fix: Current permissions -> PAK with no-auth mode #6074
GitHub Actions / Backend Tests
Jan 29, 2024 in 0s
45 passed, 1 failed and 0 skipped
✅ backend/security/build/test-results/test/
3 tests were completed in 136ms with 3 passed, 0 failed and 0 skipped.
Test suite | Passed | Failed | Skipped | Time |
---|---|---|---|---| | 3✅ | 136ms |
✅ it does not filter when request is OPTIONS()
✅ it does not require authentication to go through()
✅ it does not authenticate when authentication is enabled()
❌ backend/security/build/test-results/test/
11 tests were completed in 181ms with 10 passed, 1 failed and 0 skipped.
Test suite | Passed | Failed | Skipped | Time |
---|---|---|---|---| | 10✅ | 1❌ | 181ms |
✅ it does not allow request to go through with invalid JWT tokens()
✅ it does not filter when request is OPTIONS()
✅ it applies a rate limit on authentication attempts()
✅ it allows request to go through when using invalid PAK()
✅ it allows request to go through when using invalid PAT()
✅ it allows request to go through with valid JWT token()
❌ it does not filter when auth is disabled()
org.opentest4j.AssertionFailedError: Unexpected exception thrown: java.lang.NullPointerException: Parameter specified as non-null is null: method io.tolgee.dtos.cacheable.UserAccountDto.<init>, parameter name
✅ it allows request to go through when using expired PAK()
✅ it allows request to go through when using expired PAT()
✅ it allows request to go through when using valid PAK()
✅ it allows request to go through when using valid PAT()
✅ backend/security/build/test-results/test/
3 tests were completed in 111ms with 3 passed, 0 failed and 0 skipped.
Test suite | Passed | Failed | Skipped | Time |
---|---|---|---|---| | 3✅ | 111ms |
✅ it doesn't allow API key authentication by default()
✅ it enforces the super JWT requirement()
✅ it doesn't interfere with basic endpoints()
✅ backend/security/build/test-results/test/
5 tests were completed in 155ms with 5 passed, 0 failed and 0 skipped.
Test suite | Passed | Failed | Skipped | Time |
---|---|---|---|---| | 5✅ | 155ms |
✅ rejects access if the user does not have a sufficiently high role()
✅ it hides the organization if the user cannot see it()
✅ it has no effect on endpoints not specific to a single organization()
✅ it requires an annotation to be present on the handler()
✅ it does not allow both annotations to be present()
✅ backend/security/build/test-results/test/
10 tests were completed in 211ms with 10 passed, 0 failed and 0 skipped.
Test suite | Passed | Failed | Skipped | Time |
---|---|---|---|---| | 10✅ | 211ms |
✅ it hides the organization if the user cannot see it()
✅ permissions work as intended when using implicit project id()
✅ it does not let scopes on the key work if the authenticated user does not have them()
✅ it has no effect on endpoints not specific to a single project()
✅ ensures API key works only for the project it is bound to()
✅ rejects access if the user does not have the required scope (single scope)()
✅ it restricts scopes to the ones set to the API key()
✅ it requires an annotation to be present on the handler()
✅ it does not allow both annotations to be present()
✅ rejects access if the user does not have the required scope (multiple scopes)()
✅ backend/security/build/test-results/test/
3 tests were completed in 12ms with 3 passed, 0 failed and 0 skipped.
Test suite | Passed | Failed | Skipped | Time |
---|---|---|---|---| | 3✅ | 12ms |
✅ it lets requests through()
✅ it does not let rate limited requests through()
✅ it does rate limit if request is OPTIONS()
✅ backend/security/build/test-results/test/
3 tests were completed in 7ms with 3 passed, 0 failed and 0 skipped.
Test suite | Passed | Failed | Skipped | Time |
---|---|---|---|---| | 3✅ | 7ms |
✅ it lets requests through()
✅ it does not let rate limited requests through()
✅ it does rate limit if request is OPTIONS()
✅ backend/security/build/test-results/test/
8 tests were completed in 171ms with 8 passed, 0 failed and 0 skipped.
