elsa-core/test/unit/Elsa.Identity.UnitTests/Services
Sipke Schoorstra 723bdc0004
fix(identity): route the remaining permission checks through the evaluator (#8001)
* fix(identity): route the remaining permission checks through the evaluator

Completes T038 of the authorization model, and fixes a live defect it was
meant to catch.

RoleDeletionCoordinator.InspectAsync gated on the legacy string "delete:role",
compared by claim-value equality. Nothing has granted that spelling since the
vocabulary migration, so a caller holding identity/roles:delete passed the
endpoint's own RequirePermission check and was then refused mid-handler by the
coordinator. In practice role deletion worked only for holders of "*", across
all three routes that reach the coordinator (Delete, RemediateAndDelete and
GetDeletionImpact). The check now evaluates identity/roles:delete through
PermissionEvaluator, so structured and wildcard grants both reach it.

Every existing coordinator test acted as an administrator holding "*", which is
why this went unnoticed; the added cases exercise identity/roles:delete,
identity/*:delete and identity/roles:* and assert an unrelated grant is still
refused.

AIHttpContextIdentity matched an agent's required permissions by
case-insensitive exact-set containment, which both admitted casing the rest of
the model rejects and refused the wildcards it honours. It now evaluates each
required permission through the same evaluator.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(ai): restore the null-safe HttpContext access in the tools endpoint

The tools endpoint dereferenced HttpContext directly when passing the principal
to GetAuthorizedAgent, which threw a NullReferenceException and failed two
Elsa.AI.IntegrationTests cases on CI.

This was collateral from tightening a nullable warning in the chat endpoint. The
chat endpoint dereferences HttpContext.Response unconditionally a few lines
later, so HttpContext.User is safe there; the tools endpoint never does, and its
three sibling calls -- GetPermissions, GetActorId and GetTenantId -- all accept
a null context. The same edit was applied to both, and only chat could take it.

Reverting to HttpContext?.User preserves the endpoint's prior behaviour:
GetAuthorizedAgent treats a null principal as holding nothing, and an agent that
declares no required permissions stays authorized either way, because the
empty-requirements check runs before the null check.

Elsa.AI.IntegrationTests 69/69 (was 67 passed, 2 failed); Elsa.Identity.UnitTests
115/115; Elsa.AI.Host builds with no CS8602.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-28 22:03:15 +02:00
..
CredentiallessUserTests.cs Add external authentication broker 2026-07-24 19:04:26 +02:00
DefaultAccessTokenIssuerRegistrationTests.cs Fix external authentication review findings 2026-08-02 03:35:39 +02:00
DefaultApiKeyGeneratorAndParserTests.cs Refine identity secret hashing review fixes 2026-05-21 01:45:17 +02:00
DefaultElsaTokenServiceTests.cs Preserve Elsa permissions during external sign-in 2026-07-26 00:27:54 +02:00
DefaultIdentityRefreshTokenServiceTests.cs Fix local external authentication refresh 2026-07-26 01:49:36 +02:00
DefaultRandomStringGeneratorTests.cs Clear temporary secret hashing buffers 2026-05-21 01:16:12 +02:00
DefaultSecretHasherTests.cs feat(auth)!: structured authorization model, phases 1-6 (#7980) 2026-08-24 23:44:55 +02:00
PermissionStampValidatorTests.cs feat(auth)!: structured authorization model, phases 1-6 (#7980) 2026-08-24 23:44:55 +02:00
RoleAuthorizationServiceTests.cs feat(auth)!: structured authorization model, phases 1-6 (#7980) 2026-08-24 23:44:55 +02:00
RoleDeletionCoordinatorTests.cs fix(identity): route the remaining permission checks through the evaluator (#8001) 2026-08-28 22:03:15 +02:00
RoleManagerTests.cs feat(auth)!: structured authorization model, phases 1-6 (#7980) 2026-08-24 23:44:55 +02:00
SecretHasherDefaultOverloadTests.cs Address identity review feedback 2026-05-21 02:03:06 +02:00
UserDeletionCoordinatorTests.cs Harden external identity race compensation 2026-08-02 23:19:49 +02:00