Skip to content

test: send a real upload body in the lightwell POST-denial test - #1541

Open
CryptoRodeo wants to merge 1 commit into
pulp:mainfrom
CryptoRodeo:fix/update-lightwell-post-test
Open

CryptoRodeo wants to merge 1 commit into
pulp:mainfrom
CryptoRodeo:fix/update-lightwell-post-test

Conversation

@CryptoRodeo

@CryptoRodeo CryptoRodeo commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

The lightwell POST-denial test posted an empty JSON body to a content-create
endpoint that only accepts multipart uploads. That 400s during request parsing,
before RBAC ever runs, so to keep the test green the assertion had to tolerate a
400 alongside 401/403, which muddied what it was actually proving: that a
subscribed-but-unroled caller can't POST content (the subscription grant only
covers safe reads).

Instead of widening the assertion, send a complete, valid upload body: a file, a
relative_path, and the repository the fixture's owner created. The request now
clears multipart parsing and pulpcore's create conditions (which validate the
serializer before deciding authorization) and is denied by the access policy
itself: has_required_repo_perms_on_upload:file.modify_filerepository returns a
clean 403 because the caller holds no role on that repo. The assertion is a
strict 403, so the test fails if the caller is instead rejected during
authentication rather than by the RBAC policy. Verified in the dev container:
the test passes and the denial is specifically a 403.

Summary by Sourcery

Make the Lightwell content POST permission test validate repository authorization with a complete upload request.

Bug Fixes:

  • Ensure the Lightwell POST-denial test reaches authorization and verifies a strict 403 response instead of accepting request-validation failures.

Tests:

  • Update the content POST permission test to submit a valid multipart upload using an existing repository and assert that the unroled caller is denied.

@sourcery-ai

sourcery-ai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Reviewer's Guide

Updates the Lightwell content POST permission test to use a complete upload request, allowing pulpcore serializer and create-condition checks to succeed before the unroled caller is rejected by the repository permission policy.

File-Level Changes

Change Details Files
Make the POST-denial test submit a valid multipart upload that reaches authorization instead of failing request validation.
  • Retrieve the repository created by the fixture using the owner identity.
  • Submit a file, relative path, and repository href as multipart form data.
  • Restrict the expected response to unauthorized or forbidden, with the intended denial being 403.
pulp_service/pulp_service/tests/functional/test_lightwell_content_listing_permission.py

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="pulp_service/pulp_service/tests/functional/test_lightwell_content_listing_permission.py" line_range="176" />
<code_context>
+    )

-    assert response.status_code in (400, 401, 403)
+    assert response.status_code in (401, 403)


</code_context>
<issue_to_address>
**issue (testing):** The assertion accepts 401 as well as 403, so the test passes when the entitled caller is rejected during authentication and never reaches the content-create access policy. That does not prove the intended subscribed-but-unroled caller is denied by the repository permission check.

**Triggers:** When authentication rejects the supplied entitled-user identity header or otherwise treats the caller as unauthenticated.

**Suggested fix:** Assert `response.status_code == 403` to enforce that multipart parsing succeeds and the RBAC policy, rather than authentication, performs the denial.
</issue_to_address>

Sourcery assessment

Approval pending. 1 finding to address first.

Blocking findings: pulp_service/pulp_service/tests/functional/test_lightwell_content_listing_permission.py:176


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

The lightwell POST-denial test posted an empty JSON body to a content-create
endpoint that only accepts multipart uploads. That 400s during request parsing,
before RBAC ever runs, so to keep the test green the assertion had to tolerate a
400 alongside 401/403, which muddied what it was actually proving: that a
subscribed-but-unroled caller can't POST content (the subscription grant only
covers safe reads).

Instead of widening the assertion, send a complete, valid upload body: a file, a
relative_path, and the repository the fixture's owner created. The request now
clears multipart parsing and pulpcore's create conditions (which validate the
serializer before deciding authorization) and is denied by the access policy
itself: has_required_repo_perms_on_upload:file.modify_filerepository returns a
clean 403 because the caller holds no role on that repo. The assertion is a
strict 403, so the test fails if the caller is instead rejected during
authentication rather than by the RBAC policy. Verified in the dev container:
the test passes and the denial is specifically a 403.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Bryan ramos <bramos@redhat.com>
@CryptoRodeo
CryptoRodeo force-pushed the fix/update-lightwell-post-test branch from 71c1daa to c7c7f49 Compare September 30, 2026 20:29

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sourcery assessment

Approved.

@CryptoRodeo

Copy link
Copy Markdown
Contributor Author

@dkliban heads up

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant