refactor(user): apply chanoges to hurl tests
This commit is contained in:
@@ -56,7 +56,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
charlie_id: jsonpath "$.id"
|
||||
charlie_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -89,7 +89,7 @@ Authorization: Bearer {{charlie_token_v1}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.storage_quota_bytes" == 209715200
|
||||
jsonpath "$.full.storage_quota_bytes" == 209715200
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -108,7 +108,7 @@ Authorization: Bearer {{charlie_token_v1}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.role" == "admin"
|
||||
jsonpath "$.full.user.role" == "admin"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -19,7 +19,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.access_token" exists
|
||||
jsonpath "$.user.email" == "{{email}}"
|
||||
jsonpath "$.user.full.user.email" == "{{email}}"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -34,7 +34,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.access_token" exists
|
||||
jsonpath "$.user.email" == "{{email}}"
|
||||
jsonpath "$.user.full.user.email" == "{{email}}"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -142,10 +142,10 @@ Authorization: Bearer {{alice_magic_access_token}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.email" == "{{email}}"
|
||||
jsonpath "$.username" == "{{username}}"
|
||||
jsonpath "$.full.user.email" == "{{email}}"
|
||||
jsonpath "$.full.user.username" == "{{username}}"
|
||||
[Captures]
|
||||
admin_user_id: jsonpath "$.id"
|
||||
admin_user_id: jsonpath "$.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -78,7 +78,7 @@ Authorization: Bearer {{access_v2}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.username" == "{{username}}"
|
||||
jsonpath "$.full.user.username" == "{{username}}"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -52,7 +52,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
bob_user_id: jsonpath "$.id"
|
||||
bob_user_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -73,8 +73,8 @@ Authorization: Bearer {{bob_token}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.is_external" == true
|
||||
jsonpath "$.storage_quota_bytes" == 0
|
||||
jsonpath "$.full.user.is_external" == true
|
||||
jsonpath "$.full.storage_quota_bytes" == 0
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -88,8 +88,8 @@ Content-Type: application/json
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.is_external" == false
|
||||
jsonpath "$.storage_quota_bytes" > 0
|
||||
jsonpath "$.full.user.is_external" == false
|
||||
jsonpath "$.full.storage_quota_bytes" > 0
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -100,8 +100,8 @@ Authorization: Bearer {{bob_token}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.is_external" == false
|
||||
jsonpath "$.storage_quota_bytes" > 0
|
||||
jsonpath "$.full.user.is_external" == false
|
||||
jsonpath "$.full.storage_quota_bytes" > 0
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -179,7 +179,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
carol_user_id: jsonpath "$.id"
|
||||
carol_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
Content-Type: application/json
|
||||
@@ -204,7 +204,7 @@ Authorization: Bearer {{carol_token}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.is_external" == true
|
||||
jsonpath "$.full.user.is_external" == true
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -41,7 +41,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
alice_token: jsonpath "$.access_token"
|
||||
alice_user_id: jsonpath "$.user.id"
|
||||
alice_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -120,7 +120,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
bob_token: jsonpath "$.access_token"
|
||||
bob_user_id: jsonpath "$.user.id"
|
||||
bob_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -24,7 +24,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
token: jsonpath "$.access_token"
|
||||
admin_user_id: jsonpath "$.user.id"
|
||||
admin_user_id: jsonpath "$.user.full.user.id"
|
||||
[Asserts]
|
||||
jsonpath "$.access_token" isString
|
||||
jsonpath "$.token_type" == "Bearer"
|
||||
@@ -344,7 +344,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
bob_token: jsonpath "$.access_token"
|
||||
bob_user_id: jsonpath "$.user.id"
|
||||
bob_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# Step 17 — Bob's book listing does NOT include Alice's book.
