# API team ID based sharing

* extents api sharing via team name with team id, so that both ways are supported now
* updates tests
This commit is contained in:
2026-05-14 15:04:24 +02:00
parent 056a92b068
commit 59a1bdfb1c
4 changed files with 63 additions and 33 deletions

View File

@@ -31,9 +31,10 @@ class APIV1SharingTestCase(BaseAPIV1TestCase):
def setUpTestData(cls):
super().setUpTestData()
def _run_share_request(self, url, user_list: list):
def _run_share_request(self, url, user_list: list, team_list: list):
data = {
"users": user_list
"users": user_list,
"teams": team_list
}
data = json.dumps(data)
response = self.client.put(
@@ -58,16 +59,22 @@ class APIV1SharingTestCase(BaseAPIV1TestCase):
self.superuser.username,
self.user.username,
]
team_list = [
str(self.team.id),
]
response = self._run_share_request(url, user_list)
response = self._run_share_request(url, user_list, team_list)
# Must fail, since performing user has no access on requested object
self.assertEqual(response.status_code, 500)
self.assertTrue(len(json.loads(response.content.decode("utf-8")).get("errors", [])) > 0)
# Add performing user to shared access users and rerun the request
# Add performing user to shared access users, switch from team id to team name and rerun the request
obj.users.add(self.superuser)
response = self._run_share_request(url, user_list)
team_list = [
self.team.name
]
response = self._run_share_request(url, user_list, team_list)
shared_users = obj.shared_users
self.assertEqual(response.status_code, 200)
@@ -84,14 +91,14 @@ class APIV1SharingTestCase(BaseAPIV1TestCase):
share_url = reverse("api:v1:intervention-share", args=(self.intervention.id,))
# Expect the first request to work properly
self.intervention.users.add(self.superuser)
response = self._run_share_request(share_url, [self.superuser.username])
response = self._run_share_request(share_url, [self.superuser.username], [str(self.team.id)])
self.assertEqual(response.status_code, 200)
# Change the token
self.header_data["HTTP_ksptoken"] = f"{self.superuser.api_token.token}__X"
# Expect the request to fail now
response = self._run_share_request(share_url, [self.superuser.username])
response = self._run_share_request(share_url, [self.superuser.username], [])
self.assertEqual(response.status_code, 403)
def test_api_intervention_sharing(self):
@@ -144,11 +151,11 @@ class APIV1SharingTestCase(BaseAPIV1TestCase):
self.assertEqual(self.intervention.users.count(), 1)
# Try to add another user via API -> must work!
response = self._run_share_request(share_url, [self.superuser.username, self.user.username])
response = self._run_share_request(share_url, [self.superuser.username, self.user.username], [])
self.assertEqual(response.status_code, 200)
self.assertEqual(self.intervention.users.count(), 2)
# Now try to remove the user again -> expect no changes at all to the shared user list
response = self._run_share_request(share_url, [self.superuser.username])
response = self._run_share_request(share_url, [self.superuser.username], [])
self.assertEqual(response.status_code, 200)
self.assertEqual(self.intervention.users.count(), 2)