elsa-core/test/integration/Elsa.Hosts.SmokeTests/ClassicHostSmokeTests.cs
Sipke Schoorstra 292e4bd3ea
feat(user-tasks)!: migrate endpoints to structured permissions (#7999)
Re-authors the nine User Tasks permissions as verbs on the user-tasks and
user-tasks/participants resources with a descriptor provider, replacing the
legacy verb:resource strings (UserTasksPermissions is removed along with the
other legacy constant classes). All 17 endpoints declare access through
RequirePermission, and UserTaskActor.HasPermission matches through
PermissionMatcher instead of string equality, so pattern grants reach these
endpoints for the first time. manage:user-tasks becomes user-tasks:supervise
to reflect that it grants oversight, not an aggregate. The migration guide
and contract specs carry the full mapping.

BREAKING CHANGE: legacy user-tasks permission strings no longer authorize
anything. Rewrite grants using the mapping table in
doc/migrations/authorization-model.md.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-27 12:06:52 +02:00

39 lines
1.6 KiB
C#

using Elsa.ModularServer.Web;
using Elsa.Server.Web;
namespace Elsa.Hosts.SmokeTests;
/// <summary>Elsa.Server.Web, which registers its modules through the classic <c>Features/</c> path.</summary>
public class ClassicHostSmokeTests(HostFixture<ClassicServerHost> host) : HostSmokeTests<ClassicServerHost>(host)
{
/// <inheritdoc />
protected override IReadOnlyCollection<string> GatedRoutes =>
[
"/elsa/api/workflow-definitions",
"/elsa/api/workflow-instances",
"/elsa/api/identity/roles",
"/elsa/api/identity/permissions",
"/elsa/api/dashboard/overview"
];
}
/// <summary>Elsa.ModularServer.Web, which registers its modules through the CShells <c>ShellFeatures/</c> path.</summary>
public class ShellHostSmokeTests(HostFixture<ModularServerHost> host) : HostSmokeTests<ModularServerHost>(host)
{
/// <inheritdoc />
/// <remarks>
/// The two route sets overlap but are not identical: each lists what its own host actually configures,
/// and External Authentication and User Tasks are enabled only here. Keeping them separate is the point --
/// a route that disappears from one host and not the other is the divergence these tests are looking for.
/// </remarks>
protected override IReadOnlyCollection<string> GatedRoutes =>
[
"/elsa/api/workflow-definitions",
"/elsa/api/workflow-instances",
"/elsa/api/identity/permissions",
"/elsa/api/external-authentication/connections",
"/elsa/api/external-authentication/descriptors/adapters",
"/elsa/api/user-tasks"
];
}