|
||||
|
||||
@@ -71,7 +71,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
owner_token: jsonpath "$.access_token"
|
||||
owner_user_id: jsonpath "$.user.id"
|
||||
owner_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -67,7 +67,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
owner_token: jsonpath "$.access_token"
|
||||
owner_user_id: jsonpath "$.user.id"
|
||||
owner_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -249,7 +249,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP *
|
||||
[Captures]
|
||||
alice_id: jsonpath "$.id"
|
||||
alice_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
|
||||
@@ -103,7 +103,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP *
|
||||
[Captures]
|
||||
fresh_user_id: jsonpath "$.id"
|
||||
fresh_user_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -65,7 +65,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
owner_token: jsonpath "$.access_token"
|
||||
owner_user_id: jsonpath "$.user.id"
|
||||
owner_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# Provision `dp_intruder` — a second internal user used only to
|
||||
@@ -91,7 +91,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
intruder_token: jsonpath "$.access_token"
|
||||
intruder_user_id: jsonpath "$.user.id"
|
||||
intruder_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -60,7 +60,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
owner_token: jsonpath "$.access_token"
|
||||
owner_user_id: jsonpath "$.user.id"
|
||||
owner_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -82,7 +82,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
owner_token: jsonpath "$.access_token"
|
||||
owner_user_id: jsonpath "$.user.id"
|
||||
owner_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -107,7 +107,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 200
|
||||
[Captures]
|
||||
target_user_id: jsonpath "$.user.id"
|
||||
target_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -31,7 +31,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
admin_token: jsonpath "$.access_token"
|
||||
admin_user_id: jsonpath "$.user.id"
|
||||
admin_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -70,7 +70,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
alice_user_id: jsonpath "$.id"
|
||||
alice_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/admin/users
|
||||
Authorization: Bearer {{admin_token}}
|
||||
@@ -79,7 +79,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
bob_user_id: jsonpath "$.id"
|
||||
bob_user_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
# Alice's first login fires `PersonalDriveLifecycleHook::on_user_login`
|
||||
|
||||
@@ -64,7 +64,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
admin_token: jsonpath "$.access_token"
|
||||
admin_user_id: jsonpath "$.user.id"
|
||||
admin_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -113,7 +113,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
alice_user_id: jsonpath "$.id"
|
||||
alice_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
Content-Type: application/json
|
||||
@@ -470,7 +470,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
bob_user_id: jsonpath "$.id"
|
||||
bob_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
Content-Type: application/json
|
||||
@@ -657,7 +657,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
carol_user_id: jsonpath "$.id"
|
||||
carol_user_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
# 24a — Owner grants Carol Owner role (Owner-creates-Owner).
|
||||
@@ -836,7 +836,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
dave_user_id: jsonpath "$.id"
|
||||
dave_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
Content-Type: application/json
|
||||
|
||||
@@ -23,7 +23,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
alice_token: jsonpath "$.access_token"
|
||||
alice_user_id: jsonpath "$.user.id"
|
||||
alice_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
GET {{base_url}}/api/folders
|
||||
Authorization: Bearer {{alice_token}}
|
||||
@@ -226,13 +226,16 @@ Authorization: Bearer {{bob_access_token}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
# `/api/users/{id}` returns the slim `PublicUserDto` (9 fields) —
|
||||
# id / email / username / role / image / is_external / given_name /
|
||||
# family_name / is_online. Admin-visible fields like
|
||||
# `email_verified_at` moved to `FullUserDto` under the three-layer
|
||||
# refactor (docs/plan/userdto-refactor.md) and are checked below
|
||||
# via `/api/admin/users`.
|
||||
jsonpath "$.id" == "{{bob_user_id}}"
|
||||
jsonpath "$.is_external" == true
|
||||
jsonpath "$.email" == "bob@externalcompany.com"