Test suite | Passed | Failed | Skipped | Time |
---|---|---|---|---| | 8✅ | 171ms |
✅ it rate limits requests according to the specified policy()
✅ endpoint rate limit policy is correctly extracted from annotations()
✅ endpoint rate limit bucket correctly discriminates against major path variables()
✅ endpoint rate limit uses the correct user or ip discrimination method()
✅ it uses different buckets for different paths()
✅ it does not rate limit when limits are disabled()
✅ it does not rate limit when there are no annotations()
✅ it uses the same buckets for paths with a shared bucket()
github-actions / Backend Tests ► it does not filter when auth is disabled()
Failed test found in:
org.opentest4j.AssertionFailedError: Unexpected exception thrown: java.lang.NullPointerException: Parameter specified as non-null is null: method io.tolgee.dtos.cacheable.UserAccountDto.<init>, parameter name
Raw output
org.opentest4j.AssertionFailedError: Unexpected exception thrown: java.lang.NullPointerException: Parameter specified as non-null is null: method io.tolgee.dtos.cacheable.UserAccountDto.<init>, parameter name
at app//
at app//org.junit.jupiter.api.AssertDoesNotThrow.createAssertionFailedError(
at app//org.junit.jupiter.api.AssertDoesNotThrow.assertDoesNotThrow(
at app//org.junit.jupiter.api.AssertDoesNotThrow.assertDoesNotThrow(
at app//org.junit.jupiter.api.Assertions.assertDoesNotThrow(
at app// does not filter when auth is disabled(AuthenticationFilterTest.kt:360)
at [email protected]/jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at [email protected]/jdk.internal.reflect.NativeMethodAccessorImpl.invoke(
at [email protected]/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(
at [email protected]/java.lang.reflect.Method.invoke(
at app//org.junit.platform.commons.util.ReflectionUtils.invokeMethod(
at app//org.junit.jupiter.engine.execution.MethodInvocation.proceed(
at app//org.junit.jupiter.engine.execution.InvocationInterceptorChain$ValidatingInvocation.proceed(
at app//org.junit.jupiter.engine.extension.TimeoutExtension.intercept(
at app//org.junit.jupiter.engine.extension.TimeoutExtension.interceptTestableMethod(
at app//org.junit.jupiter.engine.extension.TimeoutExtension.interceptTestMethod(
at app//org.junit.jupiter.engine.execution.InterceptingExecutableInvoker$ReflectiveInterceptorCall.lambda$ofVoidMethod$0(
at app//org.junit.jupiter.engine.execution.InterceptingExecutableInvoker.lambda$invoke$0(
at app//org.junit.jupiter.engine.execution.InvocationInterceptorChain$InterceptedInvocation.proceed(
at app//org.junit.jupiter.engine.execution.InvocationInterceptorChain.proceed(
at app//org.junit.jupiter.engine.execution.InvocationInterceptorChain.chainAndInvoke(
at app//org.junit.jupiter.engine.execution.InvocationInterceptorChain.invoke(
at app//org.junit.jupiter.engine.execution.InterceptingExecutableInvoker.invoke(
at app//org.junit.jupiter.engine.execution.InterceptingExecutableInvoker.invoke(
at app//org.junit.jupiter.engine.descriptor.TestMethodTestDescriptor.lambda$invokeTestMethod$7(
at app//
at app//org.junit.jupiter.engine.descriptor.TestMethodTestDescriptor.invokeTestMethod(
at app//org.junit.jupiter.engine.descriptor.TestMethodTestDescriptor.execute(
at app//org.junit.jupiter.engine.descriptor.TestMethodTestDescriptor.execute(
at app//$executeRecursively$6(
at app//
at app//$executeRecursively$8(
at app//
at app//$executeRecursively$9(
