test: include per-org default roles in rbac user subjects (#26003)

Aligns the `coderdtest` user subject helper with production so per-org default member roles surface in tests.
This commit is contained in:
Steven Masley
2026-06-05 15:01:45 -05:00
committed by GitHub
parent 938c2080f3
commit 8a5e04e90f
4 changed files with 40 additions and 33 deletions
+10
View File
@@ -908,6 +908,16 @@ func AuthzUserSubjectWithDB(ctx context.Context, t testing.TB, db database.Store
require.NoError(t, err)
for _, org := range orgs {
roles = append(roles, rbac.ScopedRoleOrgMember(org.ID))
// The implicit role set (organization-member plus the org's
// default_org_member_roles) is unioned at request time by
// GetAuthorizationUserRoles. Subjects built directly here bypass
// that SQL union, so mirror it explicitly.
for _, name := range org.DefaultOrgMemberRoles {
roles = append(roles, rbac.RoleIdentifier{
Name: name,
OrganizationID: org.ID,
})
}
}
//nolint:gocritic // We need to expand DB-backed/system roles. The caller