|
||||
jsonpath "$.username" not exists
|
||||
# PR 23 — bob redeemed his invitation magic-link in Step 8, so his
|
||||
# email_verified_at was stamped at that time and stays set.
|
||||
jsonpath "$.email_verified_at" exists
|
||||
|
||||
# 11d — bob CAN look up Alice (his granter) — shared-grant relationship
|
||||
# lets the external recipient resolve the sharer's display name +
|
||||
@@ -244,14 +247,37 @@ HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.id" == "{{alice_user_id}}"
|
||||
jsonpath "$.is_external" == false
|
||||
# Setup admin is auto-verified at creation. `setup_create_admin` stamps
|
||||
|
||||
# 11c/d/verify — admin (alice) observes email_verified_at on both
|
||||
# users via `GET /api/admin/users/{id}` — returns `FullUserDto`
|
||||
# (public identity in `.user` + admin-visible extras at top level).
|
||||
#
|
||||
# `email_verified_at` lives on `FullUserDto` (admin+self-visible),
|
||||
# not on `PublicUserDto` — peer views via `/api/users/{id}` never
|
||||
# expose it. The admin single-user endpoint is the correct
|
||||
# observation surface. See `docs/plan/userdto-refactor.md` for the
|
||||
# three-layer split.
|
||||
#
|
||||
# Setup admin auto-verified rationale: `setup_create_admin` stamps
|
||||
# `email_verified_at = NOW()` — admin fiat counts as verification,
|
||||
# matching the OIDC-JIT convention. Rationale: an operator running the
|
||||
# first-run wizard is authoritative by construction (they set the
|
||||
# password at the console on a fresh install). Without this, flipping
|
||||
# matching the OIDC-JIT convention. An operator running the first-run
|
||||
# wizard is authoritative by construction. Without this, flipping
|
||||
# `OXICLOUD_REQUIRE_VERIFIED_EMAIL=true` on an existing deployment
|
||||
# would lock the sole admin out of their own instance. The admin login
|
||||
# exemption is a second layer of defense; this stamp is the primary.
|
||||
# would lock the sole admin out of their own instance.
|
||||
GET {{base_url}}/api/admin/users/{{bob_user_id}}
|
||||
Authorization: Bearer {{alice_token}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.user.id" == "{{bob_user_id}}"
|
||||
jsonpath "$.email_verified_at" exists
|
||||
|
||||
GET {{base_url}}/api/admin/users/{{alice_user_id}}
|
||||
Authorization: Bearer {{alice_token}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.user.id" == "{{alice_user_id}}"
|
||||
jsonpath "$.email_verified_at" exists
|
||||
|
||||
# 11e — bob CANNOT enumerate unrelated users. A random UUID returns 404
|
||||
|
||||
@@ -19,11 +19,11 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
token: jsonpath "$.access_token"
|
||||
admin_user_id: jsonpath "$.user.id"
|
||||
admin_user_id: jsonpath "$.user.full.user.id"
|
||||
[Asserts]
|
||||
jsonpath "$.access_token" isString
|
||||
jsonpath "$.token_type" == "Bearer"
|
||||
jsonpath "$.user.id" isString
|
||||
jsonpath "$.user.full.user.id" isString
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -29,7 +29,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
alice_token: jsonpath "$.access_token"
|
||||
alice_user_id: jsonpath "$.user.id"
|
||||
alice_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
GET {{base_url}}/api/folders
|
||||
@@ -57,7 +57,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
mallory_user_id: jsonpath "$.id"
|
||||
mallory_user_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -23,7 +23,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
alice_token: jsonpath "$.access_token"
|
||||
alice_user_id: jsonpath "$.user.id"
|
||||
alice_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
GET {{base_url}}/api/folders
|
||||
Authorization: Bearer {{alice_token}}
|
||||
@@ -45,7 +45,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
dave_user_id: jsonpath "$.id"
|
||||
dave_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/admin/users
|
||||
Authorization: Bearer {{alice_token}}
|
||||
@@ -54,7 +54,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
eve_user_id: jsonpath "$.id"
|
||||
eve_user_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -371,7 +371,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
adam_user_id: jsonpath "$.id"
|
||||
adam_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
Content-Type: application/json
|
||||
@@ -1044,7 +1044,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
frank_user_id: jsonpath "$.id"
|
||||
frank_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