at app//
at app//
at app//
at [email protected]/java.util.ArrayList.forEach(
at app//
at app//$executeRecursively$6(
at app//
at app//$executeRecursively$8(
at app//
at app//$executeRecursively$9(
at app//
at app//
at app//
at [email protected]/java.util.ArrayList.forEach(
at app//
at app//$executeRecursively$6(
at app//
at app//$executeRecursively$8(
at app//
at app//$executeRecursively$9(
at app//
at app//
at app//
at app//
at app//
at app//
at app//org.junit.platform.launcher.core.EngineExecutionOrchestrator.execute(
at app//org.junit.platform.launcher.core.EngineExecutionOrchestrator.execute(
at app//org.junit.platform.launcher.core.EngineExecutionOrchestrator.lambda$execute$0(
at app//org.junit.platform.launcher.core.EngineExecutionOrchestrator.withInterceptedStreams(
at app//org.junit.platform.launcher.core.EngineExecutionOrchestrator.execute(
at app//org.junit.platform.launcher.core.DefaultLauncher.execute(
at app//org.junit.platform.launcher.core.DefaultLauncher.execute(
at app//org.junit.platform.launcher.core.DefaultLauncherSession$DelegatingLauncher.execute(
at org.gradle.api.internal.tasks.testing.junitplatform.JUnitPlatformTestClassProcessor$CollectAllTestClassesExecutor.processAllTestClasses(
at org.gradle.api.internal.tasks.testing.junitplatform.JUnitPlatformTestClassProcessor$CollectAllTestClassesExecutor.access$000(
at org.gradle.api.internal.tasks.testing.junitplatform.JUnitPlatformTestClassProcessor.stop(
at org.gradle.api.internal.tasks.testing.SuiteTestClassProcessor.stop(
at [email protected]/jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at [email protected]/jdk.internal.reflect.NativeMethodAccessorImpl.invoke(
at [email protected]/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(
at [email protected]/java.lang.reflect.Method.invoke(
at org.gradle.internal.dispatch.ReflectionDispatch.dispatch(
at org.gradle.internal.dispatch.ReflectionDispatch.dispatch(
at org.gradle.internal.dispatch.ContextClassLoaderDispatch.dispatch(
at org.gradle.internal.dispatch.ProxyDispatchAdapter$DispatchingInvocationHandler.invoke(
at jdk.proxy1/jdk.proxy1.$Proxy2.stop(Unknown Source)
at org.gradle.api.internal.tasks.testing.worker.TestWorker$
at org.gradle.api.internal.tasks.testing.worker.TestWorker.executeAndMaintainThreadName(
at org.gradle.api.internal.tasks.testing.worker.TestWorker.execute(
at org.gradle.api.internal.tasks.testing.worker.TestWorker.execute(
at org.gradle.process.internal.worker.child.ActionExecutionWorker.execute(
at app//
at app//
Caused by: java.lang.NullPointerException: Parameter specified as non-null is null: method io.tolgee.dtos.cacheable.UserAccountDto.<init>, parameter name
at io.tolgee.dtos.cacheable.UserAccountDto.<init>(UserAccountDto.kt)
at io.tolgee.dtos.cacheable.UserAccountDto$Companion.fromEntity(UserAccountDto.kt:19)
at kotlin.SynchronizedLazyImpl.getValue(LazyJVM.kt:74)
at org.mockito.internal.stubbing.StubbedInvocationMatcher.answer(
at org.mockito.internal.handler.MockHandlerImpl.handle(
at org.mockito.internal.handler.NullResultGuardian.handle(
at org.mockito.internal.handler.InvocationNotifierHandler.handle(
at org.mockito.internal.creation.bytebuddy.MockMethodInterceptor.doIntercept(
at org.mockito.internal.creation.bytebuddy.MockMethodAdvice.handle(
at org.springframework.web.filter.OncePerRequestFilter.doFilter(
at does not filter when auth is disabled(AuthenticationFilterTest.kt:183)
... 84 more