backport of commit 0c9b963963

pull/4419/head
Johan Brandhorst-Satzkorn 2 years ago
parent a37307938c
commit 2f623e4c62

@ -123,10 +123,6 @@ func (s Service) ListRoles(ctx context.Context, req *pbs.ListRolesRequest) (*pbs
if err != nil {
return nil, err
}
// If no scopes match, return an empty response
if len(scopeIds) == 0 {
return &pbs.ListRolesResponse{}, nil
}
pageSize := int(s.maxPageSize)
// Use the requested page size only if it is smaller than

@ -760,6 +760,28 @@ func TestListPagination(t *testing.T) {
protocmp.IgnoreFields(&pbs.ListRolesResponse{}, "list_token"),
),
)
// Create unauthenticated user
unauthAt := authtoken.TestAuthToken(t, conn, kms, oWithRoles.GetPublicId())
unauthR := iam.TestRole(t, conn, pWithRoles.GetPublicId())
_ = iam.TestUserRole(t, conn, unauthR.GetPublicId(), unauthAt.GetIamUserId())
// Make a request with the unauthenticated user,
// ensure the response contains the pagination parameters.
requestInfo = authpb.RequestInfo{
TokenFormat: uint32(auth.AuthTokenTypeBearer),
PublicId: unauthAt.GetPublicId(),
Token: unauthAt.GetToken(),
}
requestContext = context.WithValue(context.Background(), requests.ContextRequestInformationKey, &requests.RequestContext{})
ctx = auth.NewVerifierContext(requestContext, iamRepoFn, tokenRepoFn, serversRepoFn, kms, &requestInfo)
_, err = a.ListRoles(ctx, &pbs.ListRolesRequest{
ScopeId: "global",
Recursive: true,
})
require.Error(t, err)
assert.ErrorIs(t, handlers.ForbiddenError(), err)
}
func TestDelete(t *testing.T) {

Loading…
Cancel
Save