Content-Type: application/json
|
||||
|
||||
@@ -44,7 +44,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
henry_user_id: jsonpath "$.id"
|
||||
henry_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
Content-Type: application/json
|
||||
|
||||
@@ -76,7 +76,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
dora_id: jsonpath "$.id"
|
||||
dora_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -48,7 +48,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
admin_token: jsonpath "$.access_token"
|
||||
admin_user_id: jsonpath "$.user.id"
|
||||
admin_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -45,7 +45,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
jwt: jsonpath "$.access_token"
|
||||
admin_user_id: jsonpath "$.user.id"
|
||||
admin_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -50,5 +50,5 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.access_token" exists
|
||||
jsonpath "$.user.username" == "bob"
|
||||
jsonpath "$.user.email" == "bob@example.com"
|
||||
jsonpath "$.user.full.user.username" == "bob"
|
||||
jsonpath "$.user.full.user.email" == "bob@example.com"
|
||||
|
||||
@@ -45,7 +45,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
admin_jwt: jsonpath "$.access_token"
|
||||
admin_user_id: jsonpath "$.user.id"
|
||||
admin_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ═════════════════════════════════════════════════════════════
|
||||
@@ -71,7 +71,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
editor_user_id: jsonpath "$.id"
|
||||
editor_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/admin/users
|
||||
Authorization: Bearer {{admin_jwt}}
|
||||
@@ -85,7 +85,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
viewer_user_id: jsonpath "$.id"
|
||||
viewer_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/admin/users
|
||||
Authorization: Bearer {{admin_jwt}}
|
||||
@@ -99,7 +99,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
outsider_user_id: jsonpath "$.id"
|
||||
outsider_user_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -434,7 +434,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
quota_owner_id: jsonpath "$.id"
|
||||
quota_owner_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
PUT {{base_url}}/api/admin/users/{{quota_owner_id}}/quota
|
||||
|
||||
@@ -40,7 +40,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
admin_jwt: jsonpath "$.access_token"
|
||||
admin_user_id: jsonpath "$.user.id"
|
||||
admin_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ═════════════════════════════════════════════════════════════
|
||||
@@ -65,7 +65,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
editor_user_id: jsonpath "$.id"
|
||||
editor_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/admin/users
|
||||
Authorization: Bearer {{admin_jwt}}
|
||||
@@ -79,7 +79,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
viewer_user_id: jsonpath "$.id"
|
||||
viewer_user_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -351,7 +351,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
quota_owner_id: jsonpath "$.id"
|
||||
quota_owner_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
PUT {{base_url}}/api/admin/users/{{quota_owner_id}}/quota
|
||||
|
||||
@@ -85,7 +85,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
ncq_owner_jwt: jsonpath "$.access_token"
|
||||
ncq_owner_id: jsonpath "$.user.id"
|
||||
ncq_owner_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
POST {{base_url}}/api/auth/app-passwords
|
||||
Authorization: Bearer {{ncq_owner_jwt}}
|
||||
|
||||
@@ -45,7 +45,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
alice_token: jsonpath "$.access_token"
|
||||
alice_user_id: jsonpath "$.user.id"
|
||||
alice_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -126,7 +126,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
bob_token: jsonpath "$.access_token"
|
||||
bob_user_id: jsonpath "$.user.id"
|
||||
bob_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
+18
-18
@@ -55,7 +55,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
charlie_token: jsonpath "$.access_token"
|
||||
charlie_user_id: jsonpath "$.user.id"
|
||||
charlie_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -139,16 +139,16 @@ Authorization: Bearer {{pr18_access_token}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.email" == "pr18-emailonly@example.com"
|
||||
jsonpath "$.is_external" == false
|
||||
jsonpath "$.username" not exists
|
||||
jsonpath "$.full.user.email" == "pr18-emailonly@example.com"
