee Are"
jsonpath "$.family_name" == "Eighteen"
jsonpath "$.username" not exists
jsonpath "$.full.user.given_name" == "Pee Are"
jsonpath "$.full.user.family_name" == "Eighteen"
jsonpath "$.full.user.username" not exists
# ─────────────────────────────────────────────────────────────
@@ -220,7 +220,7 @@ Content-Type: application/json
HTTP 200
[Asserts]
jsonpath "$.username" == "pr18handle"
jsonpath "$.full.user.username" == "pr18handle"
# ─────────────────────────────────────────────────────────────
@@ -263,7 +263,7 @@ Content-Type: application/json
HTTP 200
[Asserts]
jsonpath "$.given_name" == "Pr18@Handle"
jsonpath "$.full.user.given_name" == "Pr18@Handle"
# ─────────────────────────────────────────────────────────────
@@ -276,10 +276,10 @@ Authorization: Bearer {{pr18_access_token}}
HTTP 200
[Asserts]
jsonpath "$.username" == "pr18handle"
jsonpath "$.given_name" == "Pr18@Handle"
jsonpath "$.family_name" == "Eighteen"
jsonpath "$.email_verified_at" exists
jsonpath "$.full.user.username" == "pr18handle"
jsonpath "$.full.user.given_name" == "Pr18@Handle"
jsonpath "$.full.user.family_name" == "Eighteen"
jsonpath "$.full.email_verified_at" exists
# ─────────────────────────────────────────────────────────────
@@ -80,7 +80,7 @@ Content-Type: application/json
HTTP 200
[Captures]
user_token: jsonpath "$.access_token"
user_user_id: jsonpath "$.user.id"
user_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
+3 -3
View File
@@ -34,7 +34,7 @@ Content-Type: application/json
HTTP 200
[Captures]
admin_token: jsonpath "$.access_token"
admin_user_id: jsonpath "$.user.id"
admin_user_id: jsonpath "$.user.full.user.id"
GET {{base_url}}/api/folders
Authorization: Bearer {{admin_token}}
@@ -56,7 +56,7 @@ Content-Type: application/json
HTTP 201
[Captures]
renee_user_id: jsonpath "$.id"
renee_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/admin/users
@@ -66,7 +66,7 @@ Content-Type: application/json
HTTP 201
[Captures]
sam_user_id: jsonpath "$.id"
sam_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
+4 -1
View File
@@ -75,7 +75,10 @@ log "Probe blob and thumbnail confirmed present on disk."
# subsequent trash-empty triggers garbage_collect() to remove the
# now-orphaned blob files from disk.
# /api/admin/users returns { users: [...], total, limit, offset }
# /api/admin/users returns { users: [PublicUserDto…], total, limit, offset }
# under the default `?summary=false` path — flat public-identity rows. The
# `?summary=true` path emits nested FullUserDto rows instead (used by the
# admin table); see `docs/plan/userdto-refactor.md`.
USERS_JSON=$(curl -sf -H "$AUTH" "$base_url/api/admin/users?limit=500")
ADMIN_USER_ID=$(echo "$USERS_JSON" \
+2 -2
View File
@@ -35,7 +35,7 @@ Content-Type: application/json
HTTP 201
[Captures]
grace_user_id: jsonpath "$.id"
grace_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
Content-Type: application/json
@@ -268,7 +268,7 @@ Content-Type: application/json
HTTP 201
[Captures]
helper_user_id: jsonpath "$.id"
helper_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/groups/{{engineers_id}}/members
+2 -2
View File
@@ -51,7 +51,7 @@ Content-Type: application/json
HTTP 201
[Captures]
owner_user_id: jsonpath "$.id"
owner_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
Content-Type: application/json
@@ -209,7 +209,7 @@ Content-Type: application/json
HTTP 201
[Captures]
viewer_user_id: jsonpath "$.id"
viewer_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
Content-Type: application/json
+6 -6
View File
@@ -64,7 +64,7 @@ Content-Type: application/json
HTTP 200
[Captures]
owner_token: jsonpath "$.access_token"
owner_user_id: jsonpath "$.user.id"
owner_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
@@ -92,7 +92,7 @@ Authorization: Bearer {{owner_token}}
HTTP 200
[Asserts]
jsonpath "$.storage_used_bytes" == 0
jsonpath "$.full.storage_used_bytes" == 0
# ─────────────────────────────────────────────────────────────
@@ -173,7 +173,7 @@ Authorization: Bearer {{owner_token}}
HTTP 200
[Asserts]
jsonpath "$.storage_used_bytes" == 0
jsonpath "$.full.storage_used_bytes" == 0
# ─────────────────────────────────────────────────────────────
@@ -202,7 +202,7 @@ retry-interval: 200ms
HTTP 200
[Asserts]
jsonpath "$.storage_used_bytes" == 32
jsonpath "$.full.storage_used_bytes" == 32
# Confirm the sweep agrees with the delta — both code paths must
@@ -217,7 +217,7 @@ Authorization: Bearer {{owner_token}}
HTTP 200
[Asserts]
jsonpath "$.storage_used_bytes" == 32
jsonpath "$.full.storage_used_bytes" == 32
# ─────────────────────────────────────────────────────────────
@@ -247,7 +247,7 @@ Authorization: Bearer {{owner_token}}
HTTP 200
[Asserts]
jsonpath "$.storage_used_bytes" == 0
jsonpath "$.full.storage_used_bytes" == 0
# ─────────────────────────────────────────────────────────────
+1 -1
View File
@@ -174,7 +174,7 @@ Content-Type: application/json
HTTP 201
[Captures]
quota_owner_id: jsonpath "$.id"
quota_owner_id: jsonpath "$.user.id"
PUT {{base_url}}/api/admin/users/{{quota_owner_id}}/quota
+2 -2
View File
@@ -35,7 +35,7 @@ Content-Type: application/json
HTTP 200
[Captures]
admin_token: jsonpath "$.access_token"
admin_user_id: jsonpath "$.user.id"
admin_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────
@@ -54,7 +54,7 @@ Content-Type: application/json
HTTP 201
[Captures]
bob_user_id: jsonpath "$.id"
bob_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
+1 -1
View File
@@ -151,7 +151,7 @@ Content-Type: application/json
HTTP 200
[Captures]
wq_owner_token: jsonpath "$.access_token"
wq_owner_id: jsonpath "$.user.id"
wq_owner_id: jsonpath "$.user.full.user.id"
POST {{base_url}}/api/drives
+2 -2
View File
@@ -39,7 +39,7 @@ Content-Type: application/json
HTTP 200
[Captures]
alice_token: jsonpath "$.access_token"
alice_user_id: jsonpath "$.user.id"
alice_user_id: jsonpath "$.user.full.user.id"
GET {{base_url}}/api/folders
@@ -65,7 +65,7 @@ Content-Type: application/json
HTTP 201
[Captures]
bob_user_id: jsonpath "$.id"
bob_user_id: jsonpath "$.user.id"
POST {{base_url}}/api/auth/login
+1 -1
View File
@@ -47,7 +47,7 @@ Content-Type: application/json
HTTP 200
[Captures]
admin_token: jsonpath "$.access_token"
admin_user_id: jsonpath "$.user.id"
admin_user_id: jsonpath "$.user.full.user.id"
# ─────────────────────────────────────────────────────────────