Re-authors the nine User Tasks permissions as verbs on the user-tasks and user-tasks/participants resources with a descriptor provider, replacing the legacy verb:resource strings (UserTasksPermissions is removed along with the other legacy constant classes). All 17 endpoints declare access through RequirePermission, and UserTaskActor.HasPermission matches through PermissionMatcher instead of string equality, so pattern grants reach these endpoints for the first time. manage:user-tasks becomes user-tasks:supervise to reflect that it grants oversight, not an aggregate. The migration guide and contract specs carry the full mapping. BREAKING CHANGE: legacy user-tasks permission strings no longer authorize anything. Rewrite grants using the mapping table in doc/migrations/authorization-model.md. Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
39 lines
1.6 KiB
C#
39 lines
1.6 KiB
C#
using Elsa.ModularServer.Web;
|
|
using Elsa.Server.Web;
|
|
|
|
namespace Elsa.Hosts.SmokeTests;
|
|
|
|
/// <summary>Elsa.Server.Web, which registers its modules through the classic <c>Features/</c> path.</summary>
|
|
public class ClassicHostSmokeTests(HostFixture<ClassicServerHost> host) : HostSmokeTests<ClassicServerHost>(host)
|
|
{
|
|
/// <inheritdoc />
|
|
protected override IReadOnlyCollection<string> GatedRoutes =>
|
|
[
|
|
"/elsa/api/workflow-definitions",
|
|
"/elsa/api/workflow-instances",
|
|
"/elsa/api/identity/roles",
|
|
"/elsa/api/identity/permissions",
|
|
"/elsa/api/dashboard/overview"
|
|
];
|
|
}
|
|
|
|
/// <summary>Elsa.ModularServer.Web, which registers its modules through the CShells <c>ShellFeatures/</c> path.</summary>
|
|
public class ShellHostSmokeTests(HostFixture<ModularServerHost> host) : HostSmokeTests<ModularServerHost>(host)
|
|
{
|
|
/// <inheritdoc />
|
|
/// <remarks>
|
|
/// The two route sets overlap but are not identical: each lists what its own host actually configures,
|
|
/// and External Authentication and User Tasks are enabled only here. Keeping them separate is the point --
|
|
/// a route that disappears from one host and not the other is the divergence these tests are looking for.
|
|
/// </remarks>
|
|
protected override IReadOnlyCollection<string> GatedRoutes =>
|
|
[
|
|
"/elsa/api/workflow-definitions",
|
|
"/elsa/api/workflow-instances",
|
|
"/elsa/api/identity/permissions",
|
|
"/elsa/api/external-authentication/connections",
|
|
"/elsa/api/external-authentication/descriptors/adapters",
|
|
"/elsa/api/user-tasks"
|
|
];
|
|
}
|