|
||||
jsonpath "$.full.user.is_external" == false
|
||||
jsonpath "$.full.user.username" not exists
|
||||
# PR 23 — the user redeemed the welcome magic-link in Step 5b, so
|
||||
# email_verified_at is stamped (the click IS the proof of inbox
|
||||
# control, regardless of whether the redemption went through the
|
||||
# direct or cross-browser-confirm path).
|
||||
jsonpath "$.email_verified_at" exists
|
||||
jsonpath "$.full.email_verified_at" exists
|
||||
[Captures]
|
||||
pr18_user_id: jsonpath "$.id"
|
||||
pr18_user_id: jsonpath "$.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -162,9 +162,9 @@ Content-Type: application/json
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.id" == "{{pr18_user_id}}"
|
||||
jsonpath "$.username" not exists
|
||||
jsonpath "$.given_name" not exists
|
||||
jsonpath "$.full.user.id" == "{{pr18_user_id}}"
|
||||
jsonpath "$.full.user.username" not exists
|
||||
jsonpath "$.full.user.given_name" not exists
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -178,9 +178,9 @@ Content-Type: application/json
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.given_name" == "Pee Are"
|
||||
jsonpath "$.family_name" == "Eighteen"
|
||||
jsonpath "$.username" not exists
|
||||
jsonpath "$.full.user.given_name" == "Pee Are"
|
||||
jsonpath "$.full.user.family_name" == "Eighteen"
|
||||
jsonpath "$.full.user.username" not exists
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -220,7 +220,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.username" == "pr18handle"
|
||||
jsonpath "$.full.user.username" == "pr18handle"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -263,7 +263,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.given_name" == "Pr18@Handle"
|
||||
jsonpath "$.full.user.given_name" == "Pr18@Handle"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -276,10 +276,10 @@ Authorization: Bearer {{pr18_access_token}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.username" == "pr18handle"
|
||||
jsonpath "$.given_name" == "Pr18@Handle"
|
||||
jsonpath "$.family_name" == "Eighteen"
|
||||
jsonpath "$.email_verified_at" exists
|
||||
jsonpath "$.full.user.username" == "pr18handle"
|
||||
jsonpath "$.full.user.given_name" == "Pr18@Handle"
|
||||
jsonpath "$.full.user.family_name" == "Eighteen"
|
||||
jsonpath "$.full.email_verified_at" exists
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -80,7 +80,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
user_token: jsonpath "$.access_token"
|
||||
user_user_id: jsonpath "$.user.id"
|
||||
user_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -34,7 +34,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
admin_token: jsonpath "$.access_token"
|
||||
admin_user_id: jsonpath "$.user.id"
|
||||
admin_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
GET {{base_url}}/api/folders
|
||||
Authorization: Bearer {{admin_token}}
|
||||
@@ -56,7 +56,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
renee_user_id: jsonpath "$.id"
|
||||
renee_user_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
POST {{base_url}}/api/admin/users
|
||||
@@ -66,7 +66,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
sam_user_id: jsonpath "$.id"
|
||||
sam_user_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
|
||||
@@ -75,7 +75,10 @@ log "Probe blob and thumbnail confirmed present on disk."
