Files
galaxy/lib/galaxy_test/api/test_framework.py
T
davelopez 6ceb9d79da Fix run_as to be passed in the headers
The legacy API framework allowed to pass the `run_as` user in the payload but, moving forward to the new framework, looks like the headers is a better place for it (see https://github.com/galaxyproject/galaxy/pull/11342/commits/91e7d5191d70f3b286fdf86b39af657bede35f09).

- Adapt existing framework tests to pass in the `run_as` user in the headers instead of the payload.
- Fix the legacy framework not retrieving the `run_as` from the headers when the payload was not in JSON (i.e. Form data)
- Add a bit more of documentation for the OpenAPI schema.
2021-09-21 10:46:48 +02:00

42 lines
1.6 KiB
Python

# This file doesn't test any API in particular but is meant to functionally
# test the API framework itself.
from ._framework import ApiTestCase
class ApiFrameworkTestCase(ApiTestCase):
def test_default_xframe_options(self):
get_response = self._get("licenses")
assert get_response.headers['x-frame-options'] == "SAMEORIGIN"
# Next several tests test the API's run_as functionality.
def test_user_cannont_run_as(self):
run_as_user = self._setup_user("for_run_as@bx.psu.edu")
post_data = dict(name="TestHistory1")
# Normal user cannot run_as...
create_response = self._post(
"histories", data=post_data,
headers={'run-as': run_as_user["id"]},
)
self._assert_status_code_is(create_response, 403)
def test_run_as_invalid_user(self):
post_data = dict(name="TestHistory1")
# admin user can run_as, but this user doesn't exist, expect 400.
create_response = self._post(
"histories", data=post_data,
headers={'run-as': "another_user"}, admin=True,
)
self._assert_status_code_is(create_response, 400)
def test_run_as_valid_user(self):
run_as_user = self._setup_user("for_run_as@bx.psu.edu")
post_data = dict(name="TestHistory1")
# Use run_as with admin user and for another user just created, this
# should work.
create_response = self._post(
"histories", data=post_data,
headers={'run-as': run_as_user["id"]}, admin=True,
)
self._assert_status_code_is(create_response, 200)