chore: protect reserved builtin rolenames (#13571)

Conflicting built-in and database role names makes it hard to
disambiguate
This commit is contained in:
Steven Masley
2024-06-13 15:12:37 -05:00
committed by GitHub
parent 7d51515f9d
commit 3d30c8dc68
3 changed files with 46 additions and 0 deletions
+28
View File
@@ -210,6 +210,34 @@ func TestCustomOrganizationRole(t *testing.T) {
require.ErrorContains(t, err, "Validation")
})
t.Run("ReservedName", func(t *testing.T) {
t.Parallel()
dv := coderdtest.DeploymentValues(t)
dv.Experiments = []string{string(codersdk.ExperimentCustomRoles)}
owner, first := coderdenttest.New(t, &coderdenttest.Options{
Options: &coderdtest.Options{
DeploymentValues: dv,
},
LicenseOptions: &coderdenttest.LicenseOptions{
Features: license.Features{
codersdk.FeatureCustomRoles: 1,
},
},
})
ctx := testutil.Context(t, testutil.WaitMedium)
//nolint:gocritic // owner is required for this
_, err := owner.PatchOrganizationRole(ctx, first.OrganizationID, codersdk.Role{
Name: "owner", // Reserved
DisplayName: "Testing Purposes",
SitePermissions: nil,
OrganizationPermissions: nil,
UserPermissions: nil,
})
require.ErrorContains(t, err, "Reserved")
})
t.Run("MismatchedOrganizations", func(t *testing.T) {
t.Parallel()
dv := coderdtest.DeploymentValues(t)