|
||||
# subsequent trash-empty triggers garbage_collect() to remove the
|
||||
# now-orphaned blob files from disk.
|
||||
|
||||
# /api/admin/users returns { users: [...], total, limit, offset }
|
||||
# /api/admin/users returns { users: [PublicUserDto…], total, limit, offset }
|
||||
# under the default `?summary=false` path — flat public-identity rows. The
|
||||
# `?summary=true` path emits nested FullUserDto rows instead (used by the
|
||||
# admin table); see `docs/plan/userdto-refactor.md`.
|
||||
USERS_JSON=$(curl -sf -H "$AUTH" "$base_url/api/admin/users?limit=500")
|
||||
|
||||
ADMIN_USER_ID=$(echo "$USERS_JSON" \
|
||||
|
||||
@@ -35,7 +35,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
grace_user_id: jsonpath "$.id"
|
||||
grace_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
Content-Type: application/json
|
||||
@@ -268,7 +268,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
helper_user_id: jsonpath "$.id"
|
||||
helper_user_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
POST {{base_url}}/api/groups/{{engineers_id}}/members
|
||||
|
||||
@@ -51,7 +51,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
owner_user_id: jsonpath "$.id"
|
||||
owner_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
Content-Type: application/json
|
||||
@@ -209,7 +209,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
viewer_user_id: jsonpath "$.id"
|
||||
viewer_user_id: jsonpath "$.user.id"
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
Content-Type: application/json
|
||||
|
||||
@@ -64,7 +64,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
owner_token: jsonpath "$.access_token"
|
||||
owner_user_id: jsonpath "$.user.id"
|
||||
owner_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -92,7 +92,7 @@ Authorization: Bearer {{owner_token}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.storage_used_bytes" == 0
|
||||
jsonpath "$.full.storage_used_bytes" == 0
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -173,7 +173,7 @@ Authorization: Bearer {{owner_token}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.storage_used_bytes" == 0
|
||||
jsonpath "$.full.storage_used_bytes" == 0
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -202,7 +202,7 @@ retry-interval: 200ms
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.storage_used_bytes" == 32
|
||||
jsonpath "$.full.storage_used_bytes" == 32
|
||||
|
||||
|
||||
# Confirm the sweep agrees with the delta — both code paths must
|
||||
@@ -217,7 +217,7 @@ Authorization: Bearer {{owner_token}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.storage_used_bytes" == 32
|
||||
jsonpath "$.full.storage_used_bytes" == 32
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -247,7 +247,7 @@ Authorization: Bearer {{owner_token}}
|
||||
|
||||
HTTP 200
|
||||
[Asserts]
|
||||
jsonpath "$.storage_used_bytes" == 0
|
||||
jsonpath "$.full.storage_used_bytes" == 0
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -174,7 +174,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
quota_owner_id: jsonpath "$.id"
|
||||
quota_owner_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
PUT {{base_url}}/api/admin/users/{{quota_owner_id}}/quota
|
||||
|
||||
@@ -35,7 +35,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
admin_token: jsonpath "$.access_token"
|
||||
admin_user_id: jsonpath "$.user.id"
|
||||
admin_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
@@ -54,7 +54,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
bob_user_id: jsonpath "$.id"
|
||||
bob_user_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
|
||||
@@ -151,7 +151,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
wq_owner_token: jsonpath "$.access_token"
|
||||
wq_owner_id: jsonpath "$.user.id"
|
||||
wq_owner_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
POST {{base_url}}/api/drives
|
||||
|
||||
@@ -39,7 +39,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
alice_token: jsonpath "$.access_token"
|
||||
alice_user_id: jsonpath "$.user.id"
|
||||
alice_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
GET {{base_url}}/api/folders
|
||||
@@ -65,7 +65,7 @@ Content-Type: application/json
|
||||
|
||||
HTTP 201
|
||||
[Captures]
|
||||
bob_user_id: jsonpath "$.id"
|
||||
bob_user_id: jsonpath "$.user.id"
|
||||
|
||||
|
||||
POST {{base_url}}/api/auth/login
|
||||
|
||||
@@ -47,7 +47,7 @@ Content-Type: application/json
|
||||
HTTP 200
|
||||
[Captures]
|
||||
admin_token: jsonpath "$.access_token"
|
||||
admin_user_id: jsonpath "$.user.id"
|
||||
admin_user_id: jsonpath "$.user.full.user.id"
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
Reference in New Issue